Dashboard
PHP:
7.4.33
OS:
Linux
User:
sortthru
/
/
usr
/
local
/
apache
📤 Upload
📝 New File
📁 New Folder
Close
Editing: error_log
[Sat Aug 29 05:05:05.482813 2026] [lsapi:notice] [pid 935608:tid 935608] mod_lsapi: version 1.1-92 [Sat Aug 29 05:05:05.495618 2026] [:notice] [pid 1017433:tid 1017433] [host root@host2038.hostmonster.com] mod_lsapi: Selfstarter 1017433 started [Sat Aug 29 05:05:05.532227 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: hybridlynx.alphaprocure.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.545666 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: alphaprocure.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.546799 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: winegoddess.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.588405 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: theadvocatesorg.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.597200 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: mail.bhindi.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.597911 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: bhindi.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.653795 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: ccinva.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.658586 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: softcomsolution.rushpcb.com.pk:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.663627 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: ehfields.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.666904 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: argusproduction.centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.692849 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: ericamontgomeryphotography.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.695158 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: luminousvertex.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.701148 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: powerofcoins.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.708748 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: webmail.jarrelljohnson.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.715571 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: anthonyeverettdevelopment.anthonyeverettrealestate.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.739856 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: garrettzander.zanderenterprises.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.745151 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: productosdeortodoncia1.xbdorthodontics.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.753997 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: imagesalonus.webonlineincome.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.754675 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: imageartisticsalon.webonlineincome.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.789848 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: tpsnj.vincenzosilvano.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.790770 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: gavirestaurant.vincenzosilvano.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.791684 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: vincenzosilvano.vincenzosilvano.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.792563 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: website-f892ec95.vincenzosilvano.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.793320 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: nutritionclinicny.vincenzosilvano.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.794372 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: digitalsolutionservice.vincenzosilvano.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.797972 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: eeorep.training-center.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.798756 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: eeorepresentative.training-center.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.815226 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: ppptampa.thesign8studio.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.815993 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: carlosmua.thesign8studio.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.816692 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: davaoestates.thesign8studio.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.817505 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: patthegutterrat.thesign8studio.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.818222 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: davaocityestates.thesign8studio.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.819006 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: mizpah-ministries.thesign8studio.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:05.834170 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: termoenvases-do.termoenvases.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.046274 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: debbieandgraham.strangeworx.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.142722 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: cityinnsuites.saurabiacontractors.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.143641 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: amialalkhaleej.saurabiacontractors.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.147473 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: fox-mart.rushpcb.com.pk:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.148334 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: lapoutine-co-uk.rushpcb.com.pk:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.149382 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: pcbcompany-co-uk.rushpcb.com.pk:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.150254 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: eurolecltd-co-uk.rushpcb.com.pk:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.151129 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: grab-a-bite-co-uk.rushpcb.com.pk:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.152086 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: misselliesltd-co-uk.rushpcb.com.pk:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.152955 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: morethanjustsubs-co-uk.rushpcb.com.pk:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.166041 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: spiritofamericatour.rosenthalfoundation.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.205804 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: efremdryer.beraluz.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.206749 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: beraluz-org.beraluz.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.208444 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: beraluzgroup.beraluz.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.223005 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: xyzece.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.223791 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: capturephoto.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.224632 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: capturedgems.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.225329 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: printingbyjoe.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.226061 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: capturedart-net.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.226990 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: photosbykara-net.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.227710 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: mcdcomputers-net.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.228489 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: dienbergprinting.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.229200 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: simplybelladesign.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.229983 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: capturedancephoto-net.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.230728 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: capturedance-photography.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.231502 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: marykarpusfosterscholarship.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.232278 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: capturedancephotography-net.protypegraphics.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.245152 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: portiktravel.portiktours.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.308030 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: diagecu.obdtoolz.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.308740 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: obd2toolz.obdtoolz.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.309628 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: diagecu2021.obdtoolz.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.324834 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: realguineapigvideos.netgurunews.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.370766 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: midaytax.millionairebuildersclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.371462 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: midayins.millionairebuildersclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.376586 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: lumbeesolar.millionairebuildersclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.377992 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: buymyinfo-biz.millionairebuildersclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.380344 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: midayinsurance.millionairebuildersclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.382129 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: lumbeesolar-org.millionairebuildersclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.387234 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: lumbeeriversolar.millionairebuildersclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.388019 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: clickforinfo-biz.millionairebuildersclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.402520 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: methmobalarms.methmob.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.403229 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: allianceinvestmentsllc.methmob.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.441716 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: burtonpixels.luminousvertex.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.442605 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: burtondigital.luminousvertex.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.443373 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: considerthefuture.luminousvertex.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.447257 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: workbase-site.lsihop.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.448314 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: eastendhardware.lsihop.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.449421 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: blackolivedesign.lsihop.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.451274 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: eastend-equipment.lsihop.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.474973 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: remote.lockstockbarrel.com.au:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.518264 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: yamikin-portal.lifes-finance.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.566975 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: simijohn.jaysonjohn.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.570505 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: glamrus-rocks.hairaokerocks.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.571206 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: website-ec1e123c.hairaokerocks.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.579830 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: jhalb.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.580792 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: homsips.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.581693 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: blitz-ad.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.582695 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: snackgaro.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.583614 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: maanandjana.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.584536 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: jha-digital.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.585524 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: hoodride-lb.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.586495 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: delements-me.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.587475 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: firascoequipment.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.588429 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: haddadenterprises.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.589436 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: brotherscustomshop.iosephos.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.605744 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: tk3-mx.inetsystem.com.mx:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.607964 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: fivecorp-mx.inetsystem.com.mx:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.612158 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: website-4743079c.inetsystem.com.mx:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.613003 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: website-10d7448c.inetsystem.com.mx:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.629247 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: codyshilohbrown.hearod.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.749417 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: form8.formlabsnyc.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.750206 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: iempsg.formlabsnyc.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.758285 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: egelmail3.excellentpublicity.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.759038 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: excellentbasket1.excellentpublicity.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.759894 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: sonylivadvertising.excellentpublicity.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.760586 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: hotstaradvertising.excellentpublicity.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.761292 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: excellentpublicity1.excellentpublicity.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.761992 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: excellentpublicitycompany.excellentpublicity.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.762763 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: excellentpublicitymail-co-in.excellentpublicity.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.764146 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: excellentpublicityemail-co-in.excellentpublicity.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.764877 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: malibuvetclinic.evelienphotography.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.765749 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: rentevate.etherealpartners.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.766637 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: rinuenergy.etherealpartners.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.767644 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: vate-agency.etherealpartners.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.768622 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: vatecreative.etherealpartners.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.769532 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: nathanslafter-info.etherealpartners.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.770324 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: elevatebarcatering.etherealpartners.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.772149 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: secondwives-org.encoreboutiquenightclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.773032 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: philadelphialawworks-org.encoreboutiquenightclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.785472 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: fields.ehfields.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.786346 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: tiaandephraim.ehfields.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.787191 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: fieldsstudios.ehfields.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.801200 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: alqilaaturizm.duviatourism.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.858818 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: optimus-freight.com.ztxcloud.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.894111 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: smartamericangrowth.davidseaver.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.896314 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: tesla-referral-tesla.davidseaver.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.944414 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: twrebar.cortneywalker.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.945266 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: wishbone-city.cortneywalker.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:06.946196 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: triplewdetailing.cortneywalker.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.006131 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: yustorres.centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.007010 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: towerbomb.centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.007876 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: sipandbites.centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.009130 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: manilameals.centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.010113 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: tonetbombase.centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.011001 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: adcore-advertising.centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.011936 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: lejardinrosellatagaytay.centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.049445 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: cijeep.blaketaylorconsulting.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.051327 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: julienorthern.blaketaylorconsulting.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.052231 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: homevieweronline.blaketaylorconsulting.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.069092 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: ocprop-org.asymmetricstudios.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.069824 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: jordan-d-us.asymmetricstudios.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.175632 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: sris.irisphotocontest.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.176417 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: ukiahgardenclub.irisphotocontest.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.177118 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: website-8468b543.irisphotocontest.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.190308 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: remote.theenprogroup.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.268689 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: zanderenterprises.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.365319 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: wirearte.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.402633 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: vincenzosilvano.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.461070 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: twlcpa.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.462587 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: raithelcattle.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.501118 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: thefanon.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.532254 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: stellarstaffingca.info:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.557415 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: skycoating.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.564800 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: shopatburlington.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.568588 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: sevenstarmantis.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.572375 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: sdul.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.578363 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: scottaronow.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.608504 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: ronsseptic.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.615026 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: rm64.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.863539 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: mamiawamura.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.864270 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: malibuhotel.com.mx:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.865033 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: themainepointacupuncture.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.881263 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: lockstockbarrel.com.au:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.887602 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: liznichols.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.888435 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: lizgoodwintherapy.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.890867 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: linear-active.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.892565 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: lilypad-online.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.936229 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: kriveloff-associates.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.958187 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: kcactf4.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.960636 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: karinehnyc.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.993227 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: hairaokerocks.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.994829 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: jaimiegellerjewelry.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:07.995711 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: jacintoastiazaran.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.004271 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: it-computes.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.017954 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: inetsystem.com.mx:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.045224 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: hyannisportclub.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.058365 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: hrtgatlanta.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.087123 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: harnessre.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.103530 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: greenokie.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.132392 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: giantsfans.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.197203 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: fernandinafol.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.305261 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: davidluning.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.332496 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: cortneywalker.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.346269 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: cloverleafsystems.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.360975 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: cgarnerphoto.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.365633 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: centerfornewcinema.net:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.373623 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: cambridgeclassical.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.378589 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: burodesign.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.386912 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: bridgewaycrc.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.391562 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: boydscleaning.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.394704 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: boldfacemarketing.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.415578 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: battlecreekhunt.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.430615 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: attorneylang.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.443184 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: angelicoviolins.com:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.455626 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: irisphotocontest.org:443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.478768 2026] [ssl:warn] [pid 935608:tid 935608] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name [Sat Aug 29 05:05:08.514118 2026] [qos:notice] [pid 935608:tid 935608] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients) [Sat Aug 29 05:05:09.084402 2026] [http2:info] [pid 935608:tid 935608] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing... [Sat Aug 29 05:05:09.098830 2026] [mpm_event:notice] [pid 935608:tid 935608] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations [Sat Aug 29 05:05:09.098843 2026] [core:notice] [pid 935608:tid 935608] AH00094: Command line: '/usr/sbin/httpd' [Sat Aug 29 05:05:10.215137 2026] [http2:info] [pid 1017536:tid 1017536] h2_workers: created with min=128 max=192 idle_ms=600000 [Sat Aug 29 05:05:10.249687 2026] [security2:error] [pid 1017536:tid 1017677] [client 20.104.18.15:46997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/indo.php"] [unique_id "apK85iJcY4fy7tP-rU3ZHwAAAh8"] [Sat Aug 29 05:05:10.250081 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:13192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK85iJcY4fy7tP-rU3ZIQAAAh0"] [Sat Aug 29 05:05:10.250606 2026] [security2:error] [pid 1017536:tid 1017666] [client 4.205.62.107:61841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/test.php"] [unique_id "apK85iJcY4fy7tP-rU3ZHAAAAhQ"] [Sat Aug 29 05:05:10.250681 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.48.250.41:49817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/wp-blogs.php"] [unique_id "apK85iJcY4fy7tP-rU3ZGwAAAhY"] [Sat Aug 29 05:05:10.251649 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.18.15:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/82.php"] [unique_id "apK85iJcY4fy7tP-rU3ZIwAAAiU"] [Sat Aug 29 05:05:10.253122 2026] [security2:error] [pid 1017536:tid 1017746] [client 93.123.109.228:50748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.edwardjindovina.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK85iJcY4fy7tP-rU3ZJAAAAmQ"] [Sat Aug 29 05:05:10.254840 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.18.15:23503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ap.php"] [unique_id "apK85iJcY4fy7tP-rU3ZJwAAAis"] [Sat Aug 29 05:05:10.255669 2026] [security2:error] [pid 1017536:tid 1017773] [client 4.205.62.107:22507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/xp.php"] [unique_id "apK85iJcY4fy7tP-rU3ZKAAAAn8"] [Sat Aug 29 05:05:10.258575 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.160.90:45874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/Q3.php"] [unique_id "apK85iJcY4fy7tP-rU3ZKgAAAjQ"] [Sat Aug 29 05:05:10.260797 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.48.250.41:64204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/06.php"] [unique_id "apK85iJcY4fy7tP-rU3ZLgAAAjY"] [Sat Aug 29 05:05:10.264530 2026] [security2:error] [pid 1017536:tid 1017711] [client 68.155.159.216:40325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK85iJcY4fy7tP-rU3ZMQAAAkE"] [Sat Aug 29 05:05:10.266164 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.250.41:12368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/h2a2ck.php"] [unique_id "apK85iJcY4fy7tP-rU3ZMgAAAkA"] [Sat Aug 29 05:05:10.268049 2026] [security2:error] [pid 1017536:tid 1017717] [client 168.107.94.195:55747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK85iJcY4fy7tP-rU3ZNQAAAkc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:10.269119 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.49.130:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/ohct.php"] [unique_id "apK85iJcY4fy7tP-rU3ZNgAAAkY"] [Sat Aug 29 05:05:10.269308 2026] [security2:error] [pid 1017536:tid 1017720] [client 68.155.159.216:16235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/images/index.php"] [unique_id "apK85iJcY4fy7tP-rU3ZNwAAAko"] [Sat Aug 29 05:05:10.272955 2026] [security2:error] [pid 1017536:tid 1017723] [client 93.123.109.228:50756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.edwardjindovina.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK85iJcY4fy7tP-rU3ZOAAAAk0"] [Sat Aug 29 05:05:10.273632 2026] [security2:error] [pid 1017536:tid 1017726] [client 93.123.109.228:50752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.edwardjindovina.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK85iJcY4fy7tP-rU3ZOQAAAlA"] [Sat Aug 29 05:05:10.273802 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.104.49.130:53684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/well.php"] [unique_id "apK85iJcY4fy7tP-rU3ZOgAAAlM"] [Sat Aug 29 05:05:10.275208 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.23.147.79:23470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK85iJcY4fy7tP-rU3ZOwAAAlY"] [Sat Aug 29 05:05:10.276166 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.104.62:13648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/ahy66.php"] [unique_id "apK85iJcY4fy7tP-rU3ZPAAAAlY"] [Sat Aug 29 05:05:10.282062 2026] [security2:error] [pid 1017536:tid 1017742] [client 93.123.109.228:50806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.edwardjindovina.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK85iJcY4fy7tP-rU3ZQQAAAmA"] [Sat Aug 29 05:05:10.282831 2026] [security2:error] [pid 1017536:tid 1017742] [client 114.119.159.226:60083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_info.php/products_id/1133/action/notify/osCsid/5a931bdbc52488e3634cc6521c7fe050"] [unique_id "apK85iJcY4fy7tP-rU3ZQgAAAmA"], referer: http://www.classiclightingusa.com/catalog/product_info.php/products_id/1133/osCsid/5a931bdbc52488e3634cc6521c7fe050 [Sat Aug 29 05:05:10.282831 2026] [security2:error] [pid 1017536:tid 1017740] [client 93.123.109.228:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.edwardjindovina.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK85iJcY4fy7tP-rU3ZQAAAAl4"] [Sat Aug 29 05:05:10.285278 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.49.130:51345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/load.php"] [unique_id "apK85iJcY4fy7tP-rU3ZRAAAAmE"] [Sat Aug 29 05:05:10.288295 2026] [security2:error] [pid 1017536:tid 1017750] [client 93.123.109.228:50822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.edwardjindovina.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK85iJcY4fy7tP-rU3ZRQAAAmg"] [Sat Aug 29 05:05:10.289296 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.104.62:48493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK85iJcY4fy7tP-rU3ZRwAAAmg"] [Sat Aug 29 05:05:10.289932 2026] [security2:error] [pid 1017536:tid 1017752] [client 93.123.109.228:50854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.edwardjindovina.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK85iJcY4fy7tP-rU3ZRgAAAmo"] [Sat Aug 29 05:05:10.291639 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.104.62:14383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/Contrller.php"] [unique_id "apK85iJcY4fy7tP-rU3ZSgAAAmg"] [Sat Aug 29 05:05:10.292398 2026] [security2:error] [pid 1017536:tid 1017756] [client 158.23.147.79:24476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/lv.php"] [unique_id "apK85iJcY4fy7tP-rU3ZSwAAAm4"] [Sat Aug 29 05:05:10.293601 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.104.49.130:57672] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/1.php"] [unique_id "apK85iJcY4fy7tP-rU3ZTAAAAm4"] [Sat Aug 29 05:05:10.293663 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.104.49.130:57672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/1.php"] [unique_id "apK85iJcY4fy7tP-rU3ZTAAAAm4"] [Sat Aug 29 05:05:10.295177 2026] [security2:error] [pid 1017536:tid 1017756] [client 195.178.110.247:10794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ladiesandbabies.com"] [uri "/index.php"] [unique_id "apK85iJcY4fy7tP-rU3ZTgAAAm4"] [Sat Aug 29 05:05:10.295187 2026] [security2:error] [pid 1017536:tid 1017762] [client 68.155.159.216:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/login.php"] [unique_id "apK85iJcY4fy7tP-rU3ZTQAAAnQ"] [Sat Aug 29 05:05:10.295933 2026] [security2:error] [pid 1017536:tid 1017764] [client 158.23.147.79:58933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK85iJcY4fy7tP-rU3ZTwAAAnY"] [Sat Aug 29 05:05:10.299678 2026] [security2:error] [pid 1017536:tid 1017770] [client 4.205.62.107:57766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/services.php"] [unique_id "apK85iJcY4fy7tP-rU3ZUgAAAnw"] [Sat Aug 29 05:05:10.300614 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.48.251.3:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws_config.php"] [unique_id "apK85iJcY4fy7tP-rU3ZUwAAAi8"] [Sat Aug 29 05:05:10.300978 2026] [security2:error] [pid 1017536:tid 1017775] [client 68.155.159.216:58363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/cgi-bin/index.php"] [unique_id "apK85iJcY4fy7tP-rU3ZVQAAAoE"] [Sat Aug 29 05:05:10.301940 2026] [security2:error] [pid 1017536:tid 1017777] [client 4.205.62.107:53385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/fff.php"] [unique_id "apK85iJcY4fy7tP-rU3ZVwAAAoM"] [Sat Aug 29 05:05:10.303323 2026] [security2:error] [pid 1017536:tid 1017779] [client 68.155.159.216:50249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK85iJcY4fy7tP-rU3ZWAAAAoU"] [Sat Aug 29 05:05:10.303788 2026] [security2:error] [pid 1017536:tid 1017781] [client 68.155.159.216:51246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK85iJcY4fy7tP-rU3ZWQAAAoc"] [Sat Aug 29 05:05:10.304959 2026] [security2:error] [pid 1017536:tid 1017783] [client 4.205.62.107:22319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/xa.php"] [unique_id "apK85iJcY4fy7tP-rU3ZWgAAAok"] [Sat Aug 29 05:05:10.306305 2026] [security2:error] [pid 1017536:tid 1017785] [client 68.155.159.216:51400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK85iJcY4fy7tP-rU3ZWwAAAos"] [Sat Aug 29 05:05:10.307650 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.104.49.130:57695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/berlin.php"] [unique_id "apK85iJcY4fy7tP-rU3ZXAAAAo0"] [Sat Aug 29 05:05:10.309042 2026] [security2:error] [pid 1017536:tid 1017789] [client 68.155.159.216:18342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/wp-l0gin.php"] [unique_id "apK85iJcY4fy7tP-rU3ZXQAAAo8"] [Sat Aug 29 05:05:10.309593 2026] [security2:error] [pid 1017536:tid 1017791] [client 4.205.62.107:2892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/kedi.php"] [unique_id "apK85iJcY4fy7tP-rU3ZXgAAApE"] [Sat Aug 29 05:05:10.310917 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.23.147.79:30710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK85iJcY4fy7tP-rU3ZXwAAApM"] [Sat Aug 29 05:05:10.311147 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.18.15:7125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK85iJcY4fy7tP-rU3ZYAAAAhc"] [Sat Aug 29 05:05:10.311972 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.104.49.130:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/dragonshell.php"] [unique_id "apK85iJcY4fy7tP-rU3ZYQAAAhU"] [Sat Aug 29 05:05:10.313609 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.147.79:50143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK85iJcY4fy7tP-rU3ZYwAAAh0"] [Sat Aug 29 05:05:10.317500 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.250.41:19393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liatbehr.com"] [uri "/0byte.php"] [unique_id "apK85iJcY4fy7tP-rU3ZaAAAAjQ"] [Sat Aug 29 05:05:10.318839 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.250.41:58533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/ww.php"] [unique_id "apK85iJcY4fy7tP-rU3ZawAAAjo"] [Sat Aug 29 05:05:10.319593 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.23.147.79:63816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/radio.php"] [unique_id "apK85iJcY4fy7tP-rU3ZbAAAAkE"] [Sat Aug 29 05:05:10.319805 2026] [security2:error] [pid 1017536:tid 1017714] [client 68.155.159.216:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/file5.php"] [unique_id "apK85iJcY4fy7tP-rU3ZbgAAAkQ"] [Sat Aug 29 05:05:10.321855 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.160.90:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK85iJcY4fy7tP-rU3ZcAAAAkA"] [Sat Aug 29 05:05:10.322743 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.49.130:53839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.scubaetcfl.com"] [uri "/wp-good.php"] [unique_id "apK85iJcY4fy7tP-rU3ZcQAAAkY"] [Sat Aug 29 05:05:10.323094 2026] [security2:error] [pid 1017536:tid 1017720] [client 158.23.147.79:48349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abmacgroupcom.ab-mac.com"] [uri "/first.php"] [unique_id "apK85iJcY4fy7tP-rU3ZcgAAAko"] [Sat Aug 29 05:05:10.323864 2026] [security2:error] [pid 1017536:tid 1017722] [client 145.239.10.137:51300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "knowledgeofwater.com"] [uri "/ultra.php"] [unique_id "apK85iJcY4fy7tP-rU3ZcwAAAkw"], referer: http://knowledgeofwater.com/ultra.php [Sat Aug 29 05:05:10.324133 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.104.104.62:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/msy.php"] [unique_id "apK85iJcY4fy7tP-rU3ZdAAAAlA"] [Sat Aug 29 05:05:10.325937 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.104.62:20651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/koe.php"] [unique_id "apK85iJcY4fy7tP-rU3ZdgAAAlY"] [Sat Aug 29 05:05:10.328265 2026] [security2:error] [pid 1017536:tid 1017744] [client 93.123.109.228:50838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.edwardjindovina.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK85iJcY4fy7tP-rU3ZeAAAAmI"] [Sat Aug 29 05:05:10.328890 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.104.62:44589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK85iJcY4fy7tP-rU3ZfAAAAmg"] [Sat Aug 29 05:05:10.332448 2026] [security2:error] [pid 1017536:tid 1017768] [client 74.7.228.11:33642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ministeriosemanuel.org"] [uri "/robots.txt"] [unique_id "apK85iJcY4fy7tP-rU3ZgAAAAno"] [Sat Aug 29 05:05:10.333263 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.250.41:23501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK85iJcY4fy7tP-rU3ZggAAAnk"] [Sat Aug 29 05:05:10.334596 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.104.49.130:43029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/wpxml.php"] [unique_id "apK85iJcY4fy7tP-rU3ZgwAAAnw"] [Sat Aug 29 05:05:10.343599 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.104.49.130:36040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/jp.php"] [unique_id "apK85iJcY4fy7tP-rU3ZigAAAjo"] [Sat Aug 29 05:05:10.343914 2026] [security2:error] [pid 1017536:tid 1017715] [client 52.139.37.240:65308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/about.php7"] [unique_id "apK85iJcY4fy7tP-rU3ZhQAAAkU"] [Sat Aug 29 05:05:10.377345 2026] [core:error] [pid 1017536:tid 1017738] [client 57.141.14.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:10.377373 2026] [core:error] [pid 1017536:tid 1017738] [client 57.141.14.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:10.381978 2026] [autoindex:error] [pid 1017536:tid 1017686] [client 136.108.73.139:34350] AH01276: Cannot serve directory /home3/fdrjvmmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:10.398897 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.63.219.114:9359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/disagraeed.php"] [unique_id "apK85iJcY4fy7tP-rU3ZnAAAAkI"] [Sat Aug 29 05:05:10.400958 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.250.41:49917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/mini.php"] [unique_id "apK85iJcY4fy7tP-rU3ZnwAAAkI"] [Sat Aug 29 05:05:10.401452 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.160.90:45947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/Q1.php"] [unique_id "apK85iJcY4fy7tP-rU3ZoAAAAmY"] [Sat Aug 29 05:05:10.401480 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.48.250.41:62277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/class.php"] [unique_id "apK85iJcY4fy7tP-rU3ZoQAAAm4"] [Sat Aug 29 05:05:10.403023 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.250.41:12335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/error_log.php"] [unique_id "apK85iJcY4fy7tP-rU3ZogAAAkI"] [Sat Aug 29 05:05:10.404651 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.18.15:23449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/media.php"] [unique_id "apK85iJcY4fy7tP-rU3ZowAAAkI"] [Sat Aug 29 05:05:10.413558 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.203.141.11:29722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/f.php"] [unique_id "apK85iJcY4fy7tP-rU3ZpwAAAjA"] [Sat Aug 29 05:05:10.414048 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.104.18.15:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK85iJcY4fy7tP-rU3ZqAAAAnI"] [Sat Aug 29 05:05:10.424888 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.196.209.81:4833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK85iJcY4fy7tP-rU3ZqwAAAic"] [Sat Aug 29 05:05:10.426888 2026] [security2:error] [pid 1017536:tid 1017685] [client 68.155.159.216:24545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK85iJcY4fy7tP-rU3ZrAAAAic"] [Sat Aug 29 05:05:10.428662 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.18.15:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/dex.php"] [unique_id "apK85iJcY4fy7tP-rU3ZrQAAAic"] [Sat Aug 29 05:05:10.431407 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.104.62:13609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/gaje.php"] [unique_id "apK85iJcY4fy7tP-rU3ZrgAAApM"] [Sat Aug 29 05:05:10.435057 2026] [security2:error] [pid 1017536:tid 1017706] [client 65.111.10.219:27679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK85iJcY4fy7tP-rU3ZpgAAAjw"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:10.436802 2026] [security2:error] [pid 1017536:tid 1017674] [client 52.139.37.240:25043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/ahax.php"] [unique_id "apK85iJcY4fy7tP-rU3ZsAAAAhw"] [Sat Aug 29 05:05:10.437717 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.18.15:46993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/sign.php"] [unique_id "apK85iJcY4fy7tP-rU3ZsQAAApM"] [Sat Aug 29 05:05:10.438614 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.104.62:14359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/Zeiss.php"] [unique_id "apK85iJcY4fy7tP-rU3ZsgAAAhw"] [Sat Aug 29 05:05:10.440260 2026] [security2:error] [pid 1017536:tid 1017709] [client 74.248.24.12:3455] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.realestatetrifecta.com"] [uri "/1.php7"] [unique_id "apK85iJcY4fy7tP-rU3ZswAAAj8"] [Sat Aug 29 05:05:10.440352 2026] [security2:error] [pid 1017536:tid 1017709] [client 74.248.24.12:3455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/1.php7"] [unique_id "apK85iJcY4fy7tP-rU3ZswAAAj8"] [Sat Aug 29 05:05:10.445611 2026] [security2:error] [pid 1017536:tid 1017727] [client 4.232.148.111:18743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/bthil.php"] [unique_id "apK85iJcY4fy7tP-rU3ZtAAAAlE"] [Sat Aug 29 05:05:10.447028 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.104.18.15:7154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK85iJcY4fy7tP-rU3ZtQAAAiw"] [Sat Aug 29 05:05:10.455458 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.250.41:61783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/w1px.php"] [unique_id "apK85iJcY4fy7tP-rU3ZuAAAAj8"] [Sat Aug 29 05:05:10.459092 2026] [core:error] [pid 1017536:tid 1017739] [client 74.248.24.12:24693] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:10.459109 2026] [core:error] [pid 1017536:tid 1017739] [client 74.248.24.12:24693] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:10.461587 2026] [security2:error] [pid 1017536:tid 1017762] [client 20.104.104.62:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/siln.php"] [unique_id "apK85iJcY4fy7tP-rU3ZugAAAnQ"] [Sat Aug 29 05:05:10.466697 2026] [security2:error] [pid 1017536:tid 1017762] [client 20.48.251.3:57863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/dialog.php"] [unique_id "apK85iJcY4fy7tP-rU3ZvAAAAnQ"] [Sat Aug 29 05:05:10.490882 2026] [security2:error] [pid 1017536:tid 1017670] [client 34.7.216.49:48866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK85iJcY4fy7tP-rU3ZvwAAAhg"] [Sat Aug 29 05:05:10.491907 2026] [security2:error] [pid 1017536:tid 1017718] [client 40.83.93.50:9610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/admin-header.php"] [unique_id "apK85iJcY4fy7tP-rU3ZwQAAAkg"] [Sat Aug 29 05:05:10.493468 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.250.41:19452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liatbehr.com"] [uri "/xr.php"] [unique_id "apK85iJcY4fy7tP-rU3ZwwAAAj8"] [Sat Aug 29 05:05:10.494297 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.104.104.62:10432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK85iJcY4fy7tP-rU3ZxgAAAhg"] [Sat Aug 29 05:05:10.496862 2026] [core:error] [pid 1017536:tid 1017693] [client 34.7.216.49:48942] AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) [Sat Aug 29 05:05:10.497751 2026] [core:error] [pid 1017536:tid 1017683] [client 34.7.216.49:48930] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) [Sat Aug 29 05:05:10.498154 2026] [security2:error] [pid 1017536:tid 1017775] [client 34.7.216.49:48908] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apK85iJcY4fy7tP-rU3ZzgAAAoE"] [Sat Aug 29 05:05:10.499460 2026] [security2:error] [pid 1017536:tid 1017744] [client 34.7.216.49:48938] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apK85iJcY4fy7tP-rU3Z1AAAAmI"] [Sat Aug 29 05:05:10.503069 2026] [security2:error] [pid 1017536:tid 1017703] [client 4.232.148.111:21780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/files/index.php"] [unique_id "apK85iJcY4fy7tP-rU3Z2gAAAjk"] [Sat Aug 29 05:05:10.505198 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:23441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK85iJcY4fy7tP-rU3Z3gAAAmE"] [Sat Aug 29 05:05:10.511535 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.160.90:64701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK85iJcY4fy7tP-rU3Z6QAAAk4"] [Sat Aug 29 05:05:10.519340 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.197.61.180:16278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eeeaudio.com"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK85iJcY4fy7tP-rU3Z7AAAAl8"] [Sat Aug 29 05:05:10.539081 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.160.90:23234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/nz.php"] [unique_id "apK85iJcY4fy7tP-rU3Z_gAAAjs"] [Sat Aug 29 05:05:10.539308 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.48.250.41:64584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/amp.php"] [unique_id "apK85iJcY4fy7tP-rU3Z_wAAAiA"] [Sat Aug 29 05:05:10.549088 2026] [core:error] [pid 1017536:tid 1017791] [client 34.143.179.161:57024] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) [Sat Aug 29 05:05:10.551230 2026] [security2:error] [pid 1017536:tid 1017719] [client 62.60.130.128:59000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gjn.ukm.mybluehost.me"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apK85iJcY4fy7tP-rU3aBwAAAkk"] [Sat Aug 29 05:05:10.554129 2026] [security2:error] [pid 1017536:tid 1017738] [client 34.143.179.161:57016] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/@fs/var/run/secrets/kubernetes.io/serviceaccount/token"] [unique_id "apK85iJcY4fy7tP-rU3aCQAAAlw"] [Sat Aug 29 05:05:10.554446 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.18.15:23508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/adminfuns.php"] [unique_id "apK85iJcY4fy7tP-rU3aCgAAAj8"] [Sat Aug 29 05:05:10.554949 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.18.15:13293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ap.php"] [unique_id "apK85iJcY4fy7tP-rU3aCwAAAkk"] [Sat Aug 29 05:05:10.555008 2026] [security2:error] [pid 1017536:tid 1017792] [client 143.14.151.241:41350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.151.14.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abantiquo.aldergate.net"] [uri "/cron.php"] [unique_id "apK85iJcY4fy7tP-rU3aAgAAApI"], referer: https://abantiquo.aldergate.net/ [Sat Aug 29 05:05:10.557267 2026] [security2:error] [pid 1017536:tid 1017709] [client 93.152.221.156:53529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nme.cle.mybluehost.me"] [uri "/admin/phpinfo.php"] [unique_id "apK85iJcY4fy7tP-rU3aDAAAAj8"] [Sat Aug 29 05:05:10.559184 2026] [security2:error] [pid 1017536:tid 1017758] [client 34.143.179.161:57010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK85iJcY4fy7tP-rU3aEAAAAnA"] [Sat Aug 29 05:05:10.565135 2026] [security2:error] [pid 1017536:tid 1017672] [client 34.143.179.161:57036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/404.html"] [unique_id "apK85iJcY4fy7tP-rU3aAwAAAho"] [Sat Aug 29 05:05:10.567225 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.104.104.62:13600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/wp-admin/zwso.php"] [unique_id "apK85iJcY4fy7tP-rU3aGQAAAho"] [Sat Aug 29 05:05:10.579665 2026] [security2:error] [pid 1017536:tid 1017756] [client 34.143.179.161:57102] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apK85iJcY4fy7tP-rU3aHQAAAm4"] [Sat Aug 29 05:05:10.585041 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.250.41:65408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/8.php"] [unique_id "apK85iJcY4fy7tP-rU3aIQAAAiU"] [Sat Aug 29 05:05:10.586772 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:15303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/ww2.php"] [unique_id "apK85iJcY4fy7tP-rU3aIgAAAiU"] [Sat Aug 29 05:05:10.588374 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.18.15:47021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wnnjpsby.php"] [unique_id "apK85iJcY4fy7tP-rU3aIwAAAiU"] [Sat Aug 29 05:05:10.589825 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.250.41:12391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/403.php"] [unique_id "apK85iJcY4fy7tP-rU3aJAAAAiU"] [Sat Aug 29 05:05:10.591172 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.18.15:36826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/inso.php"] [unique_id "apK85iJcY4fy7tP-rU3aJwAAAiU"] [Sat Aug 29 05:05:10.591443 2026] [core:error] [pid 1017536:tid 1017760] [client 34.143.179.161:57064] AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) [Sat Aug 29 05:05:10.592525 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:2467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/f-401.php"] [unique_id "apK85iJcY4fy7tP-rU3aKQAAAiU"] [Sat Aug 29 05:05:10.606582 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.251.3:57807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/phpinfo01.php"] [unique_id "apK85iJcY4fy7tP-rU3aLgAAAiM"] [Sat Aug 29 05:05:10.607276 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.18.15:7166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ap.php"] [unique_id "apK85iJcY4fy7tP-rU3aLwAAAoE"] [Sat Aug 29 05:05:10.614311 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.48.250.41:58567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/to.php"] [unique_id "apK85iJcY4fy7tP-rU3aMgAAAi0"] [Sat Aug 29 05:05:10.624547 2026] [security2:error] [pid 1017536:tid 1017693] [client 52.139.37.240:64236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/aged.php"] [unique_id "apK85iJcY4fy7tP-rU3aOAAAAi8"] [Sat Aug 29 05:05:10.629730 2026] [security2:error] [pid 1017536:tid 1017690] [client 34.143.179.161:57220] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apK85iJcY4fy7tP-rU3aOwAAAiw"] [Sat Aug 29 05:05:10.648506 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.104.62:44577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/baee.php"] [unique_id "apK85iJcY4fy7tP-rU3aQQAAAoM"] [Sat Aug 29 05:05:10.658564 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.250.41:49362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liatbehr.com"] [uri "/h02ugyh.php"] [unique_id "apK85iJcY4fy7tP-rU3aSAAAAow"] [Sat Aug 29 05:05:10.667126 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.48.250.41:23495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ff1.php"] [unique_id "apK85iJcY4fy7tP-rU3aSgAAAo0"] [Sat Aug 29 05:05:10.668307 2026] [security2:error] [pid 1017536:tid 1017563] [remote 74.7.227.189:43878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pinnacleforms.com"] [uri "/m_AR223.php"] [unique_id "apK85iJcY4fy7tP-rU3aSwACgBo"], referer: https://mail.pinnacleforms.com/ [Sat Aug 29 05:05:10.669304 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.104.104.62:48591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/baee.php"] [unique_id "apK85iJcY4fy7tP-rU3aTAAAAo0"] [Sat Aug 29 05:05:10.676030 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.160.90:45859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/sg.php"] [unique_id "apK85iJcY4fy7tP-rU3aUAAAAoE"] [Sat Aug 29 05:05:10.676379 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.250.41:64537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/cc13.php"] [unique_id "apK85iJcY4fy7tP-rU3aUQAAAoI"] [Sat Aug 29 05:05:10.693654 2026] [security2:error] [pid 1017536:tid 1017763] [client 168.107.94.195:64211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK85iJcY4fy7tP-rU3aWAAAAnU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:10.694642 2026] [security2:error] [pid 1017536:tid 1017774] [client 20.104.18.15:13253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/media.php"] [unique_id "apK85iJcY4fy7tP-rU3aWQAAAoA"] [Sat Aug 29 05:05:10.696703 2026] [security2:error] [pid 1017536:tid 1017763] [client 20.48.160.90:64727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/ser.php"] [unique_id "apK85iJcY4fy7tP-rU3aWgAAAnU"] [Sat Aug 29 05:05:10.697352 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.104.62:20629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/konten.php"] [unique_id "apK85iJcY4fy7tP-rU3aXAAAAmY"] [Sat Aug 29 05:05:10.699150 2026] [security2:error] [pid 1017536:tid 1017763] [client 20.104.104.62:13754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/Contrller.php"] [unique_id "apK85iJcY4fy7tP-rU3aXQAAAnU"] [Sat Aug 29 05:05:10.720346 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.18.15:23509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/classwithtostring.php"] [unique_id "apK85iJcY4fy7tP-rU3aYAAAAkI"] [Sat Aug 29 05:05:10.737042 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.104.62:14837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/anz.php"] [unique_id "apK85iJcY4fy7tP-rU3aYwAAAoc"] [Sat Aug 29 05:05:10.739257 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.18.15:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/aa.php"] [unique_id "apK85iJcY4fy7tP-rU3aZAAAAoc"] [Sat Aug 29 05:05:10.741306 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.250.41:64945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/0x0x.php"] [unique_id "apK85iJcY4fy7tP-rU3aZgAAAoc"] [Sat Aug 29 05:05:10.759260 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.104.104.62:62978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/hq.php"] [unique_id "apK85iJcY4fy7tP-rU3aaAAAAo8"] [Sat Aug 29 05:05:10.761185 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.250.41:61796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/thui.php"] [unique_id "apK85iJcY4fy7tP-rU3aaQAAAnk"] [Sat Aug 29 05:05:10.773594 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.18.15:7117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/media.php"] [unique_id "apK85iJcY4fy7tP-rU3aawAAAjw"] [Sat Aug 29 05:05:10.776277 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.250.41:12349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/cytyr.php"] [unique_id "apK85iJcY4fy7tP-rU3abAAAAjw"] [Sat Aug 29 05:05:10.790772 2026] [security2:error] [pid 1017536:tid 1017738] [client 60.243.207.176:65131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK85iJcY4fy7tP-rU3abgAAAlw"] [Sat Aug 29 05:05:10.791013 2026] [security2:error] [pid 1017536:tid 1017738] [client 60.243.207.176:65131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK85iJcY4fy7tP-rU3abgAAAlw"] [Sat Aug 29 05:05:10.798513 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.104.18.15:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/gigi.php"] [unique_id "apK85iJcY4fy7tP-rU3acAAAAlE"] [Sat Aug 29 05:05:10.800464 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.104.104.62:44570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/d12.php"] [unique_id "apK85iJcY4fy7tP-rU3acQAAAlE"] [Sat Aug 29 05:05:10.813236 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.48.251.3:57815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/cxc.php"] [unique_id "apK85iJcY4fy7tP-rU3adAAAAoU"] [Sat Aug 29 05:05:10.814999 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.48.250.41:23392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/t.php"] [unique_id "apK85iJcY4fy7tP-rU3adQAAAoU"] [Sat Aug 29 05:05:10.816413 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.48.160.90:45948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/hypo.php"] [unique_id "apK85iJcY4fy7tP-rU3adgAAAlE"] [Sat Aug 29 05:05:10.818090 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.48.250.41:64615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/aa.php"] [unique_id "apK85iJcY4fy7tP-rU3aeQAAAoU"] [Sat Aug 29 05:05:10.830250 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.104.62:13981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/Zeiss.php"] [unique_id "apK85iJcY4fy7tP-rU3aegAAAhw"] [Sat Aug 29 05:05:10.833427 2026] [security2:error] [pid 1017536:tid 1017674] [client 93.152.221.156:50055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nme.cle.mybluehost.me"] [uri "/pinfo.php"] [unique_id "apK85iJcY4fy7tP-rU3afQAAAhw"] [Sat Aug 29 05:05:10.837397 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.160.90:64672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/431.php"] [unique_id "apK85iJcY4fy7tP-rU3afgAAAhw"] [Sat Aug 29 05:05:10.837801 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.104.18.15:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/adminfuns.php"] [unique_id "apK85iJcY4fy7tP-rU3afwAAAiw"] [Sat Aug 29 05:05:10.842379 2026] [security2:error] [pid 1017536:tid 1017775] [client 195.178.110.247:18690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ladiesandbabies.com"] [uri "/index.php"] [unique_id "apK85iJcY4fy7tP-rU3agAAAAoE"] [Sat Aug 29 05:05:10.844152 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.48.250.41:49308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liatbehr.com"] [uri "/xxw.php"] [unique_id "apK85iJcY4fy7tP-rU3agQAAAlE"] [Sat Aug 29 05:05:10.880502 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.18.15:23539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK85iJcY4fy7tP-rU3aiwAAAkU"] [Sat Aug 29 05:05:10.899196 2026] [security2:error] [pid 1017536:tid 1017754] [client 171.61.160.196:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK85iJcY4fy7tP-rU3ajgAAAmw"] [Sat Aug 29 05:05:10.899323 2026] [security2:error] [pid 1017536:tid 1017754] [client 171.61.160.196:16175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK85iJcY4fy7tP-rU3ajgAAAmw"] [Sat Aug 29 05:05:10.901582 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.104.104.62:65245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/mh.php"] [unique_id "apK85iJcY4fy7tP-rU3ajwAAAns"] [Sat Aug 29 05:05:10.902532 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.104.104.62:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/d12.php"] [unique_id "apK85iJcY4fy7tP-rU3akQAAAmw"] [Sat Aug 29 05:05:10.931247 2026] [security2:error] [pid 1017536:tid 1017774] [client 20.48.250.41:12439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/galer.php"] [unique_id "apK85iJcY4fy7tP-rU3akwAAAoA"] [Sat Aug 29 05:05:10.931671 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.104.49.130:63440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/about.php"] [unique_id "apK85iJcY4fy7tP-rU3akgAAAhg"] [Sat Aug 29 05:05:10.936609 2026] [security2:error] [pid 1017536:tid 1017679] [client 127.0.0.1:28054] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "apK85iJcY4fy7tP-rU3aewAAAiE"] [Sat Aug 29 05:05:10.936730 2026] [security2:error] [pid 1017536:tid 1017704] [client 74.7.241.190:60380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.fri.dpn.mybluehost.me"] [uri "/robots.txt"] [unique_id "apK85iJcY4fy7tP-rU3adwAAAjo"] [Sat Aug 29 05:05:10.945893 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.104.62:44584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/yyy.php"] [unique_id "apK85iJcY4fy7tP-rU3alQAAAls"] [Sat Aug 29 05:05:10.948540 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.18.15:36749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/img.php"] [unique_id "apK85iJcY4fy7tP-rU3alAAAAos"] [Sat Aug 29 05:05:10.949319 2026] [security2:error] [pid 1017536:tid 1017774] [client 20.104.18.15:7165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/adminfuns.php"] [unique_id "apK85iJcY4fy7tP-rU3alwAAAoA"] [Sat Aug 29 05:05:10.949603 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:61721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/Jcrop.php"] [unique_id "apK85iJcY4fy7tP-rU3algAAAls"] [Sat Aug 29 05:05:10.950884 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.104.62:15296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/bge.php"] [unique_id "apK85iJcY4fy7tP-rU3amAAAAiE"] [Sat Aug 29 05:05:10.952327 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.48.250.41:64533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/s1.php"] [unique_id "apK85iJcY4fy7tP-rU3amgAAAhg"] [Sat Aug 29 05:05:10.970952 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.160.90:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/Hd.php"] [unique_id "apK85iJcY4fy7tP-rU3anAAAAjk"] [Sat Aug 29 05:05:10.974562 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.104.62:13589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/ww2.php"] [unique_id "apK85iJcY4fy7tP-rU3anQAAAmE"] [Sat Aug 29 05:05:10.977050 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.160.90:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/rxr.php"] [unique_id "apK85iJcY4fy7tP-rU3anwAAAjs"] [Sat Aug 29 05:05:10.977050 2026] [security2:error] [pid 1017536:tid 1017766] [client 20.104.104.62:20833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/bekdur.php"] [unique_id "apK85iJcY4fy7tP-rU3angAAAng"] [Sat Aug 29 05:05:10.987216 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.251.3:57872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/oiko6u.php"] [unique_id "apK85iJcY4fy7tP-rU3aoQAAApI"] [Sat Aug 29 05:05:11.004537 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:49349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liatbehr.com"] [uri "/bolt.php"] [unique_id "apK85yJcY4fy7tP-rU3aowAAAmM"] [Sat Aug 29 05:05:11.004619 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.18.15:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/classwithtostring.php"] [unique_id "apK85yJcY4fy7tP-rU3apAAAApI"] [Sat Aug 29 05:05:11.007665 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.48.250.41:65507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/166.php"] [unique_id "apK85yJcY4fy7tP-rU3apQAAAic"] [Sat Aug 29 05:05:11.040324 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.18.15:47088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/info.php/new.php"] [unique_id "apK85yJcY4fy7tP-rU3aqQAAAhs"] [Sat Aug 29 05:05:11.043292 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.104.62:2465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/f2r4.php"] [unique_id "apK85yJcY4fy7tP-rU3aqgAAAoE"] [Sat Aug 29 05:05:11.048221 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.18.15:23424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK85yJcY4fy7tP-rU3aqwAAAoE"] [Sat Aug 29 05:05:11.064574 2026] [security2:error] [pid 1017536:tid 1017754] [client 201.105.19.164:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK85yJcY4fy7tP-rU3arwAAAmw"], referer: https://www.djiboutihomes.com/ [Sat Aug 29 05:05:11.073410 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.250.41:23522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/erty.php"] [unique_id "apK85yJcY4fy7tP-rU3asgAAAmw"] [Sat Aug 29 05:05:11.076337 2026] [security2:error] [pid 1017536:tid 1017733] [client 168.107.94.195:64642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK85yJcY4fy7tP-rU3aswAAAlc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:11.084556 2026] [security2:error] [pid 1017536:tid 1017677] [client 35.159.236.187:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.jobindjibouti.com"] [uri "/"] [unique_id "apK85yJcY4fy7tP-rU3atAAAAh8"] [Sat Aug 29 05:05:11.086973 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.250.41:12362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/baixy.php"] [unique_id "apK85yJcY4fy7tP-rU3atQAAAmw"] [Sat Aug 29 05:05:11.110454 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.104.62:44599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/bgymj.php"] [unique_id "apK85yJcY4fy7tP-rU3avAAAAlc"] [Sat Aug 29 05:05:11.110454 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.48.250.41:49910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/0byte.php"] [unique_id "apK85yJcY4fy7tP-rU3auwAAAjg"] [Sat Aug 29 05:05:11.112231 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.104.62:48705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/yyy.php"] [unique_id "apK85yJcY4fy7tP-rU3avQAAAiE"] [Sat Aug 29 05:05:11.115657 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.250.41:61800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/ws58.php"] [unique_id "apK85yJcY4fy7tP-rU3awAAAAlc"] [Sat Aug 29 05:05:11.126652 2026] [security2:error] [pid 1017536:tid 1017744] [client 61.9.8.5:3002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3asAAAAmI"] [Sat Aug 29 05:05:11.126841 2026] [security2:error] [pid 1017536:tid 1017744] [client 61.9.8.5:3002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3asAAAAmI"] [Sat Aug 29 05:05:11.129298 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.104.62:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/anz.php"] [unique_id "apK85yJcY4fy7tP-rU3awgAAAiE"] [Sat Aug 29 05:05:11.136814 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.104.104.62:14785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/wp-ana.php"] [unique_id "apK85yJcY4fy7tP-rU3axgAAAmI"] [Sat Aug 29 05:05:11.138307 2026] [security2:error] [pid 1017536:tid 1017767] [client 149.34.210.141:10448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3axwAAAnk"] [Sat Aug 29 05:05:11.138380 2026] [security2:error] [pid 1017536:tid 1017670] [client 52.54.254.209:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/2016/08/17/crevettes-sautees-maison/"] [unique_id "apK85yJcY4fy7tP-rU3axQAAAhg"] [Sat Aug 29 05:05:11.138420 2026] [security2:error] [pid 1017536:tid 1017767] [client 149.34.210.141:10448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3axwAAAnk"] [Sat Aug 29 05:05:11.140645 2026] [security2:error] [pid 1017536:tid 1017704] [client 93.152.221.156:64866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nme.cle.mybluehost.me"] [uri "/php_version.php"] [unique_id "apK85yJcY4fy7tP-rU3ayAAAAjo"] [Sat Aug 29 05:05:11.142875 2026] [security2:error] [pid 1017536:tid 1017744] [client 195.178.110.247:3716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ladnertesting.com"] [uri "/index.php"] [unique_id "apK85yJcY4fy7tP-rU3ayQAAAmI"] [Sat Aug 29 05:05:11.144725 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.160.90:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/csst.php"] [unique_id "apK85yJcY4fy7tP-rU3azAAAAos"] [Sat Aug 29 05:05:11.145585 2026] [security2:error] [pid 1017536:tid 1017755] [client 197.219.150.206:55222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3axAAAAm0"] [Sat Aug 29 05:05:11.145708 2026] [security2:error] [pid 1017536:tid 1017755] [client 197.219.150.206:55222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3axAAAAm0"] [Sat Aug 29 05:05:11.146080 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.160.90:45834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/im.php"] [unique_id "apK85yJcY4fy7tP-rU3azQAAAnc"] [Sat Aug 29 05:05:11.147343 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.18.15:13254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK85yJcY4fy7tP-rU3azgAAAls"] [Sat Aug 29 05:05:11.147840 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.48.251.3:57881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/fraro.php"] [unique_id "apK85yJcY4fy7tP-rU3azwAAAnM"] [Sat Aug 29 05:05:11.148551 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.18.15:7157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/classwithtostring.php"] [unique_id "apK85yJcY4fy7tP-rU3a0AAAAnc"] [Sat Aug 29 05:05:11.152784 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.104.18.15:36738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/222.php"] [unique_id "apK85yJcY4fy7tP-rU3a1AAAAjY"] [Sat Aug 29 05:05:11.155272 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.104.62:20610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/webadmin.php"] [unique_id "apK85yJcY4fy7tP-rU3a1gAAAnc"] [Sat Aug 29 05:05:11.157967 2026] [security2:error] [pid 1017536:tid 1017744] [client 57.141.14.63:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK85yJcY4fy7tP-rU3a1QAAAmI"] [Sat Aug 29 05:05:11.169748 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.49.130:43584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.scubaetcfl.com"] [uri "/as.php"] [unique_id "apK85yJcY4fy7tP-rU3a3gAAAhs"] [Sat Aug 29 05:05:11.172658 2026] [security2:error] [pid 1017536:tid 1017784] [client 103.240.76.112:42692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3a3wAAAoo"] [Sat Aug 29 05:05:11.172766 2026] [security2:error] [pid 1017536:tid 1017784] [client 103.240.76.112:42692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3a3wAAAoo"] [Sat Aug 29 05:05:11.173245 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.48.250.41:49397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liatbehr.com"] [uri "/rtx.php"] [unique_id "apK85yJcY4fy7tP-rU3a4AAAAok"] [Sat Aug 29 05:05:11.177931 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.104.62:56543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/sadis.php"] [unique_id "apK85yJcY4fy7tP-rU3a4gAAAks"] [Sat Aug 29 05:05:11.213596 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.184.117:56694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/test.php"] [unique_id "apK85yJcY4fy7tP-rU3a8QAAAls"] [Sat Aug 29 05:05:11.219574 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.18.15:23550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK85yJcY4fy7tP-rU3a8wAAAls"] [Sat Aug 29 05:05:11.228481 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.23.184.117:22178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.dj/index.php"] [unique_id "apK85yJcY4fy7tP-rU3a9gAAAos"] [Sat Aug 29 05:05:11.229641 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.48.250.41:65485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/h2a2ck.php"] [unique_id "apK85yJcY4fy7tP-rU3a9wAAAhs"] [Sat Aug 29 05:05:11.240935 2026] [security2:error] [pid 1017536:tid 1017744] [client 52.139.37.240:65327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/cron.php"] [unique_id "apK85yJcY4fy7tP-rU3a-wAAAmI"] [Sat Aug 29 05:05:11.245185 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:12383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/ava.php"] [unique_id "apK85yJcY4fy7tP-rU3a_AAAAls"] [Sat Aug 29 05:05:11.246841 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.48.250.41:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/xr.php"] [unique_id "apK85yJcY4fy7tP-rU3a_QAAAic"] [Sat Aug 29 05:05:11.265037 2026] [security2:error] [pid 1017536:tid 1017591] [remote 47.128.60.119:26128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bridal.myweddinggownpreservation.com"] [uri "/robots.txt"] [unique_id "apK85yJcY4fy7tP-rU3bAAACJzY"] [Sat Aug 29 05:05:11.269158 2026] [security2:error] [pid 1017536:tid 1017592] [remote 47.128.60.119:26138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "myweddinggownpreservation.com"] [uri "/robots.txt"] [unique_id "apK85yJcY4fy7tP-rU3bAgACJzc"] [Sat Aug 29 05:05:11.273740 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.48.250.41:61718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/xs.php"] [unique_id "apK85yJcY4fy7tP-rU3bAwAAAic"] [Sat Aug 29 05:05:11.278205 2026] [http2:info] [pid 1018003:tid 1018003] h2_workers: created with min=128 max=192 idle_ms=600000 [Sat Aug 29 05:05:11.289382 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.104.104.62:44566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/fh26.php"] [unique_id "apK85yJcY4fy7tP-rU3bBQAAAmI"] [Sat Aug 29 05:05:11.295406 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.104.62:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/bge.php"] [unique_id "apK85yJcY4fy7tP-rU3bBwAAAic"] [Sat Aug 29 05:05:11.299876 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.48.160.90:40012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/fc.php"] [unique_id "apK85yJcY4fy7tP-rU3bDAAAAic"] [Sat Aug 29 05:05:11.300974 2026] [security2:error] [pid 1017536:tid 1017753] [client 52.139.37.240:58598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/breads1.php"] [unique_id "apK85yJcY4fy7tP-rU3bDgAAAms"] [Sat Aug 29 05:05:11.305770 2026] [security2:error] [pid 1017536:tid 1017694] [client 103.171.189.88:50097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3bEQAAAjA"] [Sat Aug 29 05:05:11.305949 2026] [security2:error] [pid 1017536:tid 1017694] [client 103.171.189.88:50097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3bEQAAAjA"] [Sat Aug 29 05:05:11.335488 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.104.18.15:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK85yJcY4fy7tP-rU3bEgAAAkM"] [Sat Aug 29 05:05:11.339984 2026] [security2:error] [pid 1018003:tid 1018150] [client 20.48.160.90:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apK85zAh5Y1i2tUxg4HadQAABbc"] [Sat Aug 29 05:05:11.350430 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.251.3:57885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/thui.php"] [unique_id "apK85zAh5Y1i2tUxg4HaeAAABcU"] [Sat Aug 29 05:05:11.354842 2026] [security2:error] [pid 1017536:tid 1017750] [client 213.202.253.4:58662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/adminfuns.php"] [unique_id "apK85yJcY4fy7tP-rU3bFAAAAmg"], referer: www.google.com [Sat Aug 29 05:05:11.355530 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.104.62:56566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/xcre1.php"] [unique_id "apK85zAh5Y1i2tUxg4HaegAABco"] [Sat Aug 29 05:05:11.366428 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.250.41:23509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/0x.php"] [unique_id "apK85zAh5Y1i2tUxg4HafQAABfU"] [Sat Aug 29 05:05:11.367594 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.104.62:14392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/secret.php"] [unique_id "apK85yJcY4fy7tP-rU3bFwAAAic"] [Sat Aug 29 05:05:11.367793 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.18.15:23442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wsd.php"] [unique_id "apK85yJcY4fy7tP-rU3bFgAAAmg"] [Sat Aug 29 05:05:11.377864 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.48.250.41:12342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/gdn.php"] [unique_id "apK85yJcY4fy7tP-rU3bGgAAAkY"] [Sat Aug 29 05:05:11.383384 2026] [security2:error] [pid 1017536:tid 1017702] [client 4.205.62.107:61875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/cloud.php"] [unique_id "apK85yJcY4fy7tP-rU3bHAAAAjg"] [Sat Aug 29 05:05:11.395096 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.250.41:64903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/error_log.php"] [unique_id "apK85yJcY4fy7tP-rU3bHgAAAjA"] [Sat Aug 29 05:05:11.395167 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.250.41:49871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/h02ugyh.php"] [unique_id "apK85yJcY4fy7tP-rU3bHwAAAo4"] [Sat Aug 29 05:05:11.397144 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.18.15:47052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/w.php"] [unique_id "apK85yJcY4fy7tP-rU3bIgAAAjA"] [Sat Aug 29 05:05:11.399883 2026] [security2:error] [pid 1017536:tid 1017750] [client 68.155.159.216:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK85yJcY4fy7tP-rU3bJAAAAmg"] [Sat Aug 29 05:05:11.400712 2026] [security2:error] [pid 1017536:tid 1017719] [client 4.205.62.107:22277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wp-konfig.backup.php"] [unique_id "apK85yJcY4fy7tP-rU3bJQAAAkk"] [Sat Aug 29 05:05:11.401485 2026] [security2:error] [pid 1017536:tid 1017739] [client 103.162.125.59:49712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3bJgAAAl0"] [Sat Aug 29 05:05:11.401592 2026] [security2:error] [pid 1017536:tid 1017739] [client 103.162.125.59:49712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3bJgAAAl0"] [Sat Aug 29 05:05:11.403556 2026] [security2:error] [pid 1017536:tid 1017685] [client 74.7.228.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ministeriosemanuel.org"] [uri "/cgi-sys/404.html"] [unique_id "apK85yJcY4fy7tP-rU3bIwAAAic"], referer: http://ministeriosemanuel.org/robots.txt [Sat Aug 29 05:05:11.408961 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.49.130:43645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/ty.php"] [unique_id "apK85yJcY4fy7tP-rU3bKQAAAlc"] [Sat Aug 29 05:05:11.412591 2026] [security2:error] [pid 1017536:tid 1017704] [client 74.7.228.11:49820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ministeriosemanuel.org"] [uri "/robots.txt"] [unique_id "apK85yJcY4fy7tP-rU3a6QACOjQ"], referer: http://ministeriosemanuel.org/robots.txt [Sat Aug 29 05:05:11.420523 2026] [security2:error] [pid 1017536:tid 1017702] [client 68.155.159.216:18294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK85yJcY4fy7tP-rU3bLAAAAjg"] [Sat Aug 29 05:05:11.448341 2026] [security2:error] [pid 1017536:tid 1017675] [client 52.139.37.240:37945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/wp-2019.php"] [unique_id "apK85yJcY4fy7tP-rU3bMQAAAh0"] [Sat Aug 29 05:05:11.455602 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.104.62:25635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/wp-content/index.php"] [unique_id "apK85zAh5Y1i2tUxg4HalQAABfw"] [Sat Aug 29 05:05:11.457937 2026] [security2:error] [pid 1018003:tid 1018202] [client 52.139.37.240:28278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/essexec.php"] [unique_id "apK85zAh5Y1i2tUxg4HalgAABes"] [Sat Aug 29 05:05:11.460919 2026] [security2:error] [pid 1018003:tid 1018258] [client 68.155.159.216:16233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/file88.php"] [unique_id "apK85zAh5Y1i2tUxg4HalwAABiI"] [Sat Aug 29 05:05:11.471233 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.147.79:30604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK85yJcY4fy7tP-rU3bMgAAAmE"] [Sat Aug 29 05:05:11.474659 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.48.250.41:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/zu.php"] [unique_id "apK85zAh5Y1i2tUxg4HamQAABiM"] [Sat Aug 29 05:05:11.476198 2026] [security2:error] [pid 1017536:tid 1017715] [client 68.155.159.216:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK85yJcY4fy7tP-rU3bMwAAAkU"] [Sat Aug 29 05:05:11.482794 2026] [security2:error] [pid 1017536:tid 1017671] [client 68.155.159.216:16137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK85yJcY4fy7tP-rU3bNQAAAhk"] [Sat Aug 29 05:05:11.488156 2026] [security2:error] [pid 1017536:tid 1017709] [client 158.23.147.79:58054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK85yJcY4fy7tP-rU3bOAAAAj8"] [Sat Aug 29 05:05:11.495273 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.147.79:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/themes.php"] [unique_id "apK85zAh5Y1i2tUxg4HanAAABgY"] [Sat Aug 29 05:05:11.497237 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.104.62:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/wp-ana.php"] [unique_id "apK85yJcY4fy7tP-rU3bOQAAAos"] [Sat Aug 29 05:05:11.500043 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.104.104.62:44576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/fgd.php"] [unique_id "apK85yJcY4fy7tP-rU3bOgAAAo4"] [Sat Aug 29 05:05:11.504592 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.160.90:40059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/ke.php"] [unique_id "apK85yJcY4fy7tP-rU3bOwAAAjE"] [Sat Aug 29 05:05:11.506983 2026] [security2:error] [pid 1017536:tid 1017685] [client 4.205.62.107:22291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/maxro.php"] [unique_id "apK85yJcY4fy7tP-rU3bPAAAAic"] [Sat Aug 29 05:05:11.510187 2026] [security2:error] [pid 1017536:tid 1017758] [client 4.205.62.107:54435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/filesystems.php"] [unique_id "apK85yJcY4fy7tP-rU3bPQAAAnA"] [Sat Aug 29 05:05:11.512898 2026] [security2:error] [pid 1017536:tid 1017784] [client 168.107.94.195:64922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK85yJcY4fy7tP-rU3bPgAAAoo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:11.523787 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.196.209.81:12353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK85zAh5Y1i2tUxg4HaogAABdU"] [Sat Aug 29 05:05:11.537199 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.250.41:64609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/xxw.php"] [unique_id "apK85yJcY4fy7tP-rU3bPwAAAjE"] [Sat Aug 29 05:05:11.543485 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.203.141.11:35007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/av.php"] [unique_id "apK85zAh5Y1i2tUxg4HapAAABc4"] [Sat Aug 29 05:05:11.546266 2026] [security2:error] [pid 1017536:tid 1017733] [client 4.205.62.107:53328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/sadd.php"] [unique_id "apK85yJcY4fy7tP-rU3bQQAAAlc"] [Sat Aug 29 05:05:11.554529 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.196.209.81:15767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/wp-contentt.php"] [unique_id "apK85zAh5Y1i2tUxg4HaqAAABfA"] [Sat Aug 29 05:05:11.554826 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.250.41:64206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/403.php"] [unique_id "apK85yJcY4fy7tP-rU3bQwAAAk4"] [Sat Aug 29 05:05:11.557222 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.104.18.15:23431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/bulet.php"] [unique_id "apK85zAh5Y1i2tUxg4HaqQAABjQ"] [Sat Aug 29 05:05:11.561340 2026] [security2:error] [pid 1018003:tid 1018196] [client 4.232.148.111:19950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "strangeworxproductions.strangeworx.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK85zAh5Y1i2tUxg4HaqgAABeU"] [Sat Aug 29 05:05:11.564523 2026] [security2:error] [pid 1017536:tid 1017766] [client 68.155.159.216:24552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK85yJcY4fy7tP-rU3bRAAAAng"] [Sat Aug 29 05:05:11.568833 2026] [security2:error] [pid 1017536:tid 1017698] [client 52.139.37.240:58560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/must.php"] [unique_id "apK85yJcY4fy7tP-rU3bRQAAAjQ"] [Sat Aug 29 05:05:11.570794 2026] [security2:error] [pid 1018003:tid 1018272] [client 20.104.18.15:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK85zAh5Y1i2tUxg4HarAAABjA"] [Sat Aug 29 05:05:11.573375 2026] [security2:error] [pid 1018003:tid 1018193] [client 40.83.93.50:3606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/admin.php"] [unique_id "apK85zAh5Y1i2tUxg4HarQAABeI"] [Sat Aug 29 05:05:11.576727 2026] [security2:error] [pid 1018003:tid 1018190] [client 74.248.24.12:28170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/disagraeosc.php"] [unique_id "apK85zAh5Y1i2tUxg4HargAABd8"] [Sat Aug 29 05:05:11.577067 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.104.62:48583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/bgymj.php"] [unique_id "apK85zAh5Y1i2tUxg4HarwAABi8"] [Sat Aug 29 05:05:11.581581 2026] [security2:error] [pid 1018003:tid 1018248] [client 158.23.147.79:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/packed.php"] [unique_id "apK85zAh5Y1i2tUxg4HasAAABhg"] [Sat Aug 29 05:05:11.581893 2026] [security2:error] [pid 1018003:tid 1018229] [client 74.7.230.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ibest.ab-mac.com"] [uri "/cgi-sys/404.html"] [unique_id "apK85zAh5Y1i2tUxg4HaqwAABgU"] [Sat Aug 29 05:05:11.583958 2026] [security2:error] [pid 1018003:tid 1018159] [client 74.248.24.12:11292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "apK85zAh5Y1i2tUxg4HasgAABcA"] [Sat Aug 29 05:05:11.591607 2026] [security2:error] [pid 1018003:tid 1018251] [client 158.23.147.79:24516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK85zAh5Y1i2tUxg4HatAAABhs"] [Sat Aug 29 05:05:11.598150 2026] [security2:error] [pid 1017536:tid 1017793] [client 74.7.230.15:46130] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ibest.ab-mac.com"] [uri "/robots.txt"] [unique_id "apK85iJcY4fy7tP-rU3afAAAApM"] [Sat Aug 29 05:05:11.606148 2026] [security2:error] [pid 1018003:tid 1018189] [client 195.178.110.155:17944] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "greathairkc.com"] [uri "/wordpress/"] [unique_id "apK85zAh5Y1i2tUxg4HaswAABd4"] [Sat Aug 29 05:05:11.608334 2026] [security2:error] [pid 1018003:tid 1018153] [client 104.167.19.74:40461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.19.167.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK85zAh5Y1i2tUxg4HapQAABbo"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:11.620382 2026] [security2:error] [pid 1018003:tid 1018263] [client 158.23.184.117:22182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.info.php"] [unique_id "apK85zAh5Y1i2tUxg4HatQAABic"] [Sat Aug 29 05:05:11.635754 2026] [security2:error] [pid 1018003:tid 1018219] [client 4.205.62.107:2975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/wp-content/maintenance.php"] [unique_id "apK85zAh5Y1i2tUxg4HatwAABfw"] [Sat Aug 29 05:05:11.636943 2026] [security2:error] [pid 1018003:tid 1018171] [client 162.198.206.205:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK85zAh5Y1i2tUxg4HakgAABcw"], referer: https://www.djiboutihomes.com/ [Sat Aug 29 05:05:11.639921 2026] [security2:error] [pid 1017536:tid 1017735] [client 20.104.104.62:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/secret.php"] [unique_id "apK85yJcY4fy7tP-rU3bUQAAAlk"] [Sat Aug 29 05:05:11.648131 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.104.62:44578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/inject.php"] [unique_id "apK85yJcY4fy7tP-rU3bUgAAAms"] [Sat Aug 29 05:05:11.648566 2026] [security2:error] [pid 1017536:tid 1017720] [client 52.139.37.240:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/gecko-new.php"] [unique_id "apK85yJcY4fy7tP-rU3bUwAAAko"] [Sat Aug 29 05:05:11.648563 2026] [security2:error] [pid 1018003:tid 1018237] [client 20.104.18.15:13275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK85zAh5Y1i2tUxg4HauAAABg0"] [Sat Aug 29 05:05:11.651538 2026] [security2:error] [pid 1017536:tid 1017700] [client 57.141.14.54:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK85yJcY4fy7tP-rU3bTAAAAjY"] [Sat Aug 29 05:05:11.657805 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.250.41:23538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/66.php"] [unique_id "apK85yJcY4fy7tP-rU3bVAAAAjA"] [Sat Aug 29 05:05:11.659276 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.18.15:47028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/x.php"] [unique_id "apK85zAh5Y1i2tUxg4HauwAABb4"] [Sat Aug 29 05:05:11.661438 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.250.41:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/lanka.php"] [unique_id "apK85yJcY4fy7tP-rU3bVQAAAmc"] [Sat Aug 29 05:05:11.664977 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.48.251.3:57902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/lala.php"] [unique_id "apK85zAh5Y1i2tUxg4HavQAABg4"] [Sat Aug 29 05:05:11.667489 2026] [security2:error] [pid 1018003:tid 1018178] [client 20.197.61.180:19963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eeeaudio.com"] [uri "/wp-content/languages/index.php"] [unique_id "apK85zAh5Y1i2tUxg4HavgAABdM"] [Sat Aug 29 05:05:11.667527 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.104.62:62920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/motu.php"] [unique_id "apK85zAh5Y1i2tUxg4HavwAABgc"] [Sat Aug 29 05:05:11.668579 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.104.62:64716] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.motherssandals.com"] [uri "/r57.php"] [unique_id "apK85zAh5Y1i2tUxg4HawAAABhA"] [Sat Aug 29 05:05:11.669631 2026] [security2:error] [pid 1018003:tid 1018220] [client 4.232.148.111:24796] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tiaandephraim.com"] [uri "/1.php7"] [unique_id "apK85zAh5Y1i2tUxg4HawQAABf0"] [Sat Aug 29 05:05:11.669892 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.48.160.90:40063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/tf.php"] [unique_id "apK85yJcY4fy7tP-rU3bWAAAAkU"] [Sat Aug 29 05:05:11.670871 2026] [security2:error] [pid 1018003:tid 1018220] [client 4.232.148.111:24796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/1.php7"] [unique_id "apK85zAh5Y1i2tUxg4HawQAABf0"] [Sat Aug 29 05:05:11.676308 2026] [cgid:error] [pid 1018003:tid 1018024] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.687970 2026] [security2:error] [pid 1017536:tid 1017670] [client 111.235.68.106:57254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3bWgAAAhg"] [Sat Aug 29 05:05:11.689201 2026] [security2:error] [pid 1017536:tid 1017670] [client 111.235.68.106:57254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK85yJcY4fy7tP-rU3bWgAAAhg"] [Sat Aug 29 05:05:11.692777 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.184.117:14357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/update/da222.php"] [unique_id "apK85yJcY4fy7tP-rU3bWQAAAk4"] [Sat Aug 29 05:05:11.704379 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.104.104.62:14384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/pro.php"] [unique_id "apK85zAh5Y1i2tUxg4HazQAABig"] [Sat Aug 29 05:05:11.707924 2026] [security2:error] [pid 1017536:tid 1017717] [client 52.71.203.206:40567] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "vertmulti.com"] [uri "/robots.txt"] [unique_id "apK85yJcY4fy7tP-rU3bXAAAAkc"] [Sat Aug 29 05:05:11.708247 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.48.160.90:63532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apK85zAh5Y1i2tUxg4HaxAAABi4"] [Sat Aug 29 05:05:11.712650 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.48.250.41:19412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liatbehr.com"] [uri "/ckk.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha1QAABe8"] [Sat Aug 29 05:05:11.714464 2026] [security2:error] [pid 1018003:tid 1018031] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env"] [unique_id "apK85zAh5Y1i2tUxg4HazAAFzgo"] [Sat Aug 29 05:05:11.717144 2026] [cgid:error] [pid 1018003:tid 1018028] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.717164 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.158.54.35:6039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/.trash7206/index.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha2QAABio"] [Sat Aug 29 05:05:11.718606 2026] [cgid:error] [pid 1018003:tid 1018026] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.722802 2026] [security2:error] [pid 1018003:tid 1018074] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env"] [unique_id "apK85zAh5Y1i2tUxg4Ha2wAFzjU"] [Sat Aug 29 05:05:11.723185 2026] [cgid:error] [pid 1018003:tid 1018032] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.724561 2026] [security2:error] [pid 1018003:tid 1018232] [client 20.63.219.114:9171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/post.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha0gAABgg"] [Sat Aug 29 05:05:11.724782 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.250.41:12308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/f2.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha1wAABis"] [Sat Aug 29 05:05:11.726667 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.18.15:23523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/av.php"] [unique_id "apK85yJcY4fy7tP-rU3bXQAAAhs"] [Sat Aug 29 05:05:11.732105 2026] [cgid:error] [pid 1018003:tid 1018031] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.735348 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.63.219.114:9400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/add_actualites.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha3wAABb0"] [Sat Aug 29 05:05:11.741677 2026] [security2:error] [pid 1018003:tid 1018159] [client 4.232.148.111:7639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/cv.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha4QAABcA"] [Sat Aug 29 05:05:11.757020 2026] [security2:error] [pid 1018003:tid 1018255] [client 68.155.159.216:51461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha5AAABh8"] [Sat Aug 29 05:05:11.761250 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.104.104.62:25648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK85yJcY4fy7tP-rU3bZAAAAkQ"] [Sat Aug 29 05:05:11.767782 2026] [security2:error] [pid 1018003:tid 1018257] [client 68.155.159.216:14230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-admin/index.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha5gAABiE"] [Sat Aug 29 05:05:11.769999 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.104.18.15:7132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha5wAABeM"] [Sat Aug 29 05:05:11.771812 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.250.41:49867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/bolt.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha6AAABf4"] [Sat Aug 29 05:05:11.773133 2026] [security2:error] [pid 1018003:tid 1018029] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/static/.env"] [unique_id "apK85zAh5Y1i2tUxg4HaygAFzgg"] [Sat Aug 29 05:05:11.773496 2026] [security2:error] [pid 1017536:tid 1017746] [client 52.139.37.240:24629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/up.php"] [unique_id "apK85yJcY4fy7tP-rU3bZgAAAmQ"] [Sat Aug 29 05:05:11.773707 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.104.62:13587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/pro.php"] [unique_id "apK85yJcY4fy7tP-rU3bZwAAAik"] [Sat Aug 29 05:05:11.777807 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.104.49.130:63565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/mac.php"] [unique_id "apK85yJcY4fy7tP-rU3baAAAAmo"] [Sat Aug 29 05:05:11.778471 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.184.117:22177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.trash7206/index.php"] [unique_id "apK85yJcY4fy7tP-rU3baQAAAoc"] [Sat Aug 29 05:05:11.779887 2026] [security2:error] [pid 1018003:tid 1018030] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/static/app/.env"] [unique_id "apK85zAh5Y1i2tUxg4Ha1gAFzgk"] [Sat Aug 29 05:05:11.782110 2026] [security2:error] [pid 1017536:tid 1017692] [client 143.244.57.82:48292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK85yJcY4fy7tP-rU3bagAAAi4"] [Sat Aug 29 05:05:11.784073 2026] [security2:error] [pid 1018003:tid 1018028] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/static/home/user/.env"] [unique_id "apK85zAh5Y1i2tUxg4Ha3QAFzgc"] [Sat Aug 29 05:05:11.786157 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.184.117:56651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/mani.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha6wAABik"] [Sat Aug 29 05:05:11.789968 2026] [security2:error] [pid 1017536:tid 1017735] [client 93.152.221.156:59790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.nme.cle.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "apK85yJcY4fy7tP-rU3bbAAAAlk"] [Sat Aug 29 05:05:11.791646 2026] [security2:error] [pid 1017536:tid 1017735] [client 20.104.18.15:13199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wsd.php"] [unique_id "apK85yJcY4fy7tP-rU3bbQAAAlk"] [Sat Aug 29 05:05:11.794340 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.18.15:36807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/key.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha7AAABcI"] [Sat Aug 29 05:05:11.799526 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.48.251.3:57913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/public/bnn_.php.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha7gAABb4"] [Sat Aug 29 05:05:11.799727 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.48.250.41:65013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/cytyr.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha7wAABhk"] [Sat Aug 29 05:05:11.804073 2026] [cgid:error] [pid 1018003:tid 1018032] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.804421 2026] [cgid:error] [pid 1018003:tid 1018074] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.804998 2026] [security2:error] [pid 1017536:tid 1017766] [client 20.104.104.62:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/wefile.php"] [unique_id "apK85yJcY4fy7tP-rU3bbwAAAng"] [Sat Aug 29 05:05:11.807063 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.160.90:39969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/px.php"] [unique_id "apK85yJcY4fy7tP-rU3bcAAAAkM"] [Sat Aug 29 05:05:11.808512 2026] [security2:error] [pid 1018003:tid 1018201] [client 195.178.110.247:14244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ladnertesting.com"] [uri "/index.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha9AAABeo"] [Sat Aug 29 05:05:11.810613 2026] [security2:error] [pid 1018003:tid 1018275] [client 52.139.37.240:28256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/fw.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha9QAABjM"] [Sat Aug 29 05:05:11.824271 2026] [cgid:error] [pid 1018003:tid 1018102] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml, referer: https://www.bigbuttonscarf.com [Sat Aug 29 05:05:11.825833 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.250.41:23537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/f35.php"] [unique_id "apK85yJcY4fy7tP-rU3bdAAAAk0"] [Sat Aug 29 05:05:11.833136 2026] [cgid:error] [pid 1018003:tid 1018074] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.833224 2026] [cgid:error] [pid 1018003:tid 1018100] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.835074 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.104.62:44587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/mga.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha-gAABew"] [Sat Aug 29 05:05:11.835511 2026] [cgid:error] [pid 1018003:tid 1018067] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.840664 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.18.15:47007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/ssla.php"] [unique_id "apK85yJcY4fy7tP-rU3bdwAAAms"] [Sat Aug 29 05:05:11.849199 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.160.90:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK85yJcY4fy7tP-rU3beQAAAkI"] [Sat Aug 29 05:05:11.856448 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.184.117:14361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/xmr.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha-wAABgc"] [Sat Aug 29 05:05:11.856463 2026] [security2:error] [pid 1017536:tid 1017627] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/.env.php"] [unique_id "apK85yJcY4fy7tP-rU3begACbVo"] [Sat Aug 29 05:05:11.873868 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.139.37.240:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/add_actualites.php"] [unique_id "apK85zAh5Y1i2tUxg4Ha_gAABdg"] [Sat Aug 29 05:05:11.884270 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.48.250.41:61700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/gettest.php"] [unique_id "apK85yJcY4fy7tP-rU3bfAAAAlw"] [Sat Aug 29 05:05:11.886263 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.48.250.41:19419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liatbehr.com"] [uri "/R57.php"] [unique_id "apK85yJcY4fy7tP-rU3bfgAAAl8"] [Sat Aug 29 05:05:11.889341 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.104.62:14386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/999.php"] [unique_id "apK85yJcY4fy7tP-rU3bfwAAAkk"] [Sat Aug 29 05:05:11.896692 2026] [security2:error] [pid 1017536:tid 1017759] [client 20.104.18.15:23537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/images.php"] [unique_id "apK85yJcY4fy7tP-rU3bgQAAAnE"] [Sat Aug 29 05:05:11.907008 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.104.62:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/999.php"] [unique_id "apK85zAh5Y1i2tUxg4HbBAAABcA"] [Sat Aug 29 05:05:11.911346 2026] [access_compat:error] [pid 1018003:tid 1018168] [client 67.20.76.220:22970] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:11.914063 2026] [security2:error] [pid 1017536:tid 1017668] [client 168.107.94.195:65291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK85yJcY4fy7tP-rU3bhAAAAhY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:11.927113 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.18.15:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/bulet.php"] [unique_id "apK85zAh5Y1i2tUxg4HbCQAABh8"] [Sat Aug 29 05:05:11.927958 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.196.209.81:18239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/options-general.php"] [unique_id "apK85yJcY4fy7tP-rU3bhwAAAlQ"] [Sat Aug 29 05:05:11.930664 2026] [cgid:error] [pid 1018003:tid 1018036] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.930988 2026] [security2:error] [pid 1018003:tid 1018247] [client 20.48.250.41:49844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/rtx.php"] [unique_id "apK85zAh5Y1i2tUxg4HbCgAABhc"] [Sat Aug 29 05:05:11.932186 2026] [cgid:error] [pid 1018003:tid 1018034] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.932573 2026] [cgid:error] [pid 1018003:tid 1018035] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.933982 2026] [cgid:error] [pid 1018003:tid 1018025] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:11.936454 2026] [cgid:error] [pid 1018003:tid 1018039] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml, referer: https://www.bigbuttonscarf.com [Sat Aug 29 05:05:11.937750 2026] [security2:error] [pid 1017536:tid 1017744] [client 158.23.184.117:21856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.trash7206/min.php"] [unique_id "apK85yJcY4fy7tP-rU3bigAAAmI"] [Sat Aug 29 05:05:11.944170 2026] [security2:error] [pid 1017536:tid 1017758] [client 20.104.18.15:7140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK85yJcY4fy7tP-rU3bjAAAAnA"] [Sat Aug 29 05:05:11.953051 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:61573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/Test.php"] [unique_id "apK85yJcY4fy7tP-rU3bjgAAAjE"] [Sat Aug 29 05:05:11.980864 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.196.209.81:15134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/theme.php"] [unique_id "apK85yJcY4fy7tP-rU3bkQAAAl4"] [Sat Aug 29 05:05:12.005019 2026] [security2:error] [pid 1018003:tid 1018221] [client 45.154.98.191:64861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK86DAh5Y1i2tUxg4HbEwAABf4"] [Sat Aug 29 05:05:12.010101 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.48.250.41:12397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/grsiuk.php"] [unique_id "apK85zAh5Y1i2tUxg4HbFAAABjE"] [Sat Aug 29 05:05:12.012237 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.203.141.11:29093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/file.php"] [unique_id "apK86CJcY4fy7tP-rU3blAAAAow"] [Sat Aug 29 05:05:12.013480 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.18.15:36824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/chosen.php"] [unique_id "apK86CJcY4fy7tP-rU3blQAAAjE"] [Sat Aug 29 05:05:12.019231 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.104.18.15:47029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apK86CJcY4fy7tP-rU3bmAAAAn0"] [Sat Aug 29 05:05:12.024115 2026] [cgid:error] [pid 1018003:tid 1018040] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.031007 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.48.251.3:57888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wsws.php"] [unique_id "apK86CJcY4fy7tP-rU3bmwAAAlg"] [Sat Aug 29 05:05:12.038290 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:48507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/fh26.php"] [unique_id "apK86CJcY4fy7tP-rU3bnQAAAnM"] [Sat Aug 29 05:05:12.060872 2026] [security2:error] [pid 1018003:tid 1018271] [client 40.83.93.50:3604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK86DAh5Y1i2tUxg4HbHAAABi8"] [Sat Aug 29 05:05:12.069776 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.104.104.62:10438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/inwp.php"] [unique_id "apK86CJcY4fy7tP-rU3boQAAAlA"] [Sat Aug 29 05:05:12.076145 2026] [cgid:error] [pid 1018003:tid 1018041] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.079074 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.250.41:61725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/35.php"] [unique_id "apK86DAh5Y1i2tUxg4HbIgAABgw"] [Sat Aug 29 05:05:12.079848 2026] [security2:error] [pid 1017536:tid 1017707] [client 52.139.37.240:65336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/browse.php"] [unique_id "apK86CJcY4fy7tP-rU3bowAAAj0"] [Sat Aug 29 05:05:12.079997 2026] [security2:error] [pid 1018003:tid 1018202] [client 158.23.184.117:14384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK86DAh5Y1i2tUxg4HbIwAABes"] [Sat Aug 29 05:05:12.093002 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.104.104.62:13693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/sef.php"] [unique_id "apK86DAh5Y1i2tUxg4HbJAAABig"] [Sat Aug 29 05:05:12.095896 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.104.104.62:56575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/EM.php"] [unique_id "apK86CJcY4fy7tP-rU3bpAAAAio"] [Sat Aug 29 05:05:12.097154 2026] [security2:error] [pid 1018003:tid 1018258] [client 52.139.37.240:28286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/zwso.php"] [unique_id "apK86DAh5Y1i2tUxg4HbJQAABiI"] [Sat Aug 29 05:05:12.099426 2026] [security2:error] [pid 1018003:tid 1018229] [client 4.232.148.111:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "strangeworxproductions.strangeworx.com"] [uri "/wp-admin.php"] [unique_id "apK86DAh5Y1i2tUxg4HbJgAABgU"] [Sat Aug 29 05:05:12.103202 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.160.90:45925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/jg.php"] [unique_id "apK86CJcY4fy7tP-rU3bpgAAAmQ"] [Sat Aug 29 05:05:12.111058 2026] [security2:error] [pid 1018003:tid 1018164] [client 74.248.24.12:3355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-logs.php"] [unique_id "apK86DAh5Y1i2tUxg4HbKQAABcU"] [Sat Aug 29 05:05:12.113648 2026] [security2:error] [pid 1017536:tid 1017772] [client 177.131.19.63:12103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.19.131.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK86CJcY4fy7tP-rU3bqAAAAn4"] [Sat Aug 29 05:05:12.113856 2026] [security2:error] [pid 1017536:tid 1017772] [client 177.131.19.63:12103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK86CJcY4fy7tP-rU3bqAAAAn4"] [Sat Aug 29 05:05:12.118667 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.104.62:15319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/sef.php"] [unique_id "apK86DAh5Y1i2tUxg4HbKwAABhA"] [Sat Aug 29 05:05:12.121410 2026] [security2:error] [pid 1017536:tid 1017637] [remote 104.196.115.188:34074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/@fs/src/.env"] [unique_id "apK86CJcY4fy7tP-rU3blgACimQ"] [Sat Aug 29 05:05:12.122178 2026] [security2:error] [pid 1017536:tid 1017766] [client 20.48.160.90:64658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/haxor.php"] [unique_id "apK86CJcY4fy7tP-rU3bqwAAAng"] [Sat Aug 29 05:05:12.128130 2026] [security2:error] [pid 1017536:tid 1017735] [client 20.48.250.41:64252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/galer.php"] [unique_id "apK86CJcY4fy7tP-rU3brAAAAlk"] [Sat Aug 29 05:05:12.129801 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.250.41:64605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/ckk.php"] [unique_id "apK86DAh5Y1i2tUxg4HbLgAABcg"] [Sat Aug 29 05:05:12.129898 2026] [cgid:error] [pid 1018003:tid 1018045] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.130160 2026] [cgid:error] [pid 1018003:tid 1018047] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.131903 2026] [security2:error] [pid 1018003:tid 1018154] [client 20.104.18.15:13309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/av.php"] [unique_id "apK86DAh5Y1i2tUxg4HbMwAABbs"] [Sat Aug 29 05:05:12.131937 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.250.41:23429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wen.php"] [unique_id "apK86DAh5Y1i2tUxg4HbMgAABbo"] [Sat Aug 29 05:05:12.133135 2026] [security2:error] [pid 1018003:tid 1018051] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env"] [unique_id "apK86DAh5Y1i2tUxg4HbLAAGER4"] [Sat Aug 29 05:05:12.136070 2026] [security2:error] [pid 1017536:tid 1017783] [client 52.139.37.240:25036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-content/155.php"] [unique_id "apK86CJcY4fy7tP-rU3brgAAAok"] [Sat Aug 29 05:05:12.136842 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.63.219.114:18707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/flower.php"] [unique_id "apK86CJcY4fy7tP-rU3brQAAAkY"] [Sat Aug 29 05:05:12.139369 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.48.250.41:12406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/wp-scr1pts.php"] [unique_id "apK86CJcY4fy7tP-rU3brwAAAlQ"] [Sat Aug 29 05:05:12.141061 2026] [security2:error] [pid 1018003:tid 1018054] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/api/.env/public/.env"] [unique_id "apK86DAh5Y1i2tUxg4HbMAAGESE"] [Sat Aug 29 05:05:12.141877 2026] [cgid:error] [pid 1018003:tid 1018046] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.143537 2026] [cgid:error] [pid 1018003:tid 1018044] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.144034 2026] [cgid:error] [pid 1018003:tid 1018040] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.145986 2026] [cgid:error] [pid 1018003:tid 1018049] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml, referer: https://www.bigbuttonscarf.com [Sat Aug 29 05:05:12.149132 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.184.117:21862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known//index.php"] [unique_id "apK86DAh5Y1i2tUxg4HbOAAABgo"] [Sat Aug 29 05:05:12.151332 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.104.18.15:23545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ops.php"] [unique_id "apK86CJcY4fy7tP-rU3btAAAAjY"] [Sat Aug 29 05:05:12.156585 2026] [security2:error] [pid 1017536:tid 1017648] [remote 104.196.115.188:34074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/@fs/app/.env"] [unique_id "apK86CJcY4fy7tP-rU3buAACh28"] [Sat Aug 29 05:05:12.162910 2026] [cgid:error] [pid 1018003:tid 1018053] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.167204 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.104.18.15:47045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-aothait.php"] [unique_id "apK86DAh5Y1i2tUxg4HbOwAABdU"] [Sat Aug 29 05:05:12.168070 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.104.104.62:64755] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.motherssandals.com"] [uri "/r57.php"] [unique_id "apK86CJcY4fy7tP-rU3bvwAAAlw"] [Sat Aug 29 05:05:12.169233 2026] [cgid:error] [pid 1018003:tid 1018043] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.170951 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.104.18.15:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/file1221.php"] [unique_id "apK86CJcY4fy7tP-rU3bwgAAAn0"] [Sat Aug 29 05:05:12.188186 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.18.15:7147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wsd.php"] [unique_id "apK86DAh5Y1i2tUxg4HbPgAABis"] [Sat Aug 29 05:05:12.188593 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.48.251.3:57821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/localconf.php"] [unique_id "apK86DAh5Y1i2tUxg4HbPwAABfA"] [Sat Aug 29 05:05:12.189099 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.23.184.117:56689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/pomo.php"] [unique_id "apK86DAh5Y1i2tUxg4HbQAAABcM"] [Sat Aug 29 05:05:12.194110 2026] [security2:error] [pid 1017536:tid 1017744] [client 74.248.24.12:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/assets/images/doc.php"] [unique_id "apK86CJcY4fy7tP-rU3bygAAAmI"] [Sat Aug 29 05:05:12.200820 2026] [security2:error] [pid 1018003:tid 1018232] [client 195.178.110.155:17944] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "greathairkc.com"] [uri "/blog/"] [unique_id "apK86DAh5Y1i2tUxg4HbQQAABgg"] [Sat Aug 29 05:05:12.208863 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.104.62:48613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/fgd.php"] [unique_id "apK86DAh5Y1i2tUxg4HbQwAABdg"] [Sat Aug 29 05:05:12.211102 2026] [autoindex:error] [pid 1017536:tid 1017765] [client 74.7.241.32:0] AH01276: Cannot serve directory /home1/abmaccom/public_html/ibestek/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:12.212043 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.63.219.114:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/alfanew.php7"] [unique_id "apK86CJcY4fy7tP-rU3bzwAAAog"] [Sat Aug 29 05:05:12.212521 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.104.62:25642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/403.php"] [unique_id "apK86DAh5Y1i2tUxg4HbRAAABdg"] [Sat Aug 29 05:05:12.221240 2026] [security2:error] [pid 1018003:tid 1018221] [client 158.158.54.35:9949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wk/index.php"] [unique_id "apK86DAh5Y1i2tUxg4HbRQAABf4"] [Sat Aug 29 05:05:12.222863 2026] [security2:error] [pid 1018003:tid 1018172] [client 4.232.148.111:7621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-content/packed.php"] [unique_id "apK86DAh5Y1i2tUxg4HbRwAABc0"] [Sat Aug 29 05:05:12.224884 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.104.62:13715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/admin123.php"] [unique_id "apK86DAh5Y1i2tUxg4HbSAAABi4"] [Sat Aug 29 05:05:12.225953 2026] [security2:error] [pid 1017536:tid 1017764] [client 158.23.184.117:14352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-act.php"] [unique_id "apK86CJcY4fy7tP-rU3b0AAAAnY"] [Sat Aug 29 05:05:12.226265 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.104.104.62:53865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/ca4.php"] [unique_id "apK86DAh5Y1i2tUxg4HbSQAABcE"] [Sat Aug 29 05:05:12.229335 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.104.104.62:10436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/ad1.php"] [unique_id "apK86CJcY4fy7tP-rU3b0QAAAj0"] [Sat Aug 29 05:05:12.259499 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.48.160.90:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/yj.php"] [unique_id "apK86DAh5Y1i2tUxg4HbSwAABg8"] [Sat Aug 29 05:05:12.260744 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.104.62:14795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/admin123.php"] [unique_id "apK86CJcY4fy7tP-rU3b2AAAAkk"] [Sat Aug 29 05:05:12.261767 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.48.250.41:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jarritosmexico.com"] [uri "/R57.php"] [unique_id "apK86DAh5Y1i2tUxg4HbTAAABeM"] [Sat Aug 29 05:05:12.261929 2026] [security2:error] [pid 1017536:tid 1017706] [client 93.152.221.156:59790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.nme.cle.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "apK86CJcY4fy7tP-rU3b1wAAAjw"] [Sat Aug 29 05:05:12.264404 2026] [security2:error] [pid 1017536:tid 1017777] [client 216.26.239.122:10311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.239.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK86CJcY4fy7tP-rU3b1AAAAoM"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:12.273445 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.48.160.90:64677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/google.php"] [unique_id "apK86DAh5Y1i2tUxg4HbTQAABjE"] [Sat Aug 29 05:05:12.274256 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.48.250.41:12404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/num.php"] [unique_id "apK86DAh5Y1i2tUxg4HbTgAABjI"] [Sat Aug 29 05:05:12.274363 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.18.15:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/images.php"] [unique_id "apK86DAh5Y1i2tUxg4HbTwAABeU"] [Sat Aug 29 05:05:12.297860 2026] [security2:error] [pid 1018003:tid 1018213] [client 52.139.37.240:28267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/admin/function.php"] [unique_id "apK86DAh5Y1i2tUxg4HbUQAABfY"] [Sat Aug 29 05:05:12.298897 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.18.15:23532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/coffexium.php"] [unique_id "apK86CJcY4fy7tP-rU3b4gAAAj8"] [Sat Aug 29 05:05:12.299088 2026] [security2:error] [pid 1018003:tid 1018193] [client 52.139.37.240:65302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/contentloader1.php"] [unique_id "apK86DAh5Y1i2tUxg4HbUgAABeI"] [Sat Aug 29 05:05:12.300353 2026] [security2:error] [pid 1018003:tid 1018254] [client 158.23.184.117:22194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/about.php"] [unique_id "apK86DAh5Y1i2tUxg4HbUwAABh4"] [Sat Aug 29 05:05:12.301895 2026] [security2:error] [pid 1018003:tid 1018225] [client 168.107.94.195:49257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK86DAh5Y1i2tUxg4HbVAAABgI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:12.305632 2026] [security2:error] [pid 1018003:tid 1018251] [client 20.48.250.41:62278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/baixy.php"] [unique_id "apK86DAh5Y1i2tUxg4HbVQAABhs"] [Sat Aug 29 05:05:12.310383 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.18.15:47040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-includes/index.php"] [unique_id "apK86DAh5Y1i2tUxg4HbVwAABc8"] [Sat Aug 29 05:05:12.314907 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.250.41:58604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/maraz.php"] [unique_id "apK86CJcY4fy7tP-rU3b5AAAAlc"] [Sat Aug 29 05:05:12.331157 2026] [security2:error] [pid 1018003:tid 1018057] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/img../.env"] [unique_id "apK86DAh5Y1i2tUxg4HbWAAGNiQ"] [Sat Aug 29 05:05:12.333171 2026] [security2:error] [pid 1017536:tid 1017777] [client 52.139.37.240:24822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-update.php"] [unique_id "apK86CJcY4fy7tP-rU3b5gAAAoM"] [Sat Aug 29 05:05:12.336977 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.250.41:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/inc.php"] [unique_id "apK86CJcY4fy7tP-rU3b5wAAApI"] [Sat Aug 29 05:05:12.344023 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.196.209.81:12396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/options.php"] [unique_id "apK86DAh5Y1i2tUxg4HbWgAABhU"] [Sat Aug 29 05:05:12.347304 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.251.3:57801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/bengi.php"] [unique_id "apK86DAh5Y1i2tUxg4HbXAAABcU"] [Sat Aug 29 05:05:12.350051 2026] [security2:error] [pid 1018003:tid 1018059] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/images../.env"] [unique_id "apK86DAh5Y1i2tUxg4HbWwAGFSY"] [Sat Aug 29 05:05:12.352269 2026] [core:error] [pid 1018003:tid 1018062] [remote 104.196.51.122:58654] AH10244: invalid URI path (/%2e%2e/.env) [Sat Aug 29 05:05:12.352766 2026] [security2:error] [pid 1018003:tid 1018061] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/assets../.env"] [unique_id "apK86DAh5Y1i2tUxg4HbXQAGFSg"] [Sat Aug 29 05:05:12.361570 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.104.104.62:13614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/7h.php"] [unique_id "apK86CJcY4fy7tP-rU3b9AAAAl8"] [Sat Aug 29 05:05:12.367345 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.104.62:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/x0x.php"] [unique_id "apK86DAh5Y1i2tUxg4HbYgAABek"] [Sat Aug 29 05:05:12.367965 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.104.104.62:44567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/1vbqo.php"] [unique_id "apK86DAh5Y1i2tUxg4HbYwAABdY"] [Sat Aug 29 05:05:12.370628 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.18.15:36754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/nox.php"] [unique_id "apK86DAh5Y1i2tUxg4HbZAAABik"] [Sat Aug 29 05:05:12.375573 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.197.61.180:16974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eeeaudio.com"] [uri "/wp-content/languages/min.php"] [unique_id "apK86CJcY4fy7tP-rU3b9gAAAkQ"] [Sat Aug 29 05:05:12.376836 2026] [security2:error] [pid 1017536:tid 1017700] [client 158.23.184.117:14395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/fff.php"] [unique_id "apK86CJcY4fy7tP-rU3b9wAAAjY"] [Sat Aug 29 05:05:12.383141 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.196.209.81:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/alumni_reg.php"] [unique_id "apK86CJcY4fy7tP-rU3b-QAAAio"] [Sat Aug 29 05:05:12.395736 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.104.62:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/7h.php"] [unique_id "apK86DAh5Y1i2tUxg4HbZgAABiA"] [Sat Aug 29 05:05:12.398431 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.160.90:23242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/zi.php"] [unique_id "apK86CJcY4fy7tP-rU3b_gAAAiM"] [Sat Aug 29 05:05:12.403008 2026] [security2:error] [pid 1017536:tid 1017779] [client 93.152.221.156:59790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.nme.cle.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "apK86CJcY4fy7tP-rU3b_QAAAoU"] [Sat Aug 29 05:05:12.412093 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.18.15:7110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/bulet.php"] [unique_id "apK86CJcY4fy7tP-rU3b_wAAAi0"] [Sat Aug 29 05:05:12.414287 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.104.62:25645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/ava.php"] [unique_id "apK86DAh5Y1i2tUxg4HbZwAABgM"] [Sat Aug 29 05:05:12.414841 2026] [security2:error] [pid 1018003:tid 1018197] [client 68.155.159.216:58268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK86DAh5Y1i2tUxg4HbaAAABeY"] [Sat Aug 29 05:05:12.416239 2026] [security2:error] [pid 1017536:tid 1017724] [client 4.232.148.111:21789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/disagraeosc.php"] [unique_id "apK86CJcY4fy7tP-rU3cAQAAAk4"] [Sat Aug 29 05:05:12.416402 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.18.15:13188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ops.php"] [unique_id "apK86CJcY4fy7tP-rU3cAgAAAjQ"] [Sat Aug 29 05:05:12.417805 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.147.79:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK86CJcY4fy7tP-rU3cAwAAAkM"] [Sat Aug 29 05:05:12.419892 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/hehehehe.php"] [unique_id "apK86CJcY4fy7tP-rU3cBAAAAks"] [Sat Aug 29 05:05:12.423462 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.104.49.130:47956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/makeasmtp.php"] [unique_id "apK86DAh5Y1i2tUxg4HbagAABcw"] [Sat Aug 29 05:05:12.425490 2026] [security2:error] [pid 1017536:tid 1017778] [client 68.155.159.216:51521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK86CJcY4fy7tP-rU3cBQAAAoQ"] [Sat Aug 29 05:05:12.434972 2026] [security2:error] [pid 1017536:tid 1017690] [client 143.244.57.82:48296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wincosir.enproftp.com"] [uri "/xmlrpc.php"] [unique_id "apK86CJcY4fy7tP-rU3cBwAAAiw"] [Sat Aug 29 05:05:12.435662 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.48.160.90:62657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apK86DAh5Y1i2tUxg4HbawAABbg"] [Sat Aug 29 05:05:12.443078 2026] [security2:error] [pid 1018003:tid 1018158] [client 20.104.18.15:46998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/file31.php"] [unique_id "apK86DAh5Y1i2tUxg4HbbQAABb8"] [Sat Aug 29 05:05:12.446182 2026] [security2:error] [pid 1018003:tid 1018064] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/uploads../.env"] [unique_id "apK86DAh5Y1i2tUxg4HbbAAF_Ss"] [Sat Aug 29 05:05:12.448891 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.18.15:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/BDKR28WP.php"] [unique_id "apK86CJcY4fy7tP-rU3cCQAAAjE"] [Sat Aug 29 05:05:12.452009 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.250.41:61822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/kbfr.php"] [unique_id "apK86CJcY4fy7tP-rU3cCgAAAmI"] [Sat Aug 29 05:05:12.454872 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:12332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/a4.php"] [unique_id "apK86CJcY4fy7tP-rU3cCwAAAmM"] [Sat Aug 29 05:05:12.456754 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.250.41:64153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/ava.php"] [unique_id "apK86DAh5Y1i2tUxg4HbbgAABdc"] [Sat Aug 29 05:05:12.476950 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.203.141.11:41365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK86DAh5Y1i2tUxg4HbcAAABdA"] [Sat Aug 29 05:05:12.481296 2026] [security2:error] [pid 1017536:tid 1017727] [client 158.23.184.117:56647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-admin/link-add.php"] [unique_id "apK86CJcY4fy7tP-rU3cDQAAAlE"] [Sat Aug 29 05:05:12.484873 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.251.3:57905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/i.php"] [unique_id "apK86CJcY4fy7tP-rU3cDgAAAmA"] [Sat Aug 29 05:05:12.494850 2026] [security2:error] [pid 1017536:tid 1017786] [client 52.139.37.240:64233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/zoom1.php"] [unique_id "apK86CJcY4fy7tP-rU3cEwAAAow"] [Sat Aug 29 05:05:12.498908 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.104.62:13758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/wp-gzone.php"] [unique_id "apK86DAh5Y1i2tUxg4HbcwAABb0"] [Sat Aug 29 05:05:12.499765 2026] [security2:error] [pid 1018003:tid 1018233] [client 52.139.37.240:38087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/upfile.php"] [unique_id "apK86DAh5Y1i2tUxg4HbdAAABgk"] [Sat Aug 29 05:05:12.499879 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.104.62:20640] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.motherssandals.com"] [uri "/r57.php"] [unique_id "apK86CJcY4fy7tP-rU3cFQAAAlY"] [Sat Aug 29 05:05:12.501112 2026] [security2:error] [pid 1018003:tid 1018232] [client 20.104.18.15:36685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/akismet.php"] [unique_id "apK86DAh5Y1i2tUxg4HbdQAABgg"] [Sat Aug 29 05:05:12.501657 2026] [security2:error] [pid 1018003:tid 1018089] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/var/task/.env"] [unique_id "apK86DAh5Y1i2tUxg4HbcgAF-EQ"] [Sat Aug 29 05:05:12.502985 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.104.62:44595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/h02ugyh.php"] [unique_id "apK86DAh5Y1i2tUxg4HbdgAABds"] [Sat Aug 29 05:05:12.503025 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.104.62:65235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bv-place.com"] [uri "/fesa.php"] [unique_id "apK86DAh5Y1i2tUxg4HbdwAABe8"] [Sat Aug 29 05:05:12.505793 2026] [cgid:error] [pid 1018003:tid 1018072] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.508704 2026] [cgid:error] [pid 1018003:tid 1018076] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.527761 2026] [security2:error] [pid 1017536:tid 1017680] [client 158.23.184.117:14386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/.tmb/dropdown.php"] [unique_id "apK86CJcY4fy7tP-rU3cGAAAAiI"] [Sat Aug 29 05:05:12.527931 2026] [security2:error] [pid 1017536:tid 1017705] [client 52.139.37.240:58583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/xmrlpc.php"] [unique_id "apK86CJcY4fy7tP-rU3cGQAAAjs"] [Sat Aug 29 05:05:12.528028 2026] [security2:error] [pid 1017536:tid 1017719] [client 4.205.62.107:64311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/asdf.php"] [unique_id "apK86CJcY4fy7tP-rU3cGgAAAkk"] [Sat Aug 29 05:05:12.529482 2026] [cgid:error] [pid 1018003:tid 1018077] [remote 104.196.51.122:58654] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:12.533642 2026] [security2:error] [pid 1017536:tid 1017735] [client 158.23.184.117:22152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK86CJcY4fy7tP-rU3cHAAAAlk"] [Sat Aug 29 05:05:12.536398 2026] [security2:error] [pid 1017536:tid 1017783] [client 4.205.62.107:21607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK86CJcY4fy7tP-rU3cHwAAAok"] [Sat Aug 29 05:05:12.541676 2026] [lsapi:warn] [pid 1018003:tid 1018022] [remote 104.28.132.8:16569] [host thegrowingplace.ca] Backend log: PHP Warning: Trying to access array offset on value of type null in /home1/thegrow2/public_html/w_api/Configuration.php on line 115\n, referer: https://thegrowingplace.ca/index.html [Sat Aug 29 05:05:12.544329 2026] [security2:error] [pid 1017536:tid 1017694] [client 68.155.159.216:64857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK86CJcY4fy7tP-rU3cIAAAAjA"] [Sat Aug 29 05:05:12.545050 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.48.160.90:26747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/ue.php"] [unique_id "apK86DAh5Y1i2tUxg4HbewAABjQ"] [Sat Aug 29 05:05:12.545070 2026] [security2:error] [pid 1017536:tid 1017678] [client 40.83.93.50:3631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK86CJcY4fy7tP-rU3cIQAAAiA"] [Sat Aug 29 05:05:12.545566 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.18.15:7136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/av.php"] [unique_id "apK86DAh5Y1i2tUxg4HbfAAABf4"] [Sat Aug 29 05:05:12.546333 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.63.219.114:18708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/meta.php"] [unique_id "apK86DAh5Y1i2tUxg4HbfQAABbk"] [Sat Aug 29 05:05:12.548139 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.104.62:14792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/wp-gzone.php"] [unique_id "apK86CJcY4fy7tP-rU3cIgAAAj8"] [Sat Aug 29 05:05:12.551302 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.18.15:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/coffexium.php"] [unique_id "apK86DAh5Y1i2tUxg4HbfwAABc0"] [Sat Aug 29 05:05:12.569366 2026] [security2:error] [pid 1017536:tid 1017754] [client 35.159.236.187:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.jobindjibouti.com"] [uri "/jobs/"] [unique_id "apK86CJcY4fy7tP-rU3cIwAAAmw"] [Sat Aug 29 05:05:12.571419 2026] [security2:error] [pid 1018003:tid 1018199] [client 45.154.98.191:49233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.acovib.com"] [uri "/xmlrpc.php"] [unique_id "apK86DAh5Y1i2tUxg4HbfgAABeg"] [Sat Aug 29 05:05:12.574414 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.250.41:23519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/6bcwiqwj.php"] [unique_id "apK86DAh5Y1i2tUxg4HbggAABgY"] [Sat Aug 29 05:05:12.574848 2026] [security2:error] [pid 1018003:tid 1018080] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK86DAh5Y1i2tUxg4HbgQAGFzs"] [Sat Aug 29 05:05:12.575547 2026] [security2:error] [pid 1018003:tid 1018257] [client 158.23.147.79:30695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/chosen.php"] [unique_id "apK86DAh5Y1i2tUxg4HbgwAABiE"] [Sat Aug 29 05:05:12.578151 2026] [security2:error] [pid 1017536:tid 1017767] [client 68.155.159.216:16361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/NewFile.php/"] [unique_id "apK86CJcY4fy7tP-rU3cJwAAAnk"] [Sat Aug 29 05:05:12.578903 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.160.90:28670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/robots.php"] [unique_id "apK86CJcY4fy7tP-rU3cJgAAAos"] [Sat Aug 29 05:05:12.602230 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.48.250.41:61701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/wp-act.php"] [unique_id "apK86CJcY4fy7tP-rU3cKQAAAmU"] [Sat Aug 29 05:05:12.606435 2026] [security2:error] [pid 1018003:tid 1018194] [client 68.155.159.216:16299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK86DAh5Y1i2tUxg4HbhgAABeM"] [Sat Aug 29 05:05:12.617788 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.104.62:25657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/info.php"] [unique_id "apK86CJcY4fy7tP-rU3cLgAAAkY"] [Sat Aug 29 05:05:12.619766 2026] [security2:error] [pid 1018003:tid 1018249] [client 74.248.24.12:8446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-admin/css/about.php"] [unique_id "apK86DAh5Y1i2tUxg4HbhwAABhk"] [Sat Aug 29 05:05:12.623024 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.18.15:23506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/sf.php"] [unique_id "apK86CJcY4fy7tP-rU3cNgAAAk0"] [Sat Aug 29 05:05:12.627712 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.63.219.114:19445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/xmlrpc.php0"] [unique_id "apK86CJcY4fy7tP-rU3cKgAAAlA"] [Sat Aug 29 05:05:12.629196 2026] [security2:error] [pid 1017536:tid 1017708] [client 158.23.184.117:61599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/Text.php"] [unique_id "apK86CJcY4fy7tP-rU3cNwAAAj4"] [Sat Aug 29 05:05:12.629505 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.104.18.15:47001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/dk.php"] [unique_id "apK86CJcY4fy7tP-rU3cOAAAAjY"] [Sat Aug 29 05:05:12.632636 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.104.62:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/str.php"] [unique_id "apK86DAh5Y1i2tUxg4HbiAAABhY"] [Sat Aug 29 05:05:12.643187 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.251.3:57825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/guk.php"] [unique_id "apK86CJcY4fy7tP-rU3cOgAAAho"] [Sat Aug 29 05:05:12.646203 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.250.41:64998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/gdn.php"] [unique_id "apK86CJcY4fy7tP-rU3cOwAAAm8"] [Sat Aug 29 05:05:12.647860 2026] [security2:error] [pid 1017536:tid 1017681] [client 4.205.62.107:22334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/phina.php"] [unique_id "apK86CJcY4fy7tP-rU3cPAAAAiM"] [Sat Aug 29 05:05:12.655765 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.250.41:12384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/tfm.php"] [unique_id "apK86DAh5Y1i2tUxg4HbiQAABfY"] [Sat Aug 29 05:05:12.664947 2026] [security2:error] [pid 1018003:tid 1018082] [remote 104.196.51.122:58654] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.bigbuttonscarf.com"] [uri "/api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK86DAh5Y1i2tUxg4HbiwAGEj0"] [Sat Aug 29 05:05:12.665847 2026] [security2:error] [pid 1018003:tid 1018084] [remote 104.196.51.122:58654] ModSecurity: Access denied with code 500 (phase 1) (Error: Connection drop requested but failed to close the socket). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.bigbuttonscarf.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "apK86DAh5Y1i2tUxg4HbjQAGEj8"] [Sat Aug 29 05:05:12.669954 2026] [security2:error] [pid 1017536:tid 1017772] [client 158.158.54.35:10875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/admin.php"] [unique_id "apK86CJcY4fy7tP-rU3cQwAAAn4"] [Sat Aug 29 05:05:12.678241 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.18.15:36815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/ajax.php"] [unique_id "apK86CJcY4fy7tP-rU3cRAAAAko"] [Sat Aug 29 05:05:12.678603 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.48.160.90:45915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/nv.php"] [unique_id "apK86DAh5Y1i2tUxg4HbjwAABi8"] [Sat Aug 29 05:05:12.680866 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.184.117:21884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "apK86DAh5Y1i2tUxg4HbkAAABbw"] [Sat Aug 29 05:05:12.681690 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.104.62:14365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/str.php"] [unique_id "apK86CJcY4fy7tP-rU3cRQAAAhs"] [Sat Aug 29 05:05:12.683266 2026] [security2:error] [pid 1017536:tid 1017689] [client 168.107.94.195:49529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK86CJcY4fy7tP-rU3cRgAAAis"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:12.684755 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.49.130:47809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/133.php"] [unique_id "apK86CJcY4fy7tP-rU3cSAAAAi0"] [Sat Aug 29 05:05:12.686636 2026] [security2:error] [pid 1017536:tid 1017723] [client 158.23.184.117:14347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/robots.php"] [unique_id "apK86CJcY4fy7tP-rU3cSgAAAk0"] [Sat Aug 29 05:05:12.686863 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.104.18.15:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/BDKR28WP.php"] [unique_id "apK86CJcY4fy7tP-rU3cSwAAAo8"] [Sat Aug 29 05:05:12.689123 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.18.15:7162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/images.php"] [unique_id "apK86DAh5Y1i2tUxg4HbkQAABgw"] [Sat Aug 29 05:05:12.693676 2026] [security2:error] [pid 1017536:tid 1017771] [client 52.139.37.240:56790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/about.php7"] [unique_id "apK86CJcY4fy7tP-rU3cUwAAAn0"] [Sat Aug 29 05:05:12.696385 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.104.104.62:44598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/shelp.php"] [unique_id "apK86DAh5Y1i2tUxg4HbkgAABjY"] [Sat Aug 29 05:05:12.698120 2026] [security2:error] [pid 1018003:tid 1018150] [client 52.139.37.240:37951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/form.php"] [unique_id "apK86DAh5Y1i2tUxg4HbkwAABbc"] [Sat Aug 29 05:05:12.705053 2026] [security2:error] [pid 1017536:tid 1017751] [client 4.232.148.111:1455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-admin/js/index.php"] [unique_id "apK86CJcY4fy7tP-rU3cVgAAAmk"] [Sat Aug 29 05:05:12.709491 2026] [security2:error] [pid 1017536:tid 1017774] [client 4.205.62.107:53324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/app_dev.php"] [unique_id "apK86CJcY4fy7tP-rU3cVwAAAoA"] [Sat Aug 29 05:05:12.720924 2026] [security2:error] [pid 1017536:tid 1017703] [client 158.23.147.79:24505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/content.php"] [unique_id "apK86CJcY4fy7tP-rU3cWAAAAjk"] [Sat Aug 29 05:05:12.720947 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.48.160.90:63512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apK86CJcY4fy7tP-rU3cWQAAAlw"] [Sat Aug 29 05:05:12.730171 2026] [security2:error] [pid 1018003:tid 1018212] [client 185.104.184.230:49402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "apK86DAh5Y1i2tUxg4HblQAABfU"] [Sat Aug 29 05:05:12.736277 2026] [security2:error] [pid 1017536:tid 1017779] [client 52.139.37.240:24638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/about/function.php"] [unique_id "apK86CJcY4fy7tP-rU3cWwAAAoU"] [Sat Aug 29 05:05:12.742130 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.196.209.81:17929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/panel.php"] [unique_id "apK86DAh5Y1i2tUxg4HblgAABdQ"] [Sat Aug 29 05:05:12.757436 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.147.79:23453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/wp-content/packed.php"] [unique_id "apK86CJcY4fy7tP-rU3cXwAAAnc"] [Sat Aug 29 05:05:12.762249 2026] [security2:error] [pid 1017536:tid 1017670] [client 74.248.24.12:35473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/bgymj.php"] [unique_id "apK86CJcY4fy7tP-rU3cYAAAAhg"] [Sat Aug 29 05:05:12.771305 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.104.62:13744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/mega.php"] [unique_id "apK86CJcY4fy7tP-rU3cYQAAAhw"] [Sat Aug 29 05:05:12.779616 2026] [security2:error] [pid 1017536:tid 1017728] [client 158.23.184.117:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-trackback.php"] [unique_id "apK86CJcY4fy7tP-rU3cZAAAAlI"] [Sat Aug 29 05:05:12.781672 2026] [security2:error] [pid 1017536:tid 1017742] [client 4.205.62.107:2901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/upload.form.php"] [unique_id "apK86CJcY4fy7tP-rU3cZQAAAmA"] [Sat Aug 29 05:05:12.785418 2026] [security2:error] [pid 1017536:tid 1017606] [remote 104.196.115.188:34074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/static../.env"] [unique_id "apK86CJcY4fy7tP-rU3cZgACf0U"] [Sat Aug 29 05:05:12.791384 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.18.15:23528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/k.php"] [unique_id "apK86DAh5Y1i2tUxg4HbmAAABik"] [Sat Aug 29 05:05:12.796758 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.196.209.81:15165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/colors.php"] [unique_id "apK86DAh5Y1i2tUxg4HbmQAABc8"] [Sat Aug 29 05:05:12.801895 2026] [security2:error] [pid 1017536:tid 1017611] [remote 104.196.115.188:34074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.env"] [unique_id "apK86CJcY4fy7tP-rU3cagACPUo"] [Sat Aug 29 05:05:12.806475 2026] [security2:error] [pid 1017536:tid 1017615] [remote 104.196.115.188:34074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.env"] [unique_id "apK86CJcY4fy7tP-rU3cbgACPU4"] [Sat Aug 29 05:05:12.807273 2026] [security2:error] [pid 1017536:tid 1017616] [remote 104.196.115.188:34074] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "infinitidealership.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK86CJcY4fy7tP-rU3ccAACPU8"] [Sat Aug 29 05:05:12.807445 2026] [security2:error] [pid 1017536:tid 1017614] [remote 104.196.115.188:34074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/media../.env"] [unique_id "apK86CJcY4fy7tP-rU3cbwACPU0"] [Sat Aug 29 05:05:12.807680 2026] [security2:error] [pid 1017536:tid 1017688] [client 104.207.45.88:46959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.45.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK86CJcY4fy7tP-rU3cZwAAAio"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:12.810727 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.160.90:45835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/jw.php"] [unique_id "apK86CJcY4fy7tP-rU3ccgAAAlU"] [Sat Aug 29 05:05:12.813069 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.48.250.41:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/f2.php"] [unique_id "apK86CJcY4fy7tP-rU3cdAAAAkc"] [Sat Aug 29 05:05:12.813276 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.104.62:25805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/wp-admin/admin.php"] [unique_id "apK86CJcY4fy7tP-rU3cdQAAAkE"] [Sat Aug 29 05:05:12.817314 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.104.62:14393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/mega.php"] [unique_id "apK86DAh5Y1i2tUxg4HbmgAABcc"] [Sat Aug 29 05:05:12.817615 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.48.250.41:23438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/easy.php"] [unique_id "apK86DAh5Y1i2tUxg4HbmwAABfI"] [Sat Aug 29 05:05:12.818185 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.251.3:57903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/config_dev.php"] [unique_id "apK86DAh5Y1i2tUxg4HbnAAABd8"] [Sat Aug 29 05:05:12.824954 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.18.15:13140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/sf.php"] [unique_id "apK86DAh5Y1i2tUxg4HbnQAABhA"] [Sat Aug 29 05:05:12.830900 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.104.62:44560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/13ede.php"] [unique_id "apK86CJcY4fy7tP-rU3ceQAAAjs"] [Sat Aug 29 05:05:12.833937 2026] [core:error] [pid 1017536:tid 1017710] [client 158.23.184.117:21832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:12.833954 2026] [core:error] [pid 1017536:tid 1017710] [client 158.23.184.117:21832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:12.839519 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.104.62:64737] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.motherssandals.com"] [uri "/r57.php"] [unique_id "apK86CJcY4fy7tP-rU3cegAAAok"] [Sat Aug 29 05:05:12.843161 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.18.15:7049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ops.php"] [unique_id "apK86CJcY4fy7tP-rU3cewAAAjA"] [Sat Aug 29 05:05:12.845722 2026] [security2:error] [pid 1018003:tid 1018237] [client 20.104.18.15:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/atomlib.php"] [unique_id "apK86DAh5Y1i2tUxg4HbngAABg0"] [Sat Aug 29 05:05:12.847340 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.48.250.41:61711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/24.php"] [unique_id "apK86DAh5Y1i2tUxg4HbnwAABig"] [Sat Aug 29 05:05:12.848056 2026] [security2:error] [pid 1017536:tid 1017666] [client 68.155.159.216:18243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK86CJcY4fy7tP-rU3cfAAAAhQ"] [Sat Aug 29 05:05:12.855602 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.184.117:14489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/.well-known/install.php"] [unique_id "apK86CJcY4fy7tP-rU3cfQAAAlg"] [Sat Aug 29 05:05:12.867884 2026] [security2:error] [pid 1018003:tid 1018260] [client 20.48.250.41:12350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/Geforce.php"] [unique_id "apK86DAh5Y1i2tUxg4HboAAABiQ"] [Sat Aug 29 05:05:12.870566 2026] [security2:error] [pid 1017536:tid 1017749] [client 68.155.159.216:14169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/themes/index.php"] [unique_id "apK86CJcY4fy7tP-rU3cfgAAAmc"] [Sat Aug 29 05:05:12.871730 2026] [security2:error] [pid 1017536:tid 1017766] [client 68.155.159.216:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK86CJcY4fy7tP-rU3cfwAAAng"] [Sat Aug 29 05:05:12.873326 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.48.160.90:62611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apK86DAh5Y1i2tUxg4HboQAABfw"] [Sat Aug 29 05:05:12.883638 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.18.15:47002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/ta.php"] [unique_id "apK86CJcY4fy7tP-rU3cgAAAAoM"] [Sat Aug 29 05:05:12.890524 2026] [security2:error] [pid 1017536:tid 1017746] [client 52.139.37.240:27927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/cron.php"] [unique_id "apK86CJcY4fy7tP-rU3cgwAAAmQ"] [Sat Aug 29 05:05:12.894774 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.63.81.20:26519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK86CJcY4fy7tP-rU3chAAAAjg"] [Sat Aug 29 05:05:12.899888 2026] [security2:error] [pid 1017536:tid 1017784] [client 52.139.37.240:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/wp-sigunq.php"] [unique_id "apK86CJcY4fy7tP-rU3chQAAAoo"] [Sat Aug 29 05:05:12.900594 2026] [security2:error] [pid 1017536:tid 1017741] [client 216.73.217.8:20691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo-store.sortthru.com"] [uri "/wp-admin/core.php"] [unique_id "apK86CJcY4fy7tP-rU3chgAAAl8"] [Sat Aug 29 05:05:12.902016 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.104.62:13579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/ww3.php"] [unique_id "apK86DAh5Y1i2tUxg4HbowAABjM"] [Sat Aug 29 05:05:12.917684 2026] [security2:error] [pid 1017536:tid 1017781] [client 4.232.148.111:8515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-logs.php"] [unique_id "apK86CJcY4fy7tP-rU3cigAAAoc"] [Sat Aug 29 05:05:12.930051 2026] [security2:error] [pid 1017536:tid 1017758] [client 158.23.184.117:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-admin/maint.php"] [unique_id "apK86CJcY4fy7tP-rU3cjAAAAnA"] [Sat Aug 29 05:05:12.934186 2026] [access_compat:error] [pid 1017536:tid 1017672] [client 67.20.76.220:23054] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:12.943857 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.48.160.90:39953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/or.php"] [unique_id "apK86DAh5Y1i2tUxg4HbqQAABio"] [Sat Aug 29 05:05:12.948075 2026] [security2:error] [pid 1018003:tid 1018226] [client 52.139.37.240:25045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/an.php"] [unique_id "apK86DAh5Y1i2tUxg4HbrAAABgM"] [Sat Aug 29 05:05:12.948969 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.203.141.11:31017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/gmo.php"] [unique_id "apK86DAh5Y1i2tUxg4HbrQAABbo"] [Sat Aug 29 05:05:12.950398 2026] [access_compat:error] [pid 1017536:tid 1017739] [client 67.20.76.220:23052] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:12.951011 2026] [access_compat:error] [pid 1017536:tid 1017708] [client 67.20.76.220:23062] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:12.951836 2026] [access_compat:error] [pid 1018003:tid 1018218] [client 67.20.76.220:23040] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:12.959588 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.18.15:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/82.php"] [unique_id "apK86DAh5Y1i2tUxg4HbrgAABb0"] [Sat Aug 29 05:05:12.960526 2026] [security2:error] [pid 1018003:tid 1018232] [client 20.104.104.62:14376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/ww3.php"] [unique_id "apK86DAh5Y1i2tUxg4HbsAAABgg"] [Sat Aug 29 05:05:12.960557 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.104.62:44585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/k8.php"] [unique_id "apK86DAh5Y1i2tUxg4HbrwAABgk"] [Sat Aug 29 05:05:12.960749 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.63.219.114:9182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/randkeyword.php"] [unique_id "apK86CJcY4fy7tP-rU3cmQAAAlQ"] [Sat Aug 29 05:05:12.961114 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.18.15:13227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/k.php"] [unique_id "apK86CJcY4fy7tP-rU3cmgAAAk0"] [Sat Aug 29 05:05:12.968499 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.251.3:57812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws_credentials.php"] [unique_id "apK86DAh5Y1i2tUxg4HbsgAABds"] [Sat Aug 29 05:05:12.983103 2026] [security2:error] [pid 1017536:tid 1017681] [client 158.23.184.117:21849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK86CJcY4fy7tP-rU3cnQAAAiM"] [Sat Aug 29 05:05:12.983645 2026] [security2:error] [pid 1017536:tid 1017675] [client 143.244.57.82:48312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK86CJcY4fy7tP-rU3cngAAAh0"] [Sat Aug 29 05:05:12.986010 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.104.18.15:7158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/coffexium.php"] [unique_id "apK86DAh5Y1i2tUxg4HbswAABhg"] [Sat Aug 29 05:05:13.012508 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.250.41:23504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/fresh3.php"] [unique_id "apK86SJcY4fy7tP-rU3cqQAAAoI"] [Sat Aug 29 05:05:13.013249 2026] [security2:error] [pid 1018003:tid 1018187] [client 40.83.93.50:3594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK86TAh5Y1i2tUxg4HbtwAABdw"] [Sat Aug 29 05:05:13.013560 2026] [security2:error] [pid 1018003:tid 1018169] [client 87.219.197.128:49616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK86TAh5Y1i2tUxg4HbtQAABco"] [Sat Aug 29 05:05:13.013637 2026] [security2:error] [pid 1018003:tid 1018169] [client 87.219.197.128:49616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK86TAh5Y1i2tUxg4HbtQAABco"] [Sat Aug 29 05:05:13.015317 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.160.90:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apK86SJcY4fy7tP-rU3cqwAAAmI"] [Sat Aug 29 05:05:13.015638 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/grsiuk.php"] [unique_id "apK86SJcY4fy7tP-rU3crAAAAmM"] [Sat Aug 29 05:05:13.020157 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.104.62:25646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/wp-content/plugins/about.php"] [unique_id "apK86TAh5Y1i2tUxg4HbuQAABis"] [Sat Aug 29 05:05:13.021893 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.63.81.20:26578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK86SJcY4fy7tP-rU3crQAAAik"] [Sat Aug 29 05:05:13.024290 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.104.18.15:47010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/bo.php"] [unique_id "apK86SJcY4fy7tP-rU3crgAAAiY"] [Sat Aug 29 05:05:13.025725 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.104.18.15:36755] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "amandaandandrew.strangeworx.com"] [uri "/1.php"] [unique_id "apK86SJcY4fy7tP-rU3crwAAAog"] [Sat Aug 29 05:05:13.025793 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.104.18.15:36755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/1.php"] [unique_id "apK86SJcY4fy7tP-rU3crwAAAog"] [Sat Aug 29 05:05:13.026038 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.48.250.41:58578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/155.php"] [unique_id "apK86SJcY4fy7tP-rU3csAAAApA"] [Sat Aug 29 05:05:13.030939 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.104.104.62:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/sko.php"] [unique_id "apK86SJcY4fy7tP-rU3csgAAAlE"] [Sat Aug 29 05:05:13.049565 2026] [security2:error] [pid 1017536:tid 1017728] [client 158.23.184.117:14358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-admin/about.php"] [unique_id "apK86SJcY4fy7tP-rU3ctgAAAlI"] [Sat Aug 29 05:05:13.058073 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.48.250.41:12444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/click.php"] [unique_id "apK86TAh5Y1i2tUxg4HbvAAABiE"] [Sat Aug 29 05:05:13.063440 2026] [security2:error] [pid 1017536:tid 1017719] [client 168.107.94.195:49832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK86SJcY4fy7tP-rU3cuQAAAkk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:13.071580 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.63.219.114:15277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/content.php"] [unique_id "apK86SJcY4fy7tP-rU3cugAAAmo"] [Sat Aug 29 05:05:13.074018 2026] [security2:error] [pid 1017536:tid 1017669] [client 47.128.99.16:26934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "antiquesweeknh.com"] [uri "/robots.txt"] [unique_id "apK86SJcY4fy7tP-rU3cvwAAAhc"] [Sat Aug 29 05:05:13.074453 2026] [security2:error] [pid 1017536:tid 1017670] [client 158.23.184.117:56699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/num.php"] [unique_id "apK86SJcY4fy7tP-rU3cvgAAAhg"] [Sat Aug 29 05:05:13.083188 2026] [security2:error] [pid 1017536:tid 1017763] [client 103.185.242.143:58448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK86SJcY4fy7tP-rU3cwAAAAnU"] [Sat Aug 29 05:05:13.083309 2026] [security2:error] [pid 1017536:tid 1017763] [client 103.185.242.143:58448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK86SJcY4fy7tP-rU3cwAAAAnU"] [Sat Aug 29 05:05:13.086316 2026] [security2:error] [pid 1018003:tid 1018191] [client 52.139.37.240:28236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/wp-2019.php"] [unique_id "apK86TAh5Y1i2tUxg4HbvgAABeA"] [Sat Aug 29 05:05:13.090685 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.104.18.15:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/82.php"] [unique_id "apK86TAh5Y1i2tUxg4HbvwAABjE"] [Sat Aug 29 05:05:13.091014 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.104.62:10442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/alog.php"] [unique_id "apK86SJcY4fy7tP-rU3cwgAAAok"] [Sat Aug 29 05:05:13.094184 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.104.18.15:23527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/dex.php"] [unique_id "apK86SJcY4fy7tP-rU3cwwAAAnw"] [Sat Aug 29 05:05:13.095380 2026] [security2:error] [pid 1017536:tid 1017671] [client 20.197.61.180:19935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eeeaudio.com"] [uri "/wp-content/languages/pk.php"] [unique_id "apK86SJcY4fy7tP-rU3cxAAAAhk"] [Sat Aug 29 05:05:13.098369 2026] [security2:error] [pid 1017536:tid 1017674] [client 52.139.37.240:37891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "skyyentertainment.skyytalent.com"] [uri "/07.php"] [unique_id "apK86SJcY4fy7tP-rU3cxQAAAhw"] [Sat Aug 29 05:05:13.105408 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.104.104.62:15305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/sko.php"] [unique_id "apK86TAh5Y1i2tUxg4HbwAAABfc"] [Sat Aug 29 05:05:13.108534 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.48.251.3:57874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws-credentials.php"] [unique_id "apK86SJcY4fy7tP-rU3cxgAAAjI"] [Sat Aug 29 05:05:13.111078 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.160.90:40000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/ile56.php"] [unique_id "apK86SJcY4fy7tP-rU3cxwAAAnk"] [Sat Aug 29 05:05:13.119582 2026] [security2:error] [pid 1017536:tid 1017740] [client 158.158.54.35:6016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/php8.php"] [unique_id "apK86SJcY4fy7tP-rU3cyAAAAl4"] [Sat Aug 29 05:05:13.123401 2026] [security2:error] [pid 1018003:tid 1018210] [client 74.248.24.12:25724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/system_log.php"] [unique_id "apK86TAh5Y1i2tUxg4HbwgAABfM"] [Sat Aug 29 05:05:13.129996 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.184.117:21834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "apK86SJcY4fy7tP-rU3czAAAAiA"] [Sat Aug 29 05:05:13.131607 2026] [security2:error] [pid 1018003:tid 1018095] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/.env"] [unique_id "apK86TAh5Y1i2tUxg4HbxQAGFko"] [Sat Aug 29 05:05:13.132598 2026] [security2:error] [pid 1018003:tid 1018097] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/.env"] [unique_id "apK86TAh5Y1i2tUxg4HbxgAGFkw"] [Sat Aug 29 05:05:13.135381 2026] [security2:error] [pid 1018003:tid 1018098] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/.env"] [unique_id "apK86TAh5Y1i2tUxg4HbygAGFk0"] [Sat Aug 29 05:05:13.139180 2026] [security2:error] [pid 1018003:tid 1018193] [client 20.104.18.15:7072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/BDKR28WP.php"] [unique_id "apK86TAh5Y1i2tUxg4HbzAAABeI"] [Sat Aug 29 05:05:13.140191 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.196.209.81:17927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/pk.php"] [unique_id "apK86SJcY4fy7tP-rU3czgAAAjk"] [Sat Aug 29 05:05:13.140996 2026] [security2:error] [pid 1018003:tid 1018247] [client 52.139.37.240:20748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/ahax.php"] [unique_id "apK86TAh5Y1i2tUxg4HbzQAABhc"] [Sat Aug 29 05:05:13.153648 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.104.18.15:36705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/samll.php"] [unique_id "apK86TAh5Y1i2tUxg4HbzgAABfY"] [Sat Aug 29 05:05:13.154448 2026] [security2:error] [pid 1017536:tid 1017709] [client 52.139.37.240:25057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/asw.php"] [unique_id "apK86SJcY4fy7tP-rU3c0AAAAj8"] [Sat Aug 29 05:05:13.160830 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.104.62:13742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/zoz.php"] [unique_id "apK86SJcY4fy7tP-rU3c0QAAAkY"] [Sat Aug 29 05:05:13.161042 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.160.90:63507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apK86SJcY4fy7tP-rU3c0gAAAkQ"] [Sat Aug 29 05:05:13.168574 2026] [security2:error] [pid 1018003:tid 1018099] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.bigbuttonscarf.com"] [uri "/wp-config.php.bak"] [unique_id "apK86TAh5Y1i2tUxg4Hb0AAGAU4"] [Sat Aug 29 05:05:13.168871 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.250.41:64166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/wp-scr1pts.php"] [unique_id "apK86SJcY4fy7tP-rU3c1AAAAm8"] [Sat Aug 29 05:05:13.183739 2026] [security2:error] [pid 1018003:tid 1018255] [client 4.232.148.111:19930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/core.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb0QAABh8"] [Sat Aug 29 05:05:13.189986 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.250.41:23498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/bgymj.php"] [unique_id "apK86SJcY4fy7tP-rU3c1gAAAjw"] [Sat Aug 29 05:05:13.197563 2026] [security2:error] [pid 1017536:tid 1017702] [client 158.23.184.117:14356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-content/backup.php"] [unique_id "apK86SJcY4fy7tP-rU3c2AAAAjg"] [Sat Aug 29 05:05:13.208838 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.63.81.20:26526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/adminfuns.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb0gAABjY"] [Sat Aug 29 05:05:13.220252 2026] [security2:error] [pid 1017536:tid 1017758] [client 158.23.184.117:56685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/identity.php"] [unique_id "apK86SJcY4fy7tP-rU3c2gAAAnA"] [Sat Aug 29 05:05:13.220997 2026] [security2:error] [pid 1018003:tid 1018150] [client 20.48.250.41:58526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/file.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb0wAABbc"] [Sat Aug 29 05:05:13.223827 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.104.104.62:44575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/adin.php"] [unique_id "apK86SJcY4fy7tP-rU3c3QAAAl0"] [Sat Aug 29 05:05:13.226669 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.104.62:25606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "apK86SJcY4fy7tP-rU3c3wAAAoE"] [Sat Aug 29 05:05:13.227393 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.196.209.81:5011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/Js.php"] [unique_id "apK86SJcY4fy7tP-rU3c4AAAAjA"] [Sat Aug 29 05:05:13.235297 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.104.62:14391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/zoz.php"] [unique_id "apK86SJcY4fy7tP-rU3c4QAAAik"] [Sat Aug 29 05:05:13.236271 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.104.18.15:47016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/44.php"] [unique_id "apK86SJcY4fy7tP-rU3c4gAAAog"] [Sat Aug 29 05:05:13.237811 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.104.62:64763] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.motherssandals.com"] [uri "/c99.php"] [unique_id "apK86SJcY4fy7tP-rU3c4wAAApA"] [Sat Aug 29 05:05:13.238458 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.18.15:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/dex.php"] [unique_id "apK86SJcY4fy7tP-rU3c5AAAAoY"] [Sat Aug 29 05:05:13.240151 2026] [security2:error] [pid 1017536:tid 1017651] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/.wp-config.php.swp"] [unique_id "apK86SJcY4fy7tP-rU3c5QACcnI"] [Sat Aug 29 05:05:13.244698 2026] [security2:error] [pid 1018003:tid 1018105] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.bigbuttonscarf.com"] [uri "/wp-config.php.old"] [unique_id "apK86TAh5Y1i2tUxg4Hb2QAGIlQ"] [Sat Aug 29 05:05:13.246139 2026] [security2:error] [pid 1018003:tid 1018107] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/laravel/.env"] [unique_id "apK86TAh5Y1i2tUxg4Hb2gAGIlY"] [Sat Aug 29 05:05:13.248990 2026] [cgid:error] [pid 1018003:tid 1018106] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.249624 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.18.15:23437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/inso.php"] [unique_id "apK86SJcY4fy7tP-rU3c6AAAAnM"] [Sat Aug 29 05:05:13.250081 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.160.90:45855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/emmh.php"] [unique_id "apK86SJcY4fy7tP-rU3c6QAAAmA"] [Sat Aug 29 05:05:13.255006 2026] [security2:error] [pid 1018003:tid 1018263] [client 45.154.98.191:49629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK86TAh5Y1i2tUxg4Hb2wAABic"] [Sat Aug 29 05:05:13.255075 2026] [security2:error] [pid 1018003:tid 1018104] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.51.196.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbuttonscarf.com"] [uri "/config/.env.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb1wAGIlM"] [Sat Aug 29 05:05:13.255599 2026] [security2:error] [pid 1018003:tid 1018066] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.51.196.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbuttonscarf.com"] [uri "/.env.php.bak"] [unique_id "apK86TAh5Y1i2tUxg4Hb1gAGIi0"] [Sat Aug 29 05:05:13.262055 2026] [security2:error] [pid 1018003:tid 1018253] [client 20.48.251.3:57887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/4563.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb3gAABh0"] [Sat Aug 29 05:05:13.282813 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.250.41:12365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/ms.php"] [unique_id "apK86SJcY4fy7tP-rU3c7QAAAkE"] [Sat Aug 29 05:05:13.282978 2026] [security2:error] [pid 1017536:tid 1017745] [client 158.23.184.117:21876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/admin.php"] [unique_id "apK86SJcY4fy7tP-rU3c7AAAAmM"] [Sat Aug 29 05:05:13.291519 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.48.160.90:63553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb4AAABfI"] [Sat Aug 29 05:05:13.291529 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.104.104.62:13592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/mmm.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb4QAABd8"] [Sat Aug 29 05:05:13.294695 2026] [security2:error] [pid 1017536:tid 1017744] [client 52.139.37.240:28247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/gecko-new.php"] [unique_id "apK86SJcY4fy7tP-rU3c7gAAAmI"] [Sat Aug 29 05:05:13.305109 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.250.41:65415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/num.php"] [unique_id "apK86SJcY4fy7tP-rU3c7wAAAjs"] [Sat Aug 29 05:05:13.308562 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:36706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/she11.php"] [unique_id "apK86SJcY4fy7tP-rU3c8AAAAkA"] [Sat Aug 29 05:05:13.310188 2026] [security2:error] [pid 1018003:tid 1018196] [client 74.248.24.12:31584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb5AAABeU"] [Sat Aug 29 05:05:13.314545 2026] [security2:error] [pid 1017536:tid 1017728] [client 52.139.37.240:37920] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "skyyentertainment.skyytalent.com"] [uri "/c99.php"] [unique_id "apK86SJcY4fy7tP-rU3c8QAAAlI"] [Sat Aug 29 05:05:13.317442 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.63.219.114:2002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/goods.php"] [unique_id "apK86SJcY4fy7tP-rU3c8gAAAho"] [Sat Aug 29 05:05:13.322555 2026] [security2:error] [pid 1017536:tid 1017712] [client 185.104.184.230:49406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "apK86SJcY4fy7tP-rU3c8wAAAkI"] [Sat Aug 29 05:05:13.331055 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:23516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ws69.php"] [unique_id "apK86SJcY4fy7tP-rU3c-gAAAnw"] [Sat Aug 29 05:05:13.334485 2026] [security2:error] [pid 1018003:tid 1018179] [client 52.139.37.240:21393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/breads1.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb5gAABdQ"] [Sat Aug 29 05:05:13.343815 2026] [security2:error] [pid 1018003:tid 1018113] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env.swp"] [unique_id "apK86TAh5Y1i2tUxg4Hb6AAGIFw"] [Sat Aug 29 05:05:13.344283 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.184.117:14387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/.well-known/aa.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb6QAABhA"] [Sat Aug 29 05:05:13.350883 2026] [security2:error] [pid 1017536:tid 1017719] [client 52.139.37.240:24644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/item.php"] [unique_id "apK86SJcY4fy7tP-rU3c_QAAAkk"] [Sat Aug 29 05:05:13.354805 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.104.62:44605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/sf9.php"] [unique_id "apK86SJcY4fy7tP-rU3c_wAAAoM"] [Sat Aug 29 05:05:13.365608 2026] [security2:error] [pid 1018003:tid 1018168] [client 20.48.250.41:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb7AAABck"] [Sat Aug 29 05:05:13.367616 2026] [security2:error] [pid 1018003:tid 1018114] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/static/.env"] [unique_id "apK86TAh5Y1i2tUxg4Hb7QAGLF0"] [Sat Aug 29 05:05:13.369907 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.104.104.62:15249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/mmm.php"] [unique_id "apK86SJcY4fy7tP-rU3dAgAAAl8"] [Sat Aug 29 05:05:13.371277 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.18.15:47064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/h2.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb7gAABeQ"] [Sat Aug 29 05:05:13.373269 2026] [security2:error] [pid 1018003:tid 1018115] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/core/.env"] [unique_id "apK86TAh5Y1i2tUxg4Hb7wAGCl4"] [Sat Aug 29 05:05:13.375575 2026] [security2:error] [pid 1018003:tid 1018201] [client 20.63.81.20:26520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/goods.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb8AAABeo"] [Sat Aug 29 05:05:13.377289 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.104.18.15:7156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/sf.php"] [unique_id "apK86SJcY4fy7tP-rU3dBAAAAlA"] [Sat Aug 29 05:05:13.378658 2026] [security2:error] [pid 1017536:tid 1017759] [client 20.104.18.15:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/inso.php"] [unique_id "apK86SJcY4fy7tP-rU3dBQAAAnE"] [Sat Aug 29 05:05:13.390450 2026] [security2:error] [pid 1017536:tid 1017729] [client 104.207.55.231:45121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK86SJcY4fy7tP-rU3dAwAAAlM"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:13.391037 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.48.160.90:39945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/em.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb8QAABjM"] [Sat Aug 29 05:05:13.395139 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.18.15:23425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/aa.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb8gAABdA"] [Sat Aug 29 05:05:13.398007 2026] [security2:error] [pid 1018003:tid 1018116] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/files../.env"] [unique_id "apK86TAh5Y1i2tUxg4Hb8wAGKl8"] [Sat Aug 29 05:05:13.400065 2026] [security2:error] [pid 1018003:tid 1018117] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/static/home/user/.env"] [unique_id "apK86TAh5Y1i2tUxg4Hb9AAGKmA"] [Sat Aug 29 05:05:13.400294 2026] [security2:error] [pid 1018003:tid 1018068] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.env"] [unique_id "apK86TAh5Y1i2tUxg4Hb9QAGKi8"] [Sat Aug 29 05:05:13.401406 2026] [security2:error] [pid 1017536:tid 1017765] [client 4.232.148.111:8526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-admin/css/about.php"] [unique_id "apK86SJcY4fy7tP-rU3dBgAAAnc"] [Sat Aug 29 05:05:13.413381 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.203.141.11:31001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/classwithtostring.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb9wAABcU"] [Sat Aug 29 05:05:13.423279 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.104.62:25808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "apK86SJcY4fy7tP-rU3dCAAAAl4"] [Sat Aug 29 05:05:13.424384 2026] [security2:error] [pid 1017536:tid 1017772] [client 158.23.184.117:61572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/Radio.php"] [unique_id "apK86SJcY4fy7tP-rU3dCQAAAn4"] [Sat Aug 29 05:05:13.424429 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.48.251.3:57867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/cp2.php"] [unique_id "apK86SJcY4fy7tP-rU3dCgAAAic"] [Sat Aug 29 05:05:13.425660 2026] [security2:error] [pid 1017536:tid 1017722] [client 158.23.184.117:21927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/api.php"] [unique_id "apK86SJcY4fy7tP-rU3dCwAAAkw"] [Sat Aug 29 05:05:13.430108 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.104.62:13583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/advanced.php"] [unique_id "apK86SJcY4fy7tP-rU3dDgAAAis"] [Sat Aug 29 05:05:13.432742 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.48.160.90:63543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apK86SJcY4fy7tP-rU3dDwAAAiE"] [Sat Aug 29 05:05:13.443843 2026] [security2:error] [pid 1018003:tid 1018153] [client 168.107.94.195:50152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb-AAABbo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:13.449455 2026] [security2:error] [pid 1018003:tid 1018158] [client 20.48.250.41:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/a4.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb-QAABb8"] [Sat Aug 29 05:05:13.467590 2026] [security2:error] [pid 1017536:tid 1017551] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env"] [unique_id "apK86SJcY4fy7tP-rU3dGwACFQ4"] [Sat Aug 29 05:05:13.471858 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.104.18.15:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/kerang.php"] [unique_id "apK86SJcY4fy7tP-rU3dHgAAAjo"] [Sat Aug 29 05:05:13.483375 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.63.219.114:11920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/wxo.php"] [unique_id "apK86SJcY4fy7tP-rU3dIgAAAns"] [Sat Aug 29 05:05:13.483768 2026] [security2:error] [pid 1018003:tid 1018121] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.51.196.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbuttonscarf.com"] [uri "/configuration.php.bak"] [unique_id "apK86TAh5Y1i2tUxg4Hb_AAF-GQ"] [Sat Aug 29 05:05:13.484171 2026] [security2:error] [pid 1018003:tid 1018119] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/public/.env"] [unique_id "apK86TAh5Y1i2tUxg4Hb-gAF-GI"] [Sat Aug 29 05:05:13.485229 2026] [security2:error] [pid 1018003:tid 1018122] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.51.196.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbuttonscarf.com"] [uri "/config.php.bak"] [unique_id "apK86TAh5Y1i2tUxg4Hb_QAF-GU"] [Sat Aug 29 05:05:13.486713 2026] [lsapi:warn] [pid 1018003:tid 1018111] [remote 104.28.132.8:16569] [host thegrowingplace.ca] Backend log: PHP Warning: Trying to access array offset on value of type null in /home1/thegrow2/public_html/w_api/Configuration.php on line 115\n, referer: https://thegrowingplace.ca/index.html [Sat Aug 29 05:05:13.487759 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.48.250.41:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ccs.php"] [unique_id "apK86SJcY4fy7tP-rU3dIwAAAjg"] [Sat Aug 29 05:05:13.489430 2026] [security2:error] [pid 1017536:tid 1017723] [client 158.23.184.117:14355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK86SJcY4fy7tP-rU3dJAAAAk0"] [Sat Aug 29 05:05:13.491745 2026] [cgid:error] [pid 1018003:tid 1018120] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.492526 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.104.104.62:10454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/lte7.php"] [unique_id "apK86SJcY4fy7tP-rU3dJQAAAiw"] [Sat Aug 29 05:05:13.493084 2026] [security2:error] [pid 1017536:tid 1017736] [client 52.139.37.240:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/add_actualites.php"] [unique_id "apK86SJcY4fy7tP-rU3dJgAAAlo"] [Sat Aug 29 05:05:13.496661 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.48.250.41:12361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/zxekqlxb.php"] [unique_id "apK86TAh5Y1i2tUxg4Hb_wAABb4"] [Sat Aug 29 05:05:13.499092 2026] [cgid:error] [pid 1018003:tid 1018123] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.499570 2026] [security2:error] [pid 1018003:tid 1018120] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.env"] [unique_id "apK86TAh5Y1i2tUxg4HcAAAF02M"] [Sat Aug 29 05:05:13.499570 2026] [security2:error] [pid 1018003:tid 1018069] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/static/app/.env"] [unique_id "apK86TAh5Y1i2tUxg4HcAQAF0zA"] [Sat Aug 29 05:05:13.503411 2026] [security2:error] [pid 1017536:tid 1017696] [client 40.83.93.50:1975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/config.php"] [unique_id "apK86SJcY4fy7tP-rU3dJwAAAjI"] [Sat Aug 29 05:05:13.507437 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.104.104.62:15328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/advanced.php"] [unique_id "apK86SJcY4fy7tP-rU3dKQAAAk4"] [Sat Aug 29 05:05:13.511233 2026] [security2:error] [pid 1017536:tid 1017738] [client 68.155.159.216:57438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/content.php"] [unique_id "apK86SJcY4fy7tP-rU3dKgAAAlw"] [Sat Aug 29 05:05:13.514032 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.18.15:7116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/k.php"] [unique_id "apK86TAh5Y1i2tUxg4HcAgAABf4"] [Sat Aug 29 05:05:13.521301 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.48.250.41:58531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/06.php"] [unique_id "apK86TAh5Y1i2tUxg4HcAwAABc0"] [Sat Aug 29 05:05:13.529453 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.147.79:53998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK86TAh5Y1i2tUxg4HcBAAABco"] [Sat Aug 29 05:05:13.530002 2026] [security2:error] [pid 1018003:tid 1018277] [client 68.155.159.216:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK86TAh5Y1i2tUxg4HcBQAABjU"] [Sat Aug 29 05:05:13.531519 2026] [core:error] [pid 1018003:tid 1018125] [remote 104.196.115.188:34080] AH10244: invalid URI path (/%2e%2e/.env) [Sat Aug 29 05:05:13.533328 2026] [security2:error] [pid 1017536:tid 1017681] [client 52.139.37.240:65286] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "skyyentertainment.skyytalent.com"] [uri "/c99.php"] [unique_id "apK86SJcY4fy7tP-rU3dLAAAAiM"] [Sat Aug 29 05:05:13.534303 2026] [security2:error] [pid 1017536:tid 1017675] [client 52.139.37.240:21425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/must.php"] [unique_id "apK86SJcY4fy7tP-rU3dLQAAAh0"] [Sat Aug 29 05:05:13.536493 2026] [security2:error] [pid 1018003:tid 1018126] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.env"] [unique_id "apK86TAh5Y1i2tUxg4HcBwAGK2k"] [Sat Aug 29 05:05:13.540435 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.18.15:23530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/img.php"] [unique_id "apK86SJcY4fy7tP-rU3dLgAAAls"] [Sat Aug 29 05:05:13.540617 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.160.90:39973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/dvve.php"] [unique_id "apK86SJcY4fy7tP-rU3dLwAAAoI"] [Sat Aug 29 05:05:13.542099 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.196.209.81:19349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK86SJcY4fy7tP-rU3dMAAAAkY"] [Sat Aug 29 05:05:13.542435 2026] [security2:error] [pid 1017536:tid 1017737] [client 68.155.159.216:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK86SJcY4fy7tP-rU3dMQAAAls"] [Sat Aug 29 05:05:13.542486 2026] [security2:error] [pid 1017536:tid 1017764] [client 143.244.57.82:48326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK86SJcY4fy7tP-rU3dMgAAAnY"] [Sat Aug 29 05:05:13.544647 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.104.18.15:13249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/aa.php"] [unique_id "apK86SJcY4fy7tP-rU3dMwAAAiY"] [Sat Aug 29 05:05:13.546525 2026] [security2:error] [pid 1017536:tid 1017683] [client 52.139.37.240:58601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/jga.php"] [unique_id "apK86SJcY4fy7tP-rU3dNAAAAiU"] [Sat Aug 29 05:05:13.557201 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.48.251.3:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/xda.php"] [unique_id "apK86SJcY4fy7tP-rU3dNQAAAog"] [Sat Aug 29 05:05:13.560571 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.104.104.62:13643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/blox.php"] [unique_id "apK86SJcY4fy7tP-rU3dNgAAAo4"] [Sat Aug 29 05:05:13.569304 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.63.81.20:26521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/100.php"] [unique_id "apK86TAh5Y1i2tUxg4HcCAAABew"] [Sat Aug 29 05:05:13.576369 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:21874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/chosen.php"] [unique_id "apK86SJcY4fy7tP-rU3dOQAAAjE"] [Sat Aug 29 05:05:13.591354 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.104.62:64739] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.motherssandals.com"] [uri "/c99.php"] [unique_id "apK86SJcY4fy7tP-rU3dPAAAAn8"] [Sat Aug 29 05:05:13.592979 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.48.160.90:63572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/650.php"] [unique_id "apK86TAh5Y1i2tUxg4HcCwAABdk"] [Sat Aug 29 05:05:13.607478 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.48.250.41:65471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/tfm.php"] [unique_id "apK86TAh5Y1i2tUxg4HcDAAABjI"] [Sat Aug 29 05:05:13.607944 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.18.15:46926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apK86SJcY4fy7tP-rU3dPwAAAkE"] [Sat Aug 29 05:05:13.622169 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.104.104.62:10838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/tanjiro.php"] [unique_id "apK86SJcY4fy7tP-rU3dQwAAAnI"] [Sat Aug 29 05:05:13.629426 2026] [security2:error] [pid 1017536:tid 1017763] [client 158.23.184.117:56691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/Requests/Exception/file.php"] [unique_id "apK86SJcY4fy7tP-rU3dRQAAAnU"] [Sat Aug 29 05:05:13.635596 2026] [security2:error] [pid 1017536:tid 1017728] [client 68.155.159.216:50252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/cong.php"] [unique_id "apK86SJcY4fy7tP-rU3dRgAAAlI"] [Sat Aug 29 05:05:13.636164 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.196.209.81:4997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/access.php"] [unique_id "apK86TAh5Y1i2tUxg4HcDgAABb4"] [Sat Aug 29 05:05:13.637833 2026] [security2:error] [pid 1018003:tid 1018232] [client 74.248.24.12:21325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/24.php"] [unique_id "apK86TAh5Y1i2tUxg4HcDwAABgg"] [Sat Aug 29 05:05:13.637912 2026] [security2:error] [pid 1018003:tid 1018210] [client 20.104.104.62:14835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/blox.php"] [unique_id "apK86TAh5Y1i2tUxg4HcEAAABfM"] [Sat Aug 29 05:05:13.638432 2026] [security2:error] [pid 1018003:tid 1018191] [client 158.23.184.117:14502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK86TAh5Y1i2tUxg4HcEQAABeA"] [Sat Aug 29 05:05:13.641469 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.48.250.41:12331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/init.php"] [unique_id "apK86TAh5Y1i2tUxg4HcEgAABhk"] [Sat Aug 29 05:05:13.641593 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.147.79:62694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/login.php"] [unique_id "apK86SJcY4fy7tP-rU3dSQAAAho"] [Sat Aug 29 05:05:13.647451 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.23.147.79:50160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-mail.php"] [unique_id "apK86TAh5Y1i2tUxg4HcEwAABhM"] [Sat Aug 29 05:05:13.649730 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.104.62:48592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/inject.php"] [unique_id "apK86SJcY4fy7tP-rU3dSgAAAkI"] [Sat Aug 29 05:05:13.650495 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.104.18.15:36833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/m.php"] [unique_id "apK86SJcY4fy7tP-rU3dSwAAAm4"] [Sat Aug 29 05:05:13.662560 2026] [security2:error] [pid 1018003:tid 1018178] [client 4.232.148.111:1415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/admin/function.php"] [unique_id "apK86TAh5Y1i2tUxg4HcFAAABdM"] [Sat Aug 29 05:05:13.668719 2026] [security2:error] [pid 1017536:tid 1017749] [client 4.205.62.107:61871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apK86SJcY4fy7tP-rU3dTQAAAmc"] [Sat Aug 29 05:05:13.675672 2026] [security2:error] [pid 1017536:tid 1017770] [client 4.205.62.107:21883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/nlnub.php"] [unique_id "apK86SJcY4fy7tP-rU3dTgAAAnw"] [Sat Aug 29 05:05:13.679673 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.48.160.90:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/doo.php"] [unique_id "apK86SJcY4fy7tP-rU3dTwAAAhY"] [Sat Aug 29 05:05:13.681629 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.250.41:61740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/class.php"] [unique_id "apK86TAh5Y1i2tUxg4HcFQAABfY"] [Sat Aug 29 05:05:13.681640 2026] [security2:error] [pid 1018003:tid 1018251] [client 20.104.18.15:13283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/img.php"] [unique_id "apK86TAh5Y1i2tUxg4HcFgAABhs"] [Sat Aug 29 05:05:13.681639 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.63.219.114:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/hehe.php"] [unique_id "apK86SJcY4fy7tP-rU3dUAAAAoY"] [Sat Aug 29 05:05:13.686782 2026] [security2:error] [pid 1017536:tid 1017666] [client 20.104.104.62:13578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/kcs.php"] [unique_id "apK86SJcY4fy7tP-rU3dUQAAAhQ"] [Sat Aug 29 05:05:13.687927 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.48.251.3:57827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/pinfo.php"] [unique_id "apK86SJcY4fy7tP-rU3dUgAAAmU"] [Sat Aug 29 05:05:13.689350 2026] [security2:error] [pid 1017536:tid 1017705] [client 52.139.37.240:28284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/browse.php"] [unique_id "apK86SJcY4fy7tP-rU3dUwAAAjs"] [Sat Aug 29 05:05:13.693817 2026] [security2:error] [pid 1017536:tid 1017703] [client 158.23.147.79:30702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/goods.php"] [unique_id "apK86SJcY4fy7tP-rU3dVAAAAjk"] [Sat Aug 29 05:05:13.700037 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.104.18.15:23535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/222.php"] [unique_id "apK86SJcY4fy7tP-rU3dVgAAAl8"] [Sat Aug 29 05:05:13.713829 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.48.250.41:23505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/mar.php"] [unique_id "apK86TAh5Y1i2tUxg4HcGAAABbw"] [Sat Aug 29 05:05:13.721923 2026] [security2:error] [pid 1017536:tid 1017748] [client 68.155.159.216:16300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK86SJcY4fy7tP-rU3dWQAAAmY"] [Sat Aug 29 05:05:13.724678 2026] [security2:error] [pid 1018003:tid 1018128] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.bigbuttonscarf.com"] [uri "/wp-config.php.swp"] [unique_id "apK86TAh5Y1i2tUxg4HcGwAGH2s"] [Sat Aug 29 05:05:13.725035 2026] [security2:error] [pid 1018003:tid 1018132] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.bigbuttonscarf.com"] [uri "/wp-config.php~"] [unique_id "apK86TAh5Y1i2tUxg4HcHQAGH28"] [Sat Aug 29 05:05:13.727540 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.18.15:7150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/82.php"] [unique_id "apK86SJcY4fy7tP-rU3dXAAAAnc"] [Sat Aug 29 05:05:13.727591 2026] [security2:error] [pid 1018003:tid 1018131] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/storage/.env"] [unique_id "apK86TAh5Y1i2tUxg4HcHAAGH24"] [Sat Aug 29 05:05:13.727592 2026] [security2:error] [pid 1018003:tid 1018130] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/web/.env"] [unique_id "apK86TAh5Y1i2tUxg4HcGQAGH20"] [Sat Aug 29 05:05:13.727819 2026] [security2:error] [pid 1018003:tid 1018133] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/wp/.env"] [unique_id "apK86TAh5Y1i2tUxg4HcHgAGH3A"] [Sat Aug 29 05:05:13.727876 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.184.117:21831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/config.php"] [unique_id "apK86TAh5Y1i2tUxg4HcHwAABgI"] [Sat Aug 29 05:05:13.727951 2026] [security2:error] [pid 1017536:tid 1017734] [client 52.139.37.240:54169] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "skyyentertainment.skyytalent.com"] [uri "/c99.php"] [unique_id "apK86SJcY4fy7tP-rU3dXQAAAlg"] [Sat Aug 29 05:05:13.728734 2026] [security2:error] [pid 1018003:tid 1018129] [remote 104.196.51.122:58658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/wp-config.old"] [unique_id "apK86TAh5Y1i2tUxg4HcGgAGH2w"] [Sat Aug 29 05:05:13.731028 2026] [security2:error] [pid 1017536:tid 1017754] [client 52.139.37.240:21142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/up.php"] [unique_id "apK86SJcY4fy7tP-rU3dXgAAAmw"] [Sat Aug 29 05:05:13.735242 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.63.81.20:26448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/about.php"] [unique_id "apK86SJcY4fy7tP-rU3dXwAAAjY"] [Sat Aug 29 05:05:13.751439 2026] [security2:error] [pid 1017536:tid 1017730] [client 158.158.54.35:15886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/install.php"] [unique_id "apK86SJcY4fy7tP-rU3dYAAAAlQ"] [Sat Aug 29 05:05:13.752265 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.48.160.90:62717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/nakrip.php"] [unique_id "apK86SJcY4fy7tP-rU3dYQAAAiE"] [Sat Aug 29 05:05:13.758570 2026] [security2:error] [pid 1017536:tid 1017778] [client 68.155.159.216:16278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/dropdown.php"] [unique_id "apK86SJcY4fy7tP-rU3dZAAAAoQ"] [Sat Aug 29 05:05:13.765505 2026] [security2:error] [pid 1018003:tid 1018137] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/api/.env/public/.env"] [unique_id "apK86TAh5Y1i2tUxg4HcIQAGBHQ"] [Sat Aug 29 05:05:13.766142 2026] [security2:error] [pid 1017536:tid 1017784] [client 52.139.37.240:24591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/mac.php"] [unique_id "apK86SJcY4fy7tP-rU3dZwAAAoo"] [Sat Aug 29 05:05:13.769093 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.18.15:47074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/sao.php"] [unique_id "apK86SJcY4fy7tP-rU3daQAAAks"] [Sat Aug 29 05:05:13.787174 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.104.104.62:15332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/kcs.php"] [unique_id "apK86TAh5Y1i2tUxg4HcJQAABdY"] [Sat Aug 29 05:05:13.792960 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.250.41:12464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/term.php"] [unique_id "apK86SJcY4fy7tP-rU3dagAAAk0"] [Sat Aug 29 05:05:13.801650 2026] [cgid:error] [pid 1018003:tid 1018140] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.803714 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:10440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/Rk41.php"] [unique_id "apK86SJcY4fy7tP-rU3dcAAAAlo"] [Sat Aug 29 05:05:13.804208 2026] [security2:error] [pid 1017536:tid 1017720] [client 4.205.62.107:21859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/aws_secret_config.php"] [unique_id "apK86SJcY4fy7tP-rU3dcQAAAko"] [Sat Aug 29 05:05:13.804666 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.197.61.180:17398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eeeaudio.com"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK86TAh5Y1i2tUxg4HcKQAABcQ"] [Sat Aug 29 05:05:13.811586 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.18.15:13310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/222.php"] [unique_id "apK86TAh5Y1i2tUxg4HcKwAABcc"] [Sat Aug 29 05:05:13.815002 2026] [cgid:error] [pid 1018003:tid 1018141] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.816117 2026] [security2:error] [pid 1017536:tid 1017775] [client 45.154.98.191:50015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK86SJcY4fy7tP-rU3dcwAAAoE"] [Sat Aug 29 05:05:13.816459 2026] [cgid:error] [pid 1018003:tid 1018142] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.816489 2026] [cgid:error] [pid 1018003:tid 1018144] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.816649 2026] [cgid:error] [pid 1018003:tid 1018145] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.819632 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.48.251.3:57800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/X57.php"] [unique_id "apK86SJcY4fy7tP-rU3ddAAAAlw"] [Sat Aug 29 05:05:13.820789 2026] [security2:error] [pid 1017536:tid 1017566] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK86SJcY4fy7tP-rU3ddQACVx0"] [Sat Aug 29 05:05:13.821888 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:36679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/fling.php"] [unique_id "apK86SJcY4fy7tP-rU3ddgAAAh0"] [Sat Aug 29 05:05:13.822831 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.250.41:58571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/8.php"] [unique_id "apK86SJcY4fy7tP-rU3ddwAAAoI"] [Sat Aug 29 05:05:13.823093 2026] [security2:error] [pid 1017536:tid 1017694] [client 168.107.94.195:50443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK86SJcY4fy7tP-rU3deAAAAjA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:13.826161 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.147.79:24408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK86SJcY4fy7tP-rU3degAAAls"] [Sat Aug 29 05:05:13.826686 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:13712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/wsz.php"] [unique_id "apK86SJcY4fy7tP-rU3dfAAAAiU"] [Sat Aug 29 05:05:13.833560 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.160.90:45910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/adminer-4.6.6.php"] [unique_id "apK86SJcY4fy7tP-rU3dfgAAAmg"] [Sat Aug 29 05:05:13.839016 2026] [security2:error] [pid 1018003:tid 1018209] [client 158.23.184.117:14487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/test.php"] [unique_id "apK86TAh5Y1i2tUxg4HcMQAABfI"] [Sat Aug 29 05:05:13.845505 2026] [security2:error] [pid 1018003:tid 1018264] [client 158.23.184.117:56675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-admin/add.php"] [unique_id "apK86TAh5Y1i2tUxg4HcMwAABig"] [Sat Aug 29 05:05:13.847645 2026] [cgid:error] [pid 1018003:tid 1018147] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.848524 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.104.104.62:20827] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.motherssandals.com"] [uri "/c99.php"] [unique_id "apK86SJcY4fy7tP-rU3dgAAAAlE"] [Sat Aug 29 05:05:13.859566 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.18.15:23547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/key.php"] [unique_id "apK86TAh5Y1i2tUxg4HcNAAABdQ"] [Sat Aug 29 05:05:13.860924 2026] [core:error] [pid 1017536:tid 1017777] [client 74.248.24.12:30201] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:13.860944 2026] [core:error] [pid 1017536:tid 1017777] [client 74.248.24.12:30201] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:13.869051 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.104.18.15:7148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/dex.php"] [unique_id "apK86SJcY4fy7tP-rU3dhQAAAio"] [Sat Aug 29 05:05:13.874472 2026] [security2:error] [pid 1017536:tid 1017758] [client 172.97.247.204:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK86SJcY4fy7tP-rU3dhgAAAnA"], referer: https://www.djiboutihomes.com/ [Sat Aug 29 05:05:13.875257 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.203.141.11:29689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/404.php"] [unique_id "apK86SJcY4fy7tP-rU3dhwAAAoc"] [Sat Aug 29 05:05:13.875496 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.184.117:21859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/core.php"] [unique_id "apK86SJcY4fy7tP-rU3diAAAAoI"] [Sat Aug 29 05:05:13.880548 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.104.62:48670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/mga.php"] [unique_id "apK86SJcY4fy7tP-rU3diQAAAig"] [Sat Aug 29 05:05:13.882878 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.48.250.41:23370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ccu.php"] [unique_id "apK86TAh5Y1i2tUxg4HcNgAABhA"] [Sat Aug 29 05:05:13.884304 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.250.41:64156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/Geforce.php"] [unique_id "apK86SJcY4fy7tP-rU3digAAAkE"] [Sat Aug 29 05:05:13.885729 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.63.81.20:26507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/about.php"] [unique_id "apK86SJcY4fy7tP-rU3diwAAAhc"] [Sat Aug 29 05:05:13.887863 2026] [security2:error] [pid 1017536:tid 1017681] [client 52.139.37.240:56785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/contentloader1.php"] [unique_id "apK86SJcY4fy7tP-rU3djAAAAiM"] [Sat Aug 29 05:05:13.894910 2026] [security2:error] [pid 1017536:tid 1017729] [client 4.232.148.111:21028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/system_log.php"] [unique_id "apK86SJcY4fy7tP-rU3djQAAAlM"] [Sat Aug 29 05:05:13.903960 2026] [security2:error] [pid 1017536:tid 1017735] [client 20.48.160.90:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apK86SJcY4fy7tP-rU3dkAAAAlk"] [Sat Aug 29 05:05:13.911841 2026] [security2:error] [pid 1017536:tid 1017670] [client 185.104.184.230:49416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK86SJcY4fy7tP-rU3dkwAAAhg"] [Sat Aug 29 05:05:13.913412 2026] [access_compat:error] [pid 1018003:tid 1018207] [client 67.20.76.220:23066] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:13.919406 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.63.219.114:15274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/as.php"] [unique_id "apK86SJcY4fy7tP-rU3dlAAAAi0"] [Sat Aug 29 05:05:13.927314 2026] [security2:error] [pid 1018003:tid 1018260] [client 52.139.37.240:37903] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "skyyentertainment.skyytalent.com"] [uri "/c99.php"] [unique_id "apK86TAh5Y1i2tUxg4HcQgAABiQ"] [Sat Aug 29 05:05:13.936832 2026] [cgid:error] [pid 1018003:tid 1018021] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.939219 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.196.209.81:12368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK86SJcY4fy7tP-rU3dlwAAAkM"] [Sat Aug 29 05:05:13.941879 2026] [access_compat:error] [pid 1018003:tid 1018235] [client 67.20.76.220:23072] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:13.953845 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.104.62:25627] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.flicklister.com"] [uri "/1.php"] [unique_id "apK86TAh5Y1i2tUxg4HcSAAABjM"] [Sat Aug 29 05:05:13.954002 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.104.62:25627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/1.php"] [unique_id "apK86TAh5Y1i2tUxg4HcSAAABjM"] [Sat Aug 29 05:05:13.955753 2026] [security2:error] [pid 1018003:tid 1018269] [client 4.205.62.107:53342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/thui.php"] [unique_id "apK86TAh5Y1i2tUxg4HcSQAABi0"] [Sat Aug 29 05:05:13.957615 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.48.250.41:12303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/aaa.php"] [unique_id "apK86TAh5Y1i2tUxg4HcSgAABc4"] [Sat Aug 29 05:05:13.957615 2026] [security2:error] [pid 1017536:tid 1017671] [client 20.104.104.62:15259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/wsz.php"] [unique_id "apK86SJcY4fy7tP-rU3dnQAAAhk"] [Sat Aug 29 05:05:13.961445 2026] [security2:error] [pid 1018003:tid 1018026] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/uploads../.env"] [unique_id "apK86TAh5Y1i2tUxg4HcRQAGFAU"] [Sat Aug 29 05:05:13.963856 2026] [security2:error] [pid 1018003:tid 1018075] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/assets../.env"] [unique_id "apK86TAh5Y1i2tUxg4HcRAAGFDY"] [Sat Aug 29 05:05:13.965549 2026] [security2:error] [pid 1018003:tid 1018171] [client 52.139.37.240:58572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK86TAh5Y1i2tUxg4HcTAAABcw"] [Sat Aug 29 05:05:13.967617 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.104.62:13960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/msy.php"] [unique_id "apK86TAh5Y1i2tUxg4HcTQAABio"] [Sat Aug 29 05:05:13.968981 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.18.15:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/key.php"] [unique_id "apK86SJcY4fy7tP-rU3doQAAAhY"] [Sat Aug 29 05:05:13.969054 2026] [cgid:error] [pid 1018003:tid 1018024] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.969795 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.104.62:44562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/7logs.php"] [unique_id "apK86SJcY4fy7tP-rU3dogAAAoY"] [Sat Aug 29 05:05:13.970591 2026] [access_compat:error] [pid 1017536:tid 1017712] [client 67.20.76.220:12590] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:13.971211 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.23.147.79:23329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/wp-l0gin.php"] [unique_id "apK86TAh5Y1i2tUxg4HcTwAABho"] [Sat Aug 29 05:05:13.971230 2026] [cgid:error] [pid 1018003:tid 1018033] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.972673 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.160.90:39938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/gelap1.php"] [unique_id "apK86SJcY4fy7tP-rU3dowAAAj8"] [Sat Aug 29 05:05:13.972867 2026] [cgid:error] [pid 1018003:tid 1018021] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.973201 2026] [security2:error] [pid 1017536:tid 1017558] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env.backup"] [unique_id "apK86SJcY4fy7tP-rU3dngACFRU"] [Sat Aug 29 05:05:13.973581 2026] [cgid:error] [pid 1018003:tid 1018071] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:13.974306 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.250.41:58541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/0x0x.php"] [unique_id "apK86SJcY4fy7tP-rU3dpAAAAjk"] [Sat Aug 29 05:05:13.974443 2026] [security2:error] [pid 1017536:tid 1017674] [client 4.205.62.107:2981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/v3.php"] [unique_id "apK86SJcY4fy7tP-rU3dpQAAAhw"] [Sat Aug 29 05:05:13.979072 2026] [security2:error] [pid 1017536:tid 1017734] [client 68.155.159.216:14212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/about.php"] [unique_id "apK86SJcY4fy7tP-rU3dqAAAAlg"] [Sat Aug 29 05:05:13.981642 2026] [security2:error] [pid 1017536:tid 1017754] [client 68.155.159.216:51894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-content/radio.php"] [unique_id "apK86SJcY4fy7tP-rU3dqQAAAmw"] [Sat Aug 29 05:05:13.989031 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.104.18.15:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/dapa.php"] [unique_id "apK86SJcY4fy7tP-rU3dqgAAAjY"] [Sat Aug 29 05:05:13.990743 2026] [security2:error] [pid 1017536:tid 1017687] [client 40.83.93.50:3618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/cong.php"] [unique_id "apK86SJcY4fy7tP-rU3dqwAAAik"] [Sat Aug 29 05:05:13.990892 2026] [security2:error] [pid 1017536:tid 1017702] [client 151.123.177.79:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK86SJcY4fy7tP-rU3dpgAAAjg"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:13.998098 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.48.251.3:28425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/register.php"] [unique_id "apK86TAh5Y1i2tUxg4HcSwAABeE"] [Sat Aug 29 05:05:14.001267 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.104.18.15:23369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/chosen.php"] [unique_id "apK86SJcY4fy7tP-rU3drwAAAn4"] [Sat Aug 29 05:05:14.015414 2026] [security2:error] [pid 1017536:tid 1017767] [client 158.23.184.117:61568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/assets/about.php"] [unique_id "apK86iJcY4fy7tP-rU3dtwAAAnk"] [Sat Aug 29 05:05:14.022917 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.184.117:21844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/data.php"] [unique_id "apK86iJcY4fy7tP-rU3duAAAAjs"] [Sat Aug 29 05:05:14.032960 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.104.18.15:36834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/btyuio.php"] [unique_id "apK86iJcY4fy7tP-rU3dugAAAoU"] [Sat Aug 29 05:05:14.036772 2026] [security2:error] [pid 1018003:tid 1018208] [client 20.63.81.20:26602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/admin.php"] [unique_id "apK86jAh5Y1i2tUxg4HcUwAABfE"] [Sat Aug 29 05:05:14.037900 2026] [security2:error] [pid 1017536:tid 1017755] [client 52.139.37.240:21414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-content/155.php"] [unique_id "apK86iJcY4fy7tP-rU3duwAAAm0"] [Sat Aug 29 05:05:14.046029 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.23.147.79:25551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK86jAh5Y1i2tUxg4HcVAAABdg"] [Sat Aug 29 05:05:14.047698 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.160.90:64693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/xcc.php"] [unique_id "apK86iJcY4fy7tP-rU3dvAAAAoE"] [Sat Aug 29 05:05:14.051277 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.48.250.41:64914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/click.php"] [unique_id "apK86iJcY4fy7tP-rU3dvQAAAh0"] [Sat Aug 29 05:05:14.056481 2026] [security2:error] [pid 1018003:tid 1018201] [client 20.196.209.81:15161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/classsmtps.php"] [unique_id "apK86jAh5Y1i2tUxg4HcVQAABeo"] [Sat Aug 29 05:05:14.056746 2026] [security2:error] [pid 1017536:tid 1017737] [client 4.205.62.107:54407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/tax.php"] [unique_id "apK86iJcY4fy7tP-rU3dvgAAAls"] [Sat Aug 29 05:05:14.058139 2026] [security2:error] [pid 1017536:tid 1017679] [client 158.23.184.117:14493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/mani.php"] [unique_id "apK86iJcY4fy7tP-rU3dvwAAAiE"] [Sat Aug 29 05:05:14.073684 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.250.41:23503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ak.php"] [unique_id "apK86jAh5Y1i2tUxg4HcWAAABfs"] [Sat Aug 29 05:05:14.076666 2026] [cgid:error] [pid 1018003:tid 1018030] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.087755 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.104.62:14828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/msy.php"] [unique_id "apK86jAh5Y1i2tUxg4HcWQAABjU"] [Sat Aug 29 05:05:14.087810 2026] [security2:error] [pid 1018003:tid 1018233] [client 52.139.37.240:28229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/upfile.php"] [unique_id "apK86jAh5Y1i2tUxg4HcWgAABgk"] [Sat Aug 29 05:05:14.094612 2026] [cgid:error] [pid 1018003:tid 1018023] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.098725 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.104.104.62:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/siln.php"] [unique_id "apK86iJcY4fy7tP-rU3dxQAAAoI"] [Sat Aug 29 05:05:14.099238 2026] [security2:error] [pid 1017536:tid 1017716] [client 143.244.57.82:48328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK86iJcY4fy7tP-rU3dxgAAAkY"] [Sat Aug 29 05:05:14.099666 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.104.62:48504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/inwp.php"] [unique_id "apK86jAh5Y1i2tUxg4HcXgAABdw"] [Sat Aug 29 05:05:14.101809 2026] [cgid:error] [pid 1018003:tid 1018032] [remote 104.196.51.122:58658] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.106762 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.18.15:13234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/chosen.php"] [unique_id "apK86iJcY4fy7tP-rU3dyAAAAig"] [Sat Aug 29 05:05:14.110063 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.104.62:44565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/sf.php"] [unique_id "apK86jAh5Y1i2tUxg4HcXwAABis"] [Sat Aug 29 05:05:14.113041 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.250.41:12409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/xsox.php"] [unique_id "apK86jAh5Y1i2tUxg4HcYAAABis"] [Sat Aug 29 05:05:14.113214 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.160.90:40031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/rsjlrria.php"] [unique_id "apK86iJcY4fy7tP-rU3dyQAAAmM"] [Sat Aug 29 05:05:14.120759 2026] [security2:error] [pid 1018003:tid 1018135] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/images../.env"] [unique_id "apK86jAh5Y1i2tUxg4HcYQAF7HI"] [Sat Aug 29 05:05:14.123331 2026] [security2:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/admin/phpinfo.php"] [unique_id "apK86iJcY4fy7tP-rU3dygACVw0"] [Sat Aug 29 05:05:14.130601 2026] [security2:error] [pid 1018003:tid 1018074] [remote 104.196.115.188:34080] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "infinitidealership.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "apK86jAh5Y1i2tUxg4HcZAAGBjU"] [Sat Aug 29 05:05:14.133548 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.48.251.3:57890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/xqq.php"] [unique_id "apK86jAh5Y1i2tUxg4HcZgAABiE"] [Sat Aug 29 05:05:14.134824 2026] [security2:error] [pid 1018003:tid 1018074] [remote 104.196.115.188:34080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK86jAh5Y1i2tUxg4HcZQAGBjU"] [Sat Aug 29 05:05:14.135856 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.48.250.41:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/166.php"] [unique_id "apK86jAh5Y1i2tUxg4HcaAAABfc"] [Sat Aug 29 05:05:14.138325 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.104.18.15:23453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/file1221.php"] [unique_id "apK86jAh5Y1i2tUxg4HcaQAABjI"] [Sat Aug 29 05:05:14.142484 2026] [security2:error] [pid 1017536:tid 1017757] [client 4.232.148.111:1459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/admin/index.php"] [unique_id "apK86iJcY4fy7tP-rU3dzgAAAm8"] [Sat Aug 29 05:05:14.148598 2026] [security2:error] [pid 1017536:tid 1017572] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/admin_phpinfo.php"] [unique_id "apK86iJcY4fy7tP-rU3dzwACVyM"] [Sat Aug 29 05:05:14.150105 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.63.219.114:9184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK86iJcY4fy7tP-rU3d0AAAAjw"] [Sat Aug 29 05:05:14.153183 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.104.62:25651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/admin/function.php"] [unique_id "apK86jAh5Y1i2tUxg4HcagAABc0"] [Sat Aug 29 05:05:14.160515 2026] [core:error] [pid 1018003:tid 1018220] [client 74.248.24.12:16534] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:14.160538 2026] [core:error] [pid 1018003:tid 1018220] [client 74.248.24.12:16534] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:14.162505 2026] [security2:error] [pid 1017536:tid 1017731] [client 52.139.37.240:24642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK86iJcY4fy7tP-rU3d0QAAAlU"] [Sat Aug 29 05:05:14.170678 2026] [security2:error] [pid 1018003:tid 1018199] [client 158.23.184.117:21892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/db-status.php"] [unique_id "apK86jAh5Y1i2tUxg4HcbAAABeg"] [Sat Aug 29 05:05:14.172079 2026] [security2:error] [pid 1018003:tid 1018036] [remote 104.196.51.122:58658] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.bigbuttonscarf.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK86jAh5Y1i2tUxg4HcbQAFvg8"] [Sat Aug 29 05:05:14.178421 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.104.18.15:7059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/inso.php"] [unique_id "apK86jAh5Y1i2tUxg4HcbgAABhk"] [Sat Aug 29 05:05:14.179474 2026] [security2:error] [pid 1017536:tid 1017763] [client 20.63.81.20:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/admin.php"] [unique_id "apK86iJcY4fy7tP-rU3d1AAAAnU"] [Sat Aug 29 05:05:14.181945 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.18.15:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-content/l.php"] [unique_id "apK86jAh5Y1i2tUxg4HcbwAABeA"] [Sat Aug 29 05:05:14.186697 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.160.90:63593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apK86iJcY4fy7tP-rU3d1QAAAho"] [Sat Aug 29 05:05:14.203643 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.184.117:14515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/Test.php"] [unique_id "apK86jAh5Y1i2tUxg4HccAAABiY"] [Sat Aug 29 05:05:14.203645 2026] [security2:error] [pid 1017536:tid 1017739] [client 158.158.54.35:9921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/ioxi-o.php"] [unique_id "apK86iJcY4fy7tP-rU3d1gAAAl0"] [Sat Aug 29 05:05:14.206300 2026] [security2:error] [pid 1017536:tid 1017678] [client 168.107.94.195:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK86iJcY4fy7tP-rU3d2AAAAiA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:14.214088 2026] [security2:error] [pid 1018003:tid 1018178] [client 20.104.18.15:36757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/dehnl.php"] [unique_id "apK86jAh5Y1i2tUxg4HccQAABdM"] [Sat Aug 29 05:05:14.218189 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.104.62:15357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/siln.php"] [unique_id "apK86jAh5Y1i2tUxg4HccgAABhI"] [Sat Aug 29 05:05:14.225053 2026] [security2:error] [pid 1018003:tid 1018224] [client 68.155.159.216:18354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/ans.php"] [unique_id "apK86jAh5Y1i2tUxg4HccwAABgE"] [Sat Aug 29 05:05:14.229434 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.104.62:64748] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.motherssandals.com"] [uri "/c99.php"] [unique_id "apK86iJcY4fy7tP-rU3d3AAAAok"] [Sat Aug 29 05:05:14.234178 2026] [security2:error] [pid 1017536:tid 1017726] [client 57.141.14.20:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/"] [unique_id "apK86iJcY4fy7tP-rU3d3QAAAlA"] [Sat Aug 29 05:05:14.236144 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.104.62:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/f-401.php"] [unique_id "apK86jAh5Y1i2tUxg4HcdAAABi8"] [Sat Aug 29 05:05:14.237545 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.18.15:13134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/file1221.php"] [unique_id "apK86jAh5Y1i2tUxg4HcdQAABh8"] [Sat Aug 29 05:05:14.239047 2026] [security2:error] [pid 1017536:tid 1017710] [client 52.139.37.240:20759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-update.php"] [unique_id "apK86iJcY4fy7tP-rU3d3gAAAkA"] [Sat Aug 29 05:05:14.249635 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.63.219.114:9179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/post.php"] [unique_id "apK86jAh5Y1i2tUxg4HcdgAABic"] [Sat Aug 29 05:05:14.250426 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.104.62:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/super.php"] [unique_id "apK86iJcY4fy7tP-rU3d4AAAAjE"] [Sat Aug 29 05:05:14.255290 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.250.41:65439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/ms.php"] [unique_id "apK86iJcY4fy7tP-rU3d4gAAAjk"] [Sat Aug 29 05:05:14.258605 2026] [security2:error] [pid 1018003:tid 1018247] [client 158.23.184.117:61619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-content/themes/twentytwentythree.php"] [unique_id "apK86jAh5Y1i2tUxg4HcdwAABhc"] [Sat Aug 29 05:05:14.264148 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.251.3:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/a1vx.php"] [unique_id "apK86iJcY4fy7tP-rU3d5AAAAnw"] [Sat Aug 29 05:05:14.266288 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.48.250.41:61805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/h2a2ck.php"] [unique_id "apK86jAh5Y1i2tUxg4HceAAABf8"] [Sat Aug 29 05:05:14.285252 2026] [security2:error] [pid 1018003:tid 1018170] [client 52.139.37.240:28285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/form.php"] [unique_id "apK86jAh5Y1i2tUxg4HceQAABcs"] [Sat Aug 29 05:05:14.287898 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.48.160.90:39961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/AxAo.php"] [unique_id "apK86iJcY4fy7tP-rU3d6AAAAjY"] [Sat Aug 29 05:05:14.297641 2026] [security2:error] [pid 1017536:tid 1017623] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env.bak"] [unique_id "apK86iJcY4fy7tP-rU3d6QACFVY"] [Sat Aug 29 05:05:14.297742 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.18.15:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/nox.php"] [unique_id "apK86iJcY4fy7tP-rU3d6gAAAkU"] [Sat Aug 29 05:05:14.314494 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.184.117:21829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/f35.php"] [unique_id "apK86iJcY4fy7tP-rU3d8AAAAlg"] [Sat Aug 29 05:05:14.317059 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.160.90:62682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apK86iJcY4fy7tP-rU3d8QAAAjQ"] [Sat Aug 29 05:05:14.319307 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.104.18.15:7129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/aa.php"] [unique_id "apK86iJcY4fy7tP-rU3d8wAAAn0"] [Sat Aug 29 05:05:14.319699 2026] [security2:error] [pid 1017536:tid 1017631] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/backend/.env"] [unique_id "apK86iJcY4fy7tP-rU3d8gACFV4"] [Sat Aug 29 05:05:14.323080 2026] [security2:error] [pid 1017536:tid 1017565] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/api/.env"] [unique_id "apK86iJcY4fy7tP-rU3d9AACFRw"] [Sat Aug 29 05:05:14.326901 2026] [security2:error] [pid 1017536:tid 1017637] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env.old"] [unique_id "apK86iJcY4fy7tP-rU3d9QACFWQ"] [Sat Aug 29 05:05:14.327587 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.63.81.20:26617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/themes.php"] [unique_id "apK86iJcY4fy7tP-rU3d9gAAAlQ"] [Sat Aug 29 05:05:14.336443 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.196.209.81:17950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/security.php"] [unique_id "apK86iJcY4fy7tP-rU3d-QAAAmU"] [Sat Aug 29 05:05:14.339277 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.203.141.11:41382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/php.php"] [unique_id "apK86iJcY4fy7tP-rU3d-wAAAm4"] [Sat Aug 29 05:05:14.341331 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.48.250.41:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/lib.php"] [unique_id "apK86iJcY4fy7tP-rU3d_QAAAm4"] [Sat Aug 29 05:05:14.346801 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.184.117:14792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/pomo.php"] [unique_id "apK86iJcY4fy7tP-rU3d_gAAAmc"] [Sat Aug 29 05:05:14.354436 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.63.219.114:11904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/room.php"] [unique_id "apK86jAh5Y1i2tUxg4HcfgAABhE"] [Sat Aug 29 05:05:14.358785 2026] [security2:error] [pid 1017536:tid 1017702] [client 52.139.37.240:24613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/zafir1.php"] [unique_id "apK86iJcY4fy7tP-rU3d_wAAAjg"] [Sat Aug 29 05:05:14.359204 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.104.104.62:14348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/f-401.php"] [unique_id "apK86jAh5Y1i2tUxg4HcfwAABfI"] [Sat Aug 29 05:05:14.360095 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.104.62:25806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.flicklister.com"] [uri "/autoload_classmap.php"] [unique_id "apK86iJcY4fy7tP-rU3eAQAAAik"] [Sat Aug 29 05:05:14.366872 2026] [security2:error] [pid 1017536:tid 1017707] [client 45.154.98.191:50269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK86iJcY4fy7tP-rU3eAgAAAj0"] [Sat Aug 29 05:05:14.369776 2026] [security2:error] [pid 1017536:tid 1017633] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/api/info.php"] [unique_id "apK86iJcY4fy7tP-rU3eAwACV2A"] [Sat Aug 29 05:05:14.374250 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.18.15:46935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-admin/w.php"] [unique_id "apK86jAh5Y1i2tUxg4HcgAAABdc"] [Sat Aug 29 05:05:14.380741 2026] [security2:error] [pid 1018003:tid 1018231] [client 4.232.148.111:10353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/24.php"] [unique_id "apK86jAh5Y1i2tUxg4HcgQAABgc"] [Sat Aug 29 05:05:14.382082 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.104.104.62:10441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/lufix1.php"] [unique_id "apK86iJcY4fy7tP-rU3eBgAAAoU"] [Sat Aug 29 05:05:14.382564 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.104.62:13746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/hq.php"] [unique_id "apK86iJcY4fy7tP-rU3eBwAAAmk"] [Sat Aug 29 05:05:14.390292 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.104.18.15:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/nox.php"] [unique_id "apK86jAh5Y1i2tUxg4HcggAABg4"] [Sat Aug 29 05:05:14.390296 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.104.18.15:36750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/zoo2.php"] [unique_id "apK86iJcY4fy7tP-rU3eCAAAAi8"] [Sat Aug 29 05:05:14.406420 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.48.251.3:57909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/public/vx.php"] [unique_id "apK86iJcY4fy7tP-rU3eCwAAAhs"] [Sat Aug 29 05:05:14.417781 2026] [security2:error] [pid 1017536:tid 1017741] [client 74.248.24.12:9347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-load.php"] [unique_id "apK86iJcY4fy7tP-rU3eDQAAAl8"] [Sat Aug 29 05:05:14.422825 2026] [cgid:error] [pid 1017536:tid 1017610] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.424254 2026] [cgid:error] [pid 1017536:tid 1017648] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.424273 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.48.160.90:39972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/class17.php"] [unique_id "apK86jAh5Y1i2tUxg4HchQAABiA"] [Sat Aug 29 05:05:14.424958 2026] [cgid:error] [pid 1017536:tid 1017632] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.425042 2026] [cgid:error] [pid 1017536:tid 1017646] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.425291 2026] [cgid:error] [pid 1017536:tid 1017634] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.427732 2026] [cgid:error] [pid 1017536:tid 1017555] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.429743 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.104.62:48477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/ad1.php"] [unique_id "apK86iJcY4fy7tP-rU3eFAAAAjA"] [Sat Aug 29 05:05:14.429779 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.104.18.15:23551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/akismet.php"] [unique_id "apK86iJcY4fy7tP-rU3eEwAAAnY"] [Sat Aug 29 05:05:14.432926 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/zxekqlxb.php"] [unique_id "apK86iJcY4fy7tP-rU3eFQAAAls"] [Sat Aug 29 05:05:14.436129 2026] [security2:error] [pid 1018003:tid 1018205] [client 52.139.37.240:21396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/xmrlpc.php"] [unique_id "apK86jAh5Y1i2tUxg4HchgAABe4"] [Sat Aug 29 05:05:14.445239 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.250.41:61751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/error_log.php"] [unique_id "apK86iJcY4fy7tP-rU3eGQAAAmg"] [Sat Aug 29 05:05:14.457752 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.63.81.20:26435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/biufile.php"] [unique_id "apK86iJcY4fy7tP-rU3eGgAAAog"] [Sat Aug 29 05:05:14.458336 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.18.15:7055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/img.php"] [unique_id "apK86iJcY4fy7tP-rU3eGwAAApA"] [Sat Aug 29 05:05:14.458929 2026] [security2:error] [pid 1018003:tid 1018196] [client 158.23.184.117:21894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK86jAh5Y1i2tUxg4HchwAABeU"] [Sat Aug 29 05:05:14.459599 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.184.117:61588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-content/languages/themes/num.php"] [unique_id "apK86jAh5Y1i2tUxg4HciAAABjM"] [Sat Aug 29 05:05:14.459905 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.48.160.90:63610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-settings.php"] [unique_id "apK86iJcY4fy7tP-rU3eHAAAAoM"] [Sat Aug 29 05:05:14.473019 2026] [security2:error] [pid 1017536:tid 1017649] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/api/phpinfo.php"] [unique_id "apK86iJcY4fy7tP-rU3eHQACV3A"] [Sat Aug 29 05:05:14.477134 2026] [security2:error] [pid 1017536:tid 1017719] [client 40.83.93.50:1934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/content.php"] [unique_id "apK86iJcY4fy7tP-rU3eHwAAAkk"] [Sat Aug 29 05:05:14.483116 2026] [security2:error] [pid 1017536:tid 1017788] [client 52.139.37.240:28248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/wp-sigunq.php"] [unique_id "apK86iJcY4fy7tP-rU3eIAAAAo4"] [Sat Aug 29 05:05:14.491851 2026] [security2:error] [pid 1018003:tid 1018193] [client 185.104.184.230:49428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK86jAh5Y1i2tUxg4HcigAABeI"] [Sat Aug 29 05:05:14.499534 2026] [cgid:error] [pid 1017536:tid 1017650] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.507742 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.63.219.114:17922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/wp-contentt.php"] [unique_id "apK86jAh5Y1i2tUxg4HciwAABdQ"] [Sat Aug 29 05:05:14.513985 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.48.250.41:23517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wp-style.php"] [unique_id "apK86jAh5Y1i2tUxg4HcjAAABbg"] [Sat Aug 29 05:05:14.519911 2026] [cgid:error] [pid 1017536:tid 1017609] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.520278 2026] [cgid:error] [pid 1017536:tid 1017660] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.521821 2026] [cgid:error] [pid 1017536:tid 1017641] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.522086 2026] [cgid:error] [pid 1017536:tid 1017651] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.522318 2026] [cgid:error] [pid 1017536:tid 1017661] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.531878 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.104.18.15:13206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/akismet.php"] [unique_id "apK86iJcY4fy7tP-rU3eLwAAAlU"] [Sat Aug 29 05:05:14.534440 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.49.130:50565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/classwithtostring.php"] [unique_id "apK86iJcY4fy7tP-rU3eMAAAAiM"] [Sat Aug 29 05:05:14.539466 2026] [security2:error] [pid 1017536:tid 1017728] [client 20.48.251.3:57897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/log.php"] [unique_id "apK86iJcY4fy7tP-rU3eMQAAAlI"] [Sat Aug 29 05:05:14.541103 2026] [security2:error] [pid 1017536:tid 1017789] [client 45.3.39.168:23931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.39.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK86iJcY4fy7tP-rU3eJgAAAo8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:14.556417 2026] [security2:error] [pid 1018003:tid 1018235] [client 158.23.184.117:25575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.dj/index.php"] [unique_id "apK86jAh5Y1i2tUxg4HcjQAABgs"] [Sat Aug 29 05:05:14.563818 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.48.250.41:65410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/init.php"] [unique_id "apK86jAh5Y1i2tUxg4HcjgAABb0"] [Sat Aug 29 05:05:14.564178 2026] [security2:error] [pid 1018003:tid 1018266] [client 52.139.37.240:25072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/abc.php"] [unique_id "apK86jAh5Y1i2tUxg4HcjwAABio"] [Sat Aug 29 05:05:14.564685 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.160.90:45899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/okxoby.php"] [unique_id "apK86iJcY4fy7tP-rU3eNQAAAkM"] [Sat Aug 29 05:05:14.566657 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.104.18.15:36859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/zoo1.php"] [unique_id "apK86iJcY4fy7tP-rU3eNgAAAl0"] [Sat Aug 29 05:05:14.586761 2026] [security2:error] [pid 1018003:tid 1018208] [client 168.107.94.195:51120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK86jAh5Y1i2tUxg4HckAAABfE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:14.591229 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.48.160.90:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-signup.php"] [unique_id "apK86iJcY4fy7tP-rU3eOQAAAhY"] [Sat Aug 29 05:05:14.598026 2026] [security2:error] [pid 1017536:tid 1017735] [client 158.23.184.117:14492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-admin/link-add.php"] [unique_id "apK86iJcY4fy7tP-rU3eOwAAAlk"] [Sat Aug 29 05:05:14.604516 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.63.81.20:26528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/coffexium.php"] [unique_id "apK86jAh5Y1i2tUxg4HckQAABbk"] [Sat Aug 29 05:05:14.605810 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.184.117:21934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/home.php"] [unique_id "apK86jAh5Y1i2tUxg4HckgAABeE"] [Sat Aug 29 05:05:14.607612 2026] [security2:error] [pid 1017536:tid 1017761] [client 4.232.148.111:7661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/storage/rip.php"] [unique_id "apK86iJcY4fy7tP-rU3ePgAAAnM"] [Sat Aug 29 05:05:14.608284 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.63.219.114:14597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/flower.php"] [unique_id "apK86jAh5Y1i2tUxg4HckwAABdA"] [Sat Aug 29 05:05:14.614568 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.18.15:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ajax.php"] [unique_id "apK86jAh5Y1i2tUxg4HclAAABfs"] [Sat Aug 29 05:05:14.623845 2026] [core:error] [pid 1017536:tid 1017710] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:14.623858 2026] [core:error] [pid 1017536:tid 1017710] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:14.632658 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.184.117:61597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp.php"] [unique_id "apK86iJcY4fy7tP-rU3eQAAAAiA"] [Sat Aug 29 05:05:14.635434 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.147.79:62736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK86iJcY4fy7tP-rU3eQQAAAnw"] [Sat Aug 29 05:05:14.651473 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.48.250.41:61696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/403.php"] [unique_id "apK86iJcY4fy7tP-rU3eRAAAAn4"] [Sat Aug 29 05:05:14.652473 2026] [security2:error] [pid 1017536:tid 1017666] [client 52.139.37.240:20736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/about/function.php"] [unique_id "apK86iJcY4fy7tP-rU3eRgAAAhQ"] [Sat Aug 29 05:05:14.655518 2026] [security2:error] [pid 1017536:tid 1017734] [client 68.155.159.216:57410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK86iJcY4fy7tP-rU3eRwAAAlg"] [Sat Aug 29 05:05:14.655792 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.18.15:46990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-content/k.php"] [unique_id "apK86iJcY4fy7tP-rU3eSAAAAjQ"] [Sat Aug 29 05:05:14.656169 2026] [security2:error] [pid 1017536:tid 1017748] [client 68.155.159.216:12179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/admin.php"] [unique_id "apK86iJcY4fy7tP-rU3eSQAAAmY"] [Sat Aug 29 05:05:14.661017 2026] [security2:error] [pid 1017536:tid 1017723] [client 143.244.57.82:49334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK86iJcY4fy7tP-rU3eTAAAAk0"] [Sat Aug 29 05:05:14.664140 2026] [security2:error] [pid 1018003:tid 1018171] [client 74.248.24.12:3861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK86jAh5Y1i2tUxg4HclwAABcw"] [Sat Aug 29 05:05:14.664968 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.104.18.15:7054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/222.php"] [unique_id "apK86iJcY4fy7tP-rU3eTgAAAmU"] [Sat Aug 29 05:05:14.665498 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.104.18.15:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ajax.php"] [unique_id "apK86iJcY4fy7tP-rU3eTwAAAkQ"] [Sat Aug 29 05:05:14.677249 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.48.251.3:57870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ebahvhhh.php"] [unique_id "apK86iJcY4fy7tP-rU3eUAAAAoQ"] [Sat Aug 29 05:05:14.679566 2026] [security2:error] [pid 1017536:tid 1017729] [client 52.139.37.240:28242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjfreeman.net"] [uri "/07.php"] [unique_id "apK86iJcY4fy7tP-rU3eUQAAAlM"] [Sat Aug 29 05:05:14.682801 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.196.209.81:15748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/contentloader1.php"] [unique_id "apK86jAh5Y1i2tUxg4HcmAAABfA"] [Sat Aug 29 05:05:14.688648 2026] [security2:error] [pid 1018003:tid 1018248] [client 158.158.54.35:22525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/xmlrpc.php"] [unique_id "apK86jAh5Y1i2tUxg4HclgAABhg"] [Sat Aug 29 05:05:14.695567 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.104.18.15:36831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/radio.php"] [unique_id "apK86iJcY4fy7tP-rU3eVQAAAjg"] [Sat Aug 29 05:05:14.699715 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.48.160.90:45872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/esuutzzx.php"] [unique_id "apK86jAh5Y1i2tUxg4HcmQAABfc"] [Sat Aug 29 05:05:14.701408 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.23.184.117:25116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.info.php"] [unique_id "apK86jAh5Y1i2tUxg4HcmgAABiw"] [Sat Aug 29 05:05:14.719994 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.160.90:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-conffg.php"] [unique_id "apK86iJcY4fy7tP-rU3eVwAAAj4"] [Sat Aug 29 05:05:14.730007 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.196.209.81:19356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK86iJcY4fy7tP-rU3eWQAAAlA"] [Sat Aug 29 05:05:14.741132 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.48.250.41:23547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/browse.php"] [unique_id "apK86iJcY4fy7tP-rU3eWgAAAoU"] [Sat Aug 29 05:05:14.742537 2026] [security2:error] [pid 1017536:tid 1017693] [client 68.155.159.216:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK86iJcY4fy7tP-rU3eWwAAAi8"] [Sat Aug 29 05:05:14.745966 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.184.117:14466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/Text.php"] [unique_id "apK86jAh5Y1i2tUxg4HcmwAABd0"] [Sat Aug 29 05:05:14.746447 2026] [security2:error] [pid 1017536:tid 1017574] [remote 104.196.115.188:34094] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "infinitidealership.com"] [uri "/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "apK86iJcY4fy7tP-rU3eXgACMiU"] [Sat Aug 29 05:05:14.748399 2026] [security2:error] [pid 1017536:tid 1017553] [remote 104.196.115.188:34094] ModSecurity: Access denied with code 500 (phase 1) (Error: Connection drop requested but failed to close the socket). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "infinitidealership.com"] [uri "/api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK86iJcY4fy7tP-rU3eYQACMhA"] [Sat Aug 29 05:05:14.748888 2026] [security2:error] [pid 1018003:tid 1018239] [client 158.23.147.79:38721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/hehehehe.php"] [unique_id "apK86jAh5Y1i2tUxg4HcnAAABg8"] [Sat Aug 29 05:05:14.749580 2026] [security2:error] [pid 1017536:tid 1017546] [remote 104.196.115.188:34094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/@fs/var/task/.env"] [unique_id "apK86iJcY4fy7tP-rU3eYAACMgk"] [Sat Aug 29 05:05:14.752569 2026] [security2:error] [pid 1017536:tid 1017692] [client 158.23.184.117:21905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/index.php"] [unique_id "apK86iJcY4fy7tP-rU3eYwAAAi4"] [Sat Aug 29 05:05:14.758221 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.63.81.20:26438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/coffee.php"] [unique_id "apK86iJcY4fy7tP-rU3eZQAAAkI"] [Sat Aug 29 05:05:14.759529 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.250.41:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/term.php"] [unique_id "apK86iJcY4fy7tP-rU3eZgAAAlo"] [Sat Aug 29 05:05:14.765410 2026] [security2:error] [pid 1018003:tid 1018230] [client 52.139.37.240:25068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/c1.php"] [unique_id "apK86jAh5Y1i2tUxg4HcnQAABgY"] [Sat Aug 29 05:05:14.782378 2026] [security2:error] [pid 1018003:tid 1018273] [client 158.23.184.117:6507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/xmlrpc.php"] [unique_id "apK86jAh5Y1i2tUxg4HcngAABjE"] [Sat Aug 29 05:05:14.789680 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.18.15:23502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/atomlib.php"] [unique_id "apK86jAh5Y1i2tUxg4HcnwAABb4"] [Sat Aug 29 05:05:14.793924 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.18.15:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/atomlib.php"] [unique_id "apK86iJcY4fy7tP-rU3ebQAAApI"] [Sat Aug 29 05:05:14.799801 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.203.141.11:35594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/init.php"] [unique_id "apK86iJcY4fy7tP-rU3ebwAAAkU"] [Sat Aug 29 05:05:14.800415 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:61778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/cytyr.php"] [unique_id "apK86iJcY4fy7tP-rU3ecAAAAls"] [Sat Aug 29 05:05:14.800427 2026] [security2:error] [pid 1017536:tid 1017764] [client 4.205.62.107:61858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/hochladen.form.php"] [unique_id "apK86iJcY4fy7tP-rU3ecQAAAnY"] [Sat Aug 29 05:05:14.805116 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.251.3:28420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/asa.php"] [unique_id "apK86iJcY4fy7tP-rU3edAAAAmg"] [Sat Aug 29 05:05:14.811514 2026] [security2:error] [pid 1018003:tid 1018180] [client 4.205.62.107:21868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wpver.php"] [unique_id "apK86jAh5Y1i2tUxg4HcoAAABdU"] [Sat Aug 29 05:05:14.819142 2026] [security2:error] [pid 1017536:tid 1017537] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/config/.env"] [unique_id "apK86iJcY4fy7tP-rU3edwACFQA"] [Sat Aug 29 05:05:14.819923 2026] [security2:error] [pid 1018003:tid 1018259] [client 158.23.147.79:30661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK86jAh5Y1i2tUxg4HcoQAABiM"] [Sat Aug 29 05:05:14.839454 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.104.18.15:46925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/os.php"] [unique_id "apK86iJcY4fy7tP-rU3eeQAAAio"] [Sat Aug 29 05:05:14.841176 2026] [security2:error] [pid 1017536:tid 1017758] [client 20.48.160.90:45917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/replace.php"] [unique_id "apK86iJcY4fy7tP-rU3eegAAAnA"] [Sat Aug 29 05:05:14.847060 2026] [cgid:error] [pid 1017536:tid 1017538] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.847087 2026] [cgid:error] [pid 1017536:tid 1017597] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.848092 2026] [security2:error] [pid 1018003:tid 1018249] [client 158.23.184.117:24867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.trash7206/index.php"] [unique_id "apK86jAh5Y1i2tUxg4HcogAABhk"] [Sat Aug 29 05:05:14.849647 2026] [security2:error] [pid 1018003:tid 1018199] [client 52.139.37.240:21380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/an.php"] [unique_id "apK86jAh5Y1i2tUxg4HcowAABeg"] [Sat Aug 29 05:05:14.857044 2026] [security2:error] [pid 1018003:tid 1018225] [client 68.155.159.216:16146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK86jAh5Y1i2tUxg4HcpAAABgI"] [Sat Aug 29 05:05:14.859601 2026] [cgid:error] [pid 1017536:tid 1017598] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.859715 2026] [cgid:error] [pid 1017536:tid 1017543] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.862043 2026] [cgid:error] [pid 1017536:tid 1017588] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.862068 2026] [security2:error] [pid 1017536:tid 1017755] [client 20.63.219.114:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/theme.php"] [unique_id "apK86iJcY4fy7tP-rU3ehQAAAm0"] [Sat Aug 29 05:05:14.863335 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.160.90:28631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-validate.php"] [unique_id "apK86iJcY4fy7tP-rU3ehgAAAig"] [Sat Aug 29 05:05:14.865930 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.18.15:36782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/one.php"] [unique_id "apK86jAh5Y1i2tUxg4HcpQAABi8"] [Sat Aug 29 05:05:14.866820 2026] [cgid:error] [pid 1017536:tid 1017664] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:14.876243 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.63.219.114:9349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/class-wp-cmd.php"] [unique_id "apK86iJcY4fy7tP-rU3eigAAAko"] [Sat Aug 29 05:05:14.881509 2026] [security2:error] [pid 1018003:tid 1018227] [client 68.155.159.216:16197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/.well-known/index.php"] [unique_id "apK86jAh5Y1i2tUxg4HcpgAABgQ"] [Sat Aug 29 05:05:14.891526 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.184.117:14478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-trackback.php"] [unique_id "apK86iJcY4fy7tP-rU3ejQAAAoI"] [Sat Aug 29 05:05:14.897676 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.23.184.117:21893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/login.php"] [unique_id "apK86jAh5Y1i2tUxg4HcqAAABgE"] [Sat Aug 29 05:05:14.897705 2026] [security2:error] [pid 1018003:tid 1018243] [client 52.139.37.240:64247] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "autodiscover.jjfreeman.net"] [uri "/c99.php"] [unique_id "apK86jAh5Y1i2tUxg4HcpwAABhM"] [Sat Aug 29 05:05:14.904351 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.250.41:23534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/zoo.php"] [unique_id "apK86iJcY4fy7tP-rU3ejgAAAiU"] [Sat Aug 29 05:05:14.917464 2026] [autoindex:error] [pid 1017536:tid 1017705] [client 4.232.148.111:14415] AH01276: Cannot serve directory /home4/ehfields/public_html/tiaandephraim/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:14.922261 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.63.81.20:26604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/classwithtostring.php"] [unique_id "apK86jAh5Y1i2tUxg4HcrAAABek"] [Sat Aug 29 05:05:14.932175 2026] [security2:error] [pid 1018003:tid 1018159] [client 45.154.98.191:50503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK86jAh5Y1i2tUxg4HcrQAABcA"] [Sat Aug 29 05:05:14.936303 2026] [security2:error] [pid 1018003:tid 1018263] [client 158.23.184.117:6470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/app.php"] [unique_id "apK86jAh5Y1i2tUxg4HcrgAABic"] [Sat Aug 29 05:05:14.936758 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.147.79:24560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/goat.php"] [unique_id "apK86jAh5Y1i2tUxg4HcrwAABcg"] [Sat Aug 29 05:05:14.941290 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.48.250.41:64143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/aaa.php"] [unique_id "apK86jAh5Y1i2tUxg4HcsQAABik"] [Sat Aug 29 05:05:14.947874 2026] [security2:error] [pid 1018003:tid 1018223] [client 20.48.251.3:57793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/radio.php"] [unique_id "apK86jAh5Y1i2tUxg4HcsgAABgA"] [Sat Aug 29 05:05:14.954126 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.104.18.15:7060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/key.php"] [unique_id "apK86jAh5Y1i2tUxg4HcswAABic"] [Sat Aug 29 05:05:14.954500 2026] [security2:error] [pid 1017536:tid 1017774] [client 4.205.62.107:22341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/greem_res.php"] [unique_id "apK86iJcY4fy7tP-rU3ekgAAAoA"] [Sat Aug 29 05:05:14.957442 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.18.15:23501] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "louiseandkane.strangeworx.com"] [uri "/1.php"] [unique_id "apK86jAh5Y1i2tUxg4HctAAABcQ"] [Sat Aug 29 05:05:14.957557 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.18.15:23501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/1.php"] [unique_id "apK86jAh5Y1i2tUxg4HctAAABcQ"] [Sat Aug 29 05:05:14.962618 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:13289] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.doozytrack.com"] [uri "/1.php"] [unique_id "apK86jAh5Y1i2tUxg4HctQAABi4"] [Sat Aug 29 05:05:14.963459 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.250.41:61794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/galer.php"] [unique_id "apK86jAh5Y1i2tUxg4HctgAABd8"] [Sat Aug 29 05:05:14.965843 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:13289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/1.php"] [unique_id "apK86jAh5Y1i2tUxg4HctQAABi4"] [Sat Aug 29 05:05:14.966535 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.63.219.114:1929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/meta.php"] [unique_id "apK86jAh5Y1i2tUxg4HctwAABhI"] [Sat Aug 29 05:05:14.966854 2026] [security2:error] [pid 1018003:tid 1018222] [client 52.139.37.240:24602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/index.php/feed/atom/"] [unique_id "apK86jAh5Y1i2tUxg4HcuAAABf8"] [Sat Aug 29 05:05:14.966969 2026] [security2:error] [pid 1017536:tid 1017743] [client 40.83.93.50:3641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/core.php"] [unique_id "apK86iJcY4fy7tP-rU3elQAAAmE"] [Sat Aug 29 05:05:14.970339 2026] [security2:error] [pid 1017536:tid 1017743] [client 168.107.94.195:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK86iJcY4fy7tP-rU3elgAAAmE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:14.980875 2026] [core:error] [pid 1017536:tid 1017775] [client 74.248.24.12:15231] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:14.980898 2026] [core:error] [pid 1017536:tid 1017775] [client 74.248.24.12:15231] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:14.985609 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.48.160.90:26694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/gulu.php"] [unique_id "apK86iJcY4fy7tP-rU3emAAAAl0"] [Sat Aug 29 05:05:14.996659 2026] [security2:error] [pid 1017536:tid 1017558] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/frontend/.env"] [unique_id "apK86iJcY4fy7tP-rU3emQACZBU"] [Sat Aug 29 05:05:15.000632 2026] [security2:error] [pid 1018003:tid 1018166] [client 158.23.184.117:25549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.trash7206/min.php"] [unique_id "apK86jAh5Y1i2tUxg4HcuQAABcc"] [Sat Aug 29 05:05:15.002623 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.104.18.15:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/htio.php"] [unique_id "apK86zAh5Y1i2tUxg4HcugAABdo"] [Sat Aug 29 05:05:15.019154 2026] [security2:error] [pid 1017536:tid 1017589] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/server/.env"] [unique_id "apK86yJcY4fy7tP-rU3emgACczQ"] [Sat Aug 29 05:05:15.019150 2026] [security2:error] [pid 1017536:tid 1017577] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/app/.env"] [unique_id "apK86yJcY4fy7tP-rU3enAACcyg"] [Sat Aug 29 05:05:15.027961 2026] [security2:error] [pid 1017536:tid 1017571] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/src/.env"] [unique_id "apK86yJcY4fy7tP-rU3eoAACcyI"] [Sat Aug 29 05:05:15.031592 2026] [security2:error] [pid 1017536:tid 1017603] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/production/.env"] [unique_id "apK86yJcY4fy7tP-rU3engACc0I"] [Sat Aug 29 05:05:15.031908 2026] [security2:error] [pid 1017536:tid 1017606] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/dev/.env"] [unique_id "apK86yJcY4fy7tP-rU3enwACc0U"] [Sat Aug 29 05:05:15.038017 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.184.117:14479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-admin/maint.php"] [unique_id "apK86zAh5Y1i2tUxg4HcuwAABhA"] [Sat Aug 29 05:05:15.044289 2026] [security2:error] [pid 1018003:tid 1018201] [client 20.104.18.15:36808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/503.php"] [unique_id "apK86zAh5Y1i2tUxg4HcvAAABeo"] [Sat Aug 29 05:05:15.044830 2026] [security2:error] [pid 1017536:tid 1017670] [client 52.139.37.240:21427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/asw.php"] [unique_id "apK86yJcY4fy7tP-rU3eoQAAAhg"] [Sat Aug 29 05:05:15.046853 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.184.117:21866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/logs233/index.php"] [unique_id "apK86zAh5Y1i2tUxg4HcvQAABfw"] [Sat Aug 29 05:05:15.056980 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.104.49.130:51117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/txets.php"] [unique_id "apK86yJcY4fy7tP-rU3epAAAAn0"] [Sat Aug 29 05:05:15.068257 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.63.81.20:26467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/wp-ws68.php"] [unique_id "apK86yJcY4fy7tP-rU3epQAAAlg"] [Sat Aug 29 05:05:15.072396 2026] [security2:error] [pid 1018003:tid 1018210] [client 185.104.184.230:49440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK86zAh5Y1i2tUxg4HcvwAABfM"] [Sat Aug 29 05:05:15.073887 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.250.41:23494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/elp.php"] [unique_id "apK86zAh5Y1i2tUxg4HcwAAABco"] [Sat Aug 29 05:05:15.075251 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.250.41:12392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/lkui.php"] [unique_id "apK86zAh5Y1i2tUxg4HcwQAABis"] [Sat Aug 29 05:05:15.080617 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.147.79:23536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK86zAh5Y1i2tUxg4HcwgAABiU"] [Sat Aug 29 05:05:15.083427 2026] [security2:error] [pid 1018003:tid 1018252] [client 104.207.38.99:61237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.38.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK86zAh5Y1i2tUxg4HcvgAABhw"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:15.084323 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.184.117:56671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/aaa.php"] [unique_id "apK86zAh5Y1i2tUxg4HcwwAABbk"] [Sat Aug 29 05:05:15.087205 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.251.3:57901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/xa.php"] [unique_id "apK86yJcY4fy7tP-rU3epgAAAjQ"] [Sat Aug 29 05:05:15.091609 2026] [security2:error] [pid 1018003:tid 1018236] [client 4.232.148.111:15627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/zoom1.php"] [unique_id "apK86zAh5Y1i2tUxg4HcxAAABgw"] [Sat Aug 29 05:05:15.091609 2026] [security2:error] [pid 1017536:tid 1017748] [client 68.155.159.216:51396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK86yJcY4fy7tP-rU3epwAAAmY"] [Sat Aug 29 05:05:15.094862 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.48.250.41:61705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/baixy.php"] [unique_id "apK86zAh5Y1i2tUxg4HcxQAABew"] [Sat Aug 29 05:05:15.098914 2026] [security2:error] [pid 1017536:tid 1017747] [client 4.232.148.111:14415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK86yJcY4fy7tP-rU3eqAAAAmU"] [Sat Aug 29 05:05:15.098940 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.18.15:23364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/samll.php"] [unique_id "apK86yJcY4fy7tP-rU3eqQAAAnc"] [Sat Aug 29 05:05:15.099268 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.196.209.81:9525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/al.php"] [unique_id "apK86yJcY4fy7tP-rU3eqgAAAnI"] [Sat Aug 29 05:05:15.106782 2026] [security2:error] [pid 1017536:tid 1017604] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/docker/.env"] [unique_id "apK86yJcY4fy7tP-rU3eqwACbkM"] [Sat Aug 29 05:05:15.110929 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.48.160.90:62604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/700.php"] [unique_id "apK86zAh5Y1i2tUxg4HcxgAABfc"] [Sat Aug 29 05:05:15.112114 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.48.250.41:65011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/xsox.php"] [unique_id "apK86zAh5Y1i2tUxg4HcxwAABiw"] [Sat Aug 29 05:05:15.119108 2026] [security2:error] [pid 1018003:tid 1018188] [client 4.205.62.107:2934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/sale.php"] [unique_id "apK86zAh5Y1i2tUxg4HcyQAABd0"] [Sat Aug 29 05:05:15.121925 2026] [security2:error] [pid 1018003:tid 1018175] [client 52.139.37.240:64238] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "autodiscover.jjfreeman.net"] [uri "/c99.php"] [unique_id "apK86zAh5Y1i2tUxg4HcygAABdA"] [Sat Aug 29 05:05:15.127478 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.196.209.81:19348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/system.php"] [unique_id "apK86zAh5Y1i2tUxg4HczAAABiA"] [Sat Aug 29 05:05:15.128694 2026] [security2:error] [pid 1017536:tid 1017613] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/old/.env"] [unique_id "apK86yJcY4fy7tP-rU3esQACS0w"] [Sat Aug 29 05:05:15.130787 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.160.90:45869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/gtghklk.php"] [unique_id "apK86yJcY4fy7tP-rU3esgAAAj0"] [Sat Aug 29 05:05:15.134309 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.158.54.35:15881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/filemanager.php"] [unique_id "apK86zAh5Y1i2tUxg4HczQAABdc"] [Sat Aug 29 05:05:15.135539 2026] [security2:error] [pid 1018003:tid 1018220] [client 20.104.18.15:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/samll.php"] [unique_id "apK86zAh5Y1i2tUxg4HczgAABf0"] [Sat Aug 29 05:05:15.135902 2026] [security2:error] [pid 1017536:tid 1017612] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/v2/.env"] [unique_id "apK86yJcY4fy7tP-rU3eswACLEs"] [Sat Aug 29 05:05:15.146807 2026] [security2:error] [pid 1017536:tid 1017723] [client 158.23.184.117:25561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known//index.php"] [unique_id "apK86yJcY4fy7tP-rU3etAAAAk0"] [Sat Aug 29 05:05:15.153124 2026] [security2:error] [pid 1017536:tid 1017550] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/v1/.env"] [unique_id "apK86yJcY4fy7tP-rU3etQAChQ0"] [Sat Aug 29 05:05:15.154585 2026] [security2:error] [pid 1017536:tid 1017580] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/staging/.env"] [unique_id "apK86yJcY4fy7tP-rU3etgAChSs"] [Sat Aug 29 05:05:15.165111 2026] [security2:error] [pid 1018003:tid 1018207] [client 52.139.37.240:58593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/root.php"] [unique_id "apK86zAh5Y1i2tUxg4Hc0gAABfA"] [Sat Aug 29 05:05:15.167681 2026] [core:error] [pid 1018003:tid 1018198] [client 34.12.38.134:20838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.167697 2026] [core:error] [pid 1018003:tid 1018198] [client 34.12.38.134:20838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.172588 2026] [core:error] [pid 1018003:tid 1018260] [client 34.12.38.134:20872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.172607 2026] [core:error] [pid 1018003:tid 1018260] [client 34.12.38.134:20872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.173577 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.18.15:7120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/chosen.php"] [unique_id "apK86yJcY4fy7tP-rU3euwAAAlc"] [Sat Aug 29 05:05:15.174429 2026] [core:error] [pid 1018003:tid 1018193] [client 34.12.38.134:20980] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.174450 2026] [core:error] [pid 1018003:tid 1018193] [client 34.12.38.134:20980] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.174876 2026] [core:error] [pid 1017536:tid 1017783] [client 34.12.38.134:20834] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.174889 2026] [core:error] [pid 1017536:tid 1017783] [client 34.12.38.134:20834] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.180542 2026] [core:error] [pid 1018003:tid 1018269] [client 34.12.38.134:21134] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.180546 2026] [core:error] [pid 1018003:tid 1018275] [client 34.12.38.134:20878] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.180560 2026] [core:error] [pid 1018003:tid 1018269] [client 34.12.38.134:21134] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.180561 2026] [core:error] [pid 1018003:tid 1018275] [client 34.12.38.134:20878] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.185406 2026] [core:error] [pid 1018003:tid 1018195] [client 34.12.38.134:20852] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.185426 2026] [core:error] [pid 1018003:tid 1018195] [client 34.12.38.134:20852] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.185601 2026] [security2:error] [pid 1018003:tid 1018195] [client 34.12.38.134:20852] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK86zAh5Y1i2tUxg4Hc2wAABeQ"] [Sat Aug 29 05:05:15.185800 2026] [core:error] [pid 1018003:tid 1018250] [client 34.12.38.134:20962] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.185807 2026] [core:error] [pid 1018003:tid 1018250] [client 34.12.38.134:20962] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.188688 2026] [core:error] [pid 1017536:tid 1017759] [client 34.12.38.134:20952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.188721 2026] [core:error] [pid 1017536:tid 1017759] [client 34.12.38.134:20952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.193733 2026] [security2:error] [pid 1018003:tid 1018162] [client 34.12.38.134:21064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK86zAh5Y1i2tUxg4Hc4gAABcM"] [Sat Aug 29 05:05:15.193746 2026] [security2:error] [pid 1018003:tid 1018150] [client 34.12.38.134:20902] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/.env.vault"] [unique_id "apK86zAh5Y1i2tUxg4Hc4wAABbc"] [Sat Aug 29 05:05:15.195465 2026] [security2:error] [pid 1017536:tid 1017732] [client 34.12.38.134:21160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK86yJcY4fy7tP-rU3eywAAAlY"] [Sat Aug 29 05:05:15.195911 2026] [security2:error] [pid 1017536:tid 1017751] [client 158.23.184.117:21873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/maintenance.php"] [unique_id "apK86yJcY4fy7tP-rU3e0wAAAmk"] [Sat Aug 29 05:05:15.197049 2026] [security2:error] [pid 1017536:tid 1017703] [client 4.205.62.107:53430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/session.php"] [unique_id "apK86yJcY4fy7tP-rU3e1AAAAjk"] [Sat Aug 29 05:05:15.198743 2026] [security2:error] [pid 1017536:tid 1017695] [client 34.12.38.134:21050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK86yJcY4fy7tP-rU3e0gAAAjE"] [Sat Aug 29 05:05:15.198843 2026] [security2:error] [pid 1017536:tid 1017695] [client 34.12.38.134:21050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK86yJcY4fy7tP-rU3e0gAAAjE"] [Sat Aug 29 05:05:15.199438 2026] [core:error] [pid 1018003:tid 1018235] [client 34.12.38.134:20856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.199456 2026] [core:error] [pid 1018003:tid 1018235] [client 34.12.38.134:20856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.199496 2026] [core:error] [pid 1018003:tid 1018186] [client 34.12.38.134:20892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.199506 2026] [core:error] [pid 1018003:tid 1018186] [client 34.12.38.134:20892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.199758 2026] [core:error] [pid 1018003:tid 1018156] [client 34.12.38.134:20966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.199774 2026] [core:error] [pid 1018003:tid 1018156] [client 34.12.38.134:20966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.199840 2026] [core:error] [pid 1017536:tid 1017678] [client 34.12.38.134:21122] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.199859 2026] [core:error] [pid 1017536:tid 1017678] [client 34.12.38.134:21122] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.199951 2026] [security2:error] [pid 1017536:tid 1017770] [client 34.12.38.134:21072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK86yJcY4fy7tP-rU3e1QAAAnw"] [Sat Aug 29 05:05:15.200487 2026] [security2:error] [pid 1017536:tid 1017770] [client 34.12.38.134:21072] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK86yJcY4fy7tP-rU3e1QAAAnw"] [Sat Aug 29 05:05:15.202883 2026] [security2:error] [pid 1018003:tid 1018266] [client 34.12.38.134:21028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK86zAh5Y1i2tUxg4Hc6wAABio"] [Sat Aug 29 05:05:15.203123 2026] [security2:error] [pid 1018003:tid 1018156] [client 34.12.38.134:20966] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK86zAh5Y1i2tUxg4Hc5QAABb0"] [Sat Aug 29 05:05:15.203751 2026] [core:error] [pid 1018003:tid 1018251] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.203767 2026] [core:error] [pid 1018003:tid 1018251] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.204220 2026] [core:error] [pid 1018003:tid 1018199] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.204228 2026] [core:error] [pid 1018003:tid 1018199] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.204729 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:46957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/dev.php"] [unique_id "apK86zAh5Y1i2tUxg4Hc7wAABes"] [Sat Aug 29 05:05:15.205712 2026] [core:error] [pid 1018003:tid 1018249] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.205728 2026] [core:error] [pid 1018003:tid 1018249] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.206982 2026] [security2:error] [pid 1017536:tid 1017564] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/site/.env"] [unique_id "apK86yJcY4fy7tP-rU3e1wACgxs"] [Sat Aug 29 05:05:15.207654 2026] [security2:error] [pid 1017536:tid 1017619] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/portal/.env"] [unique_id "apK86yJcY4fy7tP-rU3e2AACg1I"] [Sat Aug 29 05:05:15.211913 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.196.209.81:12092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/post.php"] [unique_id "apK86yJcY4fy7tP-rU3e2gAAAlQ"] [Sat Aug 29 05:05:15.212904 2026] [core:error] [pid 1018003:tid 1018247] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.212925 2026] [core:error] [pid 1018003:tid 1018247] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.212951 2026] [core:error] [pid 1018003:tid 1018156] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.212961 2026] [core:error] [pid 1018003:tid 1018156] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.213187 2026] [core:error] [pid 1018003:tid 1018255] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.213204 2026] [core:error] [pid 1018003:tid 1018255] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.214602 2026] [core:error] [pid 1017536:tid 1017763] [client 74.248.24.12:15881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.214623 2026] [core:error] [pid 1017536:tid 1017763] [client 74.248.24.12:15881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.218975 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.63.81.20:26531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/mgrr.php"] [unique_id "apK86zAh5Y1i2tUxg4Hc9wAABgo"] [Sat Aug 29 05:05:15.220378 2026] [core:error] [pid 1018003:tid 1018224] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.220407 2026] [core:error] [pid 1018003:tid 1018224] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.226322 2026] [core:error] [pid 1018003:tid 1018159] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.226346 2026] [core:error] [pid 1018003:tid 1018159] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.227548 2026] [core:error] [pid 1018003:tid 1018167] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.227566 2026] [core:error] [pid 1018003:tid 1018167] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.229124 2026] [core:error] [pid 1018003:tid 1018255] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.229150 2026] [core:error] [pid 1018003:tid 1018255] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.229216 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.63.219.114:17954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/alumni_reg.php"] [unique_id "apK86yJcY4fy7tP-rU3e3QAAAkQ"] [Sat Aug 29 05:05:15.231324 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.18.15:36841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/504.php"] [unique_id "apK86zAh5Y1i2tUxg4Hc_AAABhI"] [Sat Aug 29 05:05:15.239493 2026] [security2:error] [pid 1017536:tid 1017565] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.docker/.env"] [unique_id "apK86yJcY4fy7tP-rU3e3wACaxw"] [Sat Aug 29 05:05:15.240202 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.104.18.15:23428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/she11.php"] [unique_id "apK86yJcY4fy7tP-rU3e4AAAAmA"] [Sat Aug 29 05:05:15.240969 2026] [security2:error] [pid 1017536:tid 1017792] [client 52.139.37.240:21407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/item.php"] [unique_id "apK86yJcY4fy7tP-rU3e4gAAApI"] [Sat Aug 29 05:05:15.241804 2026] [security2:error] [pid 1017536:tid 1017728] [client 143.244.57.82:48358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK86yJcY4fy7tP-rU3e4wAAAlI"] [Sat Aug 29 05:05:15.243089 2026] [core:error] [pid 1018003:tid 1018181] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.243105 2026] [core:error] [pid 1018003:tid 1018181] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.244084 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.251.3:57809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ws61.php"] [unique_id "apK86yJcY4fy7tP-rU3e5AAAAmM"] [Sat Aug 29 05:05:15.244344 2026] [core:error] [pid 1018003:tid 1018270] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.244369 2026] [core:error] [pid 1018003:tid 1018270] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.244667 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.250.41:61818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/ava.php"] [unique_id "apK86yJcY4fy7tP-rU3e5QAAAig"] [Sat Aug 29 05:05:15.248111 2026] [core:error] [pid 1018003:tid 1018249] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.248129 2026] [core:error] [pid 1018003:tid 1018249] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.249796 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.48.160.90:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/c4.php"] [unique_id "apK86zAh5Y1i2tUxg4HdAgAABg4"] [Sat Aug 29 05:05:15.250448 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.203.141.11:29666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "apK86zAh5Y1i2tUxg4HdAwAABhg"] [Sat Aug 29 05:05:15.259494 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.250.41:12514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK86yJcY4fy7tP-rU3e6QAAAkE"] [Sat Aug 29 05:05:15.264697 2026] [security2:error] [pid 1018003:tid 1018192] [client 4.205.62.107:61223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/linusadmin-phpinfo.php"] [unique_id "apK86zAh5Y1i2tUxg4HdBAAABeE"] [Sat Aug 29 05:05:15.268482 2026] [core:error] [pid 1017536:tid 1017776] [client 74.7.230.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.268503 2026] [core:error] [pid 1017536:tid 1017776] [client 74.7.230.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.268650 2026] [security2:error] [pid 1017536:tid 1017776] [client 74.7.230.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.steveslivemusic.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "apK86yJcY4fy7tP-rU3e6wAAAoI"] [Sat Aug 29 05:05:15.269867 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.184.117:14339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/num.php"] [unique_id "apK86zAh5Y1i2tUxg4HdBQAABfU"] [Sat Aug 29 05:05:15.271507 2026] [security2:error] [pid 1017536:tid 1017694] [client 74.7.230.42:35202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.steveslivemusic.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "apK86yJcY4fy7tP-rU3e2wACMFY"] [Sat Aug 29 05:05:15.279910 2026] [security2:error] [pid 1017536:tid 1017541] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/@fs/.env"] [unique_id "apK86yJcY4fy7tP-rU3e8AACOwQ"] [Sat Aug 29 05:05:15.279912 2026] [security2:error] [pid 1017536:tid 1017625] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/@fs/.env"] [unique_id "apK86yJcY4fy7tP-rU3e7gACO1g"] [Sat Aug 29 05:05:15.282914 2026] [security2:error] [pid 1017536:tid 1017569] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/@fs/.env"] [unique_id "apK86yJcY4fy7tP-rU3e8QACOyA"] [Sat Aug 29 05:05:15.287440 2026] [security2:error] [pid 1017536:tid 1017648] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/apps/.env"] [unique_id "apK86yJcY4fy7tP-rU3e8wACVW8"] [Sat Aug 29 05:05:15.292206 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.104.18.15:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/she11.php"] [unique_id "apK86zAh5Y1i2tUxg4HdBgAABhM"] [Sat Aug 29 05:05:15.292821 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.160.90:45827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/comand.php"] [unique_id "apK86yJcY4fy7tP-rU3e9AAAAm8"] [Sat Aug 29 05:05:15.294165 2026] [security2:error] [pid 1017536:tid 1017720] [client 158.23.184.117:25564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/about.php"] [unique_id "apK86yJcY4fy7tP-rU3e9gAAAko"] [Sat Aug 29 05:05:15.302050 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.184.117:6479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/hehe.php"] [unique_id "apK86zAh5Y1i2tUxg4HdBwAABfs"] [Sat Aug 29 05:05:15.305646 2026] [security2:error] [pid 1017536:tid 1017646] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/env.old"] [unique_id "apK86yJcY4fy7tP-rU3e9wACI20"] [Sat Aug 29 05:05:15.306684 2026] [security2:error] [pid 1017536:tid 1017634] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/env.bak"] [unique_id "apK86yJcY4fy7tP-rU3e-AACI2E"] [Sat Aug 29 05:05:15.321653 2026] [security2:error] [pid 1018003:tid 1018165] [client 52.139.37.240:56822] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "autodiscover.jjfreeman.net"] [uri "/c99.php"] [unique_id "apK86zAh5Y1i2tUxg4HdCAAABcY"] [Sat Aug 29 05:05:15.327082 2026] [security2:error] [pid 1018003:tid 1018037] [remote 74.7.227.154:56576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK86zAh5Y1i2tUxg4HdCgAF2BA"], referer: https://goodtogo.store/sitemap_index.xml [Sat Aug 29 05:05:15.328432 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.48.250.41:65460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/lkui.php"] [unique_id "apK86zAh5Y1i2tUxg4HdCwAABbk"] [Sat Aug 29 05:05:15.331880 2026] [security2:error] [pid 1018003:tid 1018203] [client 68.155.159.216:18284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/worksec.php"] [unique_id "apK86zAh5Y1i2tUxg4HdDAAABew"] [Sat Aug 29 05:05:15.342055 2026] [security2:error] [pid 1017536:tid 1017746] [client 158.23.147.79:50087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/cgi-bin/index.php"] [unique_id "apK86yJcY4fy7tP-rU3e_AAAAmQ"] [Sat Aug 29 05:05:15.345420 2026] [security2:error] [pid 1017536:tid 1017774] [client 158.23.184.117:21919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/min.php"] [unique_id "apK86yJcY4fy7tP-rU3e_QAAAoA"] [Sat Aug 29 05:05:15.346238 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.48.250.41:23518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/666.php"] [unique_id "apK86yJcY4fy7tP-rU3e_gAAAn4"] [Sat Aug 29 05:05:15.351752 2026] [security2:error] [pid 1018003:tid 1018220] [client 168.107.94.195:51959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK86zAh5Y1i2tUxg4HdDQAABf0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:15.353666 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.63.219.114:1944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/randkeyword.php"] [unique_id "apK86zAh5Y1i2tUxg4HdDgAABhE"] [Sat Aug 29 05:05:15.363894 2026] [security2:error] [pid 1018003:tid 1018219] [client 52.139.37.240:25038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/shell.php"] [unique_id "apK86zAh5Y1i2tUxg4HdDwAABfw"] [Sat Aug 29 05:05:15.387711 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.63.81.20:26573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/55.php"] [unique_id "apK86yJcY4fy7tP-rU3fAgAAAm4"] [Sat Aug 29 05:05:15.392075 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.48.160.90:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-tymanage.php"] [unique_id "apK86zAh5Y1i2tUxg4HdEQAABgs"] [Sat Aug 29 05:05:15.395220 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.250.41:12334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/motu.php"] [unique_id "apK86zAh5Y1i2tUxg4HdEgAABds"] [Sat Aug 29 05:05:15.416086 2026] [security2:error] [pid 1018003:tid 1018156] [client 68.155.159.216:24532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK86zAh5Y1i2tUxg4HdFAAABb0"] [Sat Aug 29 05:05:15.419422 2026] [security2:error] [pid 1017536:tid 1017667] [client 158.23.184.117:14484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/identity.php"] [unique_id "apK86yJcY4fy7tP-rU3fBQAAAhU"] [Sat Aug 29 05:05:15.420630 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.48.250.41:58497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/gdn.php"] [unique_id "apK86yJcY4fy7tP-rU3fBgAAAik"] [Sat Aug 29 05:05:15.422419 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.251.3:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/xza.php"] [unique_id "apK86zAh5Y1i2tUxg4HdFQAABeU"] [Sat Aug 29 05:05:15.435108 2026] [security2:error] [pid 1017536:tid 1017638] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env.production.bak"] [unique_id "apK86yJcY4fy7tP-rU3fCAACPWU"] [Sat Aug 29 05:05:15.438484 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.48.160.90:40026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apK86yJcY4fy7tP-rU3fCgAAAns"] [Sat Aug 29 05:05:15.438740 2026] [security2:error] [pid 1018003:tid 1018254] [client 52.139.37.240:20755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/jga.php"] [unique_id "apK86zAh5Y1i2tUxg4HdFgAABh4"] [Sat Aug 29 05:05:15.439478 2026] [security2:error] [pid 1017536:tid 1017706] [client 40.83.93.50:14265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/db-status.php"] [unique_id "apK86yJcY4fy7tP-rU3fCwAAAjw"] [Sat Aug 29 05:05:15.441352 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.63.219.114:9390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/disagreed.php"] [unique_id "apK86yJcY4fy7tP-rU3fDAAAAi0"] [Sat Aug 29 05:05:15.443581 2026] [security2:error] [pid 1017536:tid 1017644] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.115.196.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "infinitidealership.com"] [uri "/config/.env.php"] [unique_id "apK86yJcY4fy7tP-rU3fDQACPms"] [Sat Aug 29 05:05:15.446787 2026] [security2:error] [pid 1017536:tid 1017702] [client 158.23.184.117:56667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/PHPMailer.php"] [unique_id "apK86yJcY4fy7tP-rU3fDgAAAjg"] [Sat Aug 29 05:05:15.455465 2026] [security2:error] [pid 1017536:tid 1017660] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/.env"] [unique_id "apK86yJcY4fy7tP-rU3fEAACUHs"] [Sat Aug 29 05:05:15.459447 2026] [security2:error] [pid 1017536:tid 1017656] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/root/.env"] [unique_id "apK86yJcY4fy7tP-rU3fFQACL3c"] [Sat Aug 29 05:05:15.459741 2026] [security2:error] [pid 1017536:tid 1017661] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env.prod.bak"] [unique_id "apK86yJcY4fy7tP-rU3fEwACL3w"] [Sat Aug 29 05:05:15.459741 2026] [security2:error] [pid 1017536:tid 1017651] [remote 104.196.51.122:56248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/api/.env.bak"] [unique_id "apK86yJcY4fy7tP-rU3fEgACL3I"] [Sat Aug 29 05:05:15.461820 2026] [cgid:error] [pid 1017536:tid 1017592] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:15.462275 2026] [security2:error] [pid 1018003:tid 1018271] [client 45.154.98.191:50742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK86zAh5Y1i2tUxg4HdGgAABi8"] [Sat Aug 29 05:05:15.478129 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.48.250.41:64158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK86zAh5Y1i2tUxg4HdGwAABdQ"] [Sat Aug 29 05:05:15.484170 2026] [security2:error] [pid 1018003:tid 1018224] [client 162.198.206.205:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK86zAh5Y1i2tUxg4HdHAAABgE"], referer: https://www.djiboutihomes.com/ [Sat Aug 29 05:05:15.491376 2026] [security2:error] [pid 1018003:tid 1018164] [client 158.23.184.117:21900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/module.php"] [unique_id "apK86zAh5Y1i2tUxg4HdHQAABcU"] [Sat Aug 29 05:05:15.502981 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.184.117:56065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK86zAh5Y1i2tUxg4HdHwAABgM"] [Sat Aug 29 05:05:15.503425 2026] [security2:error] [pid 1017536:tid 1017609] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.213.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mikeycunningham.com"] [uri "/wp-login.php"] [unique_id "apK86yJcY4fy7tP-rU3fDwACdkg"], referer: https://www.mikeycunningham.com/login [Sat Aug 29 05:05:15.521197 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.196.209.81:8947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/test.php"] [unique_id "apK86yJcY4fy7tP-rU3fJwAAAoQ"] [Sat Aug 29 05:05:15.523626 2026] [security2:error] [pid 1018003:tid 1018174] [client 52.139.37.240:28250] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "autodiscover.jjfreeman.net"] [uri "/c99.php"] [unique_id "apK86zAh5Y1i2tUxg4HdIQAABc8"] [Sat Aug 29 05:05:15.528091 2026] [security2:error] [pid 1018003:tid 1018241] [client 74.248.24.12:17502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/a.php"] [unique_id "apK86zAh5Y1i2tUxg4HdIwAABhE"] [Sat Aug 29 05:05:15.530808 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.48.250.41:12422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/Ov-Simple1.php"] [unique_id "apK86yJcY4fy7tP-rU3fKQAAAhs"] [Sat Aug 29 05:05:15.540344 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.48.160.90:62637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/ajfto.php"] [unique_id "apK86zAh5Y1i2tUxg4HdJAAABiI"] [Sat Aug 29 05:05:15.543701 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.196.209.81:9489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/global.php"] [unique_id "apK86yJcY4fy7tP-rU3fKwAAAn8"] [Sat Aug 29 05:05:15.550243 2026] [cgid:error] [pid 1017536:tid 1017575] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:15.550950 2026] [cgid:error] [pid 1017536:tid 1017539] [remote 104.196.51.122:56248] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:15.560891 2026] [security2:error] [pid 1018003:tid 1018164] [client 52.139.37.240:24611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK86zAh5Y1i2tUxg4HdJQAABcU"] [Sat Aug 29 05:05:15.560921 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.63.81.20:26542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/yj09.php"] [unique_id "apK86zAh5Y1i2tUxg4HdJgAABbg"] [Sat Aug 29 05:05:15.575981 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.160.90:26696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apK86zAh5Y1i2tUxg4HdKQAABbo"] [Sat Aug 29 05:05:15.577634 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.158.54.35:22596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/themes/admin.php"] [unique_id "apK86zAh5Y1i2tUxg4HdKgAABcQ"] [Sat Aug 29 05:05:15.577906 2026] [security2:error] [pid 1018003:tid 1018208] [client 20.48.251.3:57919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ms-edit.php"] [unique_id "apK86zAh5Y1i2tUxg4HdKwAABfE"] [Sat Aug 29 05:05:15.590020 2026] [security2:error] [pid 1018003:tid 1018173] [client 4.232.148.111:19911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/txets.php"] [unique_id "apK86zAh5Y1i2tUxg4HdLgAABc4"] [Sat Aug 29 05:05:15.592719 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.48.250.41:23424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/knmt.php"] [unique_id "apK86yJcY4fy7tP-rU3fMQAAAkk"] [Sat Aug 29 05:05:15.592737 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.48.250.41:61743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/f2.php"] [unique_id "apK86yJcY4fy7tP-rU3fLwAAAlQ"] [Sat Aug 29 05:05:15.592816 2026] [security2:error] [pid 1018003:tid 1018178] [client 158.23.184.117:6527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "apK86zAh5Y1i2tUxg4HdLwAABdM"] [Sat Aug 29 05:05:15.596399 2026] [security2:error] [pid 1017536:tid 1017663] [remote 104.196.51.122:56248] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK86yJcY4fy7tP-rU3fMgACXn4"] [Sat Aug 29 05:05:15.609070 2026] [security2:error] [pid 1017536:tid 1017576] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "infinitidealership.com"] [uri "/wp-config.php.bak"] [unique_id "apK86yJcY4fy7tP-rU3fNQACRSc"] [Sat Aug 29 05:05:15.610123 2026] [security2:error] [pid 1017536:tid 1017544] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/laravel/.env"] [unique_id "apK86yJcY4fy7tP-rU3fNAACRQc"] [Sat Aug 29 05:05:15.610183 2026] [security2:error] [pid 1017536:tid 1017553] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "infinitidealership.com"] [uri "/wp-config.php.old"] [unique_id "apK86yJcY4fy7tP-rU3fNgACRRA"] [Sat Aug 29 05:05:15.612717 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.196.209.81:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/flower.php"] [unique_id "apK86zAh5Y1i2tUxg4HdMAAABhU"] [Sat Aug 29 05:05:15.613592 2026] [security2:error] [pid 1017536:tid 1017546] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.115.196.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "infinitidealership.com"] [uri "/.env.php.bak"] [unique_id "apK86yJcY4fy7tP-rU3fOAACRQk"] [Sat Aug 29 05:05:15.615979 2026] [security2:error] [pid 1018003:tid 1018209] [client 158.23.184.117:14467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/Radio.php"] [unique_id "apK86zAh5Y1i2tUxg4HdMQAABfI"] [Sat Aug 29 05:05:15.640374 2026] [security2:error] [pid 1018003:tid 1018215] [client 158.23.184.117:21860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/options.php"] [unique_id "apK86zAh5Y1i2tUxg4HdMgAABfg"] [Sat Aug 29 05:05:15.641278 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.63.219.114:9161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/colors.php"] [unique_id "apK86yJcY4fy7tP-rU3fOgAAAnw"] [Sat Aug 29 05:05:15.647630 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.147.79:25554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK86yJcY4fy7tP-rU3fOwAAAiA"] [Sat Aug 29 05:05:15.650908 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.184.117:25537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "apK86zAh5Y1i2tUxg4HdMwAABeE"] [Sat Aug 29 05:05:15.662559 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.250.41:12363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/wp-blogs.php"] [unique_id "apK86zAh5Y1i2tUxg4HdNAAABfs"] [Sat Aug 29 05:05:15.672346 2026] [security2:error] [pid 1017536:tid 1017698] [client 185.104.184.230:49454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "apK86yJcY4fy7tP-rU3fPQAAAjQ"] [Sat Aug 29 05:05:15.673247 2026] [security2:error] [pid 1017536:tid 1017710] [client 52.139.37.240:20746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/mac.php"] [unique_id "apK86yJcY4fy7tP-rU3fPgAAAkA"] [Sat Aug 29 05:05:15.676120 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.48.250.41:65439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/motu.php"] [unique_id "apK86zAh5Y1i2tUxg4HdNQAABg8"] [Sat Aug 29 05:05:15.682275 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.160.90:28580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apK86yJcY4fy7tP-rU3fQAAAAmo"] [Sat Aug 29 05:05:15.693954 2026] [security2:error] [pid 1017536:tid 1017594] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/core/.env"] [unique_id "apK86yJcY4fy7tP-rU3fQgACkzk"] [Sat Aug 29 05:05:15.702300 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.63.81.20:26524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/scxy.php"] [unique_id "apK86zAh5Y1i2tUxg4HdNwAABiU"] [Sat Aug 29 05:05:15.706523 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.160.90:40050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/edit.php"] [unique_id "apK86zAh5Y1i2tUxg4HdOAAABgw"] [Sat Aug 29 05:05:15.723146 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.48.251.3:57792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/lmfi2.php"] [unique_id "apK86zAh5Y1i2tUxg4HdOQAABcw"] [Sat Aug 29 05:05:15.723755 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.48.250.41:61749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/grsiuk.php"] [unique_id "apK86zAh5Y1i2tUxg4HdOgAABbk"] [Sat Aug 29 05:05:15.731745 2026] [security2:error] [pid 1018003:tid 1018268] [client 168.107.94.195:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK86zAh5Y1i2tUxg4HdOwAABiw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:15.740196 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.63.219.114:7916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/goods.php"] [unique_id "apK86yJcY4fy7tP-rU3fSwAAAkQ"] [Sat Aug 29 05:05:15.740807 2026] [security2:error] [pid 1017536:tid 1017597] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.github/.env"] [unique_id "apK86yJcY4fy7tP-rU3fSgACdjw"] [Sat Aug 29 05:05:15.743820 2026] [core:error] [pid 1018003:tid 1018225] [client 74.248.24.12:21351] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.743840 2026] [core:error] [pid 1018003:tid 1018225] [client 74.248.24.12:21351] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:15.744180 2026] [security2:error] [pid 1017536:tid 1017728] [client 158.23.147.79:55904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/nf_tracking.php"] [unique_id "apK86yJcY4fy7tP-rU3fTAAAAlI"] [Sat Aug 29 05:05:15.766403 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.250.41:23462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/sbhu.php"] [unique_id "apK86yJcY4fy7tP-rU3fUgAAAjs"] [Sat Aug 29 05:05:15.771182 2026] [security2:error] [pid 1017536:tid 1017713] [client 68.155.159.216:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK86yJcY4fy7tP-rU3fUwAAAkM"] [Sat Aug 29 05:05:15.775522 2026] [security2:error] [pid 1018003:tid 1018187] [client 52.139.37.240:25039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK86zAh5Y1i2tUxg4HdPwAABdw"] [Sat Aug 29 05:05:15.786427 2026] [security2:error] [pid 1017536:tid 1017775] [client 68.155.159.216:12124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/xmlrpc.php"] [unique_id "apK86yJcY4fy7tP-rU3fVQAAAoE"] [Sat Aug 29 05:05:15.788266 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.184.117:21909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/panel.php"] [unique_id "apK86zAh5Y1i2tUxg4HdQAAABd0"] [Sat Aug 29 05:05:15.793729 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.250.41:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/mini.php"] [unique_id "apK86yJcY4fy7tP-rU3fVwAAAj8"] [Sat Aug 29 05:05:15.801904 2026] [security2:error] [pid 1017536:tid 1017724] [client 143.244.57.82:48360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK86yJcY4fy7tP-rU3fWwAAAk4"] [Sat Aug 29 05:05:15.802023 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.184.117:6485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/admin/alfa-rex.php"] [unique_id "apK86yJcY4fy7tP-rU3fWgAAAoI"] [Sat Aug 29 05:05:15.818858 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.48.250.41:64958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/Ov-Simple1.php"] [unique_id "apK86zAh5Y1i2tUxg4HdQQAABhY"] [Sat Aug 29 05:05:15.819727 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.48.160.90:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apK86yJcY4fy7tP-rU3fXAAAAnM"] [Sat Aug 29 05:05:15.820387 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.184.117:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/Requests/Exception/file.php"] [unique_id "apK86zAh5Y1i2tUxg4HdQgAABfw"] [Sat Aug 29 05:05:15.837108 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.160.90:45920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/tqkdqbbv.php"] [unique_id "apK86zAh5Y1i2tUxg4HdQwAABcM"] [Sat Aug 29 05:05:15.847506 2026] [security2:error] [pid 1017536:tid 1017601] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.env.swp"] [unique_id "apK86yJcY4fy7tP-rU3fXQACJ0A"] [Sat Aug 29 05:05:15.853368 2026] [security2:error] [pid 1017536:tid 1017725] [client 158.23.184.117:24865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK86yJcY4fy7tP-rU3fXwAAAk8"] [Sat Aug 29 05:05:15.853372 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.63.81.20:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/ws13.php"] [unique_id "apK86zAh5Y1i2tUxg4HdRAAABgs"] [Sat Aug 29 05:05:15.859714 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.251.3:57860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wpver.php"] [unique_id "apK86yJcY4fy7tP-rU3fYAAAAmY"] [Sat Aug 29 05:05:15.867700 2026] [security2:error] [pid 1018003:tid 1018260] [client 52.139.37.240:20740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK86zAh5Y1i2tUxg4HdRgAABiQ"] [Sat Aug 29 05:05:15.888552 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.63.219.114:12723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/class_api.php"] [unique_id "apK86yJcY4fy7tP-rU3fZAAAAo4"] [Sat Aug 29 05:05:15.898189 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.48.250.41:58535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/wp-scr1pts.php"] [unique_id "apK86zAh5Y1i2tUxg4HdSAAABb0"] [Sat Aug 29 05:05:15.912442 2026] [security2:error] [pid 1018003:tid 1018177] [client 104.207.50.97:58425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK86zAh5Y1i2tUxg4HdRwAABdI"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:15.925552 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.48.250.41:12373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/amp.php"] [unique_id "apK86zAh5Y1i2tUxg4HdTAAABgo"] [Sat Aug 29 05:05:15.926560 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.250.41:23457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/a332.php"] [unique_id "apK86zAh5Y1i2tUxg4HdTQAABd8"] [Sat Aug 29 05:05:15.935167 2026] [security2:error] [pid 1018003:tid 1018273] [client 40.83.93.50:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK86zAh5Y1i2tUxg4HdTgAABjE"] [Sat Aug 29 05:05:15.937278 2026] [security2:error] [pid 1017536:tid 1017769] [client 4.205.62.107:64192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/debuggen.php"] [unique_id "apK86yJcY4fy7tP-rU3fbAAAAns"] [Sat Aug 29 05:05:15.937869 2026] [security2:error] [pid 1018003:tid 1018199] [client 158.23.184.117:21869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "apK86zAh5Y1i2tUxg4HdTwAABeg"] [Sat Aug 29 05:05:15.942032 2026] [cgid:error] [pid 1018003:tid 1018180] [client 20.196.209.81:17974] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/carolinashooter/404.shtml [Sat Aug 29 05:05:15.947145 2026] [security2:error] [pid 1018003:tid 1018227] [client 158.23.184.117:6489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-content/export.php"] [unique_id "apK86zAh5Y1i2tUxg4HdUAAABgQ"] [Sat Aug 29 05:05:15.951078 2026] [security2:error] [pid 1017536:tid 1017708] [client 4.205.62.107:22469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/autogooey.php"] [unique_id "apK86yJcY4fy7tP-rU3fcQAAAj4"] [Sat Aug 29 05:05:15.954483 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.147.79:30698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK86zAh5Y1i2tUxg4HdUQAABdQ"] [Sat Aug 29 05:05:15.962155 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.196.209.81:15789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/update.php"] [unique_id "apK86zAh5Y1i2tUxg4HdUwAABi0"] [Sat Aug 29 05:05:15.983967 2026] [security2:error] [pid 1018003:tid 1018177] [client 52.139.37.240:24824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-header-json.php"] [unique_id "apK86zAh5Y1i2tUxg4HdVgAABdI"] [Sat Aug 29 05:05:15.984174 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.160.90:45939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/kjyehoxl.php"] [unique_id "apK86zAh5Y1i2tUxg4HdVwAABcg"] [Sat Aug 29 05:05:15.985749 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.48.160.90:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apK86zAh5Y1i2tUxg4HdWAAABgc"] [Sat Aug 29 05:05:15.985831 2026] [security2:error] [pid 1018003:tid 1018052] [remote 104.196.51.122:56256] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.bigbuttonscarf.com"] [uri "/_image"] [unique_id "apK86zAh5Y1i2tUxg4HdWQAF5R8"] [Sat Aug 29 05:05:15.990276 2026] [security2:error] [pid 1018003:tid 1018224] [client 68.155.159.216:16154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/themes/too.php"] [unique_id "apK86zAh5Y1i2tUxg4HdWwAABgE"] [Sat Aug 29 05:05:15.992758 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.48.251.3:28475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ah25.php"] [unique_id "apK86zAh5Y1i2tUxg4HdXAAABfA"] [Sat Aug 29 05:05:16.006656 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.203.141.11:18253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/wp-content/admin.php"] [unique_id "apK87DAh5Y1i2tUxg4HdXQAABbg"] [Sat Aug 29 05:05:16.008410 2026] [security2:error] [pid 1017536:tid 1017549] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.115.196.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "infinitidealership.com"] [uri "/config.php.bak"] [unique_id "apK87CJcY4fy7tP-rU3feAACUAw"] [Sat Aug 29 05:05:16.008438 2026] [security2:error] [pid 1017536:tid 1017578] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.115.196.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "infinitidealership.com"] [uri "/configuration.php.bak"] [unique_id "apK87CJcY4fy7tP-rU3feQACUCk"] [Sat Aug 29 05:05:16.010660 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.196.209.81:1705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/meta.php"] [unique_id "apK87CJcY4fy7tP-rU3fewAAAmU"] [Sat Aug 29 05:05:16.015433 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.104.49.130:57671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/wpxml.php"] [unique_id "apK87CJcY4fy7tP-rU3ffAAAAi8"] [Sat Aug 29 05:05:16.020635 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.250.41:64985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/wp-blogs.php"] [unique_id "apK87CJcY4fy7tP-rU3ffQAAAlo"] [Sat Aug 29 05:05:16.021226 2026] [security2:error] [pid 1018003:tid 1018269] [client 158.23.184.117:25548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "apK87DAh5Y1i2tUxg4HdXwAABi0"] [Sat Aug 29 05:05:16.023347 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.184.117:15020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-admin/add.php"] [unique_id "apK87DAh5Y1i2tUxg4HdYAAABbw"] [Sat Aug 29 05:05:16.028908 2026] [security2:error] [pid 1017536:tid 1017696] [client 34.7.216.49:61546] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/@fs/proc/self/environ"] [unique_id "apK87CJcY4fy7tP-rU3ffwAAAjI"] [Sat Aug 29 05:05:16.029015 2026] [security2:error] [pid 1017536:tid 1017760] [client 158.158.54.35:10825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/css/admin.php"] [unique_id "apK87CJcY4fy7tP-rU3ffgAAAnI"] [Sat Aug 29 05:05:16.032654 2026] [security2:error] [pid 1018003:tid 1018248] [client 68.155.159.216:16246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/nf_tracking.php"] [unique_id "apK87DAh5Y1i2tUxg4HdYgAABhg"] [Sat Aug 29 05:05:16.035733 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.63.219.114:18694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/Js.php"] [unique_id "apK87DAh5Y1i2tUxg4HdZAAABcE"] [Sat Aug 29 05:05:16.037737 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.63.81.20:26470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/btx25.php"] [unique_id "apK87CJcY4fy7tP-rU3fhAAAAh0"] [Sat Aug 29 05:05:16.046379 2026] [security2:error] [pid 1017536:tid 1017744] [client 45.154.98.191:50972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK87CJcY4fy7tP-rU3fhQAAAmI"] [Sat Aug 29 05:05:16.052786 2026] [security2:error] [pid 1017536:tid 1017611] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config.php"] [unique_id "apK87CJcY4fy7tP-rU3fhgACkko"] [Sat Aug 29 05:05:16.058932 2026] [security2:error] [pid 1018003:tid 1018158] [client 158.23.147.79:24479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK87DAh5Y1i2tUxg4HdZgAABb8"] [Sat Aug 29 05:05:16.066721 2026] [security2:error] [pid 1018003:tid 1018166] [client 52.139.37.240:21412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK87DAh5Y1i2tUxg4HdZwAABcc"] [Sat Aug 29 05:05:16.067257 2026] [security2:error] [pid 1018003:tid 1018202] [client 74.248.24.12:8176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/u.php"] [unique_id "apK87DAh5Y1i2tUxg4HdaAAABes"] [Sat Aug 29 05:05:16.073075 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.196.209.81:17974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/user/f35.php"] [unique_id "apK87DAh5Y1i2tUxg4HdaQAABc8"] [Sat Aug 29 05:05:16.077317 2026] [security2:error] [pid 1018003:tid 1018253] [client 20.48.250.41:12445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/cc13.php"] [unique_id "apK87DAh5Y1i2tUxg4HdagAABh0"] [Sat Aug 29 05:05:16.082827 2026] [security2:error] [pid 1018003:tid 1018201] [client 145.239.10.137:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfieldperformanceinc.com"] [uri "/admin.php"] [unique_id "apK87DAh5Y1i2tUxg4HdawAABeo"], referer: http://greenfieldperformanceinc.com/admin.php [Sat Aug 29 05:05:16.085243 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.23.184.117:21522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/pki-validation/pl.php"] [unique_id "apK87CJcY4fy7tP-rU3fiwAAAkI"] [Sat Aug 29 05:05:16.088268 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.250.41:61716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/num.php"] [unique_id "apK87DAh5Y1i2tUxg4HdbAAABfs"] [Sat Aug 29 05:05:16.090883 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.184.117:56673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/new.php"] [unique_id "apK87DAh5Y1i2tUxg4HdbgAABcQ"] [Sat Aug 29 05:05:16.096776 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.205.62.107:21947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apK87CJcY4fy7tP-rU3fjgAAAlY"] [Sat Aug 29 05:05:16.098789 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.250.41:23532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ws66.php"] [unique_id "apK87DAh5Y1i2tUxg4HdbwAABjU"] [Sat Aug 29 05:05:16.108305 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.63.219.114:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/hehe.php"] [unique_id "apK87DAh5Y1i2tUxg4HdcAAABig"] [Sat Aug 29 05:05:16.124730 2026] [security2:error] [pid 1018003:tid 1018217] [client 168.107.94.195:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK87DAh5Y1i2tUxg4HdcQAABfo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:16.133196 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.160.90:63511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-mini.php"] [unique_id "apK87DAh5Y1i2tUxg4HdcgAABis"] [Sat Aug 29 05:05:16.135220 2026] [security2:error] [pid 1017536:tid 1017778] [client 68.155.159.216:14213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK87CJcY4fy7tP-rU3fkQAAAoQ"] [Sat Aug 29 05:05:16.141634 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.48.251.3:57907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/groceries/index.php"] [unique_id "apK87CJcY4fy7tP-rU3fkwAAAhs"] [Sat Aug 29 05:05:16.146513 2026] [security2:error] [pid 1017536:tid 1017585] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/storage/.env"] [unique_id "apK87CJcY4fy7tP-rU3flQACKjA"] [Sat Aug 29 05:05:16.149766 2026] [security2:error] [pid 1017536:tid 1017615] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/public/.env"] [unique_id "apK87CJcY4fy7tP-rU3flgACKk4"] [Sat Aug 29 05:05:16.149811 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.48.160.90:40043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/llyuxaqd.php"] [unique_id "apK87CJcY4fy7tP-rU3flwAAAn8"] [Sat Aug 29 05:05:16.157244 2026] [security2:error] [pid 1017536:tid 1017564] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/web/.env"] [unique_id "apK87CJcY4fy7tP-rU3fmAACgxs"] [Sat Aug 29 05:05:16.177595 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.63.81.20:26523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/SDsadqwrf.php"] [unique_id "apK87DAh5Y1i2tUxg4HdcwAABiA"] [Sat Aug 29 05:05:16.181066 2026] [security2:error] [pid 1018003:tid 1018159] [client 158.23.184.117:25553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/admin.php"] [unique_id "apK87DAh5Y1i2tUxg4HddQAABcA"] [Sat Aug 29 05:05:16.181140 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.184.117:14503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/assets/about.php"] [unique_id "apK87DAh5Y1i2tUxg4HddAAABco"] [Sat Aug 29 05:05:16.186854 2026] [security2:error] [pid 1017536:tid 1017614] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/wp/.env"] [unique_id "apK87CJcY4fy7tP-rU3fmwACRU0"] [Sat Aug 29 05:05:16.206187 2026] [security2:error] [pid 1018003:tid 1018261] [client 52.139.37.240:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/zup.php"] [unique_id "apK87DAh5Y1i2tUxg4HddgAABiU"] [Sat Aug 29 05:05:16.230543 2026] [security2:error] [pid 1017536:tid 1017755] [client 20.48.250.41:58615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/a4.php"] [unique_id "apK87CJcY4fy7tP-rU3fpAAAAm0"] [Sat Aug 29 05:05:16.233464 2026] [security2:error] [pid 1018003:tid 1018154] [client 158.23.184.117:21513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/pki-validation/x.php"] [unique_id "apK87DAh5Y1i2tUxg4HddwAABbs"] [Sat Aug 29 05:05:16.237904 2026] [security2:error] [pid 1017536:tid 1017750] [client 158.23.184.117:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-content/plugins/revslider/admin.php"] [unique_id "apK87CJcY4fy7tP-rU3fpQAAAmg"] [Sat Aug 29 05:05:16.247277 2026] [security2:error] [pid 1018003:tid 1018192] [client 74.248.24.12:27422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK87DAh5Y1i2tUxg4HdeQAABeE"] [Sat Aug 29 05:05:16.258891 2026] [security2:error] [pid 1018003:tid 1018197] [client 185.104.184.230:49456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK87DAh5Y1i2tUxg4HdegAABeY"] [Sat Aug 29 05:05:16.260792 2026] [security2:error] [pid 1018003:tid 1018187] [client 4.205.62.107:2556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/wp-content/themes/luJMF.php"] [unique_id "apK87DAh5Y1i2tUxg4HdewAABdw"] [Sat Aug 29 05:05:16.262381 2026] [security2:error] [pid 1017536:tid 1017716] [client 52.139.37.240:21418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/zafir1.php"] [unique_id "apK87CJcY4fy7tP-rU3fpwAAAkY"] [Sat Aug 29 05:05:16.282873 2026] [security2:error] [pid 1017536:tid 1017569] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/wp-config.old"] [unique_id "apK87CJcY4fy7tP-rU3fqAACYCA"] [Sat Aug 29 05:05:16.286343 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.63.219.114:11929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/aksinet.php"] [unique_id "apK87CJcY4fy7tP-rU3fqQAAAlw"] [Sat Aug 29 05:05:16.287989 2026] [security2:error] [pid 1017536:tid 1017610] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "infinitidealership.com"] [uri "/wp-config.php.swp"] [unique_id "apK87CJcY4fy7tP-rU3fqgACakk"] [Sat Aug 29 05:05:16.290692 2026] [security2:error] [pid 1017536:tid 1017545] [remote 104.196.115.188:49502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "infinitidealership.com"] [uri "/wp-config.php~"] [unique_id "apK87CJcY4fy7tP-rU3fqwACYwg"] [Sat Aug 29 05:05:16.292737 2026] [security2:error] [pid 1017536:tid 1017793] [client 45.148.10.59:12534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theverystuff.com"] [uri "/wp/index.php"] [unique_id "apK87CJcY4fy7tP-rU3frAAAApM"] [Sat Aug 29 05:05:16.294071 2026] [security2:error] [pid 1018003:tid 1018251] [client 20.48.251.3:57857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/konfig.php"] [unique_id "apK87DAh5Y1i2tUxg4HdfQAABhs"] [Sat Aug 29 05:05:16.294556 2026] [security2:error] [pid 1017536:tid 1017648] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/aws.php"] [unique_id "apK87CJcY4fy7tP-rU3frQACkm8"] [Sat Aug 29 05:05:16.299988 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.48.160.90:62694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/xmini4.php"] [unique_id "apK87DAh5Y1i2tUxg4HdfgAABjY"] [Sat Aug 29 05:05:16.300279 2026] [security2:error] [pid 1017536:tid 1017634] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/config.inc.php"] [unique_id "apK87CJcY4fy7tP-rU3fsAACkmE"] [Sat Aug 29 05:05:16.327658 2026] [security2:error] [pid 1018003:tid 1018195] [client 158.23.184.117:25595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/api.php"] [unique_id "apK87DAh5Y1i2tUxg4HdfwAABeQ"] [Sat Aug 29 05:05:16.349965 2026] [security2:error] [pid 1017536:tid 1017608] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/config.php"] [unique_id "apK87CJcY4fy7tP-rU3ftQACkkc"] [Sat Aug 29 05:05:16.350301 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.160.90:40004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/nbwxolou.php"] [unique_id "apK87CJcY4fy7tP-rU3ftgAAAis"] [Sat Aug 29 05:05:16.352682 2026] [security2:error] [pid 1018003:tid 1018243] [client 143.244.57.82:48362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK87DAh5Y1i2tUxg4HdggAABhM"] [Sat Aug 29 05:05:16.353869 2026] [security2:error] [pid 1017536:tid 1017713] [client 68.155.159.216:50276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK87CJcY4fy7tP-rU3ftwAAAkM"] [Sat Aug 29 05:05:16.359592 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.63.81.20:26399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/BDKR28WP.php"] [unique_id "apK87CJcY4fy7tP-rU3fuAAAAoE"] [Sat Aug 29 05:05:16.364850 2026] [security2:error] [pid 1017536:tid 1017709] [client 4.205.62.107:53426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/saml.php"] [unique_id "apK87CJcY4fy7tP-rU3fuQAAAj8"] [Sat Aug 29 05:05:16.366536 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.196.209.81:4994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/blog.php"] [unique_id "apK87CJcY4fy7tP-rU3fugAAAkc"] [Sat Aug 29 05:05:16.376748 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.147.79:58107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK87CJcY4fy7tP-rU3fvgAAAk4"] [Sat Aug 29 05:05:16.381276 2026] [security2:error] [pid 1017536:tid 1017720] [client 158.23.184.117:21898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "apK87CJcY4fy7tP-rU3fvwAAAko"] [Sat Aug 29 05:05:16.383715 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.184.117:14477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-content/themes/twentytwentythree.php"] [unique_id "apK87CJcY4fy7tP-rU3fwQAAAiU"] [Sat Aug 29 05:05:16.385651 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.184.117:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-content/images/uploads/admin.php"] [unique_id "apK87CJcY4fy7tP-rU3fwgAAAjs"] [Sat Aug 29 05:05:16.389234 2026] [autoindex:error] [pid 1017536:tid 1017735] [client 4.232.148.111:0] AH01276: Cannot serve directory /home4/ehfields/public_html/tiaandephraim/wp-includes/css/dist/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:16.398112 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.63.219.114:18690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/access.php"] [unique_id "apK87DAh5Y1i2tUxg4HdgwAABiM"] [Sat Aug 29 05:05:16.399038 2026] [security2:error] [pid 1017536:tid 1017670] [client 4.205.62.107:57783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apK87CJcY4fy7tP-rU3fwwAAAhg"] [Sat Aug 29 05:05:16.403977 2026] [security2:error] [pid 1017536:tid 1017731] [client 52.139.37.240:25061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/a9.php"] [unique_id "apK87CJcY4fy7tP-rU3fxAAAAlU"] [Sat Aug 29 05:05:16.407846 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.196.209.81:1721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/randkeyword.php"] [unique_id "apK87DAh5Y1i2tUxg4HdhAAABjM"] [Sat Aug 29 05:05:16.409501 2026] [security2:error] [pid 1018003:tid 1018198] [client 40.83.93.50:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/f35.php"] [unique_id "apK87DAh5Y1i2tUxg4HdhQAABec"] [Sat Aug 29 05:05:16.424416 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.48.251.3:57917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/paths.php"] [unique_id "apK87CJcY4fy7tP-rU3fxgAAAn4"] [Sat Aug 29 05:05:16.435396 2026] [security2:error] [pid 1018003:tid 1018180] [client 4.232.148.111:1433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-content/themes/about.php"] [unique_id "apK87DAh5Y1i2tUxg4HdhgAABdU"] [Sat Aug 29 05:05:16.444324 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.160.90:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/reop3.php"] [unique_id "apK87CJcY4fy7tP-rU3fyQAAAnk"] [Sat Aug 29 05:05:16.447101 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.147.79:50053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK87DAh5Y1i2tUxg4HdhwAABdQ"] [Sat Aug 29 05:05:16.452308 2026] [security2:error] [pid 1017536:tid 1017784] [client 68.155.159.216:18271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/x.php"] [unique_id "apK87CJcY4fy7tP-rU3fygAAAoo"] [Sat Aug 29 05:05:16.453258 2026] [security2:error] [pid 1017536:tid 1017630] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/env.php"] [unique_id "apK87CJcY4fy7tP-rU3fywACe10"] [Sat Aug 29 05:05:16.456799 2026] [security2:error] [pid 1017536:tid 1017555] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/module.config.php"] [unique_id "apK87CJcY4fy7tP-rU3fzgACFRI"] [Sat Aug 29 05:05:16.460753 2026] [security2:error] [pid 1018003:tid 1018212] [client 213.202.253.4:56035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/adminfuns.php"] [unique_id "apK87DAh5Y1i2tUxg4HdiAAABfU"], referer: www.google.com [Sat Aug 29 05:05:16.460753 2026] [security2:error] [pid 1017536:tid 1017636] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/nexmo.php"] [unique_id "apK87CJcY4fy7tP-rU3fzwACFWM"] [Sat Aug 29 05:05:16.460796 2026] [security2:error] [pid 1017536:tid 1017680] [client 52.139.37.240:21379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/abc.php"] [unique_id "apK87CJcY4fy7tP-rU3f0AAAAiI"] [Sat Aug 29 05:05:16.462582 2026] [security2:error] [pid 1017536:tid 1017789] [client 104.207.40.104:16803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.40.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK87CJcY4fy7tP-rU3fyAAAAo8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:16.464532 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.63.219.114:1976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK87CJcY4fy7tP-rU3f0QAAAho"] [Sat Aug 29 05:05:16.469864 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.196.209.81:12403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/user/min.php"] [unique_id "apK87DAh5Y1i2tUxg4HdiQAABb0"] [Sat Aug 29 05:05:16.472936 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.158.54.35:6058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/adminfuns.php"] [unique_id "apK87CJcY4fy7tP-rU3f0gAAAkE"] [Sat Aug 29 05:05:16.473364 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.203.141.11:11980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/wp-configs.php"] [unique_id "apK87CJcY4fy7tP-rU3f0wAAAjY"] [Sat Aug 29 05:05:16.474943 2026] [security2:error] [pid 1017536:tid 1017684] [client 158.23.184.117:25140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/chosen.php"] [unique_id "apK87CJcY4fy7tP-rU3f1AAAAiY"] [Sat Aug 29 05:05:16.475953 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.104.49.130:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/static.php"] [unique_id "apK87DAh5Y1i2tUxg4HdigAABic"] [Sat Aug 29 05:05:16.482573 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.160.90:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/nsxeubyv.php"] [unique_id "apK87DAh5Y1i2tUxg4HdiwAABgY"] [Sat Aug 29 05:05:16.507757 2026] [security2:error] [pid 1017536:tid 1017757] [client 168.107.94.195:52972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK87CJcY4fy7tP-rU3f2QAAAm8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:16.525828 2026] [security2:error] [pid 1017536:tid 1017708] [client 158.23.184.117:21908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/security.php"] [unique_id "apK87CJcY4fy7tP-rU3f4AAAAj4"] [Sat Aug 29 05:05:16.528835 2026] [security2:error] [pid 1017536:tid 1017556] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/stripe.php"] [unique_id "apK87CJcY4fy7tP-rU3f4gACOBM"] [Sat Aug 29 05:05:16.536108 2026] [security2:error] [pid 1017536:tid 1017760] [client 68.155.159.216:24529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK87CJcY4fy7tP-rU3f4wAAAnI"] [Sat Aug 29 05:05:16.537867 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.184.117:6515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/tools.php"] [unique_id "apK87CJcY4fy7tP-rU3f5AAAAow"] [Sat Aug 29 05:05:16.544940 2026] [security2:error] [pid 1018003:tid 1018224] [client 4.232.148.111:21728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK87DAh5Y1i2tUxg4HdjQAABgE"] [Sat Aug 29 05:05:16.551287 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.63.81.20:26433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/sky.php"] [unique_id "apK87CJcY4fy7tP-rU3f5gAAAmI"] [Sat Aug 29 05:05:16.552870 2026] [security2:error] [pid 1017536:tid 1017707] [client 197.219.150.206:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK87CJcY4fy7tP-rU3f5wAAAj0"] [Sat Aug 29 05:05:16.553005 2026] [security2:error] [pid 1017536:tid 1017707] [client 197.219.150.206:55797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK87CJcY4fy7tP-rU3f5wAAAj0"] [Sat Aug 29 05:05:16.587116 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.184.117:14366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-content/languages/themes/num.php"] [unique_id "apK87DAh5Y1i2tUxg4HdjgAABfA"] [Sat Aug 29 05:05:16.594959 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.48.251.3:28449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/olfclass.php"] [unique_id "apK87CJcY4fy7tP-rU3f6AAAAjI"] [Sat Aug 29 05:05:16.617474 2026] [security2:error] [pid 1017536:tid 1017754] [client 74.248.24.12:35495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/r.php"] [unique_id "apK87CJcY4fy7tP-rU3f7QAAAmw"] [Sat Aug 29 05:05:16.620770 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.48.160.90:45878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/zfqipfss.php"] [unique_id "apK87DAh5Y1i2tUxg4HdkAAABbg"] [Sat Aug 29 05:05:16.622418 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.23.184.117:24837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/config.php"] [unique_id "apK87CJcY4fy7tP-rU3f7gAAAoY"] [Sat Aug 29 05:05:16.623567 2026] [security2:error] [pid 1017536:tid 1017739] [client 52.139.37.240:25026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/admin/index.php"] [unique_id "apK87CJcY4fy7tP-rU3f7wAAAl0"] [Sat Aug 29 05:05:16.640257 2026] [security2:error] [pid 1017536:tid 1017773] [client 68.155.159.216:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK87CJcY4fy7tP-rU3f8QAAAn8"] [Sat Aug 29 05:05:16.654465 2026] [security2:error] [pid 1018003:tid 1018200] [client 45.154.98.191:51297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK87DAh5Y1i2tUxg4HdkQAABek"] [Sat Aug 29 05:05:16.657923 2026] [security2:error] [pid 1018003:tid 1018258] [client 52.139.37.240:21394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/c1.php"] [unique_id "apK87DAh5Y1i2tUxg4HdkgAABiI"] [Sat Aug 29 05:05:16.669093 2026] [security2:error] [pid 1018003:tid 1018164] [client 158.23.184.117:21906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/system.php"] [unique_id "apK87DAh5Y1i2tUxg4HdlAAABcU"] [Sat Aug 29 05:05:16.685052 2026] [security2:error] [pid 1017536:tid 1017727] [client 158.23.184.117:56664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-content/uploads/my.php"] [unique_id "apK87CJcY4fy7tP-rU3f9wAAAlE"] [Sat Aug 29 05:05:16.694185 2026] [security2:error] [pid 1017536:tid 1017691] [client 60.243.207.176:49315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK87CJcY4fy7tP-rU3f-gAAAi0"] [Sat Aug 29 05:05:16.694893 2026] [security2:error] [pid 1017536:tid 1017691] [client 60.243.207.176:49315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK87CJcY4fy7tP-rU3f-gAAAi0"] [Sat Aug 29 05:05:16.696964 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.63.219.114:19407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/alfa-rex1.php"] [unique_id "apK87CJcY4fy7tP-rU3f-wAAAog"] [Sat Aug 29 05:05:16.697509 2026] [security2:error] [pid 1018003:tid 1018178] [client 20.48.160.90:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-mail.php"] [unique_id "apK87DAh5Y1i2tUxg4HdlQAABdM"] [Sat Aug 29 05:05:16.710937 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.63.81.20:26446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/file5.php"] [unique_id "apK87DAh5Y1i2tUxg4HdlgAABhU"] [Sat Aug 29 05:05:16.725676 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.251.3:28419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/gnmlc.php"] [unique_id "apK87CJcY4fy7tP-rU3f_gAAAmM"] [Sat Aug 29 05:05:16.735194 2026] [security2:error] [pid 1017536:tid 1017755] [client 158.23.184.117:14342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp.php"] [unique_id "apK87CJcY4fy7tP-rU3f_wAAAm0"] [Sat Aug 29 05:05:16.759227 2026] [security2:error] [pid 1018003:tid 1018201] [client 20.48.160.90:40025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plumplumscheese.com"] [uri "/zrjuyoos.php"] [unique_id "apK87DAh5Y1i2tUxg4HdlwAABeo"] [Sat Aug 29 05:05:16.766682 2026] [security2:error] [pid 1018003:tid 1018166] [client 158.23.184.117:24873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/core.php"] [unique_id "apK87DAh5Y1i2tUxg4HdmAAABcc"] [Sat Aug 29 05:05:16.768160 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.196.209.81:15793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/bypass.php"] [unique_id "apK87DAh5Y1i2tUxg4HdmQAABbw"] [Sat Aug 29 05:05:16.779497 2026] [cgid:error] [pid 1018003:tid 1018054] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.779898 2026] [security2:error] [pid 1018003:tid 1018222] [client 74.248.24.12:25703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/num.php"] [unique_id "apK87DAh5Y1i2tUxg4HdngAABf8"] [Sat Aug 29 05:05:16.780546 2026] [cgid:error] [pid 1018003:tid 1018046] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.780916 2026] [cgid:error] [pid 1018003:tid 1018044] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.781909 2026] [cgid:error] [pid 1018003:tid 1018040] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.784147 2026] [cgid:error] [pid 1018003:tid 1018054] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.784518 2026] [cgid:error] [pid 1018003:tid 1018051] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.809983 2026] [security2:error] [pid 1018003:tid 1018239] [client 158.23.184.117:21918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/users.php"] [unique_id "apK87DAh5Y1i2tUxg4HdoQAABg8"] [Sat Aug 29 05:05:16.811718 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.196.209.81:16297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/goods.php"] [unique_id "apK87DAh5Y1i2tUxg4HdogAABbo"] [Sat Aug 29 05:05:16.832279 2026] [security2:error] [pid 1018003:tid 1018215] [client 52.139.37.240:25081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/makeasmtp.php"] [unique_id "apK87DAh5Y1i2tUxg4HdowAABfg"] [Sat Aug 29 05:05:16.838931 2026] [security2:error] [pid 1017536:tid 1017675] [client 185.104.184.230:49462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK87CJcY4fy7tP-rU3gBgAAAh0"] [Sat Aug 29 05:05:16.841812 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.48.160.90:62599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-conffg.php"] [unique_id "apK87CJcY4fy7tP-rU3gBwAAAhg"] [Sat Aug 29 05:05:16.850168 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.23.147.79:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wzy.php"] [unique_id "apK87CJcY4fy7tP-rU3gCgAAAos"] [Sat Aug 29 05:05:16.854045 2026] [security2:error] [pid 1017536:tid 1017713] [client 52.139.37.240:21144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/index.php/feed/atom/"] [unique_id "apK87CJcY4fy7tP-rU3gDQAAAkM"] [Sat Aug 29 05:05:16.858536 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.48.251.3:57853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/koiy.php"] [unique_id "apK87CJcY4fy7tP-rU3gDgAAAn0"] [Sat Aug 29 05:05:16.863887 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.196.209.81:18217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/users.php"] [unique_id "apK87CJcY4fy7tP-rU3gEAAAAjk"] [Sat Aug 29 05:05:16.872531 2026] [security2:error] [pid 1017536:tid 1017734] [client 145.239.10.137:55863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfieldperformanceparts.com"] [uri "/admin.php"] [unique_id "apK87CJcY4fy7tP-rU3gEgAAAlg"], referer: http://greenfieldperformanceparts.com/admin.php [Sat Aug 29 05:05:16.874301 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.63.81.20:26447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/xyn.php"] [unique_id "apK87CJcY4fy7tP-rU3gEwAAAmc"] [Sat Aug 29 05:05:16.876700 2026] [cgid:error] [pid 1018003:tid 1018050] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.877318 2026] [cgid:error] [pid 1018003:tid 1018053] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.879723 2026] [security2:error] [pid 1017536:tid 1017591] [remote 104.196.115.188:49502] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "infinitidealership.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK87CJcY4fy7tP-rU3gFQACUzY"] [Sat Aug 29 05:05:16.881962 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.184.117:14519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/xmlrpc.php"] [unique_id "apK87DAh5Y1i2tUxg4HdqQAABbk"] [Sat Aug 29 05:05:16.882670 2026] [cgid:error] [pid 1018003:tid 1018043] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.883820 2026] [security2:error] [pid 1017536:tid 1017752] [client 40.83.93.50:10840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/index.php"] [unique_id "apK87CJcY4fy7tP-rU3gFwAAAmo"] [Sat Aug 29 05:05:16.887289 2026] [cgid:error] [pid 1018003:tid 1018055] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.887301 2026] [cgid:error] [pid 1018003:tid 1018056] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:16.890669 2026] [security2:error] [pid 1017536:tid 1017784] [client 168.107.94.195:53355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK87CJcY4fy7tP-rU3gGQAAAoo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:16.891070 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.63.219.114:9183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/wp-contentt.php"] [unique_id "apK87DAh5Y1i2tUxg4HdqgAABjI"] [Sat Aug 29 05:05:16.896163 2026] [security2:error] [pid 1018003:tid 1018269] [client 143.244.57.82:48376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK87DAh5Y1i2tUxg4HdqwAABi0"] [Sat Aug 29 05:05:16.898030 2026] [security2:error] [pid 1018003:tid 1018261] [client 35.198.240.194:3542] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.omni-staffing.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK87DAh5Y1i2tUxg4HdrAAABiU"] [Sat Aug 29 05:05:16.898826 2026] [security2:error] [pid 1018003:tid 1018261] [client 35.198.240.194:3542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/403.html"] [unique_id "apK87DAh5Y1i2tUxg4HdrAAABiU"] [Sat Aug 29 05:05:16.902961 2026] [security2:error] [pid 1017536:tid 1017789] [client 35.198.240.194:3528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/root/.env"] [unique_id "apK87CJcY4fy7tP-rU3gHAAAAo8"] [Sat Aug 29 05:05:16.909469 2026] [security2:error] [pid 1018003:tid 1018203] [client 35.198.240.194:3586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apK87DAh5Y1i2tUxg4HdrgAABew"] [Sat Aug 29 05:05:16.915761 2026] [core:error] [pid 1018003:tid 1018208] [client 35.198.240.194:3634] AH10244: invalid URI path (/@fs/../../.env?raw??) [Sat Aug 29 05:05:16.916145 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.158.54.35:9924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/goods.php"] [unique_id "apK87DAh5Y1i2tUxg4HdsQAABfs"] [Sat Aug 29 05:05:16.916293 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.184.117:24878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/data.php"] [unique_id "apK87DAh5Y1i2tUxg4HdswAABco"] [Sat Aug 29 05:05:16.917475 2026] [security2:error] [pid 1018003:tid 1018221] [client 4.232.148.111:7652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK87DAh5Y1i2tUxg4HdtAAABf4"] [Sat Aug 29 05:05:16.946023 2026] [security2:error] [pid 1017536:tid 1017767] [client 158.23.184.117:56654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/themes/uploads/config.php"] [unique_id "apK87CJcY4fy7tP-rU3gIgAAAnk"] [Sat Aug 29 05:05:16.955280 2026] [security2:error] [pid 1018003:tid 1018184] [client 35.198.240.194:3576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/@fs/src/.env"] [unique_id "apK87DAh5Y1i2tUxg4HdtQAABdk"] [Sat Aug 29 05:05:16.963142 2026] [security2:error] [pid 1017536:tid 1017671] [client 20.203.141.11:41360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/wp-includes/index.php"] [unique_id "apK87CJcY4fy7tP-rU3gIwAAAhk"] [Sat Aug 29 05:05:16.968348 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.23.184.117:21536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/wp-blog-header.php"] [unique_id "apK87DAh5Y1i2tUxg4HdtgAABdw"] [Sat Aug 29 05:05:16.982469 2026] [security2:error] [pid 1018003:tid 1018220] [client 35.198.240.194:3558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/app/.env"] [unique_id "apK87DAh5Y1i2tUxg4HdrQAABf0"] [Sat Aug 29 05:05:16.985605 2026] [security2:error] [pid 1017536:tid 1017680] [client 35.198.240.194:3526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/.env"] [unique_id "apK87CJcY4fy7tP-rU3gHQAAAiI"] [Sat Aug 29 05:05:16.992814 2026] [security2:error] [pid 1017536:tid 1017735] [client 104.207.42.220:13631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK87CJcY4fy7tP-rU3gJQAAAlk"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:17.000806 2026] [security2:error] [pid 1018003:tid 1018262] [client 35.198.240.194:3686] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/@fs/.env.production"] [unique_id "apK87DAh5Y1i2tUxg4HduAAABiY"] [Sat Aug 29 05:05:17.006307 2026] [security2:error] [pid 1018003:tid 1018233] [client 35.198.240.194:3600] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.omni-staffing.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK87TAh5Y1i2tUxg4HduQAABgk"] [Sat Aug 29 05:05:17.007518 2026] [security2:error] [pid 1018003:tid 1018233] [client 35.198.240.194:3600] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/403.html"] [unique_id "apK87TAh5Y1i2tUxg4HduQAABgk"] [Sat Aug 29 05:05:17.018712 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.49.130:55153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/666.php"] [unique_id "apK87TAh5Y1i2tUxg4HduwAABhI"] [Sat Aug 29 05:05:17.021149 2026] [security2:error] [pid 1017536:tid 1017690] [client 145.239.10.137:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfieldparts.com"] [uri "/admin.php"] [unique_id "apK87SJcY4fy7tP-rU3gKAAAAiw"], referer: http://greenfieldparts.com/admin.php [Sat Aug 29 05:05:17.028596 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.63.81.20:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/inso.php"] [unique_id "apK87TAh5Y1i2tUxg4HdvgAABfA"] [Sat Aug 29 05:05:17.038630 2026] [security2:error] [pid 1018003:tid 1018273] [client 158.23.184.117:14520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/app.php"] [unique_id "apK87TAh5Y1i2tUxg4HdvwAABjE"] [Sat Aug 29 05:05:17.044342 2026] [security2:error] [pid 1018003:tid 1018249] [client 52.139.37.240:25074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/paku.php"] [unique_id "apK87TAh5Y1i2tUxg4HdwgAABhk"] [Sat Aug 29 05:05:17.044724 2026] [security2:error] [pid 1018003:tid 1018181] [client 35.198.240.194:3718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/root/.aws/credentials.bak"] [unique_id "apK87TAh5Y1i2tUxg4HdwAAABdY"] [Sat Aug 29 05:05:17.077867 2026] [security2:error] [pid 1017536:tid 1017748] [client 4.232.148.111:32958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/num.php"] [unique_id "apK87SJcY4fy7tP-rU3gMQAAAmY"] [Sat Aug 29 05:05:17.078295 2026] [security2:error] [pid 1018003:tid 1018177] [client 52.139.37.240:21377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/root.php"] [unique_id "apK87TAh5Y1i2tUxg4HdxwAABdI"] [Sat Aug 29 05:05:17.079077 2026] [security2:error] [pid 1018003:tid 1018202] [client 4.205.62.107:64206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/pouhg.php"] [unique_id "apK87TAh5Y1i2tUxg4HdywAABes"] [Sat Aug 29 05:05:17.082291 2026] [security2:error] [pid 1018003:tid 1018278] [client 35.198.240.194:3704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/root/.aws/credentials.backup"] [unique_id "apK87TAh5Y1i2tUxg4HdygAABjY"] [Sat Aug 29 05:05:17.088579 2026] [security2:error] [pid 1017536:tid 1017778] [client 4.205.62.107:22328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/aws_keys.php"] [unique_id "apK87SJcY4fy7tP-rU3gMgAAAoQ"] [Sat Aug 29 05:05:17.089575 2026] [security2:error] [pid 1017536:tid 1017746] [client 158.23.184.117:24892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/db-status.php"] [unique_id "apK87SJcY4fy7tP-rU3gMwAAAmQ"] [Sat Aug 29 05:05:17.092261 2026] [security2:error] [pid 1018003:tid 1018244] [client 158.23.184.117:6481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/av.php"] [unique_id "apK87TAh5Y1i2tUxg4HdzwAABhQ"] [Sat Aug 29 05:05:17.098688 2026] [security2:error] [pid 1018003:tid 1018197] [client 35.198.240.194:3608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.env"] [unique_id "apK87TAh5Y1i2tUxg4Hd0AAABeY"] [Sat Aug 29 05:05:17.101214 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.48.251.3:57875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/w.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd0gAABgc"] [Sat Aug 29 05:05:17.106145 2026] [security2:error] [pid 1017536:tid 1017780] [client 68.155.159.216:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/radio.php"] [unique_id "apK87SJcY4fy7tP-rU3gNQAAAoY"] [Sat Aug 29 05:05:17.116548 2026] [security2:error] [pid 1018003:tid 1018186] [client 35.198.240.194:3702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apK87TAh5Y1i2tUxg4Hd1gAABds"] [Sat Aug 29 05:05:17.126515 2026] [security2:error] [pid 1018003:tid 1018173] [client 158.23.184.117:21528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/wp-links-opml.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd2AAABc4"] [Sat Aug 29 05:05:17.127885 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.48.160.90:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/filefuns.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd2QAABiI"] [Sat Aug 29 05:05:17.132575 2026] [security2:error] [pid 1018003:tid 1018158] [client 158.23.147.79:30685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/file.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd2wAABb8"] [Sat Aug 29 05:05:17.139879 2026] [security2:error] [pid 1018003:tid 1018160] [client 162.198.206.205:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK87TAh5Y1i2tUxg4Hd3AAABcE"], referer: https://www.djiboutihomes.com/ [Sat Aug 29 05:05:17.147294 2026] [security2:error] [pid 1018003:tid 1018259] [client 35.198.240.194:3778] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK87TAh5Y1i2tUxg4HdxgAABiM"] [Sat Aug 29 05:05:17.154660 2026] [security2:error] [pid 1017536:tid 1017763] [client 68.155.159.216:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wzy.php"] [unique_id "apK87SJcY4fy7tP-rU3gOQAAAnU"] [Sat Aug 29 05:05:17.157601 2026] [security2:error] [pid 1017536:tid 1017760] [client 45.148.10.59:12542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theverystuff.com"] [uri "/wp/index.php"] [unique_id "apK87SJcY4fy7tP-rU3gOwAAAnI"] [Sat Aug 29 05:05:17.163508 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.63.219.114:2043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/classsmtps.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd4QAABeQ"] [Sat Aug 29 05:05:17.164837 2026] [cgid:error] [pid 1018003:tid 1018061] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.165698 2026] [cgid:error] [pid 1018003:tid 1018062] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.165890 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.147.79:24459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd4gAABbo"] [Sat Aug 29 05:05:17.166455 2026] [cgid:error] [pid 1018003:tid 1018060] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.168286 2026] [cgid:error] [pid 1018003:tid 1018059] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.169579 2026] [security2:error] [pid 1018003:tid 1018215] [client 35.213.70.61:48734] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "spellsoupdesign.com"] [uri "/"] [unique_id "apK87TAh5Y1i2tUxg4Hd4wAABfg"] [Sat Aug 29 05:05:17.188208 2026] [security2:error] [pid 1018003:tid 1018264] [client 158.23.184.117:14483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/aaa.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd5AAABig"] [Sat Aug 29 05:05:17.198258 2026] [cgid:error] [pid 1018003:tid 1018027] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.199281 2026] [cgid:error] [pid 1018003:tid 1018058] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.206565 2026] [security2:error] [pid 1018003:tid 1018154] [client 20.63.81.20:26440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/puc.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd5wAABbs"] [Sat Aug 29 05:05:17.216836 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:51843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/login.php"] [unique_id "apK87SJcY4fy7tP-rU3gQAAAAms"] [Sat Aug 29 05:05:17.220144 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.196.209.81:21086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/hehe.php"] [unique_id "apK87SJcY4fy7tP-rU3gQQAAAjI"] [Sat Aug 29 05:05:17.228664 2026] [security2:error] [pid 1018003:tid 1018218] [client 4.205.62.107:22502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-jufsis.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd6QAABfs"] [Sat Aug 29 05:05:17.231542 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.63.219.114:12708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/headerg.php"] [unique_id "apK87SJcY4fy7tP-rU3gQwAAAi8"] [Sat Aug 29 05:05:17.237643 2026] [security2:error] [pid 1017536:tid 1017679] [client 158.23.184.117:24863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/f35.php"] [unique_id "apK87SJcY4fy7tP-rU3gRAAAAiE"] [Sat Aug 29 05:05:17.244946 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.48.251.3:57876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/btx25.php"] [unique_id "apK87SJcY4fy7tP-rU3gRQAAAiE"] [Sat Aug 29 05:05:17.249246 2026] [security2:error] [pid 1018003:tid 1018184] [client 68.155.159.216:14248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/themes.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd6wAABdk"] [Sat Aug 29 05:05:17.260141 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.196.209.81:15802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/extractable-loader-head.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd7QAABbg"] [Sat Aug 29 05:05:17.263019 2026] [security2:error] [pid 1017536:tid 1017750] [client 52.139.37.240:24590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/rtx.php"] [unique_id "apK87SJcY4fy7tP-rU3gRgAAAmg"] [Sat Aug 29 05:05:17.273514 2026] [security2:error] [pid 1017536:tid 1017705] [client 168.107.94.195:53741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK87SJcY4fy7tP-rU3gSAAAAjs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:17.277769 2026] [security2:error] [pid 1018003:tid 1018165] [client 158.23.184.117:21558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/wp-load.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd7wAABcY"] [Sat Aug 29 05:05:17.278362 2026] [security2:error] [pid 1017536:tid 1017710] [client 52.139.37.240:20743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/shell.php"] [unique_id "apK87SJcY4fy7tP-rU3gSQAAAkA"] [Sat Aug 29 05:05:17.280100 2026] [cgid:error] [pid 1018003:tid 1018064] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.280730 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.196.209.81:12413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd8AAABf8"] [Sat Aug 29 05:05:17.289692 2026] [cgid:error] [pid 1018003:tid 1018063] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.289771 2026] [cgid:error] [pid 1018003:tid 1018089] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.291182 2026] [cgid:error] [pid 1018003:tid 1018065] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.292133 2026] [cgid:error] [pid 1018003:tid 1018072] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.292830 2026] [security2:error] [pid 1017536:tid 1017702] [client 74.248.24.12:8131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-blog.php"] [unique_id "apK87SJcY4fy7tP-rU3gSgAAAjg"] [Sat Aug 29 05:05:17.295804 2026] [security2:error] [pid 1018003:tid 1018174] [client 171.61.160.196:6254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd9gAABc8"] [Sat Aug 29 05:05:17.295880 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.63.219.114:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/theme.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd9QAABiE"] [Sat Aug 29 05:05:17.296529 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.184.117:6464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-includes/ID3/file.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd9wAABfA"] [Sat Aug 29 05:05:17.296967 2026] [security2:error] [pid 1017536:tid 1017723] [client 45.154.98.191:51567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK87SJcY4fy7tP-rU3gSwAAAk0"] [Sat Aug 29 05:05:17.297230 2026] [security2:error] [pid 1018003:tid 1018174] [client 171.61.160.196:6254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd9gAABc8"] [Sat Aug 29 05:05:17.328336 2026] [security2:error] [pid 1018003:tid 1018150] [client 158.23.147.79:25557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd-AAABbc"] [Sat Aug 29 05:05:17.328828 2026] [core:error] [pid 1017536:tid 1017730] [client 74.248.24.12:28216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:17.328846 2026] [core:error] [pid 1017536:tid 1017730] [client 74.248.24.12:28216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:17.339501 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.49.130:57617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/log.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd-gAABek"] [Sat Aug 29 05:05:17.359629 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.63.81.20:26533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/19.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd_AAABhU"] [Sat Aug 29 05:05:17.365497 2026] [security2:error] [pid 1017536:tid 1017738] [client 158.158.54.35:18408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/css.php"] [unique_id "apK87SJcY4fy7tP-rU3gUwAAAlw"] [Sat Aug 29 05:05:17.371245 2026] [security2:error] [pid 1017536:tid 1017782] [client 40.83.93.50:10844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/install.php"] [unique_id "apK87SJcY4fy7tP-rU3gVwAAAog"] [Sat Aug 29 05:05:17.378888 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.251.3:28471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/app_dev.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd_gAABd8"] [Sat Aug 29 05:05:17.380524 2026] [authz_core:error] [pid 1017536:tid 1017561] [remote 35.243.213.218:46954] AH01630: client denied by server configuration: /home2/mikeycun/public_html/.htpasswd [Sat Aug 29 05:05:17.381174 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.160.90:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-cron.php"] [unique_id "apK87SJcY4fy7tP-rU3gXAAAAlo"] [Sat Aug 29 05:05:17.382706 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.23.184.117:25554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK87SJcY4fy7tP-rU3gXQAAAo4"] [Sat Aug 29 05:05:17.390073 2026] [security2:error] [pid 1018003:tid 1018211] [client 158.23.184.117:14351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/hehe.php"] [unique_id "apK87TAh5Y1i2tUxg4Hd_wAABfQ"] [Sat Aug 29 05:05:17.396609 2026] [security2:error] [pid 1017536:tid 1017747] [client 4.205.62.107:2645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/packed.php"] [unique_id "apK87SJcY4fy7tP-rU3gYQAAAmU"] [Sat Aug 29 05:05:17.402544 2026] [security2:error] [pid 1017536:tid 1017694] [client 4.232.148.111:23750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-admin/index.php"] [unique_id "apK87SJcY4fy7tP-rU3gZAAAAjA"] [Sat Aug 29 05:05:17.414445 2026] [security2:error] [pid 1017536:tid 1017557] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.213.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mikeycunningham.com"] [uri "/wp-login.php"] [unique_id "apK87SJcY4fy7tP-rU3gZgACdhQ"], referer: https://www.mikeycunningham.com/wp-admin/ [Sat Aug 29 05:05:17.415037 2026] [security2:error] [pid 1017536:tid 1017585] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.213.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mikeycunningham.com"] [uri "/wp-login.php"] [unique_id "apK87SJcY4fy7tP-rU3gaAACdjA"], referer: https://www.mikeycunningham.com/wp-admin/ [Sat Aug 29 05:05:17.423243 2026] [security2:error] [pid 1018003:tid 1018258] [client 185.104.184.230:49476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "apK87TAh5Y1i2tUxg4HeAgAABiI"] [Sat Aug 29 05:05:17.429440 2026] [security2:error] [pid 1017536:tid 1017782] [client 158.23.184.117:21888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/wp-mail.php"] [unique_id "apK87SJcY4fy7tP-rU3gagAAAog"] [Sat Aug 29 05:05:17.429934 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.203.141.11:29671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/wp-admin/a.php"] [unique_id "apK87TAh5Y1i2tUxg4HeAwAABiY"] [Sat Aug 29 05:05:17.441500 2026] [security2:error] [pid 1017536:tid 1017744] [client 158.23.184.117:6478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.howtostudyexams.com"] [uri "/wp-admin/css/fff.php"] [unique_id "apK87SJcY4fy7tP-rU3gawAAAmI"] [Sat Aug 29 05:05:17.445460 2026] [security2:error] [pid 1017536:tid 1017695] [client 143.244.57.82:48386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK87SJcY4fy7tP-rU3gbAAAAjE"] [Sat Aug 29 05:05:17.462695 2026] [security2:error] [pid 1018003:tid 1018161] [client 68.155.159.216:50231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK87TAh5Y1i2tUxg4HeBQAABcI"] [Sat Aug 29 05:05:17.472249 2026] [security2:error] [pid 1018003:tid 1018198] [client 52.139.37.240:24784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/update/da222.php"] [unique_id "apK87TAh5Y1i2tUxg4HeBgAABec"] [Sat Aug 29 05:05:17.474689 2026] [security2:error] [pid 1018003:tid 1018247] [client 52.139.37.240:21410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK87TAh5Y1i2tUxg4HeBwAABhc"] [Sat Aug 29 05:05:17.490119 2026] [cgid:error] [pid 1018003:tid 1018077] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.501629 2026] [cgid:error] [pid 1018003:tid 1018022] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.506133 2026] [cgid:error] [pid 1018003:tid 1018148] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.513261 2026] [security2:error] [pid 1018003:tid 1018157] [client 4.205.62.107:53405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/aws_settings.php"] [unique_id "apK87TAh5Y1i2tUxg4HeCwAABb4"] [Sat Aug 29 05:05:17.516305 2026] [security2:error] [pid 1017536:tid 1017772] [client 158.23.147.79:63868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/admin.php"] [unique_id "apK87SJcY4fy7tP-rU3gbwAAAn4"] [Sat Aug 29 05:05:17.520839 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.48.251.3:28458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/php-info.php"] [unique_id "apK87TAh5Y1i2tUxg4HeDAAABjM"] [Sat Aug 29 05:05:17.531256 2026] [security2:error] [pid 1018003:tid 1018210] [client 20.63.81.20:26434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/133.php"] [unique_id "apK87TAh5Y1i2tUxg4HeDgAABfM"] [Sat Aug 29 05:05:17.532867 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.63.219.114:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/contentloader1.php"] [unique_id "apK87TAh5Y1i2tUxg4HeDwAABhA"] [Sat Aug 29 05:05:17.532901 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.23.184.117:25572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/home.php"] [unique_id "apK87SJcY4fy7tP-rU3gcgAAAlY"] [Sat Aug 29 05:05:17.552755 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.23.147.79:50077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/content.php"] [unique_id "apK87SJcY4fy7tP-rU3gdQAAAoY"] [Sat Aug 29 05:05:17.559967 2026] [security2:error] [pid 1018003:tid 1018234] [client 68.155.159.216:18248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/wp-content/x.php"] [unique_id "apK87TAh5Y1i2tUxg4HeEgAABgo"] [Sat Aug 29 05:05:17.561110 2026] [security2:error] [pid 1018003:tid 1018221] [client 35.213.70.61:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "spellsoupdesign.com"] [uri "/"] [unique_id "apK87TAh5Y1i2tUxg4HeEAAABf4"] [Sat Aug 29 05:05:17.563704 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.184.117:14464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-includes/PHPMailer.php"] [unique_id "apK87TAh5Y1i2tUxg4HeFAAABiU"] [Sat Aug 29 05:05:17.565001 2026] [security2:error] [pid 1018003:tid 1018220] [client 35.213.70.61:55864] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "spellsoupdesign.com"] [uri "/"] [unique_id "apK87TAh5Y1i2tUxg4HeDQAF_Tk"] [Sat Aug 29 05:05:17.565412 2026] [cgid:error] [pid 1018003:tid 1018081] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.565690 2026] [cgid:error] [pid 1018003:tid 1018080] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.576948 2026] [security2:error] [pid 1018003:tid 1018253] [client 158.23.184.117:21929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/wp-settings.php"] [unique_id "apK87TAh5Y1i2tUxg4HeFgAABh0"] [Sat Aug 29 05:05:17.580384 2026] [security2:error] [pid 1017536:tid 1017777] [client 4.205.62.107:61240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/agg.php"] [unique_id "apK87SJcY4fy7tP-rU3gdwAAAoM"] [Sat Aug 29 05:05:17.588877 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.48.160.90:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/lock360.php"] [unique_id "apK87TAh5Y1i2tUxg4HeFwAABg4"] [Sat Aug 29 05:05:17.620551 2026] [security2:error] [pid 1018003:tid 1018202] [client 216.26.249.248:9065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.249.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK87TAh5Y1i2tUxg4HeFQAABes"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:17.630903 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.196.209.81:21071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK87TAh5Y1i2tUxg4HeHQAABc4"] [Sat Aug 29 05:05:17.636808 2026] [security2:error] [pid 1018003:tid 1018083] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/web.config"] [unique_id "apK87TAh5Y1i2tUxg4HeHwAF3j4"] [Sat Aug 29 05:05:17.642610 2026] [security2:error] [pid 1018003:tid 1018269] [client 68.155.159.216:24481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/simple.php"] [unique_id "apK87TAh5Y1i2tUxg4HeIgAABi0"] [Sat Aug 29 05:05:17.643183 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.63.219.114:15233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/meta.php"] [unique_id "apK87SJcY4fy7tP-rU3gfQAAAoQ"] [Sat Aug 29 05:05:17.649768 2026] [cgid:error] [pid 1018003:tid 1018086] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.650159 2026] [autoindex:error] [pid 1018003:tid 1018186] [client 4.232.148.111:3051] AH01276: Cannot serve directory /home4/ehfields/public_html/tiaandephraim/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:17.653140 2026] [security2:error] [pid 1018003:tid 1018169] [client 168.107.94.195:54169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK87TAh5Y1i2tUxg4HeJAAABco"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:17.656326 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.196.209.81:4998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/defaults.php"] [unique_id "apK87TAh5Y1i2tUxg4HeJQAABgs"] [Sat Aug 29 05:05:17.660842 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.48.251.3:57883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/infos.php"] [unique_id "apK87TAh5Y1i2tUxg4HeJgAABeg"] [Sat Aug 29 05:05:17.670411 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.139.37.240:20758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK87TAh5Y1i2tUxg4HeJwAABdg"] [Sat Aug 29 05:05:17.677716 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.184.117:24846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/index.php"] [unique_id "apK87SJcY4fy7tP-rU3gfwAAAls"] [Sat Aug 29 05:05:17.678180 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.63.81.20:26370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/1xmomo.php"] [unique_id "apK87SJcY4fy7tP-rU3ggAAAAms"] [Sat Aug 29 05:05:17.678405 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.196.209.81:19388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK87TAh5Y1i2tUxg4HeKgAABhM"] [Sat Aug 29 05:05:17.683241 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.63.219.114:1513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/alumni_reg.php"] [unique_id "apK87SJcY4fy7tP-rU3gggAAAl0"] [Sat Aug 29 05:05:17.685253 2026] [cgid:error] [pid 1018003:tid 1018085] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.706945 2026] [security2:error] [pid 1017536:tid 1017610] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/info.php"] [unique_id "apK87SJcY4fy7tP-rU3giAACREk"] [Sat Aug 29 05:05:17.712204 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.184.117:14794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "apK87TAh5Y1i2tUxg4HeLgAABfU"] [Sat Aug 29 05:05:17.721415 2026] [security2:error] [pid 1017536:tid 1017728] [client 35.213.70.61:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "spellsoupdesign.com"] [uri "/index.html"] [unique_id "apK87SJcY4fy7tP-rU3giQAAAlI"] [Sat Aug 29 05:05:17.723058 2026] [security2:error] [pid 1018003:tid 1018165] [client 35.213.70.61:55864] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "spellsoupdesign.com"] [uri "/index.html"] [unique_id "apK87TAh5Y1i2tUxg4HeLAAFxkU"] [Sat Aug 29 05:05:17.723799 2026] [security2:error] [pid 1018003:tid 1018263] [client 158.23.184.117:21940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/.well-known/wp-signup.php"] [unique_id "apK87TAh5Y1i2tUxg4HeMgAABic"] [Sat Aug 29 05:05:17.724031 2026] [cgid:error] [pid 1018003:tid 1018091] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.724184 2026] [cgid:error] [pid 1018003:tid 1018092] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.724985 2026] [cgid:error] [pid 1018003:tid 1018095] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.744730 2026] [security2:error] [pid 1017536:tid 1017545] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/infophp.php"] [unique_id "apK87SJcY4fy7tP-rU3giwACRAg"] [Sat Aug 29 05:05:17.744730 2026] [security2:error] [pid 1017536:tid 1017648] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/infos.php"] [unique_id "apK87SJcY4fy7tP-rU3gigACRG8"] [Sat Aug 29 05:05:17.751661 2026] [security2:error] [pid 1018003:tid 1018191] [client 52.139.37.240:25031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-admin/min.php"] [unique_id "apK87TAh5Y1i2tUxg4HeMwAABeA"] [Sat Aug 29 05:05:17.757336 2026] [cgid:error] [pid 1018003:tid 1018042] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.759877 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.48.160.90:63527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-theme.php"] [unique_id "apK87TAh5Y1i2tUxg4HeNQAABdY"] [Sat Aug 29 05:05:17.788736 2026] [security2:error] [pid 1018003:tid 1018209] [client 216.73.217.8:24665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo-store.sortthru.com"] [uri "/webapp/wp-admin/customize.php"] [unique_id "apK87TAh5Y1i2tUxg4HeNwAABfI"] [Sat Aug 29 05:05:17.790843 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.49.130:60987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/ccc.php"] [unique_id "apK87SJcY4fy7tP-rU3gjwAAAh0"] [Sat Aug 29 05:05:17.792448 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.48.251.3:28465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/env.php"] [unique_id "apK87SJcY4fy7tP-rU3gkAAAAhg"] [Sat Aug 29 05:05:17.809178 2026] [security2:error] [pid 1017536:tid 1017774] [client 35.213.70.61:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "spellsoupdesign.com"] [uri "/"] [unique_id "apK87SJcY4fy7tP-rU3gkQAAAoA"] [Sat Aug 29 05:05:17.810812 2026] [security2:error] [pid 1018003:tid 1018232] [client 35.213.70.61:55870] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "spellsoupdesign.com"] [uri "/"] [unique_id "apK87TAh5Y1i2tUxg4HeNgAGCEw"] [Sat Aug 29 05:05:17.827534 2026] [security2:error] [pid 1017536:tid 1017720] [client 158.23.184.117:24848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/login.php"] [unique_id "apK87SJcY4fy7tP-rU3glAAAAko"] [Sat Aug 29 05:05:17.835613 2026] [cgid:error] [pid 1018003:tid 1018096] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.845828 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.63.81.20:26459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/mosty.php"] [unique_id "apK87SJcY4fy7tP-rU3gmAAAAjw"] [Sat Aug 29 05:05:17.850069 2026] [core:error] [pid 1017536:tid 1017742] [client 74.248.24.12:3137] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:17.850086 2026] [core:error] [pid 1017536:tid 1017742] [client 74.248.24.12:3137] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:17.851254 2026] [cgid:error] [pid 1018003:tid 1018098] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.856882 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.184.117:14360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/admin/alfa-rex.php"] [unique_id "apK87SJcY4fy7tP-rU3gmgAAAkM"] [Sat Aug 29 05:05:17.866815 2026] [security2:error] [pid 1018003:tid 1018226] [client 74.248.24.12:26273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/xxx.php"] [unique_id "apK87TAh5Y1i2tUxg4HePgAABgM"] [Sat Aug 29 05:05:17.866844 2026] [security2:error] [pid 1018003:tid 1018242] [client 45.148.10.246:30958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eastsidepride.com"] [uri "/blog/index.php"] [unique_id "apK87TAh5Y1i2tUxg4HePQAABhI"] [Sat Aug 29 05:05:17.868718 2026] [security2:error] [pid 1017536:tid 1017755] [client 4.232.148.111:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/radio.php"] [unique_id "apK87SJcY4fy7tP-rU3gmwAAAm0"] [Sat Aug 29 05:05:17.869806 2026] [security2:error] [pid 1017536:tid 1017785] [client 52.139.37.240:21386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-header-json.php"] [unique_id "apK87SJcY4fy7tP-rU3gnAAAAos"] [Sat Aug 29 05:05:17.871311 2026] [security2:error] [pid 1017536:tid 1017730] [client 158.23.184.117:21511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/002.php"] [unique_id "apK87SJcY4fy7tP-rU3gnQAAAlQ"] [Sat Aug 29 05:05:17.881064 2026] [security2:error] [pid 1018003:tid 1018099] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env"] [unique_id "apK87TAh5Y1i2tUxg4HeQAAGGE4"] [Sat Aug 29 05:05:17.884493 2026] [cgid:error] [pid 1018003:tid 1018103] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.884761 2026] [cgid:error] [pid 1018003:tid 1018101] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:17.908189 2026] [security2:error] [pid 1018003:tid 1018153] [client 45.154.98.191:51809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK87TAh5Y1i2tUxg4HeRAAABbo"] [Sat Aug 29 05:05:17.911938 2026] [access_compat:error] [pid 1018003:tid 1018179] [client 67.20.76.220:12614] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:17.924208 2026] [security2:error] [pid 1017536:tid 1017667] [client 68.155.159.216:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/index.php"] [unique_id "apK87SJcY4fy7tP-rU3gqgAAAhU"] [Sat Aug 29 05:05:17.934921 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.48.251.3:57818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/xve22.php"] [unique_id "apK87SJcY4fy7tP-rU3gqwAAAhU"] [Sat Aug 29 05:05:17.956414 2026] [security2:error] [pid 1018003:tid 1018157] [client 52.139.37.240:25029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK87TAh5Y1i2tUxg4HeSAAABb4"] [Sat Aug 29 05:05:17.964894 2026] [security2:error] [pid 1018003:tid 1018219] [client 68.155.159.216:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/atomlib.php"] [unique_id "apK87TAh5Y1i2tUxg4HeSQAABfw"] [Sat Aug 29 05:05:17.972006 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.160.90:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/2d7433/index.php"] [unique_id "apK87TAh5Y1i2tUxg4HeUAAABf4"] [Sat Aug 29 05:05:17.999794 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.63.81.20:26536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/blurbs.php"] [unique_id "apK87TAh5Y1i2tUxg4HeUgAABiA"] [Sat Aug 29 05:05:18.002526 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.184.117:24864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/logs233/index.php"] [unique_id "apK87jAh5Y1i2tUxg4HeVAAABgo"] [Sat Aug 29 05:05:18.003653 2026] [security2:error] [pid 1017536:tid 1017689] [client 185.104.184.230:49484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK87iJcY4fy7tP-rU3gsAAAAis"] [Sat Aug 29 05:05:18.011053 2026] [security2:error] [pid 1017536:tid 1017787] [client 35.213.70.61:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "spellsoupdesign.com"] [uri "/index.html"] [unique_id "apK87iJcY4fy7tP-rU3gsQAAAo0"] [Sat Aug 29 05:05:18.011521 2026] [security2:error] [pid 1017536:tid 1017750] [client 143.244.57.82:48392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK87iJcY4fy7tP-rU3gsgAAAmg"] [Sat Aug 29 05:05:18.012712 2026] [security2:error] [pid 1018003:tid 1018193] [client 35.213.70.61:55870] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "spellsoupdesign.com"] [uri "/index.html"] [unique_id "apK87TAh5Y1i2tUxg4HeRgAF4lQ"] [Sat Aug 29 05:05:18.017948 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.63.219.114:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/al.php"] [unique_id "apK87iJcY4fy7tP-rU3gswAAAnM"] [Sat Aug 29 05:05:18.023439 2026] [security2:error] [pid 1018003:tid 1018189] [client 40.83.93.50:10817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK87jAh5Y1i2tUxg4HeWAAABd4"] [Sat Aug 29 05:05:18.024571 2026] [security2:error] [pid 1018003:tid 1018220] [client 158.23.184.117:14796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-content/export.php"] [unique_id "apK87jAh5Y1i2tUxg4HeWQAABf0"] [Sat Aug 29 05:05:18.024884 2026] [cgid:error] [pid 1018003:tid 1018093] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:18.030293 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:21947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/0x.php"] [unique_id "apK87iJcY4fy7tP-rU3gtgAAAjE"] [Sat Aug 29 05:05:18.049142 2026] [security2:error] [pid 1018003:tid 1018182] [client 168.107.94.195:54478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK87jAh5Y1i2tUxg4HeWwAABdc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:18.052902 2026] [security2:error] [pid 1018003:tid 1018223] [client 20.203.141.11:29191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK87jAh5Y1i2tUxg4HeXQAABgA"] [Sat Aug 29 05:05:18.075916 2026] [security2:error] [pid 1017536:tid 1017689] [client 52.139.37.240:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/zup.php"] [unique_id "apK87iJcY4fy7tP-rU3guwAAAis"] [Sat Aug 29 05:05:18.078103 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.196.209.81:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/post.php"] [unique_id "apK87iJcY4fy7tP-rU3gvAAAAhY"] [Sat Aug 29 05:05:18.085740 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.251.3:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/06.php"] [unique_id "apK87jAh5Y1i2tUxg4HeYgAABgY"] [Sat Aug 29 05:05:18.090348 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.63.219.114:1957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/colors.php"] [unique_id "apK87iJcY4fy7tP-rU3gvgAAAns"] [Sat Aug 29 05:05:18.101336 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.196.209.81:17968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/wp-load.php"] [unique_id "apK87jAh5Y1i2tUxg4HeZgAABjQ"] [Sat Aug 29 05:05:18.105770 2026] [security2:error] [pid 1018003:tid 1018117] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env.old"] [unique_id "apK87jAh5Y1i2tUxg4HeZwAFzGA"] [Sat Aug 29 05:05:18.106434 2026] [security2:error] [pid 1018003:tid 1018118] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env.bak"] [unique_id "apK87jAh5Y1i2tUxg4HeaQAFzGE"] [Sat Aug 29 05:05:18.106471 2026] [security2:error] [pid 1018003:tid 1018121] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env.backup"] [unique_id "apK87jAh5Y1i2tUxg4HeagAFzGQ"] [Sat Aug 29 05:05:18.107063 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.196.209.81:16300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/wp-contentt.php"] [unique_id "apK87jAh5Y1i2tUxg4HebAAABhw"] [Sat Aug 29 05:05:18.109775 2026] [cgid:error] [pid 1018003:tid 1018068] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:18.110478 2026] [cgid:error] [pid 1018003:tid 1018119] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:18.114141 2026] [security2:error] [pid 1017536:tid 1017732] [client 35.213.70.61:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "spellsoupdesign.com"] [uri "/robots.txt"] [unique_id "apK87iJcY4fy7tP-rU3gwAAAAlY"] [Sat Aug 29 05:05:18.116620 2026] [security2:error] [pid 1018003:tid 1018195] [client 35.213.70.61:55878] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "spellsoupdesign.com"] [uri "/robots.txt"] [unique_id "apK87jAh5Y1i2tUxg4HeZAAF5F4"] [Sat Aug 29 05:05:18.127119 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.63.219.114:2935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/dxc.php"] [unique_id "apK87iJcY4fy7tP-rU3gwQAAAiY"] [Sat Aug 29 05:05:18.129674 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.158.54.35:22504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/w.php"] [unique_id "apK87iJcY4fy7tP-rU3gwgAAAhs"] [Sat Aug 29 05:05:18.130202 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.63.81.20:26432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/h.php"] [unique_id "apK87iJcY4fy7tP-rU3gwwAAAmQ"] [Sat Aug 29 05:05:18.145990 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.48.160.90:62633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-login.php"] [unique_id "apK87jAh5Y1i2tUxg4HebgAABig"] [Sat Aug 29 05:05:18.148291 2026] [security2:error] [pid 1018003:tid 1018265] [client 34.143.179.161:19506] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK87jAh5Y1i2tUxg4HebwAABik"] [Sat Aug 29 05:05:18.155772 2026] [security2:error] [pid 1017536:tid 1017766] [client 158.23.184.117:24884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/maintenance.php"] [unique_id "apK87iJcY4fy7tP-rU3gxgAAAng"] [Sat Aug 29 05:05:18.163422 2026] [security2:error] [pid 1018003:tid 1018165] [client 34.143.179.161:19396] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/@vite/env"] [unique_id "apK87jAh5Y1i2tUxg4HecAAABcY"] [Sat Aug 29 05:05:18.174416 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.184.117:14472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/new.php"] [unique_id "apK87iJcY4fy7tP-rU3gyQAAAks"] [Sat Aug 29 05:05:18.177921 2026] [security2:error] [pid 1017536:tid 1017747] [client 52.139.37.240:25064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK87iJcY4fy7tP-rU3gywAAAmU"] [Sat Aug 29 05:05:18.180342 2026] [security2:error] [pid 1018003:tid 1018151] [client 158.23.184.117:21543] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/1.php"] [unique_id "apK87jAh5Y1i2tUxg4HecQAABbg"] [Sat Aug 29 05:05:18.180450 2026] [security2:error] [pid 1018003:tid 1018151] [client 158.23.184.117:21543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/1.php"] [unique_id "apK87jAh5Y1i2tUxg4HecQAABbg"] [Sat Aug 29 05:05:18.185500 2026] [security2:error] [pid 1017536:tid 1017763] [client 20.104.49.130:53644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/new.php"] [unique_id "apK87iJcY4fy7tP-rU3gzAAAAnU"] [Sat Aug 29 05:05:18.211440 2026] [security2:error] [pid 1017536:tid 1017727] [client 68.155.159.216:16229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK87iJcY4fy7tP-rU3gzwAAAlE"] [Sat Aug 29 05:05:18.218102 2026] [security2:error] [pid 1018003:tid 1018274] [client 151.123.177.244:23827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK87jAh5Y1i2tUxg4HecgAABjI"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:18.218696 2026] [security2:error] [pid 1018003:tid 1018174] [client 4.205.62.107:64971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/phpversion.php"] [unique_id "apK87jAh5Y1i2tUxg4HecwAABc8"] [Sat Aug 29 05:05:18.231350 2026] [security2:error] [pid 1018003:tid 1018191] [client 4.205.62.107:22298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/adminer-4.7.6-en.php"] [unique_id "apK87jAh5Y1i2tUxg4HedAAABeA"] [Sat Aug 29 05:05:18.249025 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.251.3:57871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/xin1.php"] [unique_id "apK87jAh5Y1i2tUxg4HedQAABcU"] [Sat Aug 29 05:05:18.251039 2026] [security2:error] [pid 1018003:tid 1018164] [client 158.23.147.79:30680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/file17.php"] [unique_id "apK87jAh5Y1i2tUxg4HedgAABcU"] [Sat Aug 29 05:05:18.258615 2026] [security2:error] [pid 1017536:tid 1017693] [client 68.155.159.216:16219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK87iJcY4fy7tP-rU3g1AAAAi8"] [Sat Aug 29 05:05:18.269525 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.147.79:24564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK87iJcY4fy7tP-rU3g1gAAAoc"] [Sat Aug 29 05:05:18.281158 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.49.130:36334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/crgio.php"] [unique_id "apK87iJcY4fy7tP-rU3g1wAAAoE"] [Sat Aug 29 05:05:18.299740 2026] [security2:error] [pid 1018003:tid 1018241] [client 158.23.184.117:24853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.newfweiler.com"] [uri "/.well-known/min.php"] [unique_id "apK87jAh5Y1i2tUxg4HeegAABhE"] [Sat Aug 29 05:05:18.302048 2026] [security2:error] [pid 1017536:tid 1017715] [client 52.139.37.240:21128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/a9.php"] [unique_id "apK87iJcY4fy7tP-rU3g2QAAAkU"] [Sat Aug 29 05:05:18.313971 2026] [security2:error] [pid 1018003:tid 1018258] [client 68.155.159.216:51556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/hehehehe.php"] [unique_id "apK87jAh5Y1i2tUxg4HefQAABiI"] [Sat Aug 29 05:05:18.316927 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.23.184.117:14372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.uscgpipeband.org"] [uri "/wp-content/plugins/revslider/admin.php"] [unique_id "apK87iJcY4fy7tP-rU3g3AAAAjI"] [Sat Aug 29 05:05:18.318053 2026] [security2:error] [pid 1018003:tid 1018120] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/api/.env"] [unique_id "apK87jAh5Y1i2tUxg4HefgAGFmM"] [Sat Aug 29 05:05:18.326980 2026] [security2:error] [pid 1017536:tid 1017679] [client 158.23.184.117:21889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.angelaandkenny.strangeworx.com"] [uri "/10.php"] [unique_id "apK87iJcY4fy7tP-rU3g3QAAAiE"] [Sat Aug 29 05:05:18.327045 2026] [security2:error] [pid 1018003:tid 1018208] [client 20.63.81.20:26492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/ano.php"] [unique_id "apK87jAh5Y1i2tUxg4HefwAABfE"] [Sat Aug 29 05:05:18.330748 2026] [cgid:error] [pid 1018003:tid 1018125] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:18.334899 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.160.90:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/images.php"] [unique_id "apK87iJcY4fy7tP-rU3g4QAAAlU"] [Sat Aug 29 05:05:18.346989 2026] [security2:error] [pid 1017536:tid 1017760] [client 4.232.148.111:17518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/item.php"] [unique_id "apK87iJcY4fy7tP-rU3g4wAAAnI"] [Sat Aug 29 05:05:18.352921 2026] [security2:error] [pid 1018003:tid 1018270] [client 74.248.24.12:22566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apK87jAh5Y1i2tUxg4HehAAABi4"] [Sat Aug 29 05:05:18.375906 2026] [security2:error] [pid 1018003:tid 1018232] [client 52.139.37.240:24593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK87jAh5Y1i2tUxg4HehQAABgg"] [Sat Aug 29 05:05:18.381988 2026] [security2:error] [pid 1018003:tid 1018196] [client 4.205.62.107:22218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-content/admin.php"] [unique_id "apK87jAh5Y1i2tUxg4HehgAABeU"] [Sat Aug 29 05:05:18.384419 2026] [security2:error] [pid 1018003:tid 1018158] [client 103.240.76.112:49561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK87jAh5Y1i2tUxg4HehwAABb8"] [Sat Aug 29 05:05:18.384521 2026] [security2:error] [pid 1018003:tid 1018158] [client 103.240.76.112:49561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK87jAh5Y1i2tUxg4HehwAABb8"] [Sat Aug 29 05:05:18.385073 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.48.251.3:28424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/sadd.php"] [unique_id "apK87iJcY4fy7tP-rU3g5wAAAko"] [Sat Aug 29 05:05:18.407833 2026] [security2:error] [pid 1017536:tid 1017742] [client 68.155.159.216:33722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK87iJcY4fy7tP-rU3g6AAAAmA"] [Sat Aug 29 05:05:18.425648 2026] [security2:error] [pid 1017536:tid 1017755] [client 158.23.147.79:25473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK87iJcY4fy7tP-rU3g6gAAAm0"] [Sat Aug 29 05:05:18.434647 2026] [core:error] [pid 1017536:tid 1017728] [client 74.248.24.12:33427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:18.435330 2026] [core:error] [pid 1017536:tid 1017728] [client 74.248.24.12:33427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:18.449298 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.63.219.114:18313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/global.php"] [unique_id "apK87iJcY4fy7tP-rU3g7wAAAhg"] [Sat Aug 29 05:05:18.451268 2026] [security2:error] [pid 1018003:tid 1018267] [client 168.107.94.195:54865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK87jAh5Y1i2tUxg4HejAAABis"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:18.456650 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.63.81.20:26378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/ai.php"] [unique_id "apK87iJcY4fy7tP-rU3g8AAAAl8"] [Sat Aug 29 05:05:18.456821 2026] [security2:error] [pid 1017536:tid 1017777] [client 45.154.98.191:52067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK87iJcY4fy7tP-rU3g8QAAAoM"] [Sat Aug 29 05:05:18.460749 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.147.79:58919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK87jAh5Y1i2tUxg4HejQAABfw"] [Sat Aug 29 05:05:18.462794 2026] [security2:error] [pid 1018003:tid 1018271] [client 4.232.148.111:3051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apK87jAh5Y1i2tUxg4HejgAABi8"] [Sat Aug 29 05:05:18.479709 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.160.90:64719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/ops.php"] [unique_id "apK87jAh5Y1i2tUxg4HejwAABcE"] [Sat Aug 29 05:05:18.480722 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.196.209.81:9499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/csv.php"] [unique_id "apK87iJcY4fy7tP-rU3g9QAAAn0"] [Sat Aug 29 05:05:18.490518 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.63.219.114:1964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/Js.php"] [unique_id "apK87jAh5Y1i2tUxg4HekQAABhg"] [Sat Aug 29 05:05:18.497330 2026] [security2:error] [pid 1018003:tid 1018217] [client 52.139.37.240:21390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/admin/index.php"] [unique_id "apK87jAh5Y1i2tUxg4HekgAABfo"] [Sat Aug 29 05:05:18.499516 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.196.209.81:18191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK87iJcY4fy7tP-rU3g-AAAApI"] [Sat Aug 29 05:05:18.507558 2026] [security2:error] [pid 1018003:tid 1018132] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.jobindjibouti.com"] [uri "/wp-json/wp/v2/job-listings"] [unique_id "apK87jAh5Y1i2tUxg4HekwAF-G8"] [Sat Aug 29 05:05:18.512021 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.203.141.11:31328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanmorenoperez.com"] [uri "/wp-admin.php"] [unique_id "apK87jAh5Y1i2tUxg4HelAAABc0"] [Sat Aug 29 05:05:18.526230 2026] [security2:error] [pid 1018003:tid 1018250] [client 40.83.93.50:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK87jAh5Y1i2tUxg4HelQAABho"] [Sat Aug 29 05:05:18.536472 2026] [security2:error] [pid 1017536:tid 1017576] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/php-info.php"] [unique_id "apK87iJcY4fy7tP-rU3g_AACUCc"] [Sat Aug 29 05:05:18.543287 2026] [security2:error] [pid 1017536:tid 1017744] [client 4.205.62.107:2916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/phpi.php"] [unique_id "apK87iJcY4fy7tP-rU3g_QAAAmI"] [Sat Aug 29 05:05:18.554099 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.196.209.81:16276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/theme.php"] [unique_id "apK87iJcY4fy7tP-rU3g_wAAAlo"] [Sat Aug 29 05:05:18.555433 2026] [security2:error] [pid 1017536:tid 1017553] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/php_info.php"] [unique_id "apK87iJcY4fy7tP-rU3hAAACUBA"] [Sat Aug 29 05:05:18.568196 2026] [security2:error] [pid 1017536:tid 1017789] [client 68.155.159.216:50256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/radio.php"] [unique_id "apK87iJcY4fy7tP-rU3hBAAAAo8"] [Sat Aug 29 05:05:18.569438 2026] [security2:error] [pid 1017536:tid 1017738] [client 158.158.54.35:15875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/ahax.php"] [unique_id "apK87iJcY4fy7tP-rU3hBQAAAlw"] [Sat Aug 29 05:05:18.572598 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:23304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK87jAh5Y1i2tUxg4HemQAABdA"] [Sat Aug 29 05:05:18.575537 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.48.251.3:28422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/application.config.php"] [unique_id "apK87jAh5Y1i2tUxg4HemgAABbk"] [Sat Aug 29 05:05:18.585216 2026] [security2:error] [pid 1018003:tid 1018244] [client 143.244.57.82:48402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK87jAh5Y1i2tUxg4HenAAABhQ"] [Sat Aug 29 05:05:18.585637 2026] [security2:error] [pid 1017536:tid 1017591] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/php.php"] [unique_id "apK87iJcY4fy7tP-rU3hBgACUDY"] [Sat Aug 29 05:05:18.596744 2026] [security2:error] [pid 1017536:tid 1017594] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/phpinfo.php"] [unique_id "apK87iJcY4fy7tP-rU3hBwACUDk"] [Sat Aug 29 05:05:18.604690 2026] [security2:error] [pid 1017536:tid 1017683] [client 185.104.184.230:49490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "apK87iJcY4fy7tP-rU3hCAAAAiU"] [Sat Aug 29 05:05:18.606261 2026] [security2:error] [pid 1018003:tid 1018130] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/app/.env"] [unique_id "apK87jAh5Y1i2tUxg4HenQAF720"] [Sat Aug 29 05:05:18.606305 2026] [security2:error] [pid 1018003:tid 1018133] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/frontend/.env"] [unique_id "apK87jAh5Y1i2tUxg4HengAF73A"] [Sat Aug 29 05:05:18.623932 2026] [security2:error] [pid 1018003:tid 1018154] [client 158.23.147.79:63000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/xmlrpc.php"] [unique_id "apK87jAh5Y1i2tUxg4HenwAABbs"] [Sat Aug 29 05:05:18.632748 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.160.90:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK87iJcY4fy7tP-rU3hCQAAAjE"] [Sat Aug 29 05:05:18.635290 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.63.81.20:26479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/sf.php"] [unique_id "apK87jAh5Y1i2tUxg4HeoAAABcI"] [Sat Aug 29 05:05:18.647171 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.63.219.114:15284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/wp-2019.php"] [unique_id "apK87iJcY4fy7tP-rU3hCgAAAk0"] [Sat Aug 29 05:05:18.649639 2026] [security2:error] [pid 1018003:tid 1018203] [client 52.139.37.240:24608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK87jAh5Y1i2tUxg4HeoQAABew"] [Sat Aug 29 05:05:18.667474 2026] [security2:error] [pid 1017536:tid 1017680] [client 4.205.62.107:53357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/aws-credentials.php"] [unique_id "apK87iJcY4fy7tP-rU3hCwAAAiI"] [Sat Aug 29 05:05:18.674310 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:18279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK87jAh5Y1i2tUxg4HeogAABco"] [Sat Aug 29 05:05:18.692981 2026] [security2:error] [pid 1017536:tid 1017711] [client 52.139.37.240:21391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/makeasmtp.php"] [unique_id "apK87iJcY4fy7tP-rU3hDQAAAkE"] [Sat Aug 29 05:05:18.711001 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.48.251.3:57849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/xp.php"] [unique_id "apK87iJcY4fy7tP-rU3hDwAAApA"] [Sat Aug 29 05:05:18.711102 2026] [security2:error] [pid 1018003:tid 1018129] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/dev/.env"] [unique_id "apK87jAh5Y1i2tUxg4HeowAF52w"] [Sat Aug 29 05:05:18.711103 2026] [security2:error] [pid 1018003:tid 1018138] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/server/.env"] [unique_id "apK87jAh5Y1i2tUxg4HepAAF53U"] [Sat Aug 29 05:05:18.711111 2026] [security2:error] [pid 1018003:tid 1018137] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/production/.env"] [unique_id "apK87jAh5Y1i2tUxg4HepQAF53Q"] [Sat Aug 29 05:05:18.723319 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.49.130:47974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/wp.php"] [unique_id "apK87iJcY4fy7tP-rU3hEwAAAnk"] [Sat Aug 29 05:05:18.732083 2026] [security2:error] [pid 1017536:tid 1017668] [client 4.205.62.107:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/requirements.php"] [unique_id "apK87iJcY4fy7tP-rU3hFAAAAhY"] [Sat Aug 29 05:05:18.735971 2026] [security2:error] [pid 1018003:tid 1018088] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/src/.env"] [unique_id "apK87jAh5Y1i2tUxg4HepgAGBkM"] [Sat Aug 29 05:05:18.748290 2026] [security2:error] [pid 1017536:tid 1017769] [client 162.198.206.205:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK87iJcY4fy7tP-rU3hFwAAAns"], referer: https://www.bing.com/ [Sat Aug 29 05:05:18.755601 2026] [security2:error] [pid 1017536:tid 1017597] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/public/phpinfo.php"] [unique_id "apK87iJcY4fy7tP-rU3hGwACFDw"] [Sat Aug 29 05:05:18.794038 2026] [security2:error] [pid 1018003:tid 1018239] [client 209.50.160.228:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.160.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK87jAh5Y1i2tUxg4HepwAABg8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:18.804653 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.160.90:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK87iJcY4fy7tP-rU3hIwAAAjk"] [Sat Aug 29 05:05:18.825991 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.63.81.20:26511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/xx.php"] [unique_id "apK87iJcY4fy7tP-rU3hJAAAAm8"] [Sat Aug 29 05:05:18.832544 2026] [security2:error] [pid 1017536:tid 1017740] [client 168.107.94.195:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK87iJcY4fy7tP-rU3hJQAAAl4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:18.835683 2026] [security2:error] [pid 1018003:tid 1018223] [client 4.232.148.111:1410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/t.php"] [unique_id "apK87jAh5Y1i2tUxg4HeqQAABgA"] [Sat Aug 29 05:05:18.843514 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.63.219.114:1489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/update.php"] [unique_id "apK87iJcY4fy7tP-rU3hJwAAAm4"] [Sat Aug 29 05:05:18.844422 2026] [security2:error] [pid 1017536:tid 1017671] [client 20.48.251.3:57918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/g3.php"] [unique_id "apK87iJcY4fy7tP-rU3hKAAAAhk"] [Sat Aug 29 05:05:18.849292 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.63.219.114:2045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/access.php"] [unique_id "apK87iJcY4fy7tP-rU3hKQAAAis"] [Sat Aug 29 05:05:18.854745 2026] [security2:error] [pid 1017536:tid 1017773] [client 52.139.37.240:25059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-info.php"] [unique_id "apK87iJcY4fy7tP-rU3hKwAAAn8"] [Sat Aug 29 05:05:18.867741 2026] [security2:error] [pid 1017536:tid 1017672] [client 74.248.24.12:8399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "apK87iJcY4fy7tP-rU3hLAAAAho"] [Sat Aug 29 05:05:18.879153 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.196.209.81:9480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/fox.php"] [unique_id "apK87iJcY4fy7tP-rU3hLQAAAn4"] [Sat Aug 29 05:05:18.889535 2026] [security2:error] [pid 1017536:tid 1017766] [client 52.139.37.240:21420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/paku.php"] [unique_id "apK87iJcY4fy7tP-rU3hLgAAAng"] [Sat Aug 29 05:05:18.895079 2026] [security2:error] [pid 1017536:tid 1017758] [client 20.196.209.81:9125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "apK87iJcY4fy7tP-rU3hLwAAAnA"] [Sat Aug 29 05:05:18.916443 2026] [security2:error] [pid 1018003:tid 1018139] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/v2/.env"] [unique_id "apK87jAh5Y1i2tUxg4HeqgAGKnY"] [Sat Aug 29 05:05:18.919082 2026] [security2:error] [pid 1018003:tid 1018140] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/staging/.env"] [unique_id "apK87jAh5Y1i2tUxg4HeqwAGKnc"] [Sat Aug 29 05:05:18.919081 2026] [security2:error] [pid 1018003:tid 1018141] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/backend/.env"] [unique_id "apK87jAh5Y1i2tUxg4HerAAF_3g"] [Sat Aug 29 05:05:18.934064 2026] [security2:error] [pid 1018003:tid 1018145] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/docker/.env"] [unique_id "apK87jAh5Y1i2tUxg4HerwAGKnw"] [Sat Aug 29 05:05:18.934976 2026] [cgid:error] [pid 1018003:tid 1018139] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:18.936951 2026] [access_compat:error] [pid 1017536:tid 1017775] [client 67.20.76.220:12638] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:18.937149 2026] [access_compat:error] [pid 1017536:tid 1017745] [client 67.20.76.220:12640] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:18.944589 2026] [cgid:error] [pid 1018003:tid 1018147] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:18.945516 2026] [cgid:error] [pid 1018003:tid 1018144] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:18.946235 2026] [security2:error] [pid 1018003:tid 1018073] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/config/.env"] [unique_id "apK87jAh5Y1i2tUxg4HesgAF_zQ"] [Sat Aug 29 05:05:18.950559 2026] [cgid:error] [pid 1018003:tid 1018146] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:18.969950 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.63.81.20:26555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/uwu.php"] [unique_id "apK87iJcY4fy7tP-rU3hNwAAAlU"] [Sat Aug 29 05:05:18.975947 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.48.251.3:57893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-konfig.php"] [unique_id "apK87iJcY4fy7tP-rU3hOwAAAi0"] [Sat Aug 29 05:05:18.977653 2026] [security2:error] [pid 1017536:tid 1017601] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.ssh/id_rsa"] [unique_id "apK87iJcY4fy7tP-rU3hOgACdkA"] [Sat Aug 29 05:05:18.985337 2026] [security2:error] [pid 1017536:tid 1017763] [client 20.196.209.81:12085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/alumni_reg.php"] [unique_id "apK87iJcY4fy7tP-rU3hPQAAAnU"] [Sat Aug 29 05:05:18.999270 2026] [security2:error] [pid 1017536:tid 1017705] [client 40.83.93.50:10137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/languages/index.php"] [unique_id "apK87iJcY4fy7tP-rU3hPwAAAjs"] [Sat Aug 29 05:05:19.004785 2026] [core:error] [pid 1017536:tid 1017685] [client 74.248.24.12:41943] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:19.004802 2026] [core:error] [pid 1017536:tid 1017685] [client 74.248.24.12:41943] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:19.013836 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.160.90:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/about.php"] [unique_id "apK87yJcY4fy7tP-rU3hQgAAAo4"] [Sat Aug 29 05:05:19.015513 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.158.54.35:19349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/shell.php"] [unique_id "apK87yJcY4fy7tP-rU3hQwAAAoQ"] [Sat Aug 29 05:05:19.021756 2026] [security2:error] [pid 1017536:tid 1017770] [client 4.232.148.111:24812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "apK87yJcY4fy7tP-rU3hRgAAAnw"] [Sat Aug 29 05:05:19.030530 2026] [security2:error] [pid 1017536:tid 1017694] [client 68.155.159.216:58258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/mah.php"] [unique_id "apK87yJcY4fy7tP-rU3hTQAAAjA"] [Sat Aug 29 05:05:19.034885 2026] [cgid:error] [pid 1018003:tid 1018026] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.054722 2026] [security2:error] [pid 1018003:tid 1018212] [client 52.139.37.240:58578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK87zAh5Y1i2tUxg4HetAAABfU"] [Sat Aug 29 05:05:19.065953 2026] [security2:error] [pid 1018003:tid 1018243] [client 45.154.98.191:52265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK87zAh5Y1i2tUxg4HetgAABhM"] [Sat Aug 29 05:05:19.070656 2026] [security2:error] [pid 1017536:tid 1017667] [client 68.155.159.216:12273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/lv.php"] [unique_id "apK87yJcY4fy7tP-rU3hVgAAAhU"] [Sat Aug 29 05:05:19.073561 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.219.114:9384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/menu.php"] [unique_id "apK87yJcY4fy7tP-rU3hVwAAAkc"] [Sat Aug 29 05:05:19.115233 2026] [security2:error] [pid 1017536:tid 1017728] [client 52.139.37.240:21417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/rtx.php"] [unique_id "apK87yJcY4fy7tP-rU3hXAAAAlI"] [Sat Aug 29 05:05:19.118259 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.251.3:57804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/25.php"] [unique_id "apK87yJcY4fy7tP-rU3hXgAAAlo"] [Sat Aug 29 05:05:19.118876 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.63.81.20:26530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/signon.php"] [unique_id "apK87yJcY4fy7tP-rU3hXwAAAo8"] [Sat Aug 29 05:05:19.135812 2026] [security2:error] [pid 1017536:tid 1017727] [client 143.244.57.82:48408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK87yJcY4fy7tP-rU3hYQAAAlE"] [Sat Aug 29 05:05:19.159043 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.160.90:64743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/admin.php/admin.php"] [unique_id "apK87yJcY4fy7tP-rU3hYgAAAjE"] [Sat Aug 29 05:05:19.199718 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.63.219.114:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/blog.php"] [unique_id "apK87yJcY4fy7tP-rU3hZwAAAj0"] [Sat Aug 29 05:05:19.209122 2026] [security2:error] [pid 1017536:tid 1017693] [client 185.104.184.230:36420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK87yJcY4fy7tP-rU3haQAAAi8"] [Sat Aug 29 05:05:19.212539 2026] [security2:error] [pid 1018003:tid 1018257] [client 168.107.94.195:55634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK87zAh5Y1i2tUxg4HeuQAABiE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:19.216035 2026] [cgid:error] [pid 1018003:tid 1018024] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.223686 2026] [security2:error] [pid 1017536:tid 1017558] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.ssh/id_dsa"] [unique_id "apK87yJcY4fy7tP-rU3hbQACdhU"] [Sat Aug 29 05:05:19.234611 2026] [security2:error] [pid 1017536:tid 1017739] [client 61.9.8.240:164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK87yJcY4fy7tP-rU3hbgAAAl0"] [Sat Aug 29 05:05:19.234738 2026] [security2:error] [pid 1017536:tid 1017739] [client 61.9.8.240:164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK87yJcY4fy7tP-rU3hbgAAAl0"] [Sat Aug 29 05:05:19.252051 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.251.3:57891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/nlnub.php"] [unique_id "apK87yJcY4fy7tP-rU3hcAAAAmw"] [Sat Aug 29 05:05:19.254131 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.63.219.114:1497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/classsmtps.php"] [unique_id "apK87yJcY4fy7tP-rU3hcQAAAkA"] [Sat Aug 29 05:05:19.254717 2026] [security2:error] [pid 1017536:tid 1017668] [client 52.139.37.240:24684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/ws49.php"] [unique_id "apK87yJcY4fy7tP-rU3hcgAAAhY"] [Sat Aug 29 05:05:19.263196 2026] [security2:error] [pid 1017536:tid 1017684] [client 68.155.159.216:24536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/about.php"] [unique_id "apK87yJcY4fy7tP-rU3hcwAAAiY"] [Sat Aug 29 05:05:19.264135 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.63.81.20:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/file61.php"] [unique_id "apK87yJcY4fy7tP-rU3hdAAAAhs"] [Sat Aug 29 05:05:19.266717 2026] [security2:error] [pid 1018003:tid 1018033] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/old/.env"] [unique_id "apK87zAh5Y1i2tUxg4HeugAFtww"] [Sat Aug 29 05:05:19.274312 2026] [security2:error] [pid 1018003:tid 1018021] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.github/.env"] [unique_id "apK87zAh5Y1i2tUxg4HeuwAF4AA"] [Sat Aug 29 05:05:19.276157 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.196.209.81:15125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/disagraeosc.php"] [unique_id "apK87yJcY4fy7tP-rU3hdQAAAnc"] [Sat Aug 29 05:05:19.277848 2026] [cgid:error] [pid 1018003:tid 1018071] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.280003 2026] [security2:error] [pid 1017536:tid 1017669] [client 185.104.184.230:45792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK87yJcY4fy7tP-rU3hdgAAAhc"] [Sat Aug 29 05:05:19.280103 2026] [security2:error] [pid 1018003:tid 1018031] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/v1/.env"] [unique_id "apK87zAh5Y1i2tUxg4HevQAGMQo"] [Sat Aug 29 05:05:19.281942 2026] [security2:error] [pid 1018003:tid 1018202] [client 35.213.70.61:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "spellsoupdesign.com"] [uri "/w_api/Handler.php"] [unique_id "apK87jAh5Y1i2tUxg4HemwAABes"] [Sat Aug 29 05:05:19.291310 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.196.209.81:19360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK87yJcY4fy7tP-rU3heAAAAmo"] [Sat Aug 29 05:05:19.295648 2026] [security2:error] [pid 1018003:tid 1018143] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/apps/.env"] [unique_id "apK87zAh5Y1i2tUxg4HevwAF1no"] [Sat Aug 29 05:05:19.299462 2026] [cgid:error] [pid 1018003:tid 1018028] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.300132 2026] [security2:error] [pid 1018003:tid 1018224] [client 35.213.70.61:55880] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "spellsoupdesign.com"] [uri "/llms.txt"] [unique_id "apK87jAh5Y1i2tUxg4HelgAGAW4"] [Sat Aug 29 05:05:19.301553 2026] [cgid:error] [pid 1018003:tid 1018030] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.303999 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.48.160.90:64704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/media.php"] [unique_id "apK87yJcY4fy7tP-rU3hewAAAn8"] [Sat Aug 29 05:05:19.311131 2026] [security2:error] [pid 1018003:tid 1018174] [client 52.139.37.240:21405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/update/da222.php"] [unique_id "apK87zAh5Y1i2tUxg4HewgAABc8"] [Sat Aug 29 05:05:19.314506 2026] [security2:error] [pid 1017536:tid 1017761] [client 4.232.148.111:35085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/i.php"] [unique_id "apK87yJcY4fy7tP-rU3hfAAAAnM"] [Sat Aug 29 05:05:19.332023 2026] [security2:error] [pid 1017536:tid 1017723] [client 65.111.7.230:51897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK87yJcY4fy7tP-rU3hegAAAk0"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:19.335439 2026] [security2:error] [pid 1017536:tid 1017564] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/id_rsa"] [unique_id "apK87yJcY4fy7tP-rU3hfgACdhs"] [Sat Aug 29 05:05:19.346849 2026] [security2:error] [pid 1017536:tid 1017725] [client 4.205.62.107:64944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/adminfus.php"] [unique_id "apK87yJcY4fy7tP-rU3hfwAAAk8"] [Sat Aug 29 05:05:19.352877 2026] [cgid:error] [pid 1018003:tid 1018134] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.363441 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:16139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/makeasmtp.php"] [unique_id "apK87yJcY4fy7tP-rU3hgwAAAjI"] [Sat Aug 29 05:05:19.364870 2026] [security2:error] [pid 1017536:tid 1017679] [client 68.155.159.216:16210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK87yJcY4fy7tP-rU3hhQAAAiE"] [Sat Aug 29 05:05:19.378757 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.147.79:24570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/dropdown.php"] [unique_id "apK87zAh5Y1i2tUxg4HexAAABd0"] [Sat Aug 29 05:05:19.381107 2026] [security2:error] [pid 1018003:tid 1018023] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/site/.env"] [unique_id "apK87zAh5Y1i2tUxg4HexQAGGwI"] [Sat Aug 29 05:05:19.382789 2026] [security2:error] [pid 1017536:tid 1017751] [client 74.248.24.12:28177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/gifclass.php"] [unique_id "apK87yJcY4fy7tP-rU3hiAAAAmk"] [Sat Aug 29 05:05:19.387546 2026] [security2:error] [pid 1017536:tid 1017706] [client 4.205.62.107:22289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/api.php"] [unique_id "apK87yJcY4fy7tP-rU3hiQAAAjw"] [Sat Aug 29 05:05:19.403058 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.251.3:57847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/mga.php"] [unique_id "apK87yJcY4fy7tP-rU3hjAAAAoE"] [Sat Aug 29 05:05:19.428504 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.196.209.81:1690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/colors.php"] [unique_id "apK87yJcY4fy7tP-rU3hkQAAAks"] [Sat Aug 29 05:05:19.429484 2026] [authz_core:error] [pid 1018003:tid 1018135] [remote 104.196.51.122:56266] AH01630: client denied by server configuration: /home4/tdessixf/public_html/bigbuttonscarf/.htpasswd [Sat Aug 29 05:05:19.432211 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.63.81.20:26443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/copypaths.php"] [unique_id "apK87zAh5Y1i2tUxg4HeyAAABbo"] [Sat Aug 29 05:05:19.432583 2026] [cgid:error] [pid 1018003:tid 1018032] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.449860 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.63.219.114:11915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/alfa.php"] [unique_id "apK87yJcY4fy7tP-rU3hkgAAAnI"] [Sat Aug 29 05:05:19.450192 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.48.160.90:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/mac.php"] [unique_id "apK87yJcY4fy7tP-rU3hkwAAAi4"] [Sat Aug 29 05:05:19.450434 2026] [security2:error] [pid 1017536:tid 1017678] [client 68.155.159.216:51486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK87yJcY4fy7tP-rU3hlAAAAiA"] [Sat Aug 29 05:05:19.453686 2026] [cgid:error] [pid 1018003:tid 1018100] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.461932 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.158.54.35:9443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/elp.php"] [unique_id "apK87yJcY4fy7tP-rU3hmAAAAho"] [Sat Aug 29 05:05:19.466573 2026] [security2:error] [pid 1017536:tid 1017742] [client 52.139.37.240:24669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/xxx.php"] [unique_id "apK87yJcY4fy7tP-rU3hmQAAAmA"] [Sat Aug 29 05:05:19.472323 2026] [cgid:error] [pid 1018003:tid 1018102] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.480720 2026] [security2:error] [pid 1017536:tid 1017781] [client 40.83.93.50:10850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/languages/min.php"] [unique_id "apK87yJcY4fy7tP-rU3hmwAAAoc"] [Sat Aug 29 05:05:19.534128 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:25549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/simple.php"] [unique_id "apK87yJcY4fy7tP-rU3hngAAAkc"] [Sat Aug 29 05:05:19.540503 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.251.3:57868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ccou.php"] [unique_id "apK87yJcY4fy7tP-rU3hnwAAAkM"] [Sat Aug 29 05:05:19.545586 2026] [security2:error] [pid 1017536:tid 1017731] [client 4.232.148.111:24799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/gifclass.php"] [unique_id "apK87yJcY4fy7tP-rU3hoAAAAlU"] [Sat Aug 29 05:05:19.561192 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.63.81.20:26516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/bless6.php"] [unique_id "apK87yJcY4fy7tP-rU3hogAAAo8"] [Sat Aug 29 05:05:19.562547 2026] [security2:error] [pid 1017536:tid 1017726] [client 4.205.62.107:21943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/124.php"] [unique_id "apK87yJcY4fy7tP-rU3howAAAlA"] [Sat Aug 29 05:05:19.568242 2026] [security2:error] [pid 1018003:tid 1018271] [client 158.23.147.79:55281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK87zAh5Y1i2tUxg4HezAAABi8"] [Sat Aug 29 05:05:19.586533 2026] [security2:error] [pid 1018003:tid 1018160] [client 68.155.159.216:33620] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/blocks/post-excerpt/alfa-rex.PHP"] [unique_id "apK87zAh5Y1i2tUxg4HezQAABcE"] [Sat Aug 29 05:05:19.590658 2026] [security2:error] [pid 1018003:tid 1018157] [client 185.104.184.230:45798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "apK87zAh5Y1i2tUxg4HezgAABb4"] [Sat Aug 29 05:05:19.592986 2026] [security2:error] [pid 1018003:tid 1018178] [client 74.248.24.12:35460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/tool.php"] [unique_id "apK87zAh5Y1i2tUxg4He0AAABdM"] [Sat Aug 29 05:05:19.593070 2026] [security2:error] [pid 1018003:tid 1018253] [client 168.107.94.195:55944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK87zAh5Y1i2tUxg4HezwAABh0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:19.602562 2026] [security2:error] [pid 1018003:tid 1018190] [client 45.154.98.191:52574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK87zAh5Y1i2tUxg4He1AAABd8"] [Sat Aug 29 05:05:19.607623 2026] [security2:error] [pid 1018003:tid 1018215] [client 52.139.37.240:20793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-admin/min.php"] [unique_id "apK87zAh5Y1i2tUxg4He1gAABfg"] [Sat Aug 29 05:05:19.634627 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.48.160.90:64690] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "stampstudios.glowt-shirt.com"] [uri "/1.php"] [unique_id "apK87zAh5Y1i2tUxg4He2AAABbw"] [Sat Aug 29 05:05:19.634754 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.48.160.90:64690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/1.php"] [unique_id "apK87zAh5Y1i2tUxg4He2AAABbw"] [Sat Aug 29 05:05:19.648015 2026] [security2:error] [pid 1017536:tid 1017669] [client 149.34.210.141:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK87yJcY4fy7tP-rU3hqAAAAhc"] [Sat Aug 29 05:05:19.648146 2026] [security2:error] [pid 1017536:tid 1017669] [client 149.34.210.141:51206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK87yJcY4fy7tP-rU3hqAAAAhc"] [Sat Aug 29 05:05:19.660801 2026] [security2:error] [pid 1018003:tid 1018185] [client 52.139.37.240:24882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/0x.php"] [unique_id "apK87zAh5Y1i2tUxg4He2QAABdo"] [Sat Aug 29 05:05:19.670828 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.196.209.81:15122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/about.php525"] [unique_id "apK87yJcY4fy7tP-rU3hrQAAAj4"] [Sat Aug 29 05:05:19.671494 2026] [cgid:error] [pid 1018003:tid 1018036] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.673717 2026] [cgid:error] [pid 1018003:tid 1018034] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.676127 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.48.251.3:57879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/rum.or.php"] [unique_id "apK87zAh5Y1i2tUxg4He3QAABiw"] [Sat Aug 29 05:05:19.677499 2026] [security2:error] [pid 1017536:tid 1017728] [client 20.63.219.114:1426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/bypass.php"] [unique_id "apK87yJcY4fy7tP-rU3hrwAAAlI"] [Sat Aug 29 05:05:19.688059 2026] [cgid:error] [pid 1018003:tid 1018035] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.688483 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.196.209.81:17941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-blog-header.php"] [unique_id "apK87yJcY4fy7tP-rU3htAAAAlo"] [Sat Aug 29 05:05:19.688552 2026] [security2:error] [pid 1017536:tid 1017787] [client 103.171.189.88:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK87yJcY4fy7tP-rU3htQAAAo0"] [Sat Aug 29 05:05:19.688655 2026] [security2:error] [pid 1017536:tid 1017787] [client 103.171.189.88:50724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK87yJcY4fy7tP-rU3htQAAAo0"] [Sat Aug 29 05:05:19.690456 2026] [security2:error] [pid 1017536:tid 1017769] [client 4.205.62.107:2911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/config_dev.php"] [unique_id "apK87yJcY4fy7tP-rU3htwAAAns"] [Sat Aug 29 05:05:19.690915 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.63.81.20:26558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/special.php"] [unique_id "apK87yJcY4fy7tP-rU3huAAAAlo"] [Sat Aug 29 05:05:19.693482 2026] [security2:error] [pid 1018003:tid 1018240] [client 143.244.57.82:56270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK87zAh5Y1i2tUxg4He3wAABhA"] [Sat Aug 29 05:05:19.720112 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.63.219.114:1510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/contentloader1.php"] [unique_id "apK87zAh5Y1i2tUxg4He4AAABhg"] [Sat Aug 29 05:05:19.744994 2026] [security2:error] [pid 1018003:tid 1018205] [client 158.23.147.79:38720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/atomlib.php"] [unique_id "apK87zAh5Y1i2tUxg4He4wAABe4"] [Sat Aug 29 05:05:19.746534 2026] [security2:error] [pid 1018003:tid 1018039] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/static../.env"] [unique_id "apK87zAh5Y1i2tUxg4He5AAFuxI"] [Sat Aug 29 05:05:19.749697 2026] [cgid:error] [pid 1018003:tid 1018025] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.751429 2026] [cgid:error] [pid 1018003:tid 1018037] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.770871 2026] [security2:error] [pid 1017536:tid 1017628] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/id_dsa"] [unique_id "apK87yJcY4fy7tP-rU3hwQACdls"] [Sat Aug 29 05:05:19.780935 2026] [security2:error] [pid 1017536:tid 1017690] [client 68.155.159.216:18260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/log-mama/function.php"] [unique_id "apK87yJcY4fy7tP-rU3hxAAAAiw"] [Sat Aug 29 05:05:19.783005 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.49.130:57664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/ty.php"] [unique_id "apK87zAh5Y1i2tUxg4He5wAABdc"] [Sat Aug 29 05:05:19.784606 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.48.160.90:63590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/classwithtostring.php"] [unique_id "apK87yJcY4fy7tP-rU3hxQAAAiY"] [Sat Aug 29 05:05:19.798851 2026] [security2:error] [pid 1018003:tid 1018250] [client 4.232.148.111:9045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/deepseek_d.php"] [unique_id "apK87zAh5Y1i2tUxg4He6AAABho"] [Sat Aug 29 05:05:19.800366 2026] [security2:error] [pid 1018003:tid 1018170] [client 185.104.184.230:36436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.youthspeakoutint.org"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK87zAh5Y1i2tUxg4He6QAABcs"] [Sat Aug 29 05:05:19.804196 2026] [security2:error] [pid 1018003:tid 1018038] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/portal/.env"] [unique_id "apK87zAh5Y1i2tUxg4He6wAF-xE"] [Sat Aug 29 05:05:19.804731 2026] [security2:error] [pid 1018003:tid 1018041] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/api/.env.bak"] [unique_id "apK87zAh5Y1i2tUxg4He6gAF-xQ"] [Sat Aug 29 05:05:19.812224 2026] [security2:error] [pid 1018003:tid 1018269] [client 52.139.37.240:20737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK87zAh5Y1i2tUxg4He7AAABi0"] [Sat Aug 29 05:05:19.813167 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.251.3:28459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/xmy.php"] [unique_id "apK87zAh5Y1i2tUxg4He7QAABh8"] [Sat Aug 29 05:05:19.815217 2026] [security2:error] [pid 1018003:tid 1018198] [client 4.205.62.107:9169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/umgebung.php"] [unique_id "apK87zAh5Y1i2tUxg4He7gAABec"] [Sat Aug 29 05:05:19.830490 2026] [cgid:error] [pid 1018003:tid 1018045] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.831229 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.196.209.81:1689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/Js.php"] [unique_id "apK87yJcY4fy7tP-rU3hxwAAAj0"] [Sat Aug 29 05:05:19.833267 2026] [cgid:error] [pid 1018003:tid 1018052] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.837227 2026] [cgid:error] [pid 1018003:tid 1018047] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.842077 2026] [cgid:error] [pid 1018003:tid 1018048] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.842903 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.63.81.20:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/fz.php"] [unique_id "apK87yJcY4fy7tP-rU3hyQAAAis"] [Sat Aug 29 05:05:19.843371 2026] [security2:error] [pid 1018003:tid 1018049] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/media../.env"] [unique_id "apK87zAh5Y1i2tUxg4He8wAGAhw"] [Sat Aug 29 05:05:19.851380 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.23.147.79:23399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/ans.php"] [unique_id "apK87yJcY4fy7tP-rU3hygAAAjQ"] [Sat Aug 29 05:05:19.851971 2026] [cgid:error] [pid 1018003:tid 1018044] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.869583 2026] [security2:error] [pid 1017536:tid 1017703] [client 52.139.37.240:24694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/CDX1.php"] [unique_id "apK87yJcY4fy7tP-rU3hywAAAjk"] [Sat Aug 29 05:05:19.878180 2026] [security2:error] [pid 1017536:tid 1017651] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/key.pem"] [unique_id "apK87yJcY4fy7tP-rU3hzQACdnI"] [Sat Aug 29 05:05:19.881195 2026] [security2:error] [pid 1017536:tid 1017744] [client 185.104.184.230:45802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK87yJcY4fy7tP-rU3hzgAAAmI"] [Sat Aug 29 05:05:19.903206 2026] [core:error] [pid 1017536:tid 1017739] [client 74.248.24.12:25675] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:19.903227 2026] [core:error] [pid 1017536:tid 1017739] [client 74.248.24.12:25675] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:19.908495 2026] [security2:error] [pid 1017536:tid 1017766] [client 4.205.62.107:61112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/var/www/wallet/index.php"] [unique_id "apK87yJcY4fy7tP-rU3h1AAAAng"] [Sat Aug 29 05:05:19.909799 2026] [security2:error] [pid 1018003:tid 1018040] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.env.prod.bak"] [unique_id "apK87zAh5Y1i2tUxg4He9gAFvRM"] [Sat Aug 29 05:05:19.917484 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.158.54.35:9462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/cong.php"] [unique_id "apK87zAh5Y1i2tUxg4He-AAABdQ"] [Sat Aug 29 05:05:19.919029 2026] [security2:error] [pid 1018003:tid 1018054] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/@fs/.env"] [unique_id "apK87zAh5Y1i2tUxg4He9wAGKCE"] [Sat Aug 29 05:05:19.924169 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.63.219.114:19403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/feed-rss2-queue.php"] [unique_id "apK87yJcY4fy7tP-rU3h1wAAAhY"] [Sat Aug 29 05:05:19.924918 2026] [security2:error] [pid 1018003:tid 1018051] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/env.old"] [unique_id "apK87zAh5Y1i2tUxg4He-QAGKB4"] [Sat Aug 29 05:05:19.925807 2026] [security2:error] [pid 1018003:tid 1018043] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/env.bak"] [unique_id "apK87zAh5Y1i2tUxg4He_AAGKBY"] [Sat Aug 29 05:05:19.926309 2026] [security2:error] [pid 1018003:tid 1018054] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.docker/.env"] [unique_id "apK87zAh5Y1i2tUxg4He-gAGKCE"] [Sat Aug 29 05:05:19.927388 2026] [security2:error] [pid 1018003:tid 1018053] [remote 104.196.115.188:49512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/.env.production.bak"] [unique_id "apK87zAh5Y1i2tUxg4He-wAGKCA"] [Sat Aug 29 05:05:19.946236 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.48.251.3:28421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ms-edit.php"] [unique_id "apK87zAh5Y1i2tUxg4He_gAABik"] [Sat Aug 29 05:05:19.948583 2026] [security2:error] [pid 1017536:tid 1017554] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/privatekey.key"] [unique_id "apK87yJcY4fy7tP-rU3h2QACdhE"] [Sat Aug 29 05:05:19.952751 2026] [security2:error] [pid 1018003:tid 1018186] [client 40.83.93.50:10117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/languages/pk.php"] [unique_id "apK87zAh5Y1i2tUxg4He_wAABds"] [Sat Aug 29 05:05:19.973938 2026] [security2:error] [pid 1018003:tid 1018243] [client 168.107.94.195:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK87zAh5Y1i2tUxg4HfAAAABhM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:19.985054 2026] [security2:error] [pid 1018003:tid 1018152] [client 65.111.26.193:57745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK87zAh5Y1i2tUxg4He_QAABbk"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:19.991734 2026] [cgid:error] [pid 1018003:tid 1018055] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:19.993405 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.63.81.20:26529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/clque.php"] [unique_id "apK87yJcY4fy7tP-rU3h3gAAAjI"] [Sat Aug 29 05:05:20.009454 2026] [security2:error] [pid 1017536:tid 1017724] [client 52.139.37.240:21138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK88CJcY4fy7tP-rU3h4AAAAk4"] [Sat Aug 29 05:05:20.012834 2026] [security2:error] [pid 1018003:tid 1018056] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.ssh/id_rsa"] [unique_id "apK88DAh5Y1i2tUxg4HfAwAGMiM"] [Sat Aug 29 05:05:20.014320 2026] [security2:error] [pid 1018003:tid 1018057] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.ssh/id_dsa"] [unique_id "apK88DAh5Y1i2tUxg4HfBAAGMiQ"] [Sat Aug 29 05:05:20.016330 2026] [cgid:error] [pid 1018003:tid 1018061] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.016958 2026] [cgid:error] [pid 1018003:tid 1018062] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.017487 2026] [cgid:error] [pid 1018003:tid 1018060] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.043824 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.63.219.114:1488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/extractable-loader-head.php"] [unique_id "apK88DAh5Y1i2tUxg4HfCAAABf8"] [Sat Aug 29 05:05:20.067263 2026] [security2:error] [pid 1017536:tid 1017749] [client 52.139.37.240:25027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/akcc.php"] [unique_id "apK88CJcY4fy7tP-rU3h8wAAAmc"] [Sat Aug 29 05:05:20.080432 2026] [security2:error] [pid 1018003:tid 1018150] [client 20.48.160.90:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-ws68.php"] [unique_id "apK88DAh5Y1i2tUxg4HfCgAABbc"] [Sat Aug 29 05:05:20.084683 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.251.3:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/sys.php"] [unique_id "apK88DAh5Y1i2tUxg4HfCwAABes"] [Sat Aug 29 05:05:20.085608 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.63.219.114:1431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/al.php"] [unique_id "apK88CJcY4fy7tP-rU3h-AAAAkU"] [Sat Aug 29 05:05:20.087330 2026] [security2:error] [pid 1018003:tid 1018165] [client 20.196.209.81:17949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-blogs.php"] [unique_id "apK88DAh5Y1i2tUxg4HfDQAABcY"] [Sat Aug 29 05:05:20.107484 2026] [autoindex:error] [pid 1018003:tid 1018273] [client 4.232.148.111:0] AH01276: Cannot serve directory /home4/ehfields/public_html/tiaandephraim/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:20.129471 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.196.209.81:9533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/backup.php"] [unique_id "apK88CJcY4fy7tP-rU3h-wAAAiE"] [Sat Aug 29 05:05:20.133984 2026] [security2:error] [pid 1017536:tid 1017742] [client 68.155.159.216:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-blog-header.php"] [unique_id "apK88CJcY4fy7tP-rU3h_AAAAmA"] [Sat Aug 29 05:05:20.140835 2026] [security2:error] [pid 1018003:tid 1018027] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/id_rsa"] [unique_id "apK88DAh5Y1i2tUxg4HfEAAF1QY"] [Sat Aug 29 05:05:20.146788 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.63.81.20:26549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/nano.php"] [unique_id "apK88CJcY4fy7tP-rU3h_gAAAhU"] [Sat Aug 29 05:05:20.154572 2026] [cgid:error] [pid 1018003:tid 1018064] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.155149 2026] [security2:error] [pid 1018003:tid 1018089] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/id_dsa"] [unique_id "apK88DAh5Y1i2tUxg4HfFAAF1UQ"] [Sat Aug 29 05:05:20.155388 2026] [cgid:error] [pid 1018003:tid 1018058] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.156594 2026] [security2:error] [pid 1018003:tid 1018072] [remote 104.196.115.188:49512] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "infinitidealership.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK88DAh5Y1i2tUxg4HfFwAFujM"] [Sat Aug 29 05:05:20.158840 2026] [cgid:error] [pid 1018003:tid 1018063] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.159697 2026] [cgid:error] [pid 1018003:tid 1018065] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.188000 2026] [security2:error] [pid 1017536:tid 1017789] [client 185.104.184.230:45804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK88CJcY4fy7tP-rU3iBgAAAo8"] [Sat Aug 29 05:05:20.197531 2026] [security2:error] [pid 1017536:tid 1017772] [client 45.154.98.191:52843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK88CJcY4fy7tP-rU3iBwAAAn4"] [Sat Aug 29 05:05:20.208068 2026] [security2:error] [pid 1017536:tid 1017757] [client 52.139.37.240:21381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK88CJcY4fy7tP-rU3iCgAAAm8"] [Sat Aug 29 05:05:20.212979 2026] [security2:error] [pid 1017536:tid 1017727] [client 68.155.159.216:12258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/Text/index.php"] [unique_id "apK88CJcY4fy7tP-rU3iCwAAAlE"] [Sat Aug 29 05:05:20.215861 2026] [security2:error] [pid 1018003:tid 1018167] [client 74.248.24.12:8165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/k.php"] [unique_id "apK88DAh5Y1i2tUxg4HfGQAABcg"] [Sat Aug 29 05:05:20.222424 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.48.251.3:57826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/phpsysinfo.php"] [unique_id "apK88CJcY4fy7tP-rU3iDgAAAlM"] [Sat Aug 29 05:05:20.227327 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.160.90:64644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/simple.php"] [unique_id "apK88DAh5Y1i2tUxg4HfGgAABf4"] [Sat Aug 29 05:05:20.230857 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.196.209.81:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/access.php"] [unique_id "apK88CJcY4fy7tP-rU3iEAAAAiA"] [Sat Aug 29 05:05:20.234881 2026] [cgid:error] [pid 1018003:tid 1018022] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.239632 2026] [cgid:error] [pid 1018003:tid 1018148] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.245103 2026] [security2:error] [pid 1017536:tid 1017691] [client 143.244.57.82:56286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK88CJcY4fy7tP-rU3iEwAAAi0"] [Sat Aug 29 05:05:20.256278 2026] [cgid:error] [pid 1018003:tid 1018078] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.266902 2026] [security2:error] [pid 1017536:tid 1017726] [client 52.139.37.240:25080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK88CJcY4fy7tP-rU3iFQAAAlA"] [Sat Aug 29 05:05:20.286232 2026] [security2:error] [pid 1018003:tid 1018081] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/key.pem"] [unique_id "apK88DAh5Y1i2tUxg4HfHgAGGTw"] [Sat Aug 29 05:05:20.286234 2026] [security2:error] [pid 1018003:tid 1018080] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/privatekey.key"] [unique_id "apK88DAh5Y1i2tUxg4HfHwAGGTs"] [Sat Aug 29 05:05:20.289588 2026] [core:error] [pid 1018003:tid 1018177] [client 34.12.38.134:21234] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.289607 2026] [core:error] [pid 1018003:tid 1018177] [client 34.12.38.134:21234] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.290451 2026] [core:error] [pid 1017536:tid 1017686] [client 34.12.38.134:21190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.290468 2026] [core:error] [pid 1017536:tid 1017686] [client 34.12.38.134:21190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.290614 2026] [security2:error] [pid 1017536:tid 1017686] [client 34.12.38.134:21190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK88CJcY4fy7tP-rU3iFwAAAig"] [Sat Aug 29 05:05:20.291159 2026] [core:error] [pid 1018003:tid 1018174] [client 34.12.38.134:21244] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.291172 2026] [core:error] [pid 1018003:tid 1018174] [client 34.12.38.134:21244] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.296435 2026] [core:error] [pid 1018003:tid 1018184] [client 34.12.38.134:21168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.296451 2026] [core:error] [pid 1018003:tid 1018184] [client 34.12.38.134:21168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.299728 2026] [core:error] [pid 1018003:tid 1018241] [client 34.12.38.134:21260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.299750 2026] [core:error] [pid 1018003:tid 1018241] [client 34.12.38.134:21260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.304630 2026] [core:error] [pid 1018003:tid 1018209] [client 34.12.38.134:21246] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.304650 2026] [core:error] [pid 1018003:tid 1018209] [client 34.12.38.134:21246] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.304737 2026] [core:error] [pid 1017536:tid 1017781] [client 34.12.38.134:21264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.304751 2026] [core:error] [pid 1017536:tid 1017781] [client 34.12.38.134:21264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.304931 2026] [core:error] [pid 1017536:tid 1017713] [client 34.12.38.134:21276] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.304942 2026] [core:error] [pid 1017536:tid 1017713] [client 34.12.38.134:21276] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.305801 2026] [cgid:error] [pid 1018003:tid 1018079] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.306400 2026] [core:error] [pid 1018003:tid 1018278] [client 34.12.38.134:21202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.306416 2026] [core:error] [pid 1018003:tid 1018278] [client 34.12.38.134:21202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.306522 2026] [core:error] [pid 1018003:tid 1018258] [client 34.12.38.134:21194] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.306529 2026] [core:error] [pid 1018003:tid 1018258] [client 34.12.38.134:21194] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.306533 2026] [core:error] [pid 1017536:tid 1017717] [client 34.12.38.134:21174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.306544 2026] [core:error] [pid 1017536:tid 1017717] [client 34.12.38.134:21174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.306668 2026] [security2:error] [pid 1017536:tid 1017717] [client 34.12.38.134:21174] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK88CJcY4fy7tP-rU3iHAAAAkc"] [Sat Aug 29 05:05:20.307058 2026] [core:error] [pid 1017536:tid 1017734] [client 34.12.38.134:21228] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.307068 2026] [core:error] [pid 1017536:tid 1017734] [client 34.12.38.134:21228] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.307165 2026] [security2:error] [pid 1017536:tid 1017734] [client 34.12.38.134:21228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK88CJcY4fy7tP-rU3iGgAAAlg"] [Sat Aug 29 05:05:20.307832 2026] [core:error] [pid 1018003:tid 1018246] [client 34.12.38.134:21214] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.307849 2026] [core:error] [pid 1018003:tid 1018246] [client 34.12.38.134:21214] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.309069 2026] [core:error] [pid 1018003:tid 1018187] [client 34.12.38.134:21186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.309082 2026] [core:error] [pid 1018003:tid 1018187] [client 34.12.38.134:21186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.309577 2026] [core:error] [pid 1018003:tid 1018242] [client 34.12.38.134:21284] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.309592 2026] [core:error] [pid 1018003:tid 1018242] [client 34.12.38.134:21284] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.310296 2026] [core:error] [pid 1018003:tid 1018158] [client 34.12.38.134:21288] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.310307 2026] [core:error] [pid 1018003:tid 1018158] [client 34.12.38.134:21288] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:20.311758 2026] [security2:error] [pid 1018003:tid 1018178] [client 20.63.219.114:9403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/inputs.php"] [unique_id "apK88DAh5Y1i2tUxg4HfLAAABdM"] [Sat Aug 29 05:05:20.312653 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.63.81.20:26476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "mail.harnessrenewables.com"] [uri "/.mopj.php"] [unique_id "apK88CJcY4fy7tP-rU3iHwAAAjY"] [Sat Aug 29 05:05:20.355455 2026] [security2:error] [pid 1017536:tid 1017792] [client 168.107.94.195:56533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK88CJcY4fy7tP-rU3iJAAAApI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:20.361151 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.251.3:57880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/sgd.php"] [unique_id "apK88CJcY4fy7tP-rU3iJQAAAmo"] [Sat Aug 29 05:05:20.366036 2026] [security2:error] [pid 1017536:tid 1017784] [client 4.232.148.111:19404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK88CJcY4fy7tP-rU3iJwAAAoo"] [Sat Aug 29 05:05:20.367596 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:30686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/file5.php"] [unique_id "apK88DAh5Y1i2tUxg4HfLQAABdA"] [Sat Aug 29 05:05:20.378217 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.158.54.35:11050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/images/admin.php"] [unique_id "apK88CJcY4fy7tP-rU3iKQAAAhw"] [Sat Aug 29 05:05:20.382590 2026] [security2:error] [pid 1018003:tid 1018189] [client 68.155.159.216:24463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK88DAh5Y1i2tUxg4HfLgAABd4"] [Sat Aug 29 05:05:20.401478 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.63.219.114:2031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/defaults.php"] [unique_id "apK88DAh5Y1i2tUxg4HfLwAABc0"] [Sat Aug 29 05:05:20.405756 2026] [cgid:error] [pid 1018003:tid 1018082] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.406028 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.160.90:63537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/aaa.php"] [unique_id "apK88CJcY4fy7tP-rU3iLAAAAmI"] [Sat Aug 29 05:05:20.420575 2026] [security2:error] [pid 1017536:tid 1017711] [client 74.248.24.12:27435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK88CJcY4fy7tP-rU3iLgAAAkE"] [Sat Aug 29 05:05:20.423895 2026] [cgid:error] [pid 1018003:tid 1018083] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.434845 2026] [security2:error] [pid 1017536:tid 1017728] [client 40.83.93.50:10849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.superugly.com"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK88CJcY4fy7tP-rU3iLwAAAlI"] [Sat Aug 29 05:05:20.460353 2026] [security2:error] [pid 1017536:tid 1017782] [client 4.232.148.111:19961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "apK88CJcY4fy7tP-rU3iMgAAAog"] [Sat Aug 29 05:05:20.466382 2026] [security2:error] [pid 1018003:tid 1018205] [client 52.139.37.240:25035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/s.php"] [unique_id "apK88DAh5Y1i2tUxg4HfMwAABe4"] [Sat Aug 29 05:05:20.468009 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.63.219.114:1438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/global.php"] [unique_id "apK88DAh5Y1i2tUxg4HfNAAABgo"] [Sat Aug 29 05:05:20.472897 2026] [security2:error] [pid 1017536:tid 1017725] [client 68.155.159.216:16256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK88CJcY4fy7tP-rU3iNQAAAk8"] [Sat Aug 29 05:05:20.474110 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.63.81.20:26534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/bengi.php"] [unique_id "apK88CJcY4fy7tP-rU3iNgAAAh0"] [Sat Aug 29 05:05:20.474252 2026] [security2:error] [pid 1018003:tid 1018070] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/app/.env"] [unique_id "apK88DAh5Y1i2tUxg4HfNgAF2DE"] [Sat Aug 29 05:05:20.476428 2026] [cgid:error] [pid 1018003:tid 1018084] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.483274 2026] [cgid:error] [pid 1018003:tid 1018086] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.483451 2026] [security2:error] [pid 1018003:tid 1018270] [client 52.139.37.240:20747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK88DAh5Y1i2tUxg4HfOQAABi4"] [Sat Aug 29 05:05:20.485065 2026] [cgid:error] [pid 1018003:tid 1018087] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.485609 2026] [security2:error] [pid 1018003:tid 1018214] [client 185.104.184.230:45818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK88DAh5Y1i2tUxg4HfOgAABfc"] [Sat Aug 29 05:05:20.489237 2026] [security2:error] [pid 1018003:tid 1018076] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/src/.env"] [unique_id "apK88DAh5Y1i2tUxg4HfOwAF9zc"] [Sat Aug 29 05:05:20.492517 2026] [security2:error] [pid 1018003:tid 1018225] [client 4.205.62.107:64997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/avim.php"] [unique_id "apK88DAh5Y1i2tUxg4HfPAAABgI"] [Sat Aug 29 05:05:20.493861 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.48.251.3:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/fleen.php"] [unique_id "apK88DAh5Y1i2tUxg4HfPQAABeY"] [Sat Aug 29 05:05:20.505658 2026] [security2:error] [pid 1018003:tid 1018085] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env"] [unique_id "apK88DAh5Y1i2tUxg4HfPgAGHEA"] [Sat Aug 29 05:05:20.515037 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.196.209.81:17617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-comments-post.php"] [unique_id "apK88DAh5Y1i2tUxg4HfPwAABhg"] [Sat Aug 29 05:05:20.530255 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.196.209.81:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/haiterus.php"] [unique_id "apK88DAh5Y1i2tUxg4HfQAAABhQ"] [Sat Aug 29 05:05:20.552456 2026] [security2:error] [pid 1017536:tid 1017788] [client 4.205.62.107:22309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/txets.php"] [unique_id "apK88CJcY4fy7tP-rU3iOgAAAo4"] [Sat Aug 29 05:05:20.554438 2026] [security2:error] [pid 1018003:tid 1018231] [client 68.155.159.216:16251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK88DAh5Y1i2tUxg4HfQgAABgc"] [Sat Aug 29 05:05:20.581403 2026] [cgid:error] [pid 1018003:tid 1018090] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.585926 2026] [security2:error] [pid 1018003:tid 1018257] [client 145.239.10.137:60547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theverystuff.com"] [uri "/wp-content/plugins/pwnd/Footer.php"] [unique_id "apK88DAh5Y1i2tUxg4HfRQAABiE"], referer: http://theverystuff.com/wp-content/plugins/pwnd/Footer.php [Sat Aug 29 05:05:20.597107 2026] [security2:error] [pid 1018003:tid 1018091] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/.env"] [unique_id "apK88DAh5Y1i2tUxg4HfRgAFuEY"] [Sat Aug 29 05:05:20.612462 2026] [security2:error] [pid 1018003:tid 1018206] [client 209.50.161.180:35235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.161.50.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK88DAh5Y1i2tUxg4HfQQAABe8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:20.620245 2026] [security2:error] [pid 1018003:tid 1018092] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/files../.env"] [unique_id "apK88DAh5Y1i2tUxg4HfRwAFt0c"] [Sat Aug 29 05:05:20.624612 2026] [security2:error] [pid 1017536:tid 1017625] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/test.php"] [unique_id "apK88CJcY4fy7tP-rU3iQwACWVg"] [Sat Aug 29 05:05:20.631445 2026] [security2:error] [pid 1018003:tid 1018042] [remote 104.196.51.122:56266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apK88DAh5Y1i2tUxg4HfSAAF6xU"] [Sat Aug 29 05:05:20.635014 2026] [cgid:error] [pid 1018003:tid 1018095] [remote 104.196.51.122:56266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:20.636895 2026] [security2:error] [pid 1018003:tid 1018181] [client 158.23.147.79:25573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/about.php"] [unique_id "apK88DAh5Y1i2tUxg4HfSgAABdY"] [Sat Aug 29 05:05:20.638101 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.48.251.3:57861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/upload.form.php"] [unique_id "apK88DAh5Y1i2tUxg4HfSwAABjE"] [Sat Aug 29 05:05:20.649884 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.63.81.20:26368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/file2.php"] [unique_id "apK88CJcY4fy7tP-rU3iRQAAAiM"] [Sat Aug 29 05:05:20.659996 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.196.209.81:21081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/classsmtps.php"] [unique_id "apK88DAh5Y1i2tUxg4HfTQAABcw"] [Sat Aug 29 05:05:20.663533 2026] [security2:error] [pid 1018003:tid 1018222] [client 52.139.37.240:58575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/sagax.php"] [unique_id "apK88DAh5Y1i2tUxg4HfTgAABf8"] [Sat Aug 29 05:05:20.671248 2026] [security2:error] [pid 1018003:tid 1018251] [client 158.23.147.79:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK88DAh5Y1i2tUxg4HfTwAABhs"] [Sat Aug 29 05:05:20.689031 2026] [security2:error] [pid 1017536:tid 1017737] [client 52.139.37.240:21376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-info.php"] [unique_id "apK88CJcY4fy7tP-rU3iSwAAAls"] [Sat Aug 29 05:05:20.720956 2026] [security2:error] [pid 1018003:tid 1018097] [remote 104.196.51.122:56266] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.bigbuttonscarf.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK88DAh5Y1i2tUxg4HfUQAF9Ew"] [Sat Aug 29 05:05:20.729374 2026] [security2:error] [pid 1018003:tid 1018160] [client 4.205.62.107:22306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/cu.php"] [unique_id "apK88DAh5Y1i2tUxg4HfUgAABcE"] [Sat Aug 29 05:05:20.735431 2026] [security2:error] [pid 1018003:tid 1018253] [client 68.155.159.216:50262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK88DAh5Y1i2tUxg4HfUwAABh0"] [Sat Aug 29 05:05:20.738210 2026] [security2:error] [pid 1017536:tid 1017716] [client 168.107.94.195:56822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK88CJcY4fy7tP-rU3iUQAAAkY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:20.758795 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:48193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK88CJcY4fy7tP-rU3iUwAAAjE"] [Sat Aug 29 05:05:20.766803 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.63.219.114:1514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/post.php"] [unique_id "apK88DAh5Y1i2tUxg4HfVAAABhU"] [Sat Aug 29 05:05:20.779125 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.63.219.114:11912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK88DAh5Y1i2tUxg4HfVQAABeA"] [Sat Aug 29 05:05:20.786965 2026] [security2:error] [pid 1017536:tid 1017790] [client 185.104.184.230:45826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK88CJcY4fy7tP-rU3iVwAAApA"] [Sat Aug 29 05:05:20.797275 2026] [security2:error] [pid 1017536:tid 1017753] [client 57.141.14.101:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK88CJcY4fy7tP-rU3iWAAAAms"] [Sat Aug 29 05:05:20.804218 2026] [security2:error] [pid 1018003:tid 1018239] [client 45.154.98.191:53122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK88DAh5Y1i2tUxg4HfVgAABg8"] [Sat Aug 29 05:05:20.804331 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.63.81.20:26540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/gm.php"] [unique_id "apK88CJcY4fy7tP-rU3iWgAAAl8"] [Sat Aug 29 05:05:20.812042 2026] [security2:error] [pid 1018003:tid 1018179] [client 143.244.57.82:56300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wincosir.enproftp.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK88DAh5Y1i2tUxg4HfWAAABdQ"] [Sat Aug 29 05:05:20.826138 2026] [security2:error] [pid 1018003:tid 1018155] [client 4.205.62.107:2643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/oc460l3x.php"] [unique_id "apK88DAh5Y1i2tUxg4HfWQAABbw"] [Sat Aug 29 05:05:20.836431 2026] [security2:error] [pid 1017536:tid 1017731] [client 158.158.54.35:22225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-mail.php"] [unique_id "apK88CJcY4fy7tP-rU3iXgAAAlU"] [Sat Aug 29 05:05:20.841632 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.63.219.114:1454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/update.php"] [unique_id "apK88CJcY4fy7tP-rU3iYQAAAoI"] [Sat Aug 29 05:05:20.862446 2026] [security2:error] [pid 1017536:tid 1017693] [client 68.155.159.216:33658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK88CJcY4fy7tP-rU3iZQAAAi8"] [Sat Aug 29 05:05:20.863278 2026] [security2:error] [pid 1018003:tid 1018219] [client 4.232.148.111:3031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/css/index.php"] [unique_id "apK88DAh5Y1i2tUxg4HfWgAABfw"] [Sat Aug 29 05:05:20.866922 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.147.79:38762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/lv.php"] [unique_id "apK88CJcY4fy7tP-rU3iZgAAAks"] [Sat Aug 29 05:05:20.883736 2026] [security2:error] [pid 1018003:tid 1018159] [client 103.162.125.59:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK88DAh5Y1i2tUxg4HfXgAABcA"] [Sat Aug 29 05:05:20.883877 2026] [security2:error] [pid 1018003:tid 1018159] [client 103.162.125.59:50320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK88DAh5Y1i2tUxg4HfXgAABcA"] [Sat Aug 29 05:05:20.887274 2026] [security2:error] [pid 1018003:tid 1018226] [client 52.139.37.240:21121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK88DAh5Y1i2tUxg4HfXwAABgM"] [Sat Aug 29 05:05:20.891116 2026] [security2:error] [pid 1017536:tid 1017754] [client 74.248.24.12:35463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/root.php"] [unique_id "apK88CJcY4fy7tP-rU3iawAAAmw"] [Sat Aug 29 05:05:20.915641 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.196.209.81:12358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-config.php"] [unique_id "apK88CJcY4fy7tP-rU3ibgAAAow"] [Sat Aug 29 05:05:20.935550 2026] [security2:error] [pid 1018003:tid 1018190] [client 74.248.24.12:25698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/css/index.php"] [unique_id "apK88DAh5Y1i2tUxg4HfYgAABd8"] [Sat Aug 29 05:05:20.946957 2026] [security2:error] [pid 1018003:tid 1018187] [client 52.139.37.240:25044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-content/plugins/ftde.php"] [unique_id "apK88DAh5Y1i2tUxg4HfYwAABdw"] [Sat Aug 29 05:05:20.948935 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.196.209.81:9504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/go.php"] [unique_id "apK88CJcY4fy7tP-rU3icQAAAhc"] [Sat Aug 29 05:05:20.970915 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.63.81.20:26489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/ws55.php"] [unique_id "apK88DAh5Y1i2tUxg4HfZQAABd4"] [Sat Aug 29 05:05:20.980326 2026] [security2:error] [pid 1017536:tid 1017780] [client 172.97.247.204:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK88CJcY4fy7tP-rU3idwAAAoY"], referer: https://www.yahoo.com/ [Sat Aug 29 05:05:21.030706 2026] [cgid:error] [pid 1018003:tid 1018103] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.035721 2026] [cgid:error] [pid 1018003:tid 1018101] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.039774 2026] [cgid:error] [pid 1018003:tid 1018106] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.042448 2026] [cgid:error] [pid 1018003:tid 1018104] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.042707 2026] [cgid:error] [pid 1018003:tid 1018066] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.045640 2026] [cgid:error] [pid 1018003:tid 1018107] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.058644 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.160.90:64679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/shiny.php"] [unique_id "apK88TAh5Y1i2tUxg4HfbAAABco"] [Sat Aug 29 05:05:21.071783 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.251.3:28416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws_auth.php"] [unique_id "apK88SJcY4fy7tP-rU3ifAAAAis"] [Sat Aug 29 05:05:21.074266 2026] [security2:error] [pid 1017536:tid 1017545] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/@fs/app/.env"] [unique_id "apK88SJcY4fy7tP-rU3ifQACHAg"] [Sat Aug 29 05:05:21.088243 2026] [security2:error] [pid 1018003:tid 1018161] [client 52.139.37.240:21433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/ws49.php"] [unique_id "apK88TAh5Y1i2tUxg4HfbQAABcI"] [Sat Aug 29 05:05:21.091575 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wp-content/db-status.php"] [unique_id "apK88SJcY4fy7tP-rU3ifwAAAnk"] [Sat Aug 29 05:05:21.091951 2026] [security2:error] [pid 1017536:tid 1017580] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/@fs/src/.env"] [unique_id "apK88SJcY4fy7tP-rU3ifgACYis"] [Sat Aug 29 05:05:21.097530 2026] [security2:error] [pid 1018003:tid 1018218] [client 185.104.184.230:45838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK88TAh5Y1i2tUxg4HfbgAABfs"] [Sat Aug 29 05:05:21.098354 2026] [security2:error] [pid 1017536:tid 1017711] [client 4.205.62.107:22838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/124.php"] [unique_id "apK88SJcY4fy7tP-rU3igAAAAkE"] [Sat Aug 29 05:05:21.104849 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.196.209.81:4488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/contentloader1.php"] [unique_id "apK88TAh5Y1i2tUxg4HfbwAABjY"] [Sat Aug 29 05:05:21.118035 2026] [security2:error] [pid 1017536:tid 1017728] [client 4.232.148.111:19610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "apK88SJcY4fy7tP-rU3ihgAAAlI"] [Sat Aug 29 05:05:21.121095 2026] [security2:error] [pid 1018003:tid 1018277] [client 168.107.94.195:57148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK88TAh5Y1i2tUxg4HfcAAABjU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:21.125326 2026] [security2:error] [pid 1017536:tid 1017608] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env"] [unique_id "apK88SJcY4fy7tP-rU3ihwACcEc"] [Sat Aug 29 05:05:21.134471 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.63.81.20:26310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/m.php"] [unique_id "apK88SJcY4fy7tP-rU3iigAAAnM"] [Sat Aug 29 05:05:21.143118 2026] [security2:error] [pid 1018003:tid 1018255] [client 52.139.37.240:58604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK88TAh5Y1i2tUxg4HfcQAABh8"] [Sat Aug 29 05:05:21.166862 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.63.219.114:2046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/csv.php"] [unique_id "apK88TAh5Y1i2tUxg4HfcgAABfo"] [Sat Aug 29 05:05:21.173290 2026] [security2:error] [pid 1018003:tid 1018093] [remote 104.196.115.188:49526] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "infinitidealership.com"] [uri "/_image"] [unique_id "apK88TAh5Y1i2tUxg4HfdgAGAkg"] [Sat Aug 29 05:05:21.173405 2026] [security2:error] [pid 1018003:tid 1018105] [remote 104.196.115.188:49526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:href. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:href"] [severity "CRITICAL"] [hostname "infinitidealership.com"] [uri "/_image"] [unique_id "apK88TAh5Y1i2tUxg4HfdAAGAlQ"] [Sat Aug 29 05:05:21.203891 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.48.160.90:63601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/goods.php"] [unique_id "apK88SJcY4fy7tP-rU3ikQAAAh0"] [Sat Aug 29 05:05:21.206602 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.48.251.3:57805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/hiquido.com/index.php"] [unique_id "apK88SJcY4fy7tP-rU3ikgAAAjI"] [Sat Aug 29 05:05:21.217475 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.63.219.114:11911] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "compropolis.mx"] [uri "/1.php7"] [unique_id "apK88TAh5Y1i2tUxg4HfegAABi0"] [Sat Aug 29 05:05:21.217589 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.63.219.114:11911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/1.php7"] [unique_id "apK88TAh5Y1i2tUxg4HfegAABi0"] [Sat Aug 29 05:05:21.235150 2026] [security2:error] [pid 1018003:tid 1018227] [client 216.26.254.241:10961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.254.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK88TAh5Y1i2tUxg4HfeQAABgQ"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:21.237806 2026] [security2:error] [pid 1017536:tid 1017766] [client 20.63.219.114:1530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/blog.php"] [unique_id "apK88SJcY4fy7tP-rU3ilQAAAng"] [Sat Aug 29 05:05:21.279869 2026] [security2:error] [pid 1017536:tid 1017739] [client 68.155.159.216:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK88SJcY4fy7tP-rU3imwAAAl0"] [Sat Aug 29 05:05:21.280919 2026] [security2:error] [pid 1017536:tid 1017745] [client 52.139.37.240:21419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/xxx.php"] [unique_id "apK88SJcY4fy7tP-rU3inAAAAmM"] [Sat Aug 29 05:05:21.281192 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.63.81.20:26501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/33.php"] [unique_id "apK88SJcY4fy7tP-rU3inQAAAiE"] [Sat Aug 29 05:05:21.287753 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.158.54.35:26037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content.php"] [unique_id "apK88SJcY4fy7tP-rU3inwAAApM"] [Sat Aug 29 05:05:21.335663 2026] [security2:error] [pid 1017536:tid 1017771] [client 68.155.159.216:12189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/content.php"] [unique_id "apK88SJcY4fy7tP-rU3ioQAAAn0"] [Sat Aug 29 05:05:21.336872 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.251.3:57796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ws79.php"] [unique_id "apK88SJcY4fy7tP-rU3iogAAAls"] [Sat Aug 29 05:05:21.342482 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.196.209.81:17622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-configs.php"] [unique_id "apK88SJcY4fy7tP-rU3iowAAAk8"] [Sat Aug 29 05:05:21.371300 2026] [security2:error] [pid 1018003:tid 1018197] [client 4.232.148.111:21051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-cron.php"] [unique_id "apK88TAh5Y1i2tUxg4HfewAABeY"] [Sat Aug 29 05:05:21.402902 2026] [security2:error] [pid 1017536:tid 1017720] [client 185.104.184.230:45848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK88SJcY4fy7tP-rU3ipQAAAko"] [Sat Aug 29 05:05:21.407085 2026] [security2:error] [pid 1018003:tid 1018213] [client 45.154.98.191:53325] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.acovib.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK88TAh5Y1i2tUxg4HffQAABfY"] [Sat Aug 29 05:05:21.419385 2026] [security2:error] [pid 1017536:tid 1017778] [client 74.248.24.12:33214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/p.php"] [unique_id "apK88SJcY4fy7tP-rU3ipgAAAoQ"] [Sat Aug 29 05:05:21.423316 2026] [security2:error] [pid 1017536:tid 1017705] [client 52.139.37.240:58591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/z.php"] [unique_id "apK88SJcY4fy7tP-rU3ipwAAAjs"] [Sat Aug 29 05:05:21.425009 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.196.209.81:15124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/gecko-new.php"] [unique_id "apK88SJcY4fy7tP-rU3iqAAAAo4"] [Sat Aug 29 05:05:21.427858 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.63.81.20:26439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/packed.php"] [unique_id "apK88SJcY4fy7tP-rU3iqQAAAjE"] [Sat Aug 29 05:05:21.443294 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.48.160.90:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/000.php/index.php"] [unique_id "apK88SJcY4fy7tP-rU3iqgAAAms"] [Sat Aug 29 05:05:21.450665 2026] [security2:error] [pid 1018003:tid 1018244] [client 74.248.24.12:4064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-cron.php"] [unique_id "apK88TAh5Y1i2tUxg4HffgAABhQ"] [Sat Aug 29 05:05:21.470717 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.48.251.3:57795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/public/wp-blog.php"] [unique_id "apK88TAh5Y1i2tUxg4HffwAABfA"] [Sat Aug 29 05:05:21.478167 2026] [security2:error] [pid 1017536:tid 1017690] [client 111.235.68.106:16775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK88SJcY4fy7tP-rU3irAAAAiw"] [Sat Aug 29 05:05:21.478329 2026] [security2:error] [pid 1017536:tid 1017690] [client 111.235.68.106:16775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK88SJcY4fy7tP-rU3irAAAAiw"] [Sat Aug 29 05:05:21.492933 2026] [security2:error] [pid 1017536:tid 1017751] [client 52.139.37.240:21413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/0x.php"] [unique_id "apK88SJcY4fy7tP-rU3irQAAAmk"] [Sat Aug 29 05:05:21.502010 2026] [security2:error] [pid 1017536:tid 1017729] [client 168.107.94.195:57480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK88SJcY4fy7tP-rU3irgAAAlM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:21.502438 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.196.209.81:21077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/al.php"] [unique_id "apK88SJcY4fy7tP-rU3irwAAAos"] [Sat Aug 29 05:05:21.504510 2026] [security2:error] [pid 1018003:tid 1018274] [client 158.23.147.79:24518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/sad/about.php"] [unique_id "apK88TAh5Y1i2tUxg4HfgAAABjI"] [Sat Aug 29 05:05:21.508516 2026] [security2:error] [pid 1017536:tid 1017555] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env"] [unique_id "apK88SJcY4fy7tP-rU3isAACcBI"] [Sat Aug 29 05:05:21.533188 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.63.219.114:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/fox.php"] [unique_id "apK88SJcY4fy7tP-rU3isgAAAmE"] [Sat Aug 29 05:05:21.539859 2026] [security2:error] [pid 1017536:tid 1017694] [client 158.23.147.79:30635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/file88.php"] [unique_id "apK88SJcY4fy7tP-rU3itAAAAjA"] [Sat Aug 29 05:05:21.577202 2026] [security2:error] [pid 1017536:tid 1017713] [client 68.155.159.216:16201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK88SJcY4fy7tP-rU3iuAAAAkM"] [Sat Aug 29 05:05:21.594668 2026] [cgid:error] [pid 1018003:tid 1018114] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.594777 2026] [cgid:error] [pid 1018003:tid 1018113] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.598538 2026] [security2:error] [pid 1017536:tid 1017678] [client 4.232.148.111:23787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/assets/images/doc.php"] [unique_id "apK88SJcY4fy7tP-rU3iyAAAAiA"] [Sat Aug 29 05:05:21.599114 2026] [cgid:error] [pid 1018003:tid 1018116] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.601238 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.48.160.90:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/Jcrop.php"] [unique_id "apK88SJcY4fy7tP-rU3iyQAAAnY"] [Sat Aug 29 05:05:21.602060 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.63.219.114:19410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/ds.php"] [unique_id "apK88SJcY4fy7tP-rU3iygAAAj4"] [Sat Aug 29 05:05:21.604514 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.251.3:57799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/php-details.php"] [unique_id "apK88SJcY4fy7tP-rU3iywAAAmo"] [Sat Aug 29 05:05:21.606336 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.63.219.114:9168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/bypass.php"] [unique_id "apK88SJcY4fy7tP-rU3izAAAAl8"] [Sat Aug 29 05:05:21.613562 2026] [cgid:error] [pid 1018003:tid 1018117] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.615204 2026] [cgid:error] [pid 1018003:tid 1018118] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.616334 2026] [cgid:error] [pid 1018003:tid 1018121] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.616686 2026] [security2:error] [pid 1018003:tid 1018193] [client 52.139.37.240:25051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/f35.php"] [unique_id "apK88TAh5Y1i2tUxg4HfkQAABeI"] [Sat Aug 29 05:05:21.623401 2026] [security2:error] [pid 1017536:tid 1017784] [client 4.205.62.107:65009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/nw.php"] [unique_id "apK88SJcY4fy7tP-rU3izgAAAoo"] [Sat Aug 29 05:05:21.660154 2026] [security2:error] [pid 1018003:tid 1018211] [client 68.155.159.216:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK88TAh5Y1i2tUxg4HfkwAABfQ"] [Sat Aug 29 05:05:21.671588 2026] [autoindex:error] [pid 1018003:tid 1018257] [client 195.178.110.103:14936] AH01276: Cannot serve directory /home3/jiazbwmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:21.686695 2026] [security2:error] [pid 1017536:tid 1017645] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apK88SJcY4fy7tP-rU3i0wACc2w"] [Sat Aug 29 05:05:21.687738 2026] [security2:error] [pid 1017536:tid 1017707] [client 52.139.37.240:21431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/CDX1.php"] [unique_id "apK88SJcY4fy7tP-rU3i1AAAAj0"] [Sat Aug 29 05:05:21.693579 2026] [security2:error] [pid 1017536:tid 1017666] [client 4.205.62.107:21882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/public/mah.php.php"] [unique_id "apK88SJcY4fy7tP-rU3i1QAAAhQ"] [Sat Aug 29 05:05:21.707968 2026] [security2:error] [pid 1017536:tid 1017696] [client 185.104.184.230:45856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK88SJcY4fy7tP-rU3i1gAAAjI"] [Sat Aug 29 05:05:21.738713 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:57889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/routes.php"] [unique_id "apK88SJcY4fy7tP-rU3i1wAAAjw"] [Sat Aug 29 05:05:21.738713 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.196.209.81:17602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-conflg.php"] [unique_id "apK88TAh5Y1i2tUxg4HflQAABcc"] [Sat Aug 29 05:05:21.740915 2026] [security2:error] [pid 1018003:tid 1018208] [client 158.158.54.35:22270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "apK88TAh5Y1i2tUxg4HflgAABfE"] [Sat Aug 29 05:05:21.742795 2026] [security2:error] [pid 1018003:tid 1018191] [client 158.23.147.79:25476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK88TAh5Y1i2tUxg4HflwAABeA"] [Sat Aug 29 05:05:21.766076 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.48.160.90:64680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apK88TAh5Y1i2tUxg4HfmAAABg8"] [Sat Aug 29 05:05:21.773289 2026] [security2:error] [pid 1017536:tid 1017554] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/static/app/.env"] [unique_id "apK88SJcY4fy7tP-rU3i2AACFRE"] [Sat Aug 29 05:05:21.773297 2026] [security2:error] [pid 1017536:tid 1017656] [remote 35.243.213.218:46954] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.mikeycunningham.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK88SJcY4fy7tP-rU3i2gACFXc"] [Sat Aug 29 05:05:21.773638 2026] [security2:error] [pid 1017536:tid 1017620] [remote 35.243.213.218:46954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/static/.env"] [unique_id "apK88SJcY4fy7tP-rU3i2QACFVM"] [Sat Aug 29 05:05:21.780731 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK88TAh5Y1i2tUxg4HfmQAABb4"] [Sat Aug 29 05:05:21.809596 2026] [security2:error] [pid 1018003:tid 1018167] [client 52.139.37.240:58566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/file61.php"] [unique_id "apK88TAh5Y1i2tUxg4HfnQAABcg"] [Sat Aug 29 05:05:21.837119 2026] [security2:error] [pid 1018003:tid 1018185] [client 195.178.110.103:14936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jia.zbw.mybluehost.me"] [uri "/livewire/update"] [unique_id "apK88TAh5Y1i2tUxg4HfnwAABdo"] [Sat Aug 29 05:05:21.841081 2026] [security2:error] [pid 1017536:tid 1017685] [client 145.239.10.137:33334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenfieldstone.com"] [uri "/admin.php"] [unique_id "apK88SJcY4fy7tP-rU3i4AAAAic"], referer: http://greenfieldstone.com/admin.php [Sat Aug 29 05:05:21.849744 2026] [cgid:error] [pid 1018003:tid 1018068] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.851761 2026] [cgid:error] [pid 1018003:tid 1018119] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.854316 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.196.209.81:15116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/wp-admin.php"] [unique_id "apK88SJcY4fy7tP-rU3i5AAAAh0"] [Sat Aug 29 05:05:21.859909 2026] [security2:error] [pid 1018003:tid 1018178] [client 68.155.159.216:50315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/login.php"] [unique_id "apK88TAh5Y1i2tUxg4HfowAABdM"] [Sat Aug 29 05:05:21.860805 2026] [security2:error] [pid 1017536:tid 1017720] [client 4.205.62.107:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/ok.php"] [unique_id "apK88SJcY4fy7tP-rU3i5gAAAko"] [Sat Aug 29 05:05:21.864204 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.23.147.79:48361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK88TAh5Y1i2tUxg4HfpAAABdw"] [Sat Aug 29 05:05:21.869639 2026] [cgid:error] [pid 1018003:tid 1018115] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.872873 2026] [cgid:error] [pid 1018003:tid 1018122] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.873497 2026] [security2:error] [pid 1017536:tid 1017782] [client 4.232.148.111:24801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-block.php"] [unique_id "apK88SJcY4fy7tP-rU3i6AAAAog"] [Sat Aug 29 05:05:21.881015 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.251.3:57856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aww.php"] [unique_id "apK88SJcY4fy7tP-rU3i6QAAAo4"] [Sat Aug 29 05:05:21.882838 2026] [security2:error] [pid 1017536:tid 1017725] [client 52.139.37.240:20774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/akcc.php"] [unique_id "apK88SJcY4fy7tP-rU3i6wAAAk8"] [Sat Aug 29 05:05:21.884787 2026] [security2:error] [pid 1018003:tid 1018258] [client 168.107.94.195:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK88TAh5Y1i2tUxg4HfqAAABiI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:21.923841 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.63.219.114:18958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/disagraeosc.php"] [unique_id "apK88SJcY4fy7tP-rU3i7gAAAkU"] [Sat Aug 29 05:05:21.924520 2026] [security2:error] [pid 1018003:tid 1018180] [client 65.111.26.173:27205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK88TAh5Y1i2tUxg4HfogAABdU"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:21.943601 2026] [cgid:error] [pid 1018003:tid 1018111] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:21.961279 2026] [security2:error] [pid 1018003:tid 1018219] [client 74.248.24.12:26132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-block.php"] [unique_id "apK88TAh5Y1i2tUxg4HfrwAABfw"] [Sat Aug 29 05:05:21.961854 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.63.81.20:26449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/w.php"] [unique_id "apK88TAh5Y1i2tUxg4HfsAAABc0"] [Sat Aug 29 05:05:21.964024 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.63.219.114:18696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/extractable-loader-head.php"] [unique_id "apK88TAh5Y1i2tUxg4HfsQAABd8"] [Sat Aug 29 05:05:21.964286 2026] [security2:error] [pid 1018003:tid 1018219] [client 4.205.62.107:2121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/wp-content/plugin-install.php"] [unique_id "apK88TAh5Y1i2tUxg4HfsgAABfw"] [Sat Aug 29 05:05:21.975252 2026] [security2:error] [pid 1018003:tid 1018199] [client 158.23.147.79:63846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK88TAh5Y1i2tUxg4HftAAABeg"] [Sat Aug 29 05:05:21.976674 2026] [security2:error] [pid 1018003:tid 1018198] [client 68.155.159.216:33708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK88TAh5Y1i2tUxg4HftQAABec"] [Sat Aug 29 05:05:21.979067 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.196.209.81:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/global.php"] [unique_id "apK88SJcY4fy7tP-rU3i9AAAAnI"] [Sat Aug 29 05:05:21.990946 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.63.219.114:19439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/GOD.php"] [unique_id "apK88SJcY4fy7tP-rU3i9gAAAoQ"] [Sat Aug 29 05:05:22.016046 2026] [security2:error] [pid 1017536:tid 1017694] [client 185.104.184.230:45858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK88iJcY4fy7tP-rU3i-gAAAjA"] [Sat Aug 29 05:05:22.016182 2026] [security2:error] [pid 1017536:tid 1017785] [client 52.139.37.240:25025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/mah.php"] [unique_id "apK88iJcY4fy7tP-rU3i-wAAAos"] [Sat Aug 29 05:05:22.016402 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.48.160.90:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/btx25.php"] [unique_id "apK88jAh5Y1i2tUxg4HfuQAABfc"] [Sat Aug 29 05:05:22.017223 2026] [security2:error] [pid 1017536:tid 1017609] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.elisefairweather.com"] [uri "/wp-config.php.bak"] [unique_id "apK88iJcY4fy7tP-rU3i_AACS0g"] [Sat Aug 29 05:05:22.017655 2026] [security2:error] [pid 1017536:tid 1017609] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.elisefairweather.com"] [uri "/wp-config.php.new"] [unique_id "apK88iJcY4fy7tP-rU3i_QACS0g"] [Sat Aug 29 05:05:22.018017 2026] [security2:error] [pid 1017536:tid 1017609] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.elisefairweather.com"] [uri "/wp-config.php.old"] [unique_id "apK88iJcY4fy7tP-rU3i_gACS0g"] [Sat Aug 29 05:05:22.020807 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.251.3:28441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/maxro.php"] [unique_id "apK88iJcY4fy7tP-rU3jAgAAAkM"] [Sat Aug 29 05:05:22.036901 2026] [security2:error] [pid 1017536:tid 1017635] [remote 93.123.109.228:48278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/wp-config.php"] [unique_id "apK88iJcY4fy7tP-rU3jAwACS2I"] [Sat Aug 29 05:05:22.044642 2026] [cgid:error] [pid 1018003:tid 1018069] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.046614 2026] [cgid:error] [pid 1018003:tid 1018123] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.068712 2026] [cgid:error] [pid 1018003:tid 1018120] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.075817 2026] [cgid:error] [pid 1018003:tid 1018126] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.082635 2026] [security2:error] [pid 1018003:tid 1018182] [client 4.232.148.111:32347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/bgymj.php"] [unique_id "apK88jAh5Y1i2tUxg4HfwQAABdc"] [Sat Aug 29 05:05:22.083721 2026] [cgid:error] [pid 1018003:tid 1018127] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.084227 2026] [security2:error] [pid 1017536:tid 1017754] [client 52.139.37.240:20745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK88iJcY4fy7tP-rU3jBQAAAmw"] [Sat Aug 29 05:05:22.110327 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.63.81.20:26551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/ccc.php"] [unique_id "apK88iJcY4fy7tP-rU3jCAAAAoo"] [Sat Aug 29 05:05:22.145988 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.196.209.81:17607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content.php"] [unique_id "apK88iJcY4fy7tP-rU3jCQAAAi8"] [Sat Aug 29 05:05:22.152064 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.160.90:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/radio.php"] [unique_id "apK88iJcY4fy7tP-rU3jCgAAAjo"] [Sat Aug 29 05:05:22.156197 2026] [security2:error] [pid 1018003:tid 1018223] [client 93.123.109.228:37254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK88jAh5Y1i2tUxg4HfwgAABgA"] [Sat Aug 29 05:05:22.162248 2026] [security2:error] [pid 1018003:tid 1018193] [client 93.123.109.228:37252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK88jAh5Y1i2tUxg4HfwwAABeI"] [Sat Aug 29 05:05:22.171446 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.48.251.3:57810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/brc.php"] [unique_id "apK88jAh5Y1i2tUxg4HfxQAABiE"] [Sat Aug 29 05:05:22.189518 2026] [security2:error] [pid 1018003:tid 1018227] [client 158.158.54.35:23960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/css/wp-login.php"] [unique_id "apK88jAh5Y1i2tUxg4HfxgAABgQ"] [Sat Aug 29 05:05:22.213095 2026] [security2:error] [pid 1017536:tid 1017781] [client 52.139.37.240:24700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/mini.php"] [unique_id "apK88iJcY4fy7tP-rU3jDAAAAoc"] [Sat Aug 29 05:05:22.216813 2026] [security2:error] [pid 1018003:tid 1018235] [client 74.248.24.12:41938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/a1.php"] [unique_id "apK88jAh5Y1i2tUxg4HfyAAABgs"] [Sat Aug 29 05:05:22.223967 2026] [autoindex:error] [pid 1018003:tid 1018206] [client 195.178.110.103:14942] AH01276: Cannot serve directory /home3/jiazbwmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:22.247033 2026] [security2:error] [pid 1017536:tid 1017685] [client 4.205.62.107:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/file59.php"] [unique_id "apK88iJcY4fy7tP-rU3jDQAAAic"] [Sat Aug 29 05:05:22.252504 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.63.81.20:26483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/file15.php"] [unique_id "apK88iJcY4fy7tP-rU3jDgAAAoU"] [Sat Aug 29 05:05:22.266084 2026] [security2:error] [pid 1017536:tid 1017782] [client 168.107.94.195:58205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK88iJcY4fy7tP-rU3jGAAAAog"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:22.267063 2026] [security2:error] [pid 1017536:tid 1017707] [client 34.7.216.49:15344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/env.json"] [unique_id "apK88iJcY4fy7tP-rU3jGQAAAj0"] [Sat Aug 29 05:05:22.280203 2026] [security2:error] [pid 1017536:tid 1017742] [client 52.139.37.240:21409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/s.php"] [unique_id "apK88iJcY4fy7tP-rU3jJwAAAmA"] [Sat Aug 29 05:05:22.287955 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.196.209.81:25078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/wp-configs.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf0AAABiM"] [Sat Aug 29 05:05:22.293551 2026] [cgid:error] [pid 1018003:tid 1018125] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.302938 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.48.251.3:57806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/vx.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf0wAABb4"] [Sat Aug 29 05:05:22.308910 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.48.160.90:63547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/dex.php"] [unique_id "apK88iJcY4fy7tP-rU3jLQAAAiw"] [Sat Aug 29 05:05:22.313961 2026] [security2:error] [pid 1017536:tid 1017715] [client 185.104.184.230:45866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK88iJcY4fy7tP-rU3jLgAAAkU"] [Sat Aug 29 05:05:22.325753 2026] [security2:error] [pid 1017536:tid 1017726] [client 4.205.62.107:57847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/test1.php"] [unique_id "apK88iJcY4fy7tP-rU3jLwAAAlA"] [Sat Aug 29 05:05:22.344695 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.63.219.114:1531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/about.php525"] [unique_id "apK88iJcY4fy7tP-rU3jMQAAAls"] [Sat Aug 29 05:05:22.353565 2026] [security2:error] [pid 1017536:tid 1017683] [client 213.202.253.4:58571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/memberfuns.php"] [unique_id "apK88iJcY4fy7tP-rU3jMgAAAiU"], referer: www.google.com [Sat Aug 29 05:05:22.362342 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.219.114:15277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/ggfi.php"] [unique_id "apK88iJcY4fy7tP-rU3jMwAAAlY"] [Sat Aug 29 05:05:22.369282 2026] [security2:error] [pid 1018003:tid 1018224] [client 93.123.109.228:37254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK88jAh5Y1i2tUxg4Hf1wAABgE"] [Sat Aug 29 05:05:22.405590 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.196.209.81:21056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/update.php"] [unique_id "apK88iJcY4fy7tP-rU3jNAAAAkY"] [Sat Aug 29 05:05:22.422652 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.63.81.20:26454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/jp.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf2wAABbw"] [Sat Aug 29 05:05:22.422964 2026] [security2:error] [pid 1018003:tid 1018184] [client 52.139.37.240:25071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/v.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf3AAABdk"] [Sat Aug 29 05:05:22.434310 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.48.251.3:28455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ty.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf3QAABhI"] [Sat Aug 29 05:05:22.438413 2026] [security2:error] [pid 1018003:tid 1018166] [client 4.232.148.111:12466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf3wAABcc"] [Sat Aug 29 05:05:22.438750 2026] [security2:error] [pid 1018003:tid 1018258] [client 68.155.159.216:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf4QAABiI"] [Sat Aug 29 05:05:22.443311 2026] [security2:error] [pid 1017536:tid 1017687] [client 93.123.109.228:37302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK88iJcY4fy7tP-rU3jNQAAAik"] [Sat Aug 29 05:05:22.452317 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.160.90:62617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/giodywky.php"] [unique_id "apK88iJcY4fy7tP-rU3jOQAAAho"] [Sat Aug 29 05:05:22.452679 2026] [security2:error] [pid 1017536:tid 1017719] [client 93.123.109.228:37338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK88iJcY4fy7tP-rU3jOAAAAkk"] [Sat Aug 29 05:05:22.465598 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.63.219.114:1780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/defaults.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf4gAABcA"] [Sat Aug 29 05:05:22.474110 2026] [cgid:error] [pid 1018003:tid 1018130] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.474465 2026] [cgid:error] [pid 1018003:tid 1018128] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.474801 2026] [security2:error] [pid 1018003:tid 1018165] [client 74.248.24.12:16526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf5gAABcY"] [Sat Aug 29 05:05:22.475149 2026] [cgid:error] [pid 1018003:tid 1018132] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.476098 2026] [security2:error] [pid 1018003:tid 1018240] [client 52.139.37.240:21383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/sagax.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf5wAABhA"] [Sat Aug 29 05:05:22.491202 2026] [cgid:error] [pid 1018003:tid 1018133] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.495935 2026] [cgid:error] [pid 1018003:tid 1018129] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.504675 2026] [cgid:error] [pid 1018003:tid 1018138] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.529173 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:24569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf7AAABd8"] [Sat Aug 29 05:05:22.568424 2026] [security2:error] [pid 1017536:tid 1017680] [client 93.123.109.228:37236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK88iJcY4fy7tP-rU3jPQAAAiI"] [Sat Aug 29 05:05:22.571604 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.251.3:57895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/adminer-4.7.6-en.php"] [unique_id "apK88iJcY4fy7tP-rU3jPgAAAkI"] [Sat Aug 29 05:05:22.575806 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.63.81.20:26383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/f35.php"] [unique_id "apK88iJcY4fy7tP-rU3jQAAAAn0"] [Sat Aug 29 05:05:22.575841 2026] [security2:error] [pid 1017536:tid 1017709] [client 4.232.148.111:24115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK88iJcY4fy7tP-rU3jPwAAAj8"] [Sat Aug 29 05:05:22.575854 2026] [cgid:error] [pid 1018003:tid 1018246] [client 20.196.209.81:17924] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/carolinashooter/404.shtml [Sat Aug 29 05:05:22.580556 2026] [security2:error] [pid 1018003:tid 1018185] [client 65.111.24.216:54843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf7QAABdo"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:22.617680 2026] [security2:error] [pid 1018003:tid 1018214] [client 158.23.147.79:24486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/admin.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf8QAABfc"] [Sat Aug 29 05:05:22.621077 2026] [security2:error] [pid 1018003:tid 1018169] [client 52.139.37.240:24598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf8gAABco"] [Sat Aug 29 05:05:22.624763 2026] [security2:error] [pid 1018003:tid 1018234] [client 185.104.184.230:45892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK88jAh5Y1i2tUxg4Hf8wAABgo"] [Sat Aug 29 05:05:22.630327 2026] [security2:error] [pid 1017536:tid 1017688] [client 177.131.19.63:16858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.19.131.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK88iJcY4fy7tP-rU3jQgAAAio"] [Sat Aug 29 05:05:22.630594 2026] [security2:error] [pid 1017536:tid 1017688] [client 177.131.19.63:16858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK88iJcY4fy7tP-rU3jQgAAAio"] [Sat Aug 29 05:05:22.636243 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.158.54.35:19376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/images/index.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf9AAABiw"] [Sat Aug 29 05:05:22.644444 2026] [security2:error] [pid 1017536:tid 1017670] [client 158.23.147.79:30675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/NewFile.php/"] [unique_id "apK88iJcY4fy7tP-rU3jRAAAAhg"] [Sat Aug 29 05:05:22.646601 2026] [security2:error] [pid 1017536:tid 1017704] [client 168.107.94.195:58528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK88iJcY4fy7tP-rU3jRQAAAjo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:22.655723 2026] [security2:error] [pid 1018003:tid 1018269] [client 68.155.159.216:64249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/.well-knownold/index.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf9QAABi0"] [Sat Aug 29 05:05:22.655723 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.160.90:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-kz.php"] [unique_id "apK88iJcY4fy7tP-rU3jRgAAAmQ"] [Sat Aug 29 05:05:22.656139 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.49.130:57485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/dk.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf9gAABeQ"] [Sat Aug 29 05:05:22.684127 2026] [security2:error] [pid 1018003:tid 1018156] [client 68.155.159.216:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/languages/about.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf9wAABb0"] [Sat Aug 29 05:05:22.700468 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.63.219.114:2021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/spip.php"] [unique_id "apK88iJcY4fy7tP-rU3jSAAAAhs"] [Sat Aug 29 05:05:22.712908 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.196.209.81:9514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/essexec.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf-AAABjY"] [Sat Aug 29 05:05:22.714666 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.196.209.81:17924] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/1.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf-QAABgc"] [Sat Aug 29 05:05:22.714738 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.196.209.81:17924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/1.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf-QAABgc"] [Sat Aug 29 05:05:22.722265 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.63.81.20:26504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/shiny.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf-gAABhM"] [Sat Aug 29 05:05:22.728291 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.48.251.3:27172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/phpi.php"] [unique_id "apK88iJcY4fy7tP-rU3jSQAAAlw"] [Sat Aug 29 05:05:22.748313 2026] [security2:error] [pid 1017536:tid 1017745] [client 52.139.37.240:21435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-content/plugins/ftde.php"] [unique_id "apK88iJcY4fy7tP-rU3jSgAAAmM"] [Sat Aug 29 05:05:22.761589 2026] [security2:error] [pid 1018003:tid 1018171] [client 4.205.62.107:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/product.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf_QAABcw"] [Sat Aug 29 05:05:22.761804 2026] [security2:error] [pid 1018003:tid 1018251] [client 68.155.159.216:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK88jAh5Y1i2tUxg4Hf_gAABhs"] [Sat Aug 29 05:05:22.765522 2026] [cgid:error] [pid 1018003:tid 1018088] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.768034 2026] [cgid:error] [pid 1018003:tid 1018142] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.770727 2026] [cgid:error] [pid 1018003:tid 1018140] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.782761 2026] [security2:error] [pid 1018003:tid 1018154] [client 93.123.109.228:37364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK88jAh5Y1i2tUxg4HgAgAABbs"] [Sat Aug 29 05:05:22.784928 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.63.219.114:11942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/alfa-rex.php"] [unique_id "apK88iJcY4fy7tP-rU3jTAAAAmU"] [Sat Aug 29 05:05:22.790067 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.160.90:63615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apK88iJcY4fy7tP-rU3jTQAAAoc"] [Sat Aug 29 05:05:22.791503 2026] [security2:error] [pid 1017536:tid 1017756] [client 216.73.217.8:21807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo-store.sortthru.com"] [uri "/webapp/wp-admin/post.php"] [unique_id "apK88iJcY4fy7tP-rU3jTgAAAm4"] [Sat Aug 29 05:05:22.794469 2026] [cgid:error] [pid 1018003:tid 1018141] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.794513 2026] [cgid:error] [pid 1018003:tid 1018145] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.794815 2026] [cgid:error] [pid 1018003:tid 1018139] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.804759 2026] [security2:error] [pid 1017536:tid 1017734] [client 185.104.184.230:45880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK88iJcY4fy7tP-rU3jTwAAAlg"] [Sat Aug 29 05:05:22.824148 2026] [security2:error] [pid 1017536:tid 1017793] [client 52.139.37.240:24678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apK88iJcY4fy7tP-rU3jUAAAApM"] [Sat Aug 29 05:05:22.827080 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.63.219.114:11885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/post.php"] [unique_id "apK88iJcY4fy7tP-rU3jUQAAAi4"] [Sat Aug 29 05:05:22.838134 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.196.209.81:4521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/blog.php"] [unique_id "apK88iJcY4fy7tP-rU3jUgAAAl0"] [Sat Aug 29 05:05:22.838954 2026] [security2:error] [pid 1018003:tid 1018277] [client 74.248.24.12:8960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK88jAh5Y1i2tUxg4HgBgAABjU"] [Sat Aug 29 05:05:22.846885 2026] [security2:error] [pid 1018003:tid 1018173] [client 158.23.147.79:25559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK88jAh5Y1i2tUxg4HgBwAABc4"] [Sat Aug 29 05:05:22.854172 2026] [security2:error] [pid 1018003:tid 1018227] [client 4.205.62.107:22286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/linusadmin-phpinfo.php"] [unique_id "apK88jAh5Y1i2tUxg4HgCAAABgQ"] [Sat Aug 29 05:05:22.856551 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.63.81.20:26465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/images.php"] [unique_id "apK88jAh5Y1i2tUxg4HgCgAABc8"] [Sat Aug 29 05:05:22.859167 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.48.251.3:57912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK88jAh5Y1i2tUxg4HgCwAABgk"] [Sat Aug 29 05:05:22.886090 2026] [security2:error] [pid 1017536:tid 1017772] [client 178.16.55.109:51875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.55.16.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.burlingtonyaroslavl.com"] [uri "/wp-login.php"] [unique_id "apK88iJcY4fy7tP-rU3jVwAAAn4"], referer: https://www.google.com/ [Sat Aug 29 05:05:22.893829 2026] [security2:error] [pid 1017536:tid 1017765] [client 172.97.247.204:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK88iJcY4fy7tP-rU3jWQAAAnc"], referer: https://www.yahoo.com/ [Sat Aug 29 05:05:22.899122 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.147.79:54014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK88iJcY4fy7tP-rU3jWgAAAhw"] [Sat Aug 29 05:05:22.909600 2026] [security2:error] [pid 1017536:tid 1017742] [client 68.155.159.216:18363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/bk/index.php"] [unique_id "apK88iJcY4fy7tP-rU3jXAAAAmA"] [Sat Aug 29 05:05:22.913887 2026] [cgid:error] [pid 1018003:tid 1018147] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:22.930189 2026] [security2:error] [pid 1017536:tid 1017592] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env"] [unique_id "apK88iJcY4fy7tP-rU3jXQACUTc"] [Sat Aug 29 05:05:22.930954 2026] [access_compat:error] [pid 1017536:tid 1017758] [client 67.20.76.220:12806] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:22.931219 2026] [security2:error] [pid 1018003:tid 1018249] [client 4.232.148.111:24824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/m.php"] [unique_id "apK88jAh5Y1i2tUxg4HgEgAABhk"] [Sat Aug 29 05:05:22.931608 2026] [security2:error] [pid 1017536:tid 1017695] [client 185.104.184.230:45904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK88iJcY4fy7tP-rU3jXwAAAjE"] [Sat Aug 29 05:05:22.942724 2026] [access_compat:error] [pid 1018003:tid 1018215] [client 67.20.76.220:12822] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:22.952130 2026] [security2:error] [pid 1018003:tid 1018230] [client 52.139.37.240:21439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK88jAh5Y1i2tUxg4HgFgAABgY"] [Sat Aug 29 05:05:22.952788 2026] [security2:error] [pid 1017536:tid 1017698] [client 93.123.109.228:37302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK88iJcY4fy7tP-rU3jYwAAAjQ"] [Sat Aug 29 05:05:22.965571 2026] [security2:error] [pid 1017536:tid 1017777] [client 68.155.159.216:50189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/hehehehe.php"] [unique_id "apK88iJcY4fy7tP-rU3jZAAAAoM"] [Sat Aug 29 05:05:22.966413 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.147.79:23508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/worksec.php"] [unique_id "apK88iJcY4fy7tP-rU3jZQAAAls"] [Sat Aug 29 05:05:22.988100 2026] [security2:error] [pid 1018003:tid 1018257] [client 74.248.24.12:28195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/m.php"] [unique_id "apK88jAh5Y1i2tUxg4HgGAAABiE"] [Sat Aug 29 05:05:22.991347 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.48.251.3:28452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/myfile.php"] [unique_id "apK88iJcY4fy7tP-rU3jawAAAkY"] [Sat Aug 29 05:05:22.995591 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.160.90:28548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/session.php"] [unique_id "apK88jAh5Y1i2tUxg4HgGQAABfY"] [Sat Aug 29 05:05:23.010852 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.63.81.20:26441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/82.php"] [unique_id "apK88zAh5Y1i2tUxg4HgGwAABfA"] [Sat Aug 29 05:05:23.019607 2026] [security2:error] [pid 1017536:tid 1017776] [client 4.205.62.107:21875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/test.config.php"] [unique_id "apK88yJcY4fy7tP-rU3jbgAAAoI"] [Sat Aug 29 05:05:23.024772 2026] [security2:error] [pid 1017536:tid 1017684] [client 52.139.37.240:25065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK88yJcY4fy7tP-rU3jbwAAAiY"] [Sat Aug 29 05:05:23.026681 2026] [security2:error] [pid 1017536:tid 1017666] [client 168.107.94.195:58851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK88yJcY4fy7tP-rU3jcAAAAhQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:23.033266 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:48167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK88yJcY4fy7tP-rU3jcwAAAkc"] [Sat Aug 29 05:05:23.042227 2026] [security2:error] [pid 1017536:tid 1017785] [client 93.123.109.228:37352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK88yJcY4fy7tP-rU3jdAAAAos"] [Sat Aug 29 05:05:23.058322 2026] [security2:error] [pid 1017536:tid 1017786] [client 57.141.8.70:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/"] [unique_id "apK88yJcY4fy7tP-rU3jdwAAAow"] [Sat Aug 29 05:05:23.063079 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:37364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/.env.php"] [unique_id "apK88zAh5Y1i2tUxg4HgHQAABdw"] [Sat Aug 29 05:05:23.079309 2026] [security2:error] [pid 1018003:tid 1018258] [client 158.23.147.79:38782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/content.php"] [unique_id "apK88zAh5Y1i2tUxg4HgHwAABiI"] [Sat Aug 29 05:05:23.081527 2026] [core:error] [pid 1017536:tid 1017542] [remote 35.243.213.218:60034] AH10244: invalid URI path (/%2e%2e/.env) [Sat Aug 29 05:05:23.081589 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.63.219.114:9204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/backup.php"] [unique_id "apK88yJcY4fy7tP-rU3jeQAAAo0"] [Sat Aug 29 05:05:23.100450 2026] [security2:error] [pid 1018003:tid 1018159] [client 185.104.184.230:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "apK88zAh5Y1i2tUxg4HgIAAABcA"] [Sat Aug 29 05:05:23.103919 2026] [security2:error] [pid 1017536:tid 1017712] [client 4.205.62.107:2925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/paypal.php"] [unique_id "apK88yJcY4fy7tP-rU3jewAAAkI"] [Sat Aug 29 05:05:23.109649 2026] [security2:error] [pid 1018003:tid 1018165] [client 68.155.159.216:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-content/admin.php"] [unique_id "apK88zAh5Y1i2tUxg4HgIQAABcY"] [Sat Aug 29 05:05:23.111997 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.196.209.81:15796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/hello.php"] [unique_id "apK88yJcY4fy7tP-rU3jfAAAAlo"] [Sat Aug 29 05:05:23.112536 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.196.209.81:17960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/about.php"] [unique_id "apK88zAh5Y1i2tUxg4HgIgAABic"] [Sat Aug 29 05:05:23.120301 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.48.251.3:28423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/lm15.php"] [unique_id "apK88yJcY4fy7tP-rU3jfQAAAjY"] [Sat Aug 29 05:05:23.136086 2026] [security2:error] [pid 1017536:tid 1017639] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/api/.env/public/.env"] [unique_id "apK88yJcY4fy7tP-rU3jgQACOGY"] [Sat Aug 29 05:05:23.136570 2026] [security2:error] [pid 1017536:tid 1017599] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env"] [unique_id "apK88yJcY4fy7tP-rU3jhAACOD4"] [Sat Aug 29 05:05:23.136624 2026] [security2:error] [pid 1017536:tid 1017546] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/static/home/user/.env"] [unique_id "apK88yJcY4fy7tP-rU3jhgACOAk"] [Sat Aug 29 05:05:23.136690 2026] [security2:error] [pid 1017536:tid 1017613] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/.env"] [unique_id "apK88yJcY4fy7tP-rU3jhQACOEw"] [Sat Aug 29 05:05:23.138765 2026] [security2:error] [pid 1017536:tid 1017789] [client 35.198.240.194:3870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/home/ubuntu/.env"] [unique_id "apK88yJcY4fy7tP-rU3jiAAAAo8"] [Sat Aug 29 05:05:23.141016 2026] [security2:error] [pid 1017536:tid 1017760] [client 216.26.227.93:25047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.227.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK88yJcY4fy7tP-rU3jfgAAAnI"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:23.158933 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.48.160.90:62607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/eagle.php"] [unique_id "apK88zAh5Y1i2tUxg4HgJQAABdU"] [Sat Aug 29 05:05:23.167956 2026] [security2:error] [pid 1018003:tid 1018203] [client 35.198.240.194:3896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/var/www/.env"] [unique_id "apK88zAh5Y1i2tUxg4HgJgAABew"] [Sat Aug 29 05:05:23.168576 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.63.81.20:26559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/files.php/new.php"] [unique_id "apK88yJcY4fy7tP-rU3jiwAAAjs"] [Sat Aug 29 05:05:23.169469 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.49.130:48529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/sta.php"] [unique_id "apK88zAh5Y1i2tUxg4HgJwAABeE"] [Sat Aug 29 05:05:23.181998 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.63.219.114:1412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/csv.php"] [unique_id "apK88yJcY4fy7tP-rU3jjgAAAks"] [Sat Aug 29 05:05:23.183569 2026] [security2:error] [pid 1017536:tid 1017667] [client 35.198.240.194:3912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/var/www/html/.env"] [unique_id "apK88yJcY4fy7tP-rU3jjwAAAhU"] [Sat Aug 29 05:05:23.184642 2026] [security2:error] [pid 1018003:tid 1018273] [client 35.198.240.194:3928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/usr/src/app/.env"] [unique_id "apK88zAh5Y1i2tUxg4HgKAAABjE"] [Sat Aug 29 05:05:23.198643 2026] [cgid:error] [pid 1018003:tid 1018146] [remote 104.196.51.122:56274] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home4/tdessixf/public_html/bigbuttonscarf/404.shtml [Sat Aug 29 05:05:23.215409 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.63.219.114:12714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/cookie.php"] [unique_id "apK88yJcY4fy7tP-rU3jkAAAAoE"] [Sat Aug 29 05:05:23.222557 2026] [security2:error] [pid 1017536:tid 1017671] [client 158.158.54.35:26027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/inputs.php"] [unique_id "apK88yJcY4fy7tP-rU3jkQAAAhk"] [Sat Aug 29 05:05:23.224093 2026] [security2:error] [pid 1017536:tid 1017685] [client 52.139.37.240:21400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/z.php"] [unique_id "apK88yJcY4fy7tP-rU3jkwAAAic"] [Sat Aug 29 05:05:23.235896 2026] [security2:error] [pid 1018003:tid 1018219] [client 185.104.184.230:45928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK88zAh5Y1i2tUxg4HgLAAABfw"] [Sat Aug 29 05:05:23.249483 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.251.3:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/test.config.php"] [unique_id "apK88yJcY4fy7tP-rU3jlAAAAj0"] [Sat Aug 29 05:05:23.263256 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.196.209.81:21094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/bypass.php"] [unique_id "apK88yJcY4fy7tP-rU3jlQAAAio"] [Sat Aug 29 05:05:23.271746 2026] [security2:error] [pid 1017536:tid 1017727] [client 35.198.240.194:3978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.omni-staffing.com"] [uri "/@fs/app/aws-exports.js"] [unique_id "apK88yJcY4fy7tP-rU3jlgAAAlE"] [Sat Aug 29 05:05:23.292856 2026] [security2:error] [pid 1018003:tid 1018234] [client 52.139.37.240:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/wp-index.php"] [unique_id "apK88zAh5Y1i2tUxg4HgMwAABgo"] [Sat Aug 29 05:05:23.299553 2026] [security2:error] [pid 1017536:tid 1017726] [client 93.123.109.228:37264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK88yJcY4fy7tP-rU3jmQAAAlA"] [Sat Aug 29 05:05:23.325422 2026] [security2:error] [pid 1018003:tid 1018195] [client 114.119.148.47:42899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_info.php/products_id/1110/action/notify/osCsid/7thp4iock98fr1qadncejc87b5"] [unique_id "apK88zAh5Y1i2tUxg4HgNAAABeQ"], referer: http://www.classiclightingusa.com/catalog/product_info.php/products_id/1110/osCsid/7thp4iock98fr1qadncejc87b5 [Sat Aug 29 05:05:23.333973 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.81.20:26444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/mghnhykio.php/new.php"] [unique_id "apK88yJcY4fy7tP-rU3jnQAAAlY"] [Sat Aug 29 05:05:23.348840 2026] [security2:error] [pid 1017536:tid 1017572] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/images../.env"] [unique_id "apK88yJcY4fy7tP-rU3jngACVSM"] [Sat Aug 29 05:05:23.349639 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.160.90:64647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/up-kon.php"] [unique_id "apK88yJcY4fy7tP-rU3jnwAAAiU"] [Sat Aug 29 05:05:23.354327 2026] [security2:error] [pid 1017536:tid 1017781] [client 74.248.24.12:5307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/alfa-rex.php7"] [unique_id "apK88yJcY4fy7tP-rU3jowAAAoc"] [Sat Aug 29 05:05:23.361065 2026] [security2:error] [pid 1017536:tid 1017758] [client 93.123.109.228:37338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK88yJcY4fy7tP-rU3jpgAAAnA"] [Sat Aug 29 05:05:23.379594 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:57830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/gecko-litespeed.php"] [unique_id "apK88yJcY4fy7tP-rU3jpwAAAjw"] [Sat Aug 29 05:05:23.401182 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.49.130:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/222.php"] [unique_id "apK88zAh5Y1i2tUxg4HgNwAABhQ"] [Sat Aug 29 05:05:23.407871 2026] [security2:error] [pid 1017536:tid 1017723] [client 168.107.94.195:59138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK88yJcY4fy7tP-rU3jqQAAAk0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:23.419397 2026] [security2:error] [pid 1018003:tid 1018264] [client 52.139.37.240:20751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/f35.php"] [unique_id "apK88zAh5Y1i2tUxg4HgOAAABig"] [Sat Aug 29 05:05:23.422485 2026] [security2:error] [pid 1017536:tid 1017666] [client 68.155.159.216:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK88yJcY4fy7tP-rU3jrAAAAhQ"] [Sat Aug 29 05:05:23.435576 2026] [security2:error] [pid 1017536:tid 1017710] [client 4.232.148.111:32371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-load.php"] [unique_id "apK88yJcY4fy7tP-rU3jrQAAAkA"] [Sat Aug 29 05:05:23.441940 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.63.219.114:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/haiterus.php"] [unique_id "apK88zAh5Y1i2tUxg4HgPAAABi0"] [Sat Aug 29 05:05:23.480060 2026] [security2:error] [pid 1017536:tid 1017695] [client 4.232.148.111:10321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "apK88yJcY4fy7tP-rU3jrwAAAjE"] [Sat Aug 29 05:05:23.481590 2026] [security2:error] [pid 1017536:tid 1017662] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/assets../.env"] [unique_id "apK88yJcY4fy7tP-rU3jsgACQ30"] [Sat Aug 29 05:05:23.486713 2026] [security2:error] [pid 1017536:tid 1017774] [client 20.48.160.90:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/tinny.php"] [unique_id "apK88yJcY4fy7tP-rU3jswAAAoA"] [Sat Aug 29 05:05:23.489422 2026] [security2:error] [pid 1018003:tid 1018171] [client 52.139.37.240:25083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/ww2.php"] [unique_id "apK88zAh5Y1i2tUxg4HgPgAABcw"] [Sat Aug 29 05:05:23.490930 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.63.81.20:26509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/admin.php/nope.php"] [unique_id "apK88yJcY4fy7tP-rU3jtAAAAow"] [Sat Aug 29 05:05:23.496529 2026] [security2:error] [pid 1017536:tid 1017602] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/img../.env"] [unique_id "apK88yJcY4fy7tP-rU3jtwACQ0E"] [Sat Aug 29 05:05:23.496646 2026] [security2:error] [pid 1017536:tid 1017587] [remote 35.243.213.218:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mikeycunningham.com"] [uri "/uploads../.env"] [unique_id "apK88yJcY4fy7tP-rU3juAACQzI"] [Sat Aug 29 05:05:23.507756 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.196.209.81:12355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/admin-header.php"] [unique_id "apK88zAh5Y1i2tUxg4HgQAAABjY"] [Sat Aug 29 05:05:23.535047 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.49.130:53746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/memberfuns.php"] [unique_id "apK88yJcY4fy7tP-rU3jvQAAApI"] [Sat Aug 29 05:05:23.535447 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.48.251.3:27143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/goods.php"] [unique_id "apK88yJcY4fy7tP-rU3jvgAAAns"] [Sat Aug 29 05:05:23.537996 2026] [security2:error] [pid 1018003:tid 1018236] [client 4.205.62.107:54443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/bigdump.php"] [unique_id "apK88zAh5Y1i2tUxg4HgQQAABgw"] [Sat Aug 29 05:05:23.546977 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.196.209.81:25038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/fi2.php"] [unique_id "apK88yJcY4fy7tP-rU3jvwAAAmE"] [Sat Aug 29 05:05:23.547006 2026] [security2:error] [pid 1018003:tid 1018265] [client 74.248.24.12:3425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "apK88zAh5Y1i2tUxg4HgPwAABik"] [Sat Aug 29 05:05:23.548068 2026] [security2:error] [pid 1018003:tid 1018271] [client 185.104.184.230:45942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK88zAh5Y1i2tUxg4HgQgAABi8"] [Sat Aug 29 05:05:23.562081 2026] [security2:error] [pid 1017536:tid 1017686] [client 185.104.184.230:45940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK88yJcY4fy7tP-rU3jwAAAAig"] [Sat Aug 29 05:05:23.563295 2026] [security2:error] [pid 1017536:tid 1017741] [client 68.155.159.216:12200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/goat.php"] [unique_id "apK88yJcY4fy7tP-rU3jwQAAAl8"] [Sat Aug 29 05:05:23.575990 2026] [security2:error] [pid 1018003:tid 1018254] [client 87.219.197.128:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK88zAh5Y1i2tUxg4HgRQAABh4"] [Sat Aug 29 05:05:23.576100 2026] [security2:error] [pid 1018003:tid 1018254] [client 87.219.197.128:50200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK88zAh5Y1i2tUxg4HgRQAABh4"] [Sat Aug 29 05:05:23.579806 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.63.219.114:19408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/NewFile.php"] [unique_id "apK88zAh5Y1i2tUxg4HgRgAABf8"] [Sat Aug 29 05:05:23.590325 2026] [security2:error] [pid 1018003:tid 1018251] [client 20.63.219.114:9167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/fox.php"] [unique_id "apK88zAh5Y1i2tUxg4HgRwAABhs"] [Sat Aug 29 05:05:23.615543 2026] [security2:error] [pid 1017536:tid 1017787] [client 52.139.37.240:21378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/file61.php"] [unique_id "apK88yJcY4fy7tP-rU3jwgAAAo0"] [Sat Aug 29 05:05:23.622758 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.160.90:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp-easy.php"] [unique_id "apK88zAh5Y1i2tUxg4HgSQAABfs"] [Sat Aug 29 05:05:23.648237 2026] [security2:error] [pid 1018003:tid 1018275] [client 68.155.159.216:24563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/chosen.php"] [unique_id "apK88zAh5Y1i2tUxg4HgSwAABjM"] [Sat Aug 29 05:05:23.669216 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.158.54.35:10869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/alfa.php"] [unique_id "apK88zAh5Y1i2tUxg4HgTAAABbo"] [Sat Aug 29 05:05:23.670838 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.63.81.20:26495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/lib.php/new.php"] [unique_id "apK88yJcY4fy7tP-rU3jxAAAAo8"] [Sat Aug 29 05:05:23.684301 2026] [security2:error] [pid 1017536:tid 1017693] [client 103.185.242.143:59017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK88yJcY4fy7tP-rU3jxQAAAi8"] [Sat Aug 29 05:05:23.684433 2026] [security2:error] [pid 1017536:tid 1017693] [client 103.185.242.143:59017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK88yJcY4fy7tP-rU3jxQAAAi8"] [Sat Aug 29 05:05:23.697973 2026] [security2:error] [pid 1017536:tid 1017670] [client 52.139.37.240:24604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/7logs.php"] [unique_id "apK88yJcY4fy7tP-rU3jxgAAAhg"] [Sat Aug 29 05:05:23.713754 2026] [security2:error] [pid 1017536:tid 1017738] [client 4.205.62.107:53336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/time.php"] [unique_id "apK88yJcY4fy7tP-rU3jxwAAAlw"] [Sat Aug 29 05:05:23.717072 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.196.209.81:10732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/extractable-loader-head.php"] [unique_id "apK88zAh5Y1i2tUxg4HgTwAABgQ"] [Sat Aug 29 05:05:23.717173 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.251.3:28486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/loxi-o.php"] [unique_id "apK88yJcY4fy7tP-rU3jyAAAAj8"] [Sat Aug 29 05:05:23.741195 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.147.79:24463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/admin.php"] [unique_id "apK88zAh5Y1i2tUxg4HgUAAABdQ"] [Sat Aug 29 05:05:23.750752 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.23.147.79:30715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/dropdown.php"] [unique_id "apK88zAh5Y1i2tUxg4HgUQAABio"] [Sat Aug 29 05:05:23.760662 2026] [security2:error] [pid 1018003:tid 1018193] [client 209.50.184.78:32429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.184.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK88zAh5Y1i2tUxg4HgTgAABeI"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:23.768721 2026] [security2:error] [pid 1017536:tid 1017750] [client 68.155.159.216:65486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK88yJcY4fy7tP-rU3jywAAAmg"] [Sat Aug 29 05:05:23.770771 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.48.160.90:64752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/d7.php"] [unique_id "apK88zAh5Y1i2tUxg4HgUgAABiE"] [Sat Aug 29 05:05:23.782832 2026] [security2:error] [pid 1017536:tid 1017655] [remote 35.243.213.218:60034] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.mikeycunningham.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "apK88yJcY4fy7tP-rU3jzAACQ3Y"] [Sat Aug 29 05:05:23.790100 2026] [security2:error] [pid 1018003:tid 1018152] [client 168.107.94.195:59477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK88zAh5Y1i2tUxg4HgUwAABbk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:23.811467 2026] [security2:error] [pid 1017536:tid 1017667] [client 52.139.37.240:20764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/mah.php"] [unique_id "apK88yJcY4fy7tP-rU3jzgAAAhU"] [Sat Aug 29 05:05:23.826942 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.63.219.114:1523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/go.php"] [unique_id "apK88yJcY4fy7tP-rU3jzwAAAiM"] [Sat Aug 29 05:05:23.841909 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.63.81.20:26455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/info.php/new.php"] [unique_id "apK88yJcY4fy7tP-rU3j0AAAAoE"] [Sat Aug 29 05:05:23.847956 2026] [security2:error] [pid 1017536:tid 1017739] [client 185.104.184.230:45954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK88yJcY4fy7tP-rU3j0QAAAl0"] [Sat Aug 29 05:05:23.848983 2026] [security2:error] [pid 1018003:tid 1018242] [client 93.123.109.228:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK88zAh5Y1i2tUxg4HgVQAABhI"] [Sat Aug 29 05:05:23.849938 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.48.251.3:28437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/f35.php"] [unique_id "apK88yJcY4fy7tP-rU3j0gAAAoU"] [Sat Aug 29 05:05:23.862687 2026] [security2:error] [pid 1018003:tid 1018166] [client 93.123.109.228:37390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK88zAh5Y1i2tUxg4HgVgAABcc"] [Sat Aug 29 05:05:23.863209 2026] [security2:error] [pid 1018003:tid 1018189] [client 93.123.109.228:37252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK88zAh5Y1i2tUxg4HgVwAABd4"] [Sat Aug 29 05:05:23.869190 2026] [security2:error] [pid 1017536:tid 1017671] [client 185.104.184.230:45962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK88yJcY4fy7tP-rU3j0wAAAhk"] [Sat Aug 29 05:05:23.870312 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:16215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/packed.php"] [unique_id "apK88zAh5Y1i2tUxg4HgWQAABbw"] [Sat Aug 29 05:05:23.891902 2026] [security2:error] [pid 1017536:tid 1017705] [client 74.248.24.12:8998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK88yJcY4fy7tP-rU3j1AAAAjs"] [Sat Aug 29 05:05:23.892989 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.104.49.130:43792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/reop3.php"] [unique_id "apK88yJcY4fy7tP-rU3j1QAAAn4"] [Sat Aug 29 05:05:23.900872 2026] [security2:error] [pid 1018003:tid 1018224] [client 52.139.37.240:24697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/ac.php"] [unique_id "apK88zAh5Y1i2tUxg4HgWgAABgE"] [Sat Aug 29 05:05:23.901483 2026] [security2:error] [pid 1018003:tid 1018216] [client 4.205.62.107:61762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/fun.php"] [unique_id "apK88zAh5Y1i2tUxg4HgWwAABfk"] [Sat Aug 29 05:05:23.931325 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.196.209.81:17606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/admin.php"] [unique_id "apK88zAh5Y1i2tUxg4HgXAAABfY"] [Sat Aug 29 05:05:23.933811 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.48.160.90:63533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/v5.php"] [unique_id "apK88zAh5Y1i2tUxg4HgXQAABiY"] [Sat Aug 29 05:05:23.944905 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.63.219.114:19420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/config.php"] [unique_id "apK88zAh5Y1i2tUxg4HgXgAABis"] [Sat Aug 29 05:05:23.947469 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.196.209.81:14571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/1p.php"] [unique_id "apK88zAh5Y1i2tUxg4HgXwAABjQ"] [Sat Aug 29 05:05:23.952556 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.63.219.114:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/disagraeosc.php"] [unique_id "apK88zAh5Y1i2tUxg4HgYAAABec"] [Sat Aug 29 05:05:23.963775 2026] [security2:error] [pid 1018003:tid 1018250] [client 4.232.148.111:3010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/222.php"] [unique_id "apK88zAh5Y1i2tUxg4HgYgAABho"] [Sat Aug 29 05:05:23.996377 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.251.3:28426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/api.php"] [unique_id "apK88zAh5Y1i2tUxg4HgZAAABcs"] [Sat Aug 29 05:05:24.001621 2026] [security2:error] [pid 1017536:tid 1017690] [client 4.205.62.107:22234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/routes.php"] [unique_id "apK88yJcY4fy7tP-rU3j3gAAAiw"] [Sat Aug 29 05:05:24.006242 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.63.81.20:26482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/db.php/new.php"] [unique_id "apK89DAh5Y1i2tUxg4HgZQAABjE"] [Sat Aug 29 05:05:24.018055 2026] [security2:error] [pid 1017536:tid 1017767] [client 52.139.37.240:21397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/mini.php"] [unique_id "apK89CJcY4fy7tP-rU3j3wAAAnk"] [Sat Aug 29 05:05:24.025558 2026] [security2:error] [pid 1017536:tid 1017781] [client 68.155.159.216:18430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.baxterevents.com"] [uri "/first.php"] [unique_id "apK89CJcY4fy7tP-rU3j4AAAAoc"] [Sat Aug 29 05:05:24.065801 2026] [security2:error] [pid 1018003:tid 1018202] [client 74.248.24.12:28169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/222.php"] [unique_id "apK89DAh5Y1i2tUxg4HgZgAABes"] [Sat Aug 29 05:05:24.068809 2026] [security2:error] [pid 1017536:tid 1017723] [client 68.155.159.216:50264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK89CJcY4fy7tP-rU3j4QAAAk0"] [Sat Aug 29 05:05:24.080131 2026] [security2:error] [pid 1017536:tid 1017687] [client 158.23.147.79:23532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/x.php"] [unique_id "apK89CJcY4fy7tP-rU3j4gAAAik"] [Sat Aug 29 05:05:24.099473 2026] [security2:error] [pid 1017536:tid 1017758] [client 52.139.37.240:24681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/ctex1.php"] [unique_id "apK89CJcY4fy7tP-rU3j5AAAAnA"] [Sat Aug 29 05:05:24.109928 2026] [security2:error] [pid 1017536:tid 1017540] [remote 34.138.108.56:57558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/assets../.env"] [unique_id "apK89CJcY4fy7tP-rU3j5QACFAM"] [Sat Aug 29 05:05:24.111885 2026] [security2:error] [pid 1017536:tid 1017710] [client 4.232.148.111:20320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/a.php"] [unique_id "apK89CJcY4fy7tP-rU3j5gAAAkA"] [Sat Aug 29 05:05:24.113004 2026] [security2:error] [pid 1017536:tid 1017541] [remote 34.138.108.56:57558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/images../.env"] [unique_id "apK89CJcY4fy7tP-rU3j5wACggQ"] [Sat Aug 29 05:05:24.113148 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.158.54.35:11041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/403.php"] [unique_id "apK89CJcY4fy7tP-rU3j6QAAAms"] [Sat Aug 29 05:05:24.113183 2026] [security2:error] [pid 1017536:tid 1017653] [remote 34.138.108.56:57558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/img../.env"] [unique_id "apK89CJcY4fy7tP-rU3j6AACgnQ"] [Sat Aug 29 05:05:24.121264 2026] [security2:error] [pid 1017536:tid 1017561] [remote 34.138.108.56:57558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/uploads../.env"] [unique_id "apK89CJcY4fy7tP-rU3j7AACRxg"] [Sat Aug 29 05:05:24.129665 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.251.3:57823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/temp.php"] [unique_id "apK89CJcY4fy7tP-rU3j7QAAAj4"] [Sat Aug 29 05:05:24.138243 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.196.209.81:10729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/defaults.php"] [unique_id "apK89CJcY4fy7tP-rU3j7wAAAls"] [Sat Aug 29 05:05:24.142180 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.23.147.79:48276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/plugins/index.php"] [unique_id "apK89DAh5Y1i2tUxg4HgaQAABdg"] [Sat Aug 29 05:05:24.145589 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:33698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/simple.php"] [unique_id "apK89DAh5Y1i2tUxg4HgagAABco"] [Sat Aug 29 05:05:24.154318 2026] [security2:error] [pid 1018003:tid 1018234] [client 185.104.184.230:45974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rtg.paw.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK89DAh5Y1i2tUxg4HgbAAABgo"] [Sat Aug 29 05:05:24.159195 2026] [security2:error] [pid 1017536:tid 1017786] [client 185.104.184.230:45982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK89CJcY4fy7tP-rU3j8AAAAow"] [Sat Aug 29 05:05:24.173246 2026] [security2:error] [pid 1018003:tid 1018195] [client 168.107.94.195:59795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK89DAh5Y1i2tUxg4HgbQAABeQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:24.173896 2026] [security2:error] [pid 1017536:tid 1017696] [client 4.205.62.107:21880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/apikeys.php"] [unique_id "apK89CJcY4fy7tP-rU3j8QAAAjI"] [Sat Aug 29 05:05:24.174980 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.48.160.90:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/az.php"] [unique_id "apK89CJcY4fy7tP-rU3j8gAAAko"] [Sat Aug 29 05:05:24.180350 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.63.81.20:26498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/kuda.php"] [unique_id "apK89CJcY4fy7tP-rU3j8wAAAoQ"] [Sat Aug 29 05:05:24.180895 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.63.219.114:1516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/gecko-new.php"] [unique_id "apK89CJcY4fy7tP-rU3j9AAAAjk"] [Sat Aug 29 05:05:24.185576 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.147.79:63004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK89CJcY4fy7tP-rU3j9gAAAk4"] [Sat Aug 29 05:05:24.201750 2026] [security2:error] [pid 1017536:tid 1017729] [client 178.16.55.109:54206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.55.16.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.burlingtonyaroslavl.com"] [uri "/wp-login.php"] [unique_id "apK89CJcY4fy7tP-rU3j-AAAAlM"] [Sat Aug 29 05:05:24.207451 2026] [security2:error] [pid 1017536:tid 1017769] [client 68.155.159.216:51513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/xmlrpc.php"] [unique_id "apK89CJcY4fy7tP-rU3j-gAAAns"] [Sat Aug 29 05:05:24.216240 2026] [security2:error] [pid 1017536:tid 1017774] [client 52.139.37.240:21403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/v.php"] [unique_id "apK89CJcY4fy7tP-rU3j-wAAAoA"] [Sat Aug 29 05:05:24.239712 2026] [security2:error] [pid 1017536:tid 1017744] [client 4.205.62.107:2894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/chosen.php"] [unique_id "apK89CJcY4fy7tP-rU3j_QAAAmI"] [Sat Aug 29 05:05:24.261225 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.251.3:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/fm.php"] [unique_id "apK89CJcY4fy7tP-rU3j_gAAAkI"] [Sat Aug 29 05:05:24.262758 2026] [security2:error] [pid 1018003:tid 1018238] [client 195.178.110.247:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "staystrongva.org"] [uri "/index.php"] [unique_id "apK89DAh5Y1i2tUxg4HgcQAABg4"] [Sat Aug 29 05:05:24.307317 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.63.219.114:1517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/about.php525"] [unique_id "apK89CJcY4fy7tP-rU3kAQAAApA"] [Sat Aug 29 05:05:24.308729 2026] [security2:error] [pid 1018003:tid 1018214] [client 209.50.162.16:12129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.162.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK89DAh5Y1i2tUxg4HgcgAABfc"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:24.335282 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.48.160.90:64715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/js.php"] [unique_id "apK89CJcY4fy7tP-rU3kAgAAAhg"] [Sat Aug 29 05:05:24.356695 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.196.209.81:17649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK89CJcY4fy7tP-rU3kBQAAAmo"] [Sat Aug 29 05:05:24.360735 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.63.81.20:26376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/sure.php"] [unique_id "apK89CJcY4fy7tP-rU3kBgAAAj8"] [Sat Aug 29 05:05:24.392341 2026] [security2:error] [pid 1017536:tid 1017557] [remote 34.138.108.56:57558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/@fs/var/task/.env"] [unique_id "apK89CJcY4fy7tP-rU3kCAACRxQ"] [Sat Aug 29 05:05:24.395847 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.48.251.3:28460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/tinyfilemanager.php"] [unique_id "apK89CJcY4fy7tP-rU3kCQAAAlg"] [Sat Aug 29 05:05:24.435302 2026] [security2:error] [pid 1017536:tid 1017700] [client 195.178.110.247:11604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "staystrongva.org"] [uri "/index.php"] [unique_id "apK89CJcY4fy7tP-rU3kCgAAAjY"] [Sat Aug 29 05:05:24.438229 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.196.209.81:13830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/Njima.php"] [unique_id "apK89CJcY4fy7tP-rU3kCwAAAi8"] [Sat Aug 29 05:05:24.440762 2026] [security2:error] [pid 1017536:tid 1017704] [client 4.232.148.111:24787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/mini.php"] [unique_id "apK89CJcY4fy7tP-rU3kDAAAAjo"] [Sat Aug 29 05:05:24.450457 2026] [security2:error] [pid 1017536:tid 1017681] [client 185.104.184.230:45998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK89CJcY4fy7tP-rU3kDQAAAiM"] [Sat Aug 29 05:05:24.474798 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.48.160.90:63515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/hd.php"] [unique_id "apK89CJcY4fy7tP-rU3kDgAAAl0"] [Sat Aug 29 05:05:24.475911 2026] [security2:error] [pid 1017536:tid 1017702] [client 74.248.24.12:5294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/upload.php"] [unique_id "apK89CJcY4fy7tP-rU3kDwAAAjg"] [Sat Aug 29 05:05:24.476781 2026] [security2:error] [pid 1017536:tid 1017779] [client 158.23.147.79:25558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/chosen.php"] [unique_id "apK89CJcY4fy7tP-rU3kEAAAAoU"] [Sat Aug 29 05:05:24.517647 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.63.81.20:26456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/gray.php"] [unique_id "apK89DAh5Y1i2tUxg4HgfwAABc8"] [Sat Aug 29 05:05:24.518716 2026] [security2:error] [pid 1018003:tid 1018253] [client 162.198.206.205:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK89DAh5Y1i2tUxg4HgfQAABh0"], referer: http://www.baidu.com/ [Sat Aug 29 05:05:24.526877 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.63.219.114:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/22.php"] [unique_id "apK89DAh5Y1i2tUxg4HggAAABhM"] [Sat Aug 29 05:05:24.528193 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:57383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK89DAh5Y1i2tUxg4HggQAABgk"] [Sat Aug 29 05:05:24.538897 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.196.209.81:10702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/post.php"] [unique_id "apK89DAh5Y1i2tUxg4HggwAABgw"] [Sat Aug 29 05:05:24.544680 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.63.219.114:11846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/wp-admin.php"] [unique_id "apK89CJcY4fy7tP-rU3kFAAAApM"] [Sat Aug 29 05:05:24.547726 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.48.251.3:57851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/05.php"] [unique_id "apK89CJcY4fy7tP-rU3kFQAAAlE"] [Sat Aug 29 05:05:24.549714 2026] [security2:error] [pid 1017536:tid 1017750] [client 158.158.54.35:21802] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.santarosairis.org"] [uri "/1.php"] [unique_id "apK89CJcY4fy7tP-rU3kFgAAAmg"] [Sat Aug 29 05:05:24.549844 2026] [security2:error] [pid 1017536:tid 1017750] [client 158.158.54.35:21802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/1.php"] [unique_id "apK89CJcY4fy7tP-rU3kFgAAAmg"] [Sat Aug 29 05:05:24.555970 2026] [security2:error] [pid 1018003:tid 1018208] [client 168.107.94.195:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK89DAh5Y1i2tUxg4HghAAABfE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:24.568749 2026] [security2:error] [pid 1017536:tid 1017714] [client 74.248.24.12:4048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/mini.php"] [unique_id "apK89CJcY4fy7tP-rU3kFwAAAkQ"] [Sat Aug 29 05:05:24.589325 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.49.130:51135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/forum.php"] [unique_id "apK89CJcY4fy7tP-rU3kGgAAAok"] [Sat Aug 29 05:05:24.590499 2026] [security2:error] [pid 1017536:tid 1017667] [client 4.232.148.111:23763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/u.php"] [unique_id "apK89CJcY4fy7tP-rU3kGwAAAhU"] [Sat Aug 29 05:05:24.617243 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.48.160.90:62593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/xl2023.php"] [unique_id "apK89DAh5Y1i2tUxg4HghwAABfo"] [Sat Aug 29 05:05:24.659170 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.63.81.20:26452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/puki.php"] [unique_id "apK89CJcY4fy7tP-rU3kIQAAAiE"] [Sat Aug 29 05:05:24.683043 2026] [security2:error] [pid 1018003:tid 1018259] [client 68.155.159.216:12160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK89DAh5Y1i2tUxg4HgiQAABiM"] [Sat Aug 29 05:05:24.683602 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.48.251.3:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-blog.php"] [unique_id "apK89CJcY4fy7tP-rU3kIwAAAhY"] [Sat Aug 29 05:05:24.709232 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.63.219.114:1519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/spip.php"] [unique_id "apK89CJcY4fy7tP-rU3kJAAAAlA"] [Sat Aug 29 05:05:24.746995 2026] [security2:error] [pid 1017536:tid 1017710] [client 4.205.62.107:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/wdf.php"] [unique_id "apK89CJcY4fy7tP-rU3kJgAAAkA"] [Sat Aug 29 05:05:24.749184 2026] [security2:error] [pid 1017536:tid 1017558] [remote 34.138.108.56:57558] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "proppastie.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "apK89CJcY4fy7tP-rU3kJwACRxU"] [Sat Aug 29 05:05:24.749821 2026] [security2:error] [pid 1017536:tid 1017595] [remote 34.138.108.56:57558] ModSecurity: Access denied with code 500 (phase 1) (Error: Connection drop requested but failed to close the socket). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "proppastie.com"] [uri "/api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK89CJcY4fy7tP-rU3kKgACRzo"] [Sat Aug 29 05:05:24.750884 2026] [security2:error] [pid 1017536:tid 1017567] [remote 34.138.108.56:57558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK89CJcY4fy7tP-rU3kKQACRx4"] [Sat Aug 29 05:05:24.754954 2026] [security2:error] [pid 1017536:tid 1017753] [client 185.104.184.230:46000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK89CJcY4fy7tP-rU3kLAAAAms"] [Sat Aug 29 05:05:24.779854 2026] [security2:error] [pid 1017536:tid 1017728] [client 20.196.209.81:17948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK89CJcY4fy7tP-rU3kLQAAAlI"] [Sat Aug 29 05:05:24.789865 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.160.90:64703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/V2.php"] [unique_id "apK89CJcY4fy7tP-rU3kLgAAAj4"] [Sat Aug 29 05:05:24.791710 2026] [autoindex:error] [pid 1018003:tid 1018270] [client 195.178.110.103:14942] AH01276: Cannot serve directory /home3/jiazbwmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:24.802325 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.63.81.20:26461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/sonic.php"] [unique_id "apK89CJcY4fy7tP-rU3kLwAAAow"] [Sat Aug 29 05:05:24.809590 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.104.49.130:52304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/wp-blogs.php"] [unique_id "apK89CJcY4fy7tP-rU3kMAAAAho"] [Sat Aug 29 05:05:24.823592 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.48.251.3:57911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/erty.php"] [unique_id "apK89CJcY4fy7tP-rU3kMgAAAko"] [Sat Aug 29 05:05:24.833370 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.196.209.81:25084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/configs.php"] [unique_id "apK89CJcY4fy7tP-rU3kNAAAAik"] [Sat Aug 29 05:05:24.872217 2026] [security2:error] [pid 1017536:tid 1017686] [client 158.23.147.79:24533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK89CJcY4fy7tP-rU3kNQAAAig"] [Sat Aug 29 05:05:24.884952 2026] [security2:error] [pid 1018003:tid 1018266] [client 45.3.55.24:55385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK89DAh5Y1i2tUxg4HgkAAABio"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:24.914602 2026] [access_compat:error] [pid 1018003:tid 1018184] [client 67.20.76.220:22210] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:24.918985 2026] [security2:error] [pid 1018003:tid 1018189] [client 4.205.62.107:53421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/old_phpinfo.php"] [unique_id "apK89DAh5Y1i2tUxg4HgkwAABd4"] [Sat Aug 29 05:05:24.920402 2026] [security2:error] [pid 1017536:tid 1017764] [client 4.232.148.111:10357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/aa.php"] [unique_id "apK89CJcY4fy7tP-rU3kNwAAAnY"] [Sat Aug 29 05:05:24.922503 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.63.219.114:1499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/wp-configs.php"] [unique_id "apK89CJcY4fy7tP-rU3kOAAAAls"] [Sat Aug 29 05:05:24.923509 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.63.219.114:9381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/bak.phps"] [unique_id "apK89DAh5Y1i2tUxg4HglAAABdw"] [Sat Aug 29 05:05:24.931043 2026] [access_compat:error] [pid 1018003:tid 1018189] [client 67.20.76.220:22250] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:24.931096 2026] [access_compat:error] [pid 1018003:tid 1018242] [client 67.20.76.220:22226] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:24.940091 2026] [security2:error] [pid 1018003:tid 1018159] [client 168.107.94.195:60551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK89DAh5Y1i2tUxg4HgmQAABcA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:24.940591 2026] [access_compat:error] [pid 1017536:tid 1017770] [client 67.20.76.220:22240] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:24.944748 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.196.209.81:21062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/csv.php"] [unique_id "apK89CJcY4fy7tP-rU3kPAAAAmc"] [Sat Aug 29 05:05:24.947541 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.63.81.20:26453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/pop.php"] [unique_id "apK89CJcY4fy7tP-rU3kPQAAAiA"] [Sat Aug 29 05:05:24.955491 2026] [security2:error] [pid 1018003:tid 1018263] [client 195.178.110.103:14942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jia.zbw.mybluehost.me"] [uri "/index.php"] [unique_id "apK89DAh5Y1i2tUxg4HgnQAABic"] [Sat Aug 29 05:05:24.955769 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.48.251.3:28473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-config.backup.php"] [unique_id "apK89CJcY4fy7tP-rU3kPgAAAlQ"] [Sat Aug 29 05:05:25.000098 2026] [security2:error] [pid 1017536:tid 1017738] [client 68.155.159.216:16349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-content/packed.php"] [unique_id "apK89CJcY4fy7tP-rU3kRAAAAlw"] [Sat Aug 29 05:05:25.010561 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.48.160.90:64676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/mad.php"] [unique_id "apK89TAh5Y1i2tUxg4HgoAAABhA"] [Sat Aug 29 05:05:25.019905 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.49.130:43611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/dk.php"] [unique_id "apK89SJcY4fy7tP-rU3kRgAAAis"] [Sat Aug 29 05:05:25.022773 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.147.79:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/packed.php"] [unique_id "apK89SJcY4fy7tP-rU3kSAAAAks"] [Sat Aug 29 05:05:25.022908 2026] [core:error] [pid 1017536:tid 1017724] [client 74.248.24.12:35497] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:25.022918 2026] [core:error] [pid 1017536:tid 1017724] [client 74.248.24.12:35497] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:25.037565 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.205.62.107:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/kedi.php"] [unique_id "apK89SJcY4fy7tP-rU3kSQAAAi0"] [Sat Aug 29 05:05:25.058732 2026] [security2:error] [pid 1017536:tid 1017704] [client 185.104.184.230:46008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK89SJcY4fy7tP-rU3kSgAAAjo"] [Sat Aug 29 05:05:25.083737 2026] [security2:error] [pid 1018003:tid 1018177] [client 4.232.148.111:15459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/r.php"] [unique_id "apK89TAh5Y1i2tUxg4HgowAABdI"] [Sat Aug 29 05:05:25.084132 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.63.81.20:26385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/503.php"] [unique_id "apK89SJcY4fy7tP-rU3kTAAAAjg"] [Sat Aug 29 05:05:25.085526 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.48.251.3:27157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/edit.php"] [unique_id "apK89SJcY4fy7tP-rU3kTQAAAoU"] [Sat Aug 29 05:05:25.086108 2026] [security2:error] [pid 1018003:tid 1018235] [client 74.248.24.12:25717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/aa.php"] [unique_id "apK89TAh5Y1i2tUxg4HgpAAABgs"] [Sat Aug 29 05:05:25.092469 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.63.219.114:14573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/backup.php"] [unique_id "apK89SJcY4fy7tP-rU3kTwAAAmo"] [Sat Aug 29 05:05:25.106592 2026] [security2:error] [pid 1017536:tid 1017757] [client 93.123.109.228:37236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/.wp-config.php.swp"] [unique_id "apK89SJcY4fy7tP-rU3kUAAAAm8"] [Sat Aug 29 05:05:25.147740 2026] [security2:error] [pid 1018003:tid 1018190] [client 93.123.109.228:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK89TAh5Y1i2tUxg4HgpwAABd8"] [Sat Aug 29 05:05:25.149123 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.158.54.35:19362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/s.php"] [unique_id "apK89SJcY4fy7tP-rU3kUQAAApM"] [Sat Aug 29 05:05:25.149832 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.205.62.107:21839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/fm.php"] [unique_id "apK89SJcY4fy7tP-rU3kUgAAAh0"] [Sat Aug 29 05:05:25.175302 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.196.209.81:10649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK89SJcY4fy7tP-rU3kUwAAAi4"] [Sat Aug 29 05:05:25.188985 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.48.160.90:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/st.php"] [unique_id "apK89SJcY4fy7tP-rU3kVQAAAok"] [Sat Aug 29 05:05:25.190513 2026] [security2:error] [pid 1017536:tid 1017667] [client 158.23.147.79:23366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/wp-content/x.php"] [unique_id "apK89SJcY4fy7tP-rU3kVgAAAhU"] [Sat Aug 29 05:05:25.190940 2026] [security2:error] [pid 1017536:tid 1017765] [client 68.155.159.216:50223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/admin.php"] [unique_id "apK89SJcY4fy7tP-rU3kVwAAAnc"] [Sat Aug 29 05:05:25.195795 2026] [security2:error] [pid 1017536:tid 1017788] [client 93.123.109.228:37338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK89SJcY4fy7tP-rU3kWAAAAo4"] [Sat Aug 29 05:05:25.215020 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.48.251.3:28470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/8.php"] [unique_id "apK89SJcY4fy7tP-rU3kWQAAAiw"] [Sat Aug 29 05:05:25.226881 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.81.20:26537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/fxp.php"] [unique_id "apK89SJcY4fy7tP-rU3kWgAAAlY"] [Sat Aug 29 05:05:25.233962 2026] [security2:error] [pid 1017536:tid 1017669] [client 103.168.67.159:3238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "naturalbasstech.com"] [uri "/wp/"] [unique_id "apK89SJcY4fy7tP-rU3kWwAAAhc"] [Sat Aug 29 05:05:25.234722 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.196.209.81:15121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/disagraeed.php"] [unique_id "apK89SJcY4fy7tP-rU3kXAAAAog"] [Sat Aug 29 05:05:25.247926 2026] [security2:error] [pid 1017536:tid 1017773] [client 192.145.125.70:35408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK89SJcY4fy7tP-rU3kXQAAAn8"] [Sat Aug 29 05:05:25.252946 2026] [security2:error] [pid 1017536:tid 1017679] [client 158.23.147.79:48297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/simple.php"] [unique_id "apK89SJcY4fy7tP-rU3kXgAAAiE"] [Sat Aug 29 05:05:25.277425 2026] [security2:error] [pid 1017536:tid 1017711] [client 68.155.159.216:24521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/goods.php"] [unique_id "apK89SJcY4fy7tP-rU3kXwAAAkE"] [Sat Aug 29 05:05:25.290150 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.63.219.114:19448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/install.php"] [unique_id "apK89SJcY4fy7tP-rU3kYQAAAio"] [Sat Aug 29 05:05:25.293204 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.63.219.114:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/essexec.php"] [unique_id "apK89SJcY4fy7tP-rU3kYgAAAhw"] [Sat Aug 29 05:05:25.293814 2026] [security2:error] [pid 1017536:tid 1017668] [client 158.23.147.79:62673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/goat.php"] [unique_id "apK89SJcY4fy7tP-rU3kZAAAAhY"] [Sat Aug 29 05:05:25.306329 2026] [security2:error] [pid 1018003:tid 1018225] [client 4.205.62.107:21855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/god.php"] [unique_id "apK89TAh5Y1i2tUxg4HgsAAABgI"] [Sat Aug 29 05:05:25.315282 2026] [security2:error] [pid 1018003:tid 1018194] [client 93.123.109.228:37252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK89TAh5Y1i2tUxg4HgsQAABeM"] [Sat Aug 29 05:05:25.320262 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:51257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/atomlib.php"] [unique_id "apK89SJcY4fy7tP-rU3kZgAAAms"] [Sat Aug 29 05:05:25.320960 2026] [security2:error] [pid 1017536:tid 1017666] [client 168.107.94.195:60969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK89SJcY4fy7tP-rU3kZwAAAhQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:25.341234 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.48.160.90:62696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/alfanew.php"] [unique_id "apK89TAh5Y1i2tUxg4HgswAABhw"] [Sat Aug 29 05:05:25.348902 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.48.251.3:57832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/thui.php"] [unique_id "apK89TAh5Y1i2tUxg4HgtAAABeQ"] [Sat Aug 29 05:05:25.365806 2026] [security2:error] [pid 1018003:tid 1018156] [client 185.104.184.230:46020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK89TAh5Y1i2tUxg4HgtQAABb0"] [Sat Aug 29 05:05:25.376975 2026] [security2:error] [pid 1018003:tid 1018231] [client 4.205.62.107:2941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/rum.or.php"] [unique_id "apK89TAh5Y1i2tUxg4HgtgAABgc"] [Sat Aug 29 05:05:25.388667 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.63.81.20:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/vv.php"] [unique_id "apK89SJcY4fy7tP-rU3kaAAAAow"] [Sat Aug 29 05:05:25.397756 2026] [security2:error] [pid 1018003:tid 1018182] [client 93.123.109.228:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK89TAh5Y1i2tUxg4HgtwAABdc"] [Sat Aug 29 05:05:25.405942 2026] [security2:error] [pid 1017536:tid 1017778] [client 93.123.109.228:37302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK89SJcY4fy7tP-rU3kaQAAAoQ"] [Sat Aug 29 05:05:25.406965 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.196.209.81:21099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/disagraeosc.php"] [unique_id "apK89SJcY4fy7tP-rU3kagAAAkU"] [Sat Aug 29 05:05:25.410532 2026] [security2:error] [pid 1017536:tid 1017713] [client 4.232.148.111:3046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/c.php"] [unique_id "apK89SJcY4fy7tP-rU3kawAAAkM"] [Sat Aug 29 05:05:25.419515 2026] [security2:error] [pid 1017536:tid 1017703] [client 93.123.109.228:37312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK89SJcY4fy7tP-rU3kbAAAAjk"] [Sat Aug 29 05:05:25.429792 2026] [security2:error] [pid 1018003:tid 1018234] [client 209.50.173.163:61849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.173.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK89TAh5Y1i2tUxg4HguAAABgo"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:25.452029 2026] [security2:error] [pid 1017536:tid 1017741] [client 93.123.109.228:37338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK89SJcY4fy7tP-rU3kbgAAAl8"] [Sat Aug 29 05:05:25.453236 2026] [security2:error] [pid 1018003:tid 1018188] [client 93.123.109.228:37254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK89TAh5Y1i2tUxg4HgugAABd0"] [Sat Aug 29 05:05:25.457706 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.63.219.114:11869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/haiterus.php"] [unique_id "apK89TAh5Y1i2tUxg4HgvAAABiw"] [Sat Aug 29 05:05:25.459000 2026] [security2:error] [pid 1017536:tid 1017744] [client 93.123.109.228:37324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK89SJcY4fy7tP-rU3kbwAAAmI"] [Sat Aug 29 05:05:25.478597 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.48.160.90:63550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/ioxi.php"] [unique_id "apK89SJcY4fy7tP-rU3kcAAAAl4"] [Sat Aug 29 05:05:25.479635 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.48.251.3:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/file21.php"] [unique_id "apK89SJcY4fy7tP-rU3kcQAAAiI"] [Sat Aug 29 05:05:25.516660 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.63.81.20:26490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/bossu.php"] [unique_id "apK89SJcY4fy7tP-rU3kcgAAAn0"] [Sat Aug 29 05:05:25.561045 2026] [security2:error] [pid 1017536:tid 1017720] [client 4.232.148.111:32380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-blog.php"] [unique_id "apK89SJcY4fy7tP-rU3kcwAAAko"] [Sat Aug 29 05:05:25.566578 2026] [security2:error] [pid 1017536:tid 1017755] [client 103.168.67.159:3238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "naturalbasstech.com"] [uri "/wordpress/"] [unique_id "apK89SJcY4fy7tP-rU3kdAAAAm0"] [Sat Aug 29 05:05:25.569193 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.196.209.81:10638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/config.php"] [unique_id "apK89SJcY4fy7tP-rU3kdgAAApI"] [Sat Aug 29 05:05:25.572124 2026] [security2:error] [pid 1017536:tid 1017615] [remote 34.138.108.56:57572] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "proppastie.com"] [uri "/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "apK89SJcY4fy7tP-rU3keAACZE4"] [Sat Aug 29 05:05:25.583110 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/goods.php"] [unique_id "apK89TAh5Y1i2tUxg4HgvwAABc8"] [Sat Aug 29 05:05:25.589764 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.158.54.35:18407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/test1.php"] [unique_id "apK89SJcY4fy7tP-rU3kewAAAmE"] [Sat Aug 29 05:05:25.591221 2026] [core:error] [pid 1017536:tid 1017784] [client 74.248.24.12:31596] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:25.591238 2026] [core:error] [pid 1017536:tid 1017784] [client 74.248.24.12:31596] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:25.603062 2026] [security2:error] [pid 1017536:tid 1017769] [client 74.248.24.12:16569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/c.php"] [unique_id "apK89SJcY4fy7tP-rU3kfAAAAns"] [Sat Aug 29 05:05:25.614198 2026] [security2:error] [pid 1018003:tid 1018211] [client 20.48.251.3:57816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/mcebraed.php"] [unique_id "apK89TAh5Y1i2tUxg4HgwgAABfQ"] [Sat Aug 29 05:05:25.643145 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:58299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK89TAh5Y1i2tUxg4HgxAAABgk"] [Sat Aug 29 05:05:25.655668 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.63.81.20:26372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/504.php"] [unique_id "apK89SJcY4fy7tP-rU3kfQAAAnI"] [Sat Aug 29 05:05:25.683804 2026] [security2:error] [pid 1017536:tid 1017738] [client 185.104.184.230:46026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK89SJcY4fy7tP-rU3kfwAAAlw"] [Sat Aug 29 05:05:25.701949 2026] [security2:error] [pid 1017536:tid 1017693] [client 168.107.94.195:61279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK89SJcY4fy7tP-rU3kggAAAi8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:25.702079 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.63.219.114:11847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/hello.php"] [unique_id "apK89SJcY4fy7tP-rU3kgwAAApA"] [Sat Aug 29 05:05:25.705303 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.48.160.90:64763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/TNT.php"] [unique_id "apK89SJcY4fy7tP-rU3khAAAAl0"] [Sat Aug 29 05:05:25.757618 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.48.251.3:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/server-info.php"] [unique_id "apK89TAh5Y1i2tUxg4HgyAAABiA"] [Sat Aug 29 05:05:25.765304 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.63.219.114:15246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/colour.php"] [unique_id "apK89SJcY4fy7tP-rU3khgAAAo0"] [Sat Aug 29 05:05:25.767313 2026] [security2:error] [pid 1017536:tid 1017757] [client 68.155.159.216:33695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/about.php"] [unique_id "apK89SJcY4fy7tP-rU3khwAAAm8"] [Sat Aug 29 05:05:25.767335 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.196.209.81:15800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/add_actualites.php"] [unique_id "apK89TAh5Y1i2tUxg4HgyQAABjU"] [Sat Aug 29 05:05:25.784148 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.63.81.20:26478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/nice.php"] [unique_id "apK89SJcY4fy7tP-rU3kiAAAAic"] [Sat Aug 29 05:05:25.812578 2026] [security2:error] [pid 1017536:tid 1017765] [client 68.155.159.216:16282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/banners/about.php"] [unique_id "apK89SJcY4fy7tP-rU3kiwAAAnc"] [Sat Aug 29 05:05:25.815172 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.63.219.114:11861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/go.php"] [unique_id "apK89TAh5Y1i2tUxg4HgygAABgY"] [Sat Aug 29 05:05:25.857564 2026] [security2:error] [pid 1017536:tid 1017749] [client 192.145.125.70:35422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.125.145.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vickiandgreg.strangeworx.com"] [uri "/xmlrpc.php"] [unique_id "apK89SJcY4fy7tP-rU3kjAAAAmc"] [Sat Aug 29 05:05:25.861641 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.48.160.90:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/cd.php"] [unique_id "apK89TAh5Y1i2tUxg4HgzQAABcc"] [Sat Aug 29 05:05:25.865896 2026] [security2:error] [pid 1017536:tid 1017669] [client 103.168.67.159:3238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "naturalbasstech.com"] [uri "/blog/"] [unique_id "apK89SJcY4fy7tP-rU3kjgAAAhc"] [Sat Aug 29 05:05:25.881875 2026] [security2:error] [pid 1018003:tid 1018154] [client 20.196.209.81:21078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/about.php525"] [unique_id "apK89TAh5Y1i2tUxg4Hg3AAABbs"] [Sat Aug 29 05:05:25.882981 2026] [security2:error] [pid 1018003:tid 1018257] [client 34.143.179.161:19736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/admin/.env"] [unique_id "apK89TAh5Y1i2tUxg4Hg3QAABiE"] [Sat Aug 29 05:05:25.893973 2026] [security2:error] [pid 1017536:tid 1017772] [client 4.232.148.111:32934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/f.php"] [unique_id "apK89SJcY4fy7tP-rU3knAAAAn4"] [Sat Aug 29 05:05:25.894968 2026] [security2:error] [pid 1018003:tid 1018270] [client 34.143.179.161:19758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/frontend/.env"] [unique_id "apK89TAh5Y1i2tUxg4Hg4AAABi4"] [Sat Aug 29 05:05:25.896328 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.251.3:57844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/gk.php"] [unique_id "apK89SJcY4fy7tP-rU3knQAAAiU"] [Sat Aug 29 05:05:25.920044 2026] [security2:error] [pid 1017536:tid 1017767] [client 68.155.159.216:64253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK89SJcY4fy7tP-rU3kngAAAnk"] [Sat Aug 29 05:05:25.923712 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.63.81.20:26437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/beence.php"] [unique_id "apK89SJcY4fy7tP-rU3knwAAAkE"] [Sat Aug 29 05:05:25.940060 2026] [access_compat:error] [pid 1018003:tid 1018189] [client 67.20.76.220:22252] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:25.958629 2026] [security2:error] [pid 1017536:tid 1017706] [client 4.205.62.107:57754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/bb.php"] [unique_id "apK89SJcY4fy7tP-rU3kogAAAjw"] [Sat Aug 29 05:05:25.965018 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.196.209.81:10667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/cong.php"] [unique_id "apK89SJcY4fy7tP-rU3kpAAAAmk"] [Sat Aug 29 05:05:25.977568 2026] [security2:error] [pid 1017536:tid 1017714] [client 216.26.226.127:18323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.226.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK89SJcY4fy7tP-rU3koQAAAkQ"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:26.018979 2026] [security2:error] [pid 1017536:tid 1017740] [client 185.104.184.230:46028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK89iJcY4fy7tP-rU3kqAAAAl4"] [Sat Aug 29 05:05:26.019941 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.160.90:62711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/luuf.php"] [unique_id "apK89jAh5Y1i2tUxg4Hg6QAABco"] [Sat Aug 29 05:05:26.027080 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.23.147.79:24448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/classwithtostring.php"] [unique_id "apK89jAh5Y1i2tUxg4Hg6wAABcI"] [Sat Aug 29 05:05:26.032203 2026] [security2:error] [pid 1017536:tid 1017671] [client 158.158.54.35:15913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/ws.php"] [unique_id "apK89iJcY4fy7tP-rU3kqQAAAhk"] [Sat Aug 29 05:05:26.038342 2026] [security2:error] [pid 1017536:tid 1017777] [client 4.232.148.111:15669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/xxx.php"] [unique_id "apK89iJcY4fy7tP-rU3kqgAAAoM"] [Sat Aug 29 05:05:26.051891 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.48.251.3:27138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/god.php"] [unique_id "apK89iJcY4fy7tP-rU3krQAAAn0"] [Sat Aug 29 05:05:26.056751 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.63.81.20:26369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/222.php"] [unique_id "apK89iJcY4fy7tP-rU3krgAAAko"] [Sat Aug 29 05:05:26.061613 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.63.219.114:1937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/fi2.php"] [unique_id "apK89iJcY4fy7tP-rU3ksAAAAhY"] [Sat Aug 29 05:05:26.081656 2026] [security2:error] [pid 1017536:tid 1017748] [client 57.141.14.53:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK89iJcY4fy7tP-rU3ksgAAAmY"] [Sat Aug 29 05:05:26.082973 2026] [security2:error] [pid 1018003:tid 1018183] [client 168.107.94.195:61628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK89jAh5Y1i2tUxg4Hg7gAABdg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:26.085252 2026] [core:error] [pid 1018003:tid 1018184] [client 34.12.38.134:40406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.085264 2026] [core:error] [pid 1018003:tid 1018184] [client 34.12.38.134:40406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.088426 2026] [core:error] [pid 1017536:tid 1017781] [client 34.12.38.134:40420] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.088441 2026] [core:error] [pid 1017536:tid 1017781] [client 34.12.38.134:40420] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.088546 2026] [core:error] [pid 1017536:tid 1017674] [client 34.12.38.134:40452] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.088553 2026] [security2:error] [pid 1017536:tid 1017781] [client 34.12.38.134:40420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK89iJcY4fy7tP-rU3kswAAAoc"] [Sat Aug 29 05:05:26.088558 2026] [core:error] [pid 1017536:tid 1017674] [client 34.12.38.134:40452] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.090278 2026] [core:error] [pid 1017536:tid 1017688] [client 34.12.38.134:40414] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.090291 2026] [core:error] [pid 1017536:tid 1017688] [client 34.12.38.134:40414] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.095041 2026] [security2:error] [pid 1017536:tid 1017684] [client 34.12.38.134:40524] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/config/prod.exs"] [unique_id "apK89iJcY4fy7tP-rU3kuAAAAiY"] [Sat Aug 29 05:05:26.097529 2026] [core:error] [pid 1017536:tid 1017758] [client 34.12.38.134:40432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.097543 2026] [core:error] [pid 1017536:tid 1017758] [client 34.12.38.134:40432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.104656 2026] [core:error] [pid 1017536:tid 1017716] [client 34.12.38.134:40434] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.104675 2026] [core:error] [pid 1017536:tid 1017716] [client 34.12.38.134:40434] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.104869 2026] [core:error] [pid 1017536:tid 1017710] [client 34.12.38.134:40464] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.104880 2026] [core:error] [pid 1017536:tid 1017710] [client 34.12.38.134:40464] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.104884 2026] [core:error] [pid 1018003:tid 1018163] [client 34.12.38.134:40482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.104894 2026] [core:error] [pid 1018003:tid 1018163] [client 34.12.38.134:40482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.104958 2026] [core:error] [pid 1018003:tid 1018203] [client 34.12.38.134:40488] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.104965 2026] [core:error] [pid 1018003:tid 1018203] [client 34.12.38.134:40488] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.105544 2026] [core:error] [pid 1018003:tid 1018242] [client 34.12.38.134:40462] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.105549 2026] [core:error] [pid 1018003:tid 1018261] [client 34.12.38.134:40442] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.105558 2026] [core:error] [pid 1018003:tid 1018242] [client 34.12.38.134:40462] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.105563 2026] [core:error] [pid 1018003:tid 1018261] [client 34.12.38.134:40442] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.107882 2026] [security2:error] [pid 1018003:tid 1018164] [client 93.123.109.228:37382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK89jAh5Y1i2tUxg4Hg-wAABcU"] [Sat Aug 29 05:05:26.108651 2026] [security2:error] [pid 1017536:tid 1017716] [client 34.12.38.134:40434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK89iJcY4fy7tP-rU3kvAAAAkY"] [Sat Aug 29 05:05:26.108803 2026] [security2:error] [pid 1018003:tid 1018242] [client 34.12.38.134:40462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK89jAh5Y1i2tUxg4Hg8QAABhI"] [Sat Aug 29 05:05:26.109140 2026] [core:error] [pid 1017536:tid 1017776] [client 34.12.38.134:40474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.109151 2026] [core:error] [pid 1017536:tid 1017776] [client 34.12.38.134:40474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.115134 2026] [security2:error] [pid 1017536:tid 1017696] [client 34.12.38.134:40664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/instance/config.py"] [unique_id "apK89iJcY4fy7tP-rU3kygAAAjI"] [Sat Aug 29 05:05:26.121608 2026] [security2:error] [pid 1018003:tid 1018240] [client 74.248.24.12:25688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/f.php"] [unique_id "apK89jAh5Y1i2tUxg4HhBwAABhA"] [Sat Aug 29 05:05:26.122740 2026] [core:error] [pid 1018003:tid 1018226] [client 34.12.38.134:40648] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.122758 2026] [core:error] [pid 1018003:tid 1018226] [client 34.12.38.134:40648] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.125193 2026] [core:error] [pid 1018003:tid 1018188] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.125207 2026] [core:error] [pid 1018003:tid 1018188] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.126158 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:62761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-content/packed.php"] [unique_id "apK89iJcY4fy7tP-rU3k0QAAAkc"] [Sat Aug 29 05:05:26.127183 2026] [core:error] [pid 1018003:tid 1018223] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.127197 2026] [core:error] [pid 1018003:tid 1018223] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.128281 2026] [core:error] [pid 1017536:tid 1017739] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.130891 2026] [core:error] [pid 1017536:tid 1017695] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.130904 2026] [core:error] [pid 1017536:tid 1017695] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.130906 2026] [core:error] [pid 1017536:tid 1017739] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.132930 2026] [core:error] [pid 1017536:tid 1017787] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.132949 2026] [core:error] [pid 1017536:tid 1017787] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.133608 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.63.219.114:11949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/OK.php"] [unique_id "apK89iJcY4fy7tP-rU3k1AAAAmI"] [Sat Aug 29 05:05:26.138832 2026] [core:error] [pid 1018003:tid 1018212] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.138846 2026] [core:error] [pid 1018003:tid 1018212] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.143497 2026] [core:error] [pid 1017536:tid 1017692] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.143514 2026] [core:error] [pid 1017536:tid 1017692] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.144790 2026] [core:error] [pid 1018003:tid 1018218] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.144807 2026] [core:error] [pid 1018003:tid 1018218] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.144854 2026] [core:error] [pid 1017536:tid 1017765] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.144865 2026] [core:error] [pid 1017536:tid 1017765] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.145230 2026] [core:error] [pid 1018003:tid 1018211] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.145241 2026] [core:error] [pid 1018003:tid 1018211] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.146003 2026] [security2:error] [pid 1017536:tid 1017698] [client 68.155.159.216:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-l0gin.php"] [unique_id "apK89iJcY4fy7tP-rU3k2AAAAjQ"] [Sat Aug 29 05:05:26.146137 2026] [core:error] [pid 1018003:tid 1018253] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.146146 2026] [core:error] [pid 1018003:tid 1018253] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.147425 2026] [core:error] [pid 1017536:tid 1017788] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.147437 2026] [core:error] [pid 1017536:tid 1017788] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.147448 2026] [core:error] [pid 1018003:tid 1018233] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.147456 2026] [core:error] [pid 1018003:tid 1018233] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.147483 2026] [core:error] [pid 1018003:tid 1018243] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.147492 2026] [core:error] [pid 1018003:tid 1018243] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.158186 2026] [core:error] [pid 1017536:tid 1017783] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.158200 2026] [core:error] [pid 1017536:tid 1017783] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.158247 2026] [core:error] [pid 1017536:tid 1017745] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.158255 2026] [core:error] [pid 1017536:tid 1017745] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.159089 2026] [security2:error] [pid 1017536:tid 1017745] [client 34.12.38.134:0] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK89iJcY4fy7tP-rU3k2gAAAmM"] [Sat Aug 29 05:05:26.160100 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.196.209.81:15140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/alfanew.php7"] [unique_id "apK89jAh5Y1i2tUxg4HhEwAABgI"] [Sat Aug 29 05:05:26.160717 2026] [security2:error] [pid 1018003:tid 1018249] [client 34.12.38.134:40528] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/config/storage.yml"] [unique_id "apK89jAh5Y1i2tUxg4Hg-AAABhk"] [Sat Aug 29 05:05:26.165320 2026] [security2:error] [pid 1018003:tid 1018157] [client 162.198.206.205:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK89jAh5Y1i2tUxg4HhFQAABb4"], referer: http://www.baidu.com/ [Sat Aug 29 05:05:26.166164 2026] [core:error] [pid 1018003:tid 1018274] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.166177 2026] [core:error] [pid 1018003:tid 1018274] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:26.179127 2026] [security2:error] [pid 1017536:tid 1017721] [client 4.205.62.107:64266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/oc460l3x.php"] [unique_id "apK89iJcY4fy7tP-rU3k2wAAAks"] [Sat Aug 29 05:05:26.181872 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.251.3:27139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/fff.php"] [unique_id "apK89iJcY4fy7tP-rU3k3AAAAkE"] [Sat Aug 29 05:05:26.185445 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.63.81.20:26469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/ops.php"] [unique_id "apK89iJcY4fy7tP-rU3k3QAAAlg"] [Sat Aug 29 05:05:26.207016 2026] [security2:error] [pid 1017536:tid 1017761] [client 74.248.24.12:25416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-content/file.php"] [unique_id "apK89iJcY4fy7tP-rU3k3gAAAnM"] [Sat Aug 29 05:05:26.209897 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.63.219.114:1483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/gecko-new.php"] [unique_id "apK89iJcY4fy7tP-rU3k3wAAAiA"] [Sat Aug 29 05:05:26.220631 2026] [security2:error] [pid 1017536:tid 1017713] [client 4.205.62.107:53377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/paths.php"] [unique_id "apK89iJcY4fy7tP-rU3k4AAAAkM"] [Sat Aug 29 05:05:26.225071 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.160.90:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/fex.php"] [unique_id "apK89iJcY4fy7tP-rU3k4QAAAjk"] [Sat Aug 29 05:05:26.285449 2026] [security2:error] [pid 1017536:tid 1017668] [client 4.205.62.107:22508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/pinfo.php"] [unique_id "apK89iJcY4fy7tP-rU3k4gAAAhY"] [Sat Aug 29 05:05:26.323884 2026] [security2:error] [pid 1018003:tid 1018216] [client 185.104.184.230:46054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK89jAh5Y1i2tUxg4HhFwAABfk"] [Sat Aug 29 05:05:26.328924 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.251.3:27175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/autogooey.php"] [unique_id "apK89jAh5Y1i2tUxg4HhGAAABeU"] [Sat Aug 29 05:05:26.349503 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.63.81.20:26539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK89iJcY4fy7tP-rU3k5QAAAj0"] [Sat Aug 29 05:05:26.358970 2026] [security2:error] [pid 1017536:tid 1017751] [client 4.232.148.111:19425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/av.php"] [unique_id "apK89iJcY4fy7tP-rU3k5gAAAmk"] [Sat Aug 29 05:05:26.359068 2026] [security2:error] [pid 1018003:tid 1018197] [client 158.23.147.79:23384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK89jAh5Y1i2tUxg4HhGQAABeY"] [Sat Aug 29 05:05:26.367302 2026] [security2:error] [pid 1018003:tid 1018181] [client 158.23.147.79:48128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/about.php"] [unique_id "apK89jAh5Y1i2tUxg4HhGgAABdY"] [Sat Aug 29 05:05:26.378571 2026] [security2:error] [pid 1017536:tid 1017728] [client 20.196.209.81:4536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/spip.php"] [unique_id "apK89iJcY4fy7tP-rU3k5wAAAlI"] [Sat Aug 29 05:05:26.386439 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.196.209.81:17625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/content.php"] [unique_id "apK89iJcY4fy7tP-rU3k6AAAAl8"] [Sat Aug 29 05:05:26.387374 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.160.90:64762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/l.php"] [unique_id "apK89iJcY4fy7tP-rU3k6QAAAjE"] [Sat Aug 29 05:05:26.391515 2026] [security2:error] [pid 1017536:tid 1017548] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "proppastie.com"] [uri "/wp-config.php.old"] [unique_id "apK89iJcY4fy7tP-rU3k6gACXQs"] [Sat Aug 29 05:05:26.394042 2026] [security2:error] [pid 1017536:tid 1017664] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "proppastie.com"] [uri "/wp-config.php.bak"] [unique_id "apK89iJcY4fy7tP-rU3k6wACb38"] [Sat Aug 29 05:05:26.396164 2026] [security2:error] [pid 1017536:tid 1017583] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/@fs/.env"] [unique_id "apK89iJcY4fy7tP-rU3k7AACby4"] [Sat Aug 29 05:05:26.396240 2026] [security2:error] [pid 1017536:tid 1017604] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/@fs/.env"] [unique_id "apK89iJcY4fy7tP-rU3k7gACb0M"] [Sat Aug 29 05:05:26.396713 2026] [security2:error] [pid 1017536:tid 1017643] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/@fs/.env"] [unique_id "apK89iJcY4fy7tP-rU3k7wACb2o"] [Sat Aug 29 05:05:26.413636 2026] [security2:error] [pid 1017536:tid 1017774] [client 93.123.109.228:37312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK89iJcY4fy7tP-rU3k8AAAAoA"] [Sat Aug 29 05:05:26.431088 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.147.79:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK89iJcY4fy7tP-rU3k8wAAAh0"] [Sat Aug 29 05:05:26.440507 2026] [security2:error] [pid 1018003:tid 1018179] [client 68.155.159.216:51853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/lv.php"] [unique_id "apK89jAh5Y1i2tUxg4HhHgAABdQ"] [Sat Aug 29 05:05:26.448908 2026] [security2:error] [pid 1018003:tid 1018185] [client 68.155.159.216:24530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK89jAh5Y1i2tUxg4HhHwAABdo"] [Sat Aug 29 05:05:26.459450 2026] [security2:error] [pid 1017536:tid 1017753] [client 4.205.62.107:21920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/fleen.php"] [unique_id "apK89iJcY4fy7tP-rU3k-AAAAms"] [Sat Aug 29 05:05:26.459474 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.251.3:57869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/sdsa.php"] [unique_id "apK89iJcY4fy7tP-rU3k9wAAAos"] [Sat Aug 29 05:05:26.463778 2026] [security2:error] [pid 1018003:tid 1018247] [client 168.107.94.195:62016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK89jAh5Y1i2tUxg4HhIAAABhc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:26.464507 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.158.54.35:10851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-themes.php"] [unique_id "apK89iJcY4fy7tP-rU3k-QAAAoI"] [Sat Aug 29 05:05:26.479972 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.63.81.20:26458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK89jAh5Y1i2tUxg4HhIgAABhU"] [Sat Aug 29 05:05:26.493570 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.63.219.114:16531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "compropolis.mx"] [uri "/aaa.php"] [unique_id "apK89iJcY4fy7tP-rU3k_QAAAlA"] [Sat Aug 29 05:05:26.498494 2026] [security2:error] [pid 1018003:tid 1018187] [client 4.205.62.107:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK89jAh5Y1i2tUxg4HhJAAABdw"] [Sat Aug 29 05:05:26.523350 2026] [security2:error] [pid 1018003:tid 1018180] [client 45.3.34.159:22577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK89jAh5Y1i2tUxg4HhIwAABdU"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:26.525953 2026] [security2:error] [pid 1017536:tid 1017782] [client 4.205.62.107:2634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/loxi-o.php"] [unique_id "apK89iJcY4fy7tP-rU3lAAAAAog"] [Sat Aug 29 05:05:26.527477 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.48.160.90:28624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/xr.php"] [unique_id "apK89jAh5Y1i2tUxg4HhJgAABfg"] [Sat Aug 29 05:05:26.553300 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.196.209.81:9485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/xmlrpc.php0"] [unique_id "apK89iJcY4fy7tP-rU3lAgAAApM"] [Sat Aug 29 05:05:26.570397 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.63.219.114:14550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/wp-admin.php"] [unique_id "apK89iJcY4fy7tP-rU3lAwAAAic"] [Sat Aug 29 05:05:26.570672 2026] [security2:error] [pid 1018003:tid 1018220] [client 20.63.219.114:14577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/1p.php"] [unique_id "apK89jAh5Y1i2tUxg4HhKQAABf0"] [Sat Aug 29 05:05:26.573491 2026] [security2:error] [pid 1018003:tid 1018260] [client 93.123.109.228:37260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/admin/phpinfo.php"] [unique_id "apK89jAh5Y1i2tUxg4HhKgAABiQ"] [Sat Aug 29 05:05:26.594448 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.251.3:28443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/sale.php"] [unique_id "apK89jAh5Y1i2tUxg4HhLAAABgM"] [Sat Aug 29 05:05:26.608925 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.63.81.20:26388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/f.php"] [unique_id "apK89iJcY4fy7tP-rU3lBgAAAjk"] [Sat Aug 29 05:05:26.611125 2026] [security2:error] [pid 1017536:tid 1017619] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/core/.env"] [unique_id "apK89iJcY4fy7tP-rU3lBwACNlI"] [Sat Aug 29 05:05:26.624119 2026] [security2:error] [pid 1017536:tid 1017714] [client 192.145.125.70:35424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK89iJcY4fy7tP-rU3lCAAAAkQ"] [Sat Aug 29 05:05:26.635065 2026] [security2:error] [pid 1018003:tid 1018170] [client 74.248.24.12:3407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/av.php"] [unique_id "apK89jAh5Y1i2tUxg4HhLQAABcs"] [Sat Aug 29 05:05:26.640315 2026] [security2:error] [pid 1017536:tid 1017681] [client 185.104.184.230:46064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK89iJcY4fy7tP-rU3lCgAAAiM"] [Sat Aug 29 05:05:26.646478 2026] [security2:error] [pid 1017536:tid 1017686] [client 93.123.109.228:37264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK89iJcY4fy7tP-rU3lDAAAAig"] [Sat Aug 29 05:05:26.646950 2026] [security2:error] [pid 1018003:tid 1018223] [client 93.123.109.228:37250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/admin_phpinfo.php"] [unique_id "apK89jAh5Y1i2tUxg4HhLgAABgA"] [Sat Aug 29 05:05:26.678519 2026] [security2:error] [pid 1018003:tid 1018265] [client 93.123.109.228:37254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK89jAh5Y1i2tUxg4HhLwAABik"] [Sat Aug 29 05:05:26.687006 2026] [security2:error] [pid 1018003:tid 1018250] [client 93.123.109.228:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK89jAh5Y1i2tUxg4HhMAAABho"] [Sat Aug 29 05:05:26.688797 2026] [security2:error] [pid 1017536:tid 1017680] [client 158.23.147.79:25560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK89iJcY4fy7tP-rU3lDwAAAiI"] [Sat Aug 29 05:05:26.710452 2026] [security2:error] [pid 1017536:tid 1017720] [client 93.123.109.228:37338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK89iJcY4fy7tP-rU3lEQAAAko"] [Sat Aug 29 05:05:26.716710 2026] [security2:error] [pid 1017536:tid 1017755] [client 185.104.184.230:46040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK89iJcY4fy7tP-rU3lEgAAAm0"] [Sat Aug 29 05:05:26.735794 2026] [security2:error] [pid 1017536:tid 1017778] [client 34.21.253.104:28288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/.env.production"] [unique_id "apK89iJcY4fy7tP-rU3lFQAAAoQ"] [Sat Aug 29 05:05:26.739444 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.160.90:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/Q3.php"] [unique_id "apK89iJcY4fy7tP-rU3lGAAAAmY"] [Sat Aug 29 05:05:26.742049 2026] [proxy_http:error] [pid 1018003:tid 1018195] (20014)Internal error (specific information not available): [client 34.21.253.104:28300] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.742064 2026] [proxy:error] [pid 1018003:tid 1018195] [client 34.21.253.104:28300] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.aws/credentials [Sat Aug 29 05:05:26.742570 2026] [proxy_http:error] [pid 1017536:tid 1017715] (20014)Internal error (specific information not available): [client 34.21.253.104:28158] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.742583 2026] [proxy:error] [pid 1017536:tid 1017715] [client 34.21.253.104:28158] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.env [Sat Aug 29 05:05:26.742941 2026] [security2:error] [pid 1017536:tid 1017729] [client 34.21.253.104:28182] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.replenishink.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK89iJcY4fy7tP-rU3lGwAAAlM"] [Sat Aug 29 05:05:26.743173 2026] [security2:error] [pid 1017536:tid 1017672] [client 34.21.253.104:28330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/home/node/.aws/config"] [unique_id "apK89iJcY4fy7tP-rU3lHAAAAho"] [Sat Aug 29 05:05:26.747221 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.63.81.20:26498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.harnessrenewables.com"] [uri "/1dfcd2d08f.php"] [unique_id "apK89jAh5Y1i2tUxg4HhNQAABfU"] [Sat Aug 29 05:05:26.747560 2026] [security2:error] [pid 1017536:tid 1017756] [client 34.21.253.104:28222] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.replenishink.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK89iJcY4fy7tP-rU3lHwAAAm4"] [Sat Aug 29 05:05:26.748501 2026] [core:error] [pid 1018003:tid 1018255] [client 34.21.253.104:28252] AH10244: invalid URI path (/@fs/../../.env?raw??) [Sat Aug 29 05:05:26.755804 2026] [proxy_http:error] [pid 1018003:tid 1018255] (20014)Internal error (specific information not available): [client 34.21.253.104:28252] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.755818 2026] [proxy:error] [pid 1018003:tid 1018255] [client 34.21.253.104:28252] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/400.shtml [Sat Aug 29 05:05:26.760924 2026] [proxy_http:error] [pid 1018003:tid 1018164] (20014)Internal error (specific information not available): [client 34.21.253.104:28260] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.760935 2026] [proxy:error] [pid 1018003:tid 1018164] [client 34.21.253.104:28260] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/app/rootkey.csv [Sat Aug 29 05:05:26.761163 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.251.3:57916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-class.php"] [unique_id "apK89iJcY4fy7tP-rU3lKgAAApI"] [Sat Aug 29 05:05:26.765107 2026] [security2:error] [pid 1017536:tid 1017706] [client 34.21.253.104:28402] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/var/www/.aws/credentials"] [unique_id "apK89iJcY4fy7tP-rU3lLQAAAjw"] [Sat Aug 29 05:05:26.765950 2026] [proxy_http:error] [pid 1018003:tid 1018261] (20014)Internal error (specific information not available): [client 34.21.253.104:28360] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.765959 2026] [proxy:error] [pid 1018003:tid 1018261] [client 34.21.253.104:28360] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ubuntu/.aws/config [Sat Aug 29 05:05:26.770522 2026] [security2:error] [pid 1017536:tid 1017585] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.108.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proppastie.com"] [uri "/config.php.bak"] [unique_id "apK89iJcY4fy7tP-rU3lJgACZDA"] [Sat Aug 29 05:05:26.771170 2026] [proxy_http:error] [pid 1018003:tid 1018164] (20014)Internal error (specific information not available): [client 34.21.253.104:28260] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.771180 2026] [proxy:error] [pid 1018003:tid 1018164] [client 34.21.253.104:28260] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:05:26.771755 2026] [security2:error] [pid 1017536:tid 1017761] [client 74.248.24.12:33199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/files.php"] [unique_id "apK89iJcY4fy7tP-rU3lLgAAAnM"] [Sat Aug 29 05:05:26.773519 2026] [security2:error] [pid 1017536:tid 1017674] [client 68.155.159.216:58272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/goat1.php"] [unique_id "apK89iJcY4fy7tP-rU3lLwAAAhw"] [Sat Aug 29 05:05:26.773543 2026] [security2:error] [pid 1017536:tid 1017600] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.108.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proppastie.com"] [uri "/configuration.php.bak"] [unique_id "apK89iJcY4fy7tP-rU3lMAACYT8"] [Sat Aug 29 05:05:26.779322 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.196.209.81:4694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/core.php"] [unique_id "apK89iJcY4fy7tP-rU3lMQAAAl4"] [Sat Aug 29 05:05:26.781525 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.196.209.81:10727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/backup.php"] [unique_id "apK89iJcY4fy7tP-rU3lMgAAAjA"] [Sat Aug 29 05:05:26.815133 2026] [security2:error] [pid 1017536:tid 1017707] [client 68.155.159.216:12253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/uploads/about.php"] [unique_id "apK89iJcY4fy7tP-rU3lNAAAAj0"] [Sat Aug 29 05:05:26.823984 2026] [security2:error] [pid 1017536:tid 1017545] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.108.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proppastie.com"] [uri "/.env.php.bak"] [unique_id "apK89iJcY4fy7tP-rU3lNgACXwg"] [Sat Aug 29 05:05:26.835514 2026] [security2:error] [pid 1017536:tid 1017580] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.108.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proppastie.com"] [uri "/config/.env.php"] [unique_id "apK89iJcY4fy7tP-rU3lNwACeys"] [Sat Aug 29 05:05:26.836037 2026] [security2:error] [pid 1017536:tid 1017631] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/laravel/.env"] [unique_id "apK89iJcY4fy7tP-rU3lOAACe14"] [Sat Aug 29 05:05:26.843005 2026] [security2:error] [pid 1017536:tid 1017787] [client 168.107.94.195:62328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK89iJcY4fy7tP-rU3lOQAAAo0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:26.848536 2026] [security2:error] [pid 1017536:tid 1017727] [client 4.232.148.111:24067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/tool.php"] [unique_id "apK89iJcY4fy7tP-rU3lOgAAAlE"] [Sat Aug 29 05:05:26.857007 2026] [proxy_http:error] [pid 1017536:tid 1017745] (20014)Internal error (specific information not available): [client 34.21.253.104:28310] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.857018 2026] [proxy:error] [pid 1017536:tid 1017745] [client 34.21.253.104:28310] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.aws/config [Sat Aug 29 05:05:26.862677 2026] [security2:error] [pid 1017536:tid 1017779] [client 4.232.148.111:8560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/file.php"] [unique_id "apK89iJcY4fy7tP-rU3lPAAAAoU"] [Sat Aug 29 05:05:26.871309 2026] [proxy_http:error] [pid 1017536:tid 1017783] (20014)Internal error (specific information not available): [client 34.21.253.104:28240] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.871329 2026] [proxy:error] [pid 1017536:tid 1017783] [client 34.21.253.104:28240] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env [Sat Aug 29 05:05:26.884544 2026] [proxy_http:error] [pid 1017536:tid 1017689] (20014)Internal error (specific information not available): [client 34.21.253.104:28316] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.884558 2026] [proxy:error] [pid 1017536:tid 1017689] [client 34.21.253.104:28316] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.aws/credentials.bak [Sat Aug 29 05:05:26.890105 2026] [proxy_http:error] [pid 1017536:tid 1017730] (20014)Internal error (specific information not available): [client 34.21.253.104:28352] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.890120 2026] [proxy:error] [pid 1017536:tid 1017730] [client 34.21.253.104:28352] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ec2-user/.aws/credentials [Sat Aug 29 05:05:26.890330 2026] [security2:error] [pid 1018003:tid 1018177] [client 68.155.159.216:33586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK89jAh5Y1i2tUxg4HhPgAABdI"] [Sat Aug 29 05:05:26.892711 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.48.251.3:28469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/database.php"] [unique_id "apK89jAh5Y1i2tUxg4HhPwAABg8"] [Sat Aug 29 05:05:26.896490 2026] [proxy_http:error] [pid 1017536:tid 1017679] (20014)Internal error (specific information not available): [client 34.21.253.104:28362] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.896499 2026] [proxy:error] [pid 1017536:tid 1017679] [client 34.21.253.104:28362] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/admin/.aws/credentials [Sat Aug 29 05:05:26.902544 2026] [proxy_http:error] [pid 1017536:tid 1017711] (20014)Internal error (specific information not available): [client 34.21.253.104:28380] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.902554 2026] [proxy:error] [pid 1017536:tid 1017711] [client 34.21.253.104:28380] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/debian/.aws/credentials [Sat Aug 29 05:05:26.909548 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.158.54.35:10829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-trackback.php"] [unique_id "apK89iJcY4fy7tP-rU3lQAAAAls"] [Sat Aug 29 05:05:26.911953 2026] [access_compat:error] [pid 1018003:tid 1018200] [client 67.20.76.220:22258] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:26.916552 2026] [proxy_http:error] [pid 1017536:tid 1017754] (20014)Internal error (specific information not available): [client 34.21.253.104:28394] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:26.916567 2026] [proxy:error] [pid 1017536:tid 1017754] [client 34.21.253.104:28394] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/www-data/.aws/credentials [Sat Aug 29 05:05:26.922560 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.48.160.90:62609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/Q1.php"] [unique_id "apK89jAh5Y1i2tUxg4HhQQAABfc"] [Sat Aug 29 05:05:26.927670 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.63.219.114:11841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/wp-configs.php"] [unique_id "apK89iJcY4fy7tP-rU3lQwAAAmU"] [Sat Aug 29 05:05:26.935537 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.63.219.114:1443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/Njima.php"] [unique_id "apK89iJcY4fy7tP-rU3lRAAAAhg"] [Sat Aug 29 05:05:26.948535 2026] [security2:error] [pid 1018003:tid 1018152] [client 68.155.159.216:16371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/Text/about.php"] [unique_id "apK89jAh5Y1i2tUxg4HhQwAABbk"] [Sat Aug 29 05:05:26.951272 2026] [security2:error] [pid 1018003:tid 1018234] [client 185.104.184.230:46066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK89jAh5Y1i2tUxg4HhRAAABgo"] [Sat Aug 29 05:05:26.987852 2026] [security2:error] [pid 1018003:tid 1018274] [client 93.123.109.228:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/api/info.php"] [unique_id "apK89jAh5Y1i2tUxg4HhSAAABjI"] [Sat Aug 29 05:05:27.011593 2026] [security2:error] [pid 1017536:tid 1017703] [client 185.104.184.230:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.mcdcomputers.net"] [uri "/xmlrpc.php"] [unique_id "apK89yJcY4fy7tP-rU3lRwAAAjk"] [Sat Aug 29 05:05:27.024233 2026] [security2:error] [pid 1017536:tid 1017700] [client 68.155.159.216:62870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/images/index.php"] [unique_id "apK89yJcY4fy7tP-rU3lSAAAAjY"] [Sat Aug 29 05:05:27.035711 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.251.3:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/atex1.php"] [unique_id "apK89yJcY4fy7tP-rU3lSQAAAkQ"] [Sat Aug 29 05:05:27.048238 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.104.49.130:58190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/f35.update.php"] [unique_id "apK89yJcY4fy7tP-rU3lSwAAAi8"] [Sat Aug 29 05:05:27.073446 2026] [security2:error] [pid 1018003:tid 1018221] [client 93.123.109.228:37252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/api/phpinfo.php"] [unique_id "apK89zAh5Y1i2tUxg4HhTAAABf4"] [Sat Aug 29 05:05:27.089382 2026] [security2:error] [pid 1018003:tid 1018172] [client 65.111.14.131:37723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.14.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK89zAh5Y1i2tUxg4HhSgAABc0"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:27.091347 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.48.160.90:63530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/nz.php"] [unique_id "apK89yJcY4fy7tP-rU3lUAAAAn0"] [Sat Aug 29 05:05:27.137223 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.147.79:24495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/install.php"] [unique_id "apK89yJcY4fy7tP-rU3lUgAAAlo"] [Sat Aug 29 05:05:27.149650 2026] [security2:error] [pid 1017536:tid 1017738] [client 74.248.24.12:21314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/file.php"] [unique_id "apK89yJcY4fy7tP-rU3lUwAAAlw"] [Sat Aug 29 05:05:27.157233 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.196.209.81:25027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/content.php"] [unique_id "apK89yJcY4fy7tP-rU3lVAAAAm8"] [Sat Aug 29 05:05:27.171147 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.196.209.81:10625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/db-status.php"] [unique_id "apK89zAh5Y1i2tUxg4HhTwAABgs"] [Sat Aug 29 05:05:27.176805 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.48.251.3:28476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws_sdk_settings.php"] [unique_id "apK89yJcY4fy7tP-rU3lVgAAAio"] [Sat Aug 29 05:05:27.182419 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.196.209.81:4535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/haiterus.php"] [unique_id "apK89yJcY4fy7tP-rU3lVwAAAig"] [Sat Aug 29 05:05:27.187020 2026] [security2:error] [pid 1018003:tid 1018275] [client 4.205.62.107:61111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/file59.php"] [unique_id "apK89zAh5Y1i2tUxg4HhUAAABjM"] [Sat Aug 29 05:05:27.192042 2026] [security2:error] [pid 1017536:tid 1017611] [remote 74.7.227.189:52570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pinnacleforms.com"] [uri "/SandBox1.php"] [unique_id "apK89yJcY4fy7tP-rU3lWAACZko"], referer: https://mail.pinnacleforms.com/ [Sat Aug 29 05:05:27.227897 2026] [security2:error] [pid 1017536:tid 1017694] [client 168.107.94.195:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK89yJcY4fy7tP-rU3lWQAAAjA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:27.230054 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.48.160.90:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/sg.php"] [unique_id "apK89zAh5Y1i2tUxg4HhUQAABiE"] [Sat Aug 29 05:05:27.237446 2026] [security2:error] [pid 1017536:tid 1017684] [client 158.23.147.79:55883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-l0gin.php"] [unique_id "apK89yJcY4fy7tP-rU3lWwAAAiY"] [Sat Aug 29 05:05:27.237487 2026] [security2:error] [pid 1017536:tid 1017732] [client 192.145.125.70:35426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK89yJcY4fy7tP-rU3lWgAAAlY"] [Sat Aug 29 05:05:27.255442 2026] [security2:error] [pid 1017536:tid 1017752] [client 185.104.184.230:46088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK89yJcY4fy7tP-rU3lXgAAAmo"] [Sat Aug 29 05:05:27.284132 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.63.219.114:11849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/essexec.php"] [unique_id "apK89yJcY4fy7tP-rU3lXwAAAk4"] [Sat Aug 29 05:05:27.288953 2026] [security2:error] [pid 1017536:tid 1017790] [client 74.248.24.12:31552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/o.php"] [unique_id "apK89yJcY4fy7tP-rU3lYAAAApA"] [Sat Aug 29 05:05:27.293686 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.104.49.130:51111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/tiny2.php"] [unique_id "apK89zAh5Y1i2tUxg4HhVQAABjQ"] [Sat Aug 29 05:05:27.294870 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.104.62:22671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK89yJcY4fy7tP-rU3lYQAAAjE"] [Sat Aug 29 05:05:27.314071 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.251.3:28466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/setup-config.php"] [unique_id "apK89zAh5Y1i2tUxg4HhVwAABfY"] [Sat Aug 29 05:05:27.315017 2026] [security2:error] [pid 1018003:tid 1018206] [client 52.139.37.240:24891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/defaults.php"] [unique_id "apK89zAh5Y1i2tUxg4HhWAAABe8"] [Sat Aug 29 05:05:27.315089 2026] [security2:error] [pid 1018003:tid 1018251] [client 4.205.62.107:64252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/drykl.php"] [unique_id "apK89zAh5Y1i2tUxg4HhWQAABhs"] [Sat Aug 29 05:05:27.315692 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.63.219.114:7454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/configs.php"] [unique_id "apK89yJcY4fy7tP-rU3lZQAAAhw"] [Sat Aug 29 05:05:27.325059 2026] [security2:error] [pid 1017536:tid 1017781] [client 4.232.148.111:35077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/k.php"] [unique_id "apK89yJcY4fy7tP-rU3laAAAAoc"] [Sat Aug 29 05:05:27.327068 2026] [security2:error] [pid 1017536:tid 1017727] [client 68.155.159.216:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/xmlrpc.php"] [unique_id "apK89yJcY4fy7tP-rU3laQAAAlE"] [Sat Aug 29 05:05:27.329151 2026] [security2:error] [pid 1017536:tid 1017634] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/public/.env"] [unique_id "apK89yJcY4fy7tP-rU3lagACjWE"] [Sat Aug 29 05:05:27.331246 2026] [security2:error] [pid 1017536:tid 1017646] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/web/.env"] [unique_id "apK89yJcY4fy7tP-rU3lawACSW0"] [Sat Aug 29 05:05:27.366995 2026] [security2:error] [pid 1017536:tid 1017667] [client 93.123.109.228:37302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK89yJcY4fy7tP-rU3lbwAAAhU"] [Sat Aug 29 05:05:27.385346 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.48.160.90:64659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/hypo.php"] [unique_id "apK89zAh5Y1i2tUxg4HhWwAABeg"] [Sat Aug 29 05:05:27.392269 2026] [security2:error] [pid 1017536:tid 1017786] [client 60.243.207.176:49892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK89yJcY4fy7tP-rU3lcwAAAow"] [Sat Aug 29 05:05:27.392365 2026] [security2:error] [pid 1017536:tid 1017786] [client 60.243.207.176:49892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK89yJcY4fy7tP-rU3lcwAAAow"] [Sat Aug 29 05:05:27.407308 2026] [security2:error] [pid 1017536:tid 1017735] [client 213.202.253.4:56570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/memberfuns.php"] [unique_id "apK89yJcY4fy7tP-rU3ldAAAAlk"], referer: www.google.com [Sat Aug 29 05:05:27.416119 2026] [security2:error] [pid 1017536:tid 1017577] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/storage/.env"] [unique_id "apK89yJcY4fy7tP-rU3ldQACSyg"] [Sat Aug 29 05:05:27.418457 2026] [security2:error] [pid 1017536:tid 1017570] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/.env.swp"] [unique_id "apK89yJcY4fy7tP-rU3ldgACSyE"] [Sat Aug 29 05:05:27.425545 2026] [security2:error] [pid 1018003:tid 1018247] [client 4.205.62.107:22362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/admin-ajax.php"] [unique_id "apK89zAh5Y1i2tUxg4HhXgAABhc"] [Sat Aug 29 05:05:27.429376 2026] [security2:error] [pid 1017536:tid 1017710] [client 197.219.150.206:56345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK89yJcY4fy7tP-rU3ldwAAAkA"] [Sat Aug 29 05:05:27.429429 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.104.62:41604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK89zAh5Y1i2tUxg4HhXwAABhY"] [Sat Aug 29 05:05:27.429517 2026] [security2:error] [pid 1017536:tid 1017710] [client 197.219.150.206:56345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK89yJcY4fy7tP-rU3ldwAAAkA"] [Sat Aug 29 05:05:27.446958 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.48.251.3:28446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-admin/sc.php"] [unique_id "apK89zAh5Y1i2tUxg4HhYgAABeM"] [Sat Aug 29 05:05:27.447104 2026] [security2:error] [pid 1017536:tid 1017785] [client 52.139.37.240:21434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK89yJcY4fy7tP-rU3leQAAAos"] [Sat Aug 29 05:05:27.450855 2026] [security2:error] [pid 1017536:tid 1017747] [client 93.123.109.228:37352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK89yJcY4fy7tP-rU3legAAAmU"] [Sat Aug 29 05:05:27.474563 2026] [security2:error] [pid 1017536:tid 1017689] [client 158.23.147.79:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/log-mama/function.php"] [unique_id "apK89yJcY4fy7tP-rU3lewAAAis"] [Sat Aug 29 05:05:27.475555 2026] [security2:error] [pid 1017536:tid 1017730] [client 158.23.147.79:48312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/uploads/index.php"] [unique_id "apK89yJcY4fy7tP-rU3lfAAAAlQ"] [Sat Aug 29 05:05:27.489369 2026] [security2:error] [pid 1017536:tid 1017754] [client 4.205.62.107:53371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/css.php"] [unique_id "apK89yJcY4fy7tP-rU3lfQAAAmw"] [Sat Aug 29 05:05:27.507715 2026] [autoindex:error] [pid 1017536:tid 1017743] [client 91.92.47.191:48204] AH01276: Cannot serve directory /home3/xqqkkxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://xqq.kkx.mybluehost.me [Sat Aug 29 05:05:27.511182 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.158.54.35:15906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/222.php"] [unique_id "apK89yJcY4fy7tP-rU3lfwAAAnc"] [Sat Aug 29 05:05:27.515548 2026] [security2:error] [pid 1017536:tid 1017691] [client 52.139.37.240:24639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/domains.php"] [unique_id "apK89yJcY4fy7tP-rU3lgAAAAi0"] [Sat Aug 29 05:05:27.523991 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.232.148.111:24810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK89yJcY4fy7tP-rU3lgQAAAh0"] [Sat Aug 29 05:05:27.550228 2026] [security2:error] [pid 1017536:tid 1017767] [client 34.7.216.49:36876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/.git/config"] [unique_id "apK89yJcY4fy7tP-rU3lhQAAAnk"] [Sat Aug 29 05:05:27.553110 2026] [security2:error] [pid 1017536:tid 1017703] [client 185.104.184.230:46094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.erv.dib.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK89yJcY4fy7tP-rU3lhgAAAjk"] [Sat Aug 29 05:05:27.560658 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.104.104.62:41602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/baee.php"] [unique_id "apK89yJcY4fy7tP-rU3liAAAAkQ"] [Sat Aug 29 05:05:27.569789 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.196.209.81:10659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK89zAh5Y1i2tUxg4HhaAAABfg"] [Sat Aug 29 05:05:27.570009 2026] [security2:error] [pid 1018003:tid 1018245] [client 34.7.216.49:36920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/.aws/credentials"] [unique_id "apK89zAh5Y1i2tUxg4HhaQAABhU"] [Sat Aug 29 05:05:27.575926 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.48.251.3:57873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/debug.php"] [unique_id "apK89yJcY4fy7tP-rU3liwAAAjg"] [Sat Aug 29 05:05:27.592842 2026] [security2:error] [pid 1017536:tid 1017680] [client 68.155.159.216:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK89yJcY4fy7tP-rU3lkAAAAiI"] [Sat Aug 29 05:05:27.599728 2026] [security2:error] [pid 1017536:tid 1017771] [client 4.205.62.107:21569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/phpinfo01.php"] [unique_id "apK89yJcY4fy7tP-rU3lkwAAAn0"] [Sat Aug 29 05:05:27.600519 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.196.209.81:4995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/wxo.php"] [unique_id "apK89yJcY4fy7tP-rU3llAAAAhg"] [Sat Aug 29 05:05:27.608271 2026] [security2:error] [pid 1018003:tid 1018170] [client 168.107.94.195:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK89zAh5Y1i2tUxg4HhbAAABcs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:27.614092 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.18.15:8186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK89zAh5Y1i2tUxg4HhbQAABd0"] [Sat Aug 29 05:05:27.629026 2026] [security2:error] [pid 1017536:tid 1017624] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "proppastie.com"] [uri "/wp-config.php~"] [unique_id "apK89yJcY4fy7tP-rU3lmwACWlc"] [Sat Aug 29 05:05:27.631796 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.160.90:63571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/Hd.php"] [unique_id "apK89yJcY4fy7tP-rU3lnQAAAho"] [Sat Aug 29 05:05:27.635676 2026] [security2:error] [pid 1017536:tid 1017593] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "proppastie.com"] [uri "/wp-config.php.swp"] [unique_id "apK89yJcY4fy7tP-rU3lnwACFjg"] [Sat Aug 29 05:05:27.636475 2026] [security2:error] [pid 1017536:tid 1017637] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/wp/.env"] [unique_id "apK89yJcY4fy7tP-rU3lngACFmQ"] [Sat Aug 29 05:05:27.644162 2026] [security2:error] [pid 1017536:tid 1017792] [client 4.205.62.107:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK89yJcY4fy7tP-rU3loAAAApI"] [Sat Aug 29 05:05:27.650493 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.63.219.114:14565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/hello.php"] [unique_id "apK89yJcY4fy7tP-rU3logAAAkM"] [Sat Aug 29 05:05:27.656795 2026] [security2:error] [pid 1017536:tid 1017711] [client 74.248.24.12:8438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK89yJcY4fy7tP-rU3lpAAAAkE"] [Sat Aug 29 05:05:27.656967 2026] [security2:error] [pid 1017536:tid 1017628] [remote 34.138.108.56:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/wp-config.old"] [unique_id "apK89yJcY4fy7tP-rU3lowACfFs"] [Sat Aug 29 05:05:27.664247 2026] [security2:error] [pid 1018003:tid 1018231] [client 4.205.62.107:2501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/luJMF.php"] [unique_id "apK89zAh5Y1i2tUxg4HhcAAABgc"] [Sat Aug 29 05:05:27.670529 2026] [security2:error] [pid 1018003:tid 1018158] [client 52.139.37.240:20777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apK89zAh5Y1i2tUxg4HhcQAABb8"] [Sat Aug 29 05:05:27.675878 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.196.209.81:10726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/go.php"] [unique_id "apK89yJcY4fy7tP-rU3lqAAAAjQ"] [Sat Aug 29 05:05:27.685426 2026] [security2:error] [pid 1017536:tid 1017783] [client 216.26.243.167:30321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.243.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK89yJcY4fy7tP-rU3lpgAAAok"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:27.693944 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.104.62:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/d12.php"] [unique_id "apK89yJcY4fy7tP-rU3lqgAAAlY"] [Sat Aug 29 05:05:27.700527 2026] [security2:error] [pid 1018003:tid 1018259] [client 185.104.184.230:46092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK89zAh5Y1i2tUxg4HhcwAABiM"] [Sat Aug 29 05:05:27.712304 2026] [security2:error] [pid 1017536:tid 1017688] [client 52.139.37.240:24656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/dropdown.php"] [unique_id "apK89yJcY4fy7tP-rU3lrAAAAio"] [Sat Aug 29 05:05:27.714780 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.63.219.114:11848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/disagraeed.php"] [unique_id "apK89yJcY4fy7tP-rU3lrQAAAi8"] [Sat Aug 29 05:05:27.740028 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.48.251.3:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/nzv.php"] [unique_id "apK89zAh5Y1i2tUxg4HhdAAABew"] [Sat Aug 29 05:05:27.746339 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.18.15:8141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK89zAh5Y1i2tUxg4HhdgAABcU"] [Sat Aug 29 05:05:27.778835 2026] [security2:error] [pid 1017536:tid 1017666] [client 68.155.159.216:16296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK89yJcY4fy7tP-rU3lswAAAhQ"] [Sat Aug 29 05:05:27.795531 2026] [security2:error] [pid 1017536:tid 1017777] [client 74.248.24.12:33174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/file2.php"] [unique_id "apK89yJcY4fy7tP-rU3ltAAAAoM"] [Sat Aug 29 05:05:27.808422 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.48.160.90:28637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/im.php"] [unique_id "apK89yJcY4fy7tP-rU3ltgAAAhU"] [Sat Aug 29 05:05:27.827149 2026] [security2:error] [pid 1018003:tid 1018254] [client 4.232.148.111:19627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/root.php"] [unique_id "apK89zAh5Y1i2tUxg4HheAAABh4"] [Sat Aug 29 05:05:27.828411 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.104.62:41633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/yyy.php"] [unique_id "apK89yJcY4fy7tP-rU3luAAAAjs"] [Sat Aug 29 05:05:27.836207 2026] [security2:error] [pid 1017536:tid 1017780] [client 192.145.125.70:35428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK89yJcY4fy7tP-rU3luQAAAoY"] [Sat Aug 29 05:05:27.864723 2026] [security2:error] [pid 1018003:tid 1018191] [client 52.139.37.240:21422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK89zAh5Y1i2tUxg4HheQAABeA"] [Sat Aug 29 05:05:27.872754 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.49.130:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/txets.php"] [unique_id "apK89yJcY4fy7tP-rU3lvwAAAiE"] [Sat Aug 29 05:05:27.873862 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.48.251.3:28433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/66.php"] [unique_id "apK89yJcY4fy7tP-rU3lwAAAAjI"] [Sat Aug 29 05:05:27.881282 2026] [security2:error] [pid 1017536:tid 1017793] [client 68.155.159.216:58256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK89yJcY4fy7tP-rU3lwQAAApM"] [Sat Aug 29 05:05:27.913091 2026] [security2:error] [pid 1017536:tid 1017710] [client 52.139.37.240:24667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/files/index.php"] [unique_id "apK89yJcY4fy7tP-rU3lwgAAAkA"] [Sat Aug 29 05:05:27.918317 2026] [security2:error] [pid 1017536:tid 1017722] [client 93.123.109.228:37324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK89yJcY4fy7tP-rU3lwwAAAkw"] [Sat Aug 29 05:05:27.924992 2026] [security2:error] [pid 1017536:tid 1017675] [client 93.123.109.228:37240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK89yJcY4fy7tP-rU3lxAAAAh0"] [Sat Aug 29 05:05:27.926789 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.18.15:8152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ap.php"] [unique_id "apK89zAh5Y1i2tUxg4HhegAABdI"] [Sat Aug 29 05:05:27.931596 2026] [security2:error] [pid 1018003:tid 1018214] [client 68.155.159.216:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/maint/index.php"] [unique_id "apK89zAh5Y1i2tUxg4HhfAAABfc"] [Sat Aug 29 05:05:27.951110 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.48.250.41:26935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK89yJcY4fy7tP-rU3lyQAAAn0"] [Sat Aug 29 05:05:27.959733 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.104.62:22699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/bgymj.php"] [unique_id "apK89zAh5Y1i2tUxg4HhfgAABcg"] [Sat Aug 29 05:05:27.961195 2026] [security2:error] [pid 1017536:tid 1017779] [client 158.158.54.35:18420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/x.php"] [unique_id "apK89yJcY4fy7tP-rU3lzAAAAoU"] [Sat Aug 29 05:05:27.965346 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.196.209.81:10647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/f35.php"] [unique_id "apK89yJcY4fy7tP-rU3lzQAAAlU"] [Sat Aug 29 05:05:27.986847 2026] [security2:error] [pid 1017536:tid 1017736] [client 168.107.94.195:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK89yJcY4fy7tP-rU3l0AAAAlo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:27.990801 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.160.90:62653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/fc.php"] [unique_id "apK89yJcY4fy7tP-rU3l0gAAAmM"] [Sat Aug 29 05:05:27.990833 2026] [security2:error] [pid 1017536:tid 1017668] [client 68.155.159.216:33703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK89yJcY4fy7tP-rU3l0QAAAhY"] [Sat Aug 29 05:05:27.993857 2026] [security2:error] [pid 1017536:tid 1017757] [client 185.104.184.230:46098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK89yJcY4fy7tP-rU3l0wAAAm8"] [Sat Aug 29 05:05:28.000939 2026] [security2:error] [pid 1017536:tid 1017737] [client 4.232.148.111:32909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/gmo.php"] [unique_id "apK89yJcY4fy7tP-rU3l1AAAAls"] [Sat Aug 29 05:05:28.005845 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.196.209.81:15163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/as.php"] [unique_id "apK8-CJcY4fy7tP-rU3l1QAAAmw"] [Sat Aug 29 05:05:28.007430 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.48.251.3:57865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/admin.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhgAAABek"] [Sat Aug 29 05:05:28.052680 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.104.49.130:57681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/talkxkej.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhggAABjI"] [Sat Aug 29 05:05:28.065066 2026] [security2:error] [pid 1018003:tid 1018219] [client 68.155.159.216:24464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhgwAABfw"] [Sat Aug 29 05:05:28.078493 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.63.219.114:7428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/fi2.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhhAAABhE"] [Sat Aug 29 05:05:28.084342 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.196.209.81:10737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/gecko-new.php"] [unique_id "apK8-CJcY4fy7tP-rU3l2wAAAo4"] [Sat Aug 29 05:05:28.085239 2026] [security2:error] [pid 1017536:tid 1017746] [client 172.97.247.204:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK8-CJcY4fy7tP-rU3l2gAAAmQ"], referer: https://www.djiboutihomes.com/ [Sat Aug 29 05:05:28.105858 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:8142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/media.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhhwAABes"] [Sat Aug 29 05:05:28.107476 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.104.62:22678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/fh26.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhiAAABf4"] [Sat Aug 29 05:05:28.109853 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.63.219.114:14568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/add_actualites.php"] [unique_id "apK8-CJcY4fy7tP-rU3l3AAAAko"] [Sat Aug 29 05:05:28.110855 2026] [security2:error] [pid 1017536:tid 1017749] [client 52.139.37.240:25040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofboardcraft.com"] [uri "/flower.php"] [unique_id "apK8-CJcY4fy7tP-rU3l3QAAAmc"] [Sat Aug 29 05:05:28.132280 2026] [security2:error] [pid 1018003:tid 1018166] [client 68.155.159.216:62862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhiQAABcc"] [Sat Aug 29 05:05:28.148722 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.48.251.3:57803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/png.php"] [unique_id "apK8-CJcY4fy7tP-rU3l5AAAAi8"] [Sat Aug 29 05:05:28.155418 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.160.90:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/ke.php"] [unique_id "apK8-CJcY4fy7tP-rU3l5QAAAk4"] [Sat Aug 29 05:05:28.165387 2026] [security2:error] [pid 1018003:tid 1018154] [client 52.139.37.240:21122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/wp-index.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhigAABbs"] [Sat Aug 29 05:05:28.171954 2026] [security2:error] [pid 1018003:tid 1018209] [client 74.248.24.12:21777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/gmo.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhiwAABfI"] [Sat Aug 29 05:05:28.242756 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.104.62:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/fgd.php"] [unique_id "apK8-CJcY4fy7tP-rU3l7AAAAn8"] [Sat Aug 29 05:05:28.244896 2026] [security2:error] [pid 1017536:tid 1017686] [client 104.207.37.45:31503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.37.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8-CJcY4fy7tP-rU3l6AAAAig"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:28.246816 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.147.79:24488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/x/index.php"] [unique_id "apK8-CJcY4fy7tP-rU3l7QAAAjs"] [Sat Aug 29 05:05:28.264622 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.48.250.41:27645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhjwAABfk"] [Sat Aug 29 05:05:28.276310 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.104.18.15:8131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/adminfuns.php"] [unique_id "apK8-CJcY4fy7tP-rU3l8gAAAlA"] [Sat Aug 29 05:05:28.301078 2026] [security2:error] [pid 1017536:tid 1017747] [client 185.104.184.230:46100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK8-CJcY4fy7tP-rU3l8wAAAmU"] [Sat Aug 29 05:05:28.308373 2026] [security2:error] [pid 1018003:tid 1018235] [client 74.248.24.12:25452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhkgAABgs"] [Sat Aug 29 05:05:28.315979 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.48.251.3:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/chosen.php"] [unique_id "apK8-CJcY4fy7tP-rU3l9gAAAiE"] [Sat Aug 29 05:05:28.320018 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.48.160.90:63591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/tf.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhkwAABeg"] [Sat Aug 29 05:05:28.331948 2026] [security2:error] [pid 1017536:tid 1017765] [client 4.205.62.107:61190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/cli_bootstrap.php"] [unique_id "apK8-CJcY4fy7tP-rU3l-QAAAnc"] [Sat Aug 29 05:05:28.335940 2026] [security2:error] [pid 1017536:tid 1017769] [client 4.232.148.111:5917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/p.php"] [unique_id "apK8-CJcY4fy7tP-rU3l-gAAAns"] [Sat Aug 29 05:05:28.340630 2026] [security2:error] [pid 1017536:tid 1017710] [client 158.23.147.79:62722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK8-CJcY4fy7tP-rU3l_AAAAkA"] [Sat Aug 29 05:05:28.358720 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.196.209.81:10665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/index.php"] [unique_id "apK8-CJcY4fy7tP-rU3l_gAAAoM"] [Sat Aug 29 05:05:28.365578 2026] [security2:error] [pid 1017536:tid 1017685] [client 168.107.94.195:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8-CJcY4fy7tP-rU3l_wAAAic"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:28.381199 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.104.104.62:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/inject.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhlQAABd4"] [Sat Aug 29 05:05:28.386790 2026] [security2:error] [pid 1017536:tid 1017793] [client 52.139.37.240:20773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/ww2.php"] [unique_id "apK8-CJcY4fy7tP-rU3mAgAAApM"] [Sat Aug 29 05:05:28.400181 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.250.41:26924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ff1.php"] [unique_id "apK8-CJcY4fy7tP-rU3mAwAAAnk"] [Sat Aug 29 05:05:28.407327 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.158.54.35:23708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/new.php"] [unique_id "apK8-CJcY4fy7tP-rU3mBAAAAoY"] [Sat Aug 29 05:05:28.412642 2026] [security2:error] [pid 1018003:tid 1018248] [client 93.123.109.228:36612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK8-DAh5Y1i2tUxg4HhlgAABhg"] [Sat Aug 29 05:05:28.426110 2026] [security2:error] [pid 1018003:tid 1018252] [client 66.248.203.2:52422] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2017/12/24/the-cultural-war/"] [unique_id "apK8-DAh5Y1i2tUxg4HhlwAABhw"] [Sat Aug 29 05:05:28.426273 2026] [security2:error] [pid 1017536:tid 1017716] [client 192.145.125.70:35436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK8-CJcY4fy7tP-rU3mBgAAAkY"] [Sat Aug 29 05:05:28.439983 2026] [security2:error] [pid 1018003:tid 1018220] [client 68.155.159.216:50323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/atomlib.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhmAAABf0"] [Sat Aug 29 05:05:28.447569 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.48.251.3:28457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/admin-ajax.php"] [unique_id "apK8-CJcY4fy7tP-rU3mBwAAAi4"] [Sat Aug 29 05:05:28.451573 2026] [security2:error] [pid 1017536:tid 1017766] [client 4.205.62.107:64196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/rpk.php"] [unique_id "apK8-CJcY4fy7tP-rU3mCAAAAng"] [Sat Aug 29 05:05:28.457295 2026] [security2:error] [pid 1018003:tid 1018169] [client 93.123.109.228:37390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK8-DAh5Y1i2tUxg4HhmQAABco"] [Sat Aug 29 05:05:28.457301 2026] [security2:error] [pid 1017536:tid 1017755] [client 93.123.109.228:37302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK8-CJcY4fy7tP-rU3mCgAAAm0"] [Sat Aug 29 05:05:28.458580 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.48.251.3:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhmwAABfg"] [Sat Aug 29 05:05:28.465602 2026] [security2:error] [pid 1018003:tid 1018247] [client 20.63.219.114:7479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/1p.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhnAAABhc"] [Sat Aug 29 05:05:28.467823 2026] [security2:error] [pid 1017536:tid 1017730] [client 4.232.148.111:21788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/classwithtostring.php"] [unique_id "apK8-CJcY4fy7tP-rU3mCwAAAlQ"] [Sat Aug 29 05:05:28.473451 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.160.90:63586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/px.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhnQAABgM"] [Sat Aug 29 05:05:28.477052 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.196.209.81:25085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/room.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhngAABbo"] [Sat Aug 29 05:05:28.479595 2026] [security2:error] [pid 1018003:tid 1018238] [client 171.61.160.196:4714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhnwAABg4"] [Sat Aug 29 05:05:28.479663 2026] [security2:error] [pid 1018003:tid 1018238] [client 171.61.160.196:4714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhnwAABg4"] [Sat Aug 29 05:05:28.480949 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.196.209.81:10735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/wp-admin.php"] [unique_id "apK8-CJcY4fy7tP-rU3mDAAAAkw"] [Sat Aug 29 05:05:28.485467 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.18.15:8162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/classwithtostring.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhoQAABdw"] [Sat Aug 29 05:05:28.493194 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.63.219.114:1430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/alfanew.php7"] [unique_id "apK8-DAh5Y1i2tUxg4HhogAABcA"] [Sat Aug 29 05:05:28.514321 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.104.62:41622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/mga.php"] [unique_id "apK8-CJcY4fy7tP-rU3mEAAAAmM"] [Sat Aug 29 05:05:28.550849 2026] [security2:error] [pid 1017536:tid 1017776] [client 93.123.109.228:37324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK8-CJcY4fy7tP-rU3mEgAAAoI"] [Sat Aug 29 05:05:28.555470 2026] [security2:error] [pid 1017536:tid 1017713] [client 93.123.109.228:37312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK8-CJcY4fy7tP-rU3mEwAAAkM"] [Sat Aug 29 05:05:28.559935 2026] [security2:error] [pid 1017536:tid 1017770] [client 4.205.62.107:22208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wdf.php"] [unique_id "apK8-CJcY4fy7tP-rU3mFAAAAnw"] [Sat Aug 29 05:05:28.573841 2026] [security2:error] [pid 1017536:tid 1017746] [client 158.23.147.79:23394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/bk/index.php"] [unique_id "apK8-CJcY4fy7tP-rU3mFgAAAmQ"] [Sat Aug 29 05:05:28.584580 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.48.251.3:28427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ms.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhpQAABho"] [Sat Aug 29 05:05:28.585281 2026] [security2:error] [pid 1017536:tid 1017789] [client 158.23.147.79:48230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK8-CJcY4fy7tP-rU3mFwAAAo8"] [Sat Aug 29 05:05:28.585506 2026] [security2:error] [pid 1017536:tid 1017737] [client 52.139.37.240:20799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/7logs.php"] [unique_id "apK8-CJcY4fy7tP-rU3mGAAAAls"] [Sat Aug 29 05:05:28.590284 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.48.250.41:27604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/t.php"] [unique_id "apK8-CJcY4fy7tP-rU3mGQAAAl4"] [Sat Aug 29 05:05:28.605950 2026] [security2:error] [pid 1017536:tid 1017728] [client 185.104.184.230:55956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK8-CJcY4fy7tP-rU3mHQAAAlI"] [Sat Aug 29 05:05:28.608001 2026] [security2:error] [pid 1017536:tid 1017556] [remote 34.138.108.56:57588] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "proppastie.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK8-CJcY4fy7tP-rU3mHgACLBM"] [Sat Aug 29 05:05:28.648457 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.104.62:41659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/inwp.php"] [unique_id "apK8-CJcY4fy7tP-rU3mIQAAApA"] [Sat Aug 29 05:05:28.657590 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.18.15:8142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK8-CJcY4fy7tP-rU3mIgAAAhw"] [Sat Aug 29 05:05:28.665376 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.49.130:57516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/k.php"] [unique_id "apK8-CJcY4fy7tP-rU3mIwAAAoc"] [Sat Aug 29 05:05:28.668838 2026] [security2:error] [pid 1017536:tid 1017681] [client 4.205.62.107:53417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/erty.php"] [unique_id "apK8-CJcY4fy7tP-rU3mJQAAAiM"] [Sat Aug 29 05:05:28.670116 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.160.90:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/jg.php"] [unique_id "apK8-CJcY4fy7tP-rU3mJgAAAmA"] [Sat Aug 29 05:05:28.689105 2026] [security2:error] [pid 1017536:tid 1017668] [client 74.248.24.12:28168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/classwithtostring.php"] [unique_id "apK8-CJcY4fy7tP-rU3mKAAAAhY"] [Sat Aug 29 05:05:28.705343 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.49.130:43008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/txets.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhqgAABiU"] [Sat Aug 29 05:05:28.714765 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.48.251.3:57839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/fucku.php"] [unique_id "apK8-CJcY4fy7tP-rU3mKQAAAms"] [Sat Aug 29 05:05:28.726990 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.48.250.41:26880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/erty.php"] [unique_id "apK8-CJcY4fy7tP-rU3mKwAAAn8"] [Sat Aug 29 05:05:28.728707 2026] [security2:error] [pid 1017536:tid 1017726] [client 68.155.159.216:51522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/content.php"] [unique_id "apK8-CJcY4fy7tP-rU3mLQAAAlA"] [Sat Aug 29 05:05:28.750711 2026] [security2:error] [pid 1018003:tid 1018242] [client 4.205.62.107:22318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-info.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhqwAABhI"] [Sat Aug 29 05:05:28.775030 2026] [security2:error] [pid 1017536:tid 1017685] [client 4.205.62.107:65486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/cloud.php"] [unique_id "apK8-CJcY4fy7tP-rU3mNQAAAic"] [Sat Aug 29 05:05:28.775652 2026] [security2:error] [pid 1017536:tid 1017782] [client 104.207.43.100:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.43.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8-CJcY4fy7tP-rU3mLwAAAog"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:28.782157 2026] [security2:error] [pid 1017536:tid 1017756] [client 168.107.94.195:64736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8-CJcY4fy7tP-rU3mNgAAAm4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:28.783308 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.104.62:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/ad1.php"] [unique_id "apK8-CJcY4fy7tP-rU3mNwAAApM"] [Sat Aug 29 05:05:28.784091 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.196.209.81:8999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/install.php"] [unique_id "apK8-CJcY4fy7tP-rU3mOQAAAi8"] [Sat Aug 29 05:05:28.784895 2026] [security2:error] [pid 1017536:tid 1017667] [client 52.139.37.240:20757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/ac.php"] [unique_id "apK8-CJcY4fy7tP-rU3mOAAAAhU"] [Sat Aug 29 05:05:28.786208 2026] [security2:error] [pid 1017536:tid 1017708] [client 158.23.147.79:38770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK8-CJcY4fy7tP-rU3mOgAAAj4"] [Sat Aug 29 05:05:28.812116 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.48.251.3:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK8-CJcY4fy7tP-rU3mPQAAAjY"] [Sat Aug 29 05:05:28.821843 2026] [security2:error] [pid 1017536:tid 1017666] [client 20.63.219.114:11889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/Njima.php"] [unique_id "apK8-CJcY4fy7tP-rU3mPgAAAhQ"] [Sat Aug 29 05:05:28.825590 2026] [security2:error] [pid 1018003:tid 1018255] [client 4.232.148.111:32376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/a1.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhrQAABh8"] [Sat Aug 29 05:05:28.828257 2026] [security2:error] [pid 1017536:tid 1017717] [client 4.205.62.107:2511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/drykl.php"] [unique_id "apK8-CJcY4fy7tP-rU3mPwAAAkc"] [Sat Aug 29 05:05:28.833294 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.48.160.90:64689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/yj.php"] [unique_id "apK8-CJcY4fy7tP-rU3mQAAAAiI"] [Sat Aug 29 05:05:28.846547 2026] [security2:error] [pid 1018003:tid 1018160] [client 93.123.109.228:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK8-DAh5Y1i2tUxg4HhrgAABcE"] [Sat Aug 29 05:05:28.852443 2026] [security2:error] [pid 1018003:tid 1018254] [client 20.104.18.15:8165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhrwAABh4"] [Sat Aug 29 05:05:28.854530 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.158.54.35:9936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/menu.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhsAAABew"] [Sat Aug 29 05:05:28.862188 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.48.251.3:57828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/error_log.php"] [unique_id "apK8-CJcY4fy7tP-rU3mQQAAAkw"] [Sat Aug 29 05:05:28.866816 2026] [security2:error] [pid 1017536:tid 1017751] [client 74.248.24.12:8168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/xda.php"] [unique_id "apK8-CJcY4fy7tP-rU3mQgAAAmk"] [Sat Aug 29 05:05:28.881163 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.63.219.114:1425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/xmlrpc.php0"] [unique_id "apK8-CJcY4fy7tP-rU3mQwAAAnI"] [Sat Aug 29 05:05:28.888216 2026] [security2:error] [pid 1017536:tid 1017775] [client 93.123.109.228:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK8-CJcY4fy7tP-rU3mRQAAAoE"] [Sat Aug 29 05:05:28.909273 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.196.209.81:15770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/class-wp-cmd.php"] [unique_id "apK8-DAh5Y1i2tUxg4HhsgAABfs"] [Sat Aug 29 05:05:28.919832 2026] [security2:error] [pid 1017536:tid 1017670] [client 185.104.184.230:55964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK8-CJcY4fy7tP-rU3mRwAAAhg"] [Sat Aug 29 05:05:28.920588 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.196.209.81:12731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/wp-configs.php"] [unique_id "apK8-CJcY4fy7tP-rU3mSAAAAmE"] [Sat Aug 29 05:05:28.925572 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.104.104.62:45964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/1vbqo.php"] [unique_id "apK8-CJcY4fy7tP-rU3mSQAAAhg"] [Sat Aug 29 05:05:28.936914 2026] [security2:error] [pid 1018003:tid 1018265] [client 93.123.109.228:37254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK8-DAh5Y1i2tUxg4HhswAABik"] [Sat Aug 29 05:05:28.944297 2026] [security2:error] [pid 1017536:tid 1017710] [client 4.232.148.111:19452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/404.php"] [unique_id "apK8-CJcY4fy7tP-rU3mSgAAAkA"] [Sat Aug 29 05:05:28.947115 2026] [security2:error] [pid 1017536:tid 1017714] [client 103.240.76.112:49643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK8-CJcY4fy7tP-rU3mTQAAAkQ"] [Sat Aug 29 05:05:28.947221 2026] [security2:error] [pid 1017536:tid 1017714] [client 103.240.76.112:49643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK8-CJcY4fy7tP-rU3mTQAAAkQ"] [Sat Aug 29 05:05:28.954715 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.251.3:14291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/cloud.php"] [unique_id "apK8-CJcY4fy7tP-rU3mTgAAAnw"] [Sat Aug 29 05:05:28.962770 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.48.250.41:27619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/0x.php"] [unique_id "apK8-CJcY4fy7tP-rU3mTwAAAoQ"] [Sat Aug 29 05:05:28.972774 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:16313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK8-CJcY4fy7tP-rU3mUAAAAjo"] [Sat Aug 29 05:05:28.984662 2026] [security2:error] [pid 1017536:tid 1017673] [client 68.155.159.216:57377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK8-CJcY4fy7tP-rU3mUwAAAhs"] [Sat Aug 29 05:05:28.989843 2026] [security2:error] [pid 1017536:tid 1017702] [client 52.139.37.240:21145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/ctex1.php"] [unique_id "apK8-CJcY4fy7tP-rU3mVAAAAjg"] [Sat Aug 29 05:05:28.994382 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.48.251.3:57864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/phina.php"] [unique_id "apK8-CJcY4fy7tP-rU3mVQAAAo0"] [Sat Aug 29 05:05:29.002454 2026] [security2:error] [pid 1017536:tid 1017728] [client 20.104.18.15:8144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK8-SJcY4fy7tP-rU3mVwAAAlI"] [Sat Aug 29 05:05:29.019101 2026] [security2:error] [pid 1017536:tid 1017705] [client 192.145.125.70:35448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK8-SJcY4fy7tP-rU3mWgAAAjs"] [Sat Aug 29 05:05:29.033623 2026] [security2:error] [pid 1017536:tid 1017774] [client 68.155.159.216:12106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/dropdown.php"] [unique_id "apK8-SJcY4fy7tP-rU3mXAAAAoA"] [Sat Aug 29 05:05:29.054275 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.104.62:22668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/h02ugyh.php"] [unique_id "apK8-SJcY4fy7tP-rU3mXgAAAhY"] [Sat Aug 29 05:05:29.077519 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.160.90:28615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/zi.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhtAAABcg"] [Sat Aug 29 05:05:29.094846 2026] [security2:error] [pid 1018003:tid 1018152] [client 93.123.109.228:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK8-TAh5Y1i2tUxg4HhtgAABbk"] [Sat Aug 29 05:05:29.096626 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.250.41:26903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/66.php"] [unique_id "apK8-SJcY4fy7tP-rU3mXwAAAmg"] [Sat Aug 29 05:05:29.100060 2026] [security2:error] [pid 1018003:tid 1018234] [client 68.155.159.216:16087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/asd.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhtwAABgo"] [Sat Aug 29 05:05:29.125097 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.48.251.3:57908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/koiy.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhuQAABgI"] [Sat Aug 29 05:05:29.141137 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.18.15:8188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wsd.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhugAABb4"] [Sat Aug 29 05:05:29.153365 2026] [security2:error] [pid 1017536:tid 1017652] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/web.config"] [unique_id "apK8-SJcY4fy7tP-rU3mZAACJ3M"] [Sat Aug 29 05:05:29.158946 2026] [security2:error] [pid 1017536:tid 1017782] [client 68.155.159.216:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/chosen.php"] [unique_id "apK8-SJcY4fy7tP-rU3maAAAAog"] [Sat Aug 29 05:05:29.162039 2026] [security2:error] [pid 1017536:tid 1017669] [client 168.107.94.195:65166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8-SJcY4fy7tP-rU3maQAAAhc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:29.170291 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.48.251.3:14308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/kerang.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhuwAABhk"] [Sat Aug 29 05:05:29.182285 2026] [security2:error] [pid 1018003:tid 1018186] [client 68.155.159.216:24449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/file.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhvAAABds"] [Sat Aug 29 05:05:29.182589 2026] [security2:error] [pid 1018003:tid 1018178] [client 52.139.37.240:21436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/defaults.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhvQAABdM"] [Sat Aug 29 05:05:29.188649 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.104.62:41625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/shelp.php"] [unique_id "apK8-SJcY4fy7tP-rU3mawAAAnk"] [Sat Aug 29 05:05:29.190288 2026] [cgid:error] [pid 1018003:tid 1018273] [client 20.196.209.81:8966] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/carolinashooter/404.shtml [Sat Aug 29 05:05:29.211466 2026] [security2:error] [pid 1017536:tid 1017724] [client 74.248.24.12:28824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/404.php"] [unique_id "apK8-SJcY4fy7tP-rU3mbAAAAk4"] [Sat Aug 29 05:05:29.220977 2026] [security2:error] [pid 1018003:tid 1018221] [client 185.104.184.230:55976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK8-TAh5Y1i2tUxg4HhvwAABf4"] [Sat Aug 29 05:05:29.222648 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.63.219.114:11844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/configs.php"] [unique_id "apK8-SJcY4fy7tP-rU3mbgAAAlA"] [Sat Aug 29 05:05:29.224930 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.48.160.90:28665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/ue.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhwQAABc0"] [Sat Aug 29 05:05:29.229389 2026] [security2:error] [pid 1017536:tid 1017716] [client 93.123.109.228:37352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config.php"] [unique_id "apK8-SJcY4fy7tP-rU3mbwAAAkY"] [Sat Aug 29 05:05:29.246896 2026] [security2:error] [pid 1018003:tid 1018154] [client 68.155.159.216:62864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhwgAABbs"] [Sat Aug 29 05:05:29.253567 2026] [security2:error] [pid 1017536:tid 1017700] [client 93.123.109.228:36610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK8-SJcY4fy7tP-rU3mcQAAAjY"] [Sat Aug 29 05:05:29.256026 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.48.251.3:57884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/queue.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhwwAABiI"] [Sat Aug 29 05:05:29.268661 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.63.219.114:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/content.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhxAAABio"] [Sat Aug 29 05:05:29.269260 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.18.15:8081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/bulet.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhxQAABjU"] [Sat Aug 29 05:05:29.292215 2026] [security2:error] [pid 1018003:tid 1018241] [client 158.158.54.35:26001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhxgAABhE"] [Sat Aug 29 05:05:29.312302 2026] [security2:error] [pid 1017536:tid 1017671] [client 195.178.110.247:50342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.landonrian.com"] [uri "/index.php"] [unique_id "apK8-SJcY4fy7tP-rU3meAAAAhk"] [Sat Aug 29 05:05:29.315643 2026] [security2:error] [pid 1017536:tid 1017675] [client 209.50.174.88:60835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.174.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8-SJcY4fy7tP-rU3mdQAAAh0"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:29.317896 2026] [security2:error] [pid 1017536:tid 1017756] [client 4.232.148.111:24945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK8-SJcY4fy7tP-rU3meQAAAm4"] [Sat Aug 29 05:05:29.322191 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.104.62:22662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/13ede.php"] [unique_id "apK8-SJcY4fy7tP-rU3megAAAiI"] [Sat Aug 29 05:05:29.322191 2026] [security2:error] [pid 1018003:tid 1018251] [client 20.196.209.81:8966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhyAAABhs"] [Sat Aug 29 05:05:29.338234 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.196.209.81:25048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/disagreed.php"] [unique_id "apK8-SJcY4fy7tP-rU3mewAAAj4"] [Sat Aug 29 05:05:29.357702 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.48.160.90:63502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/nv.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhygAABdY"] [Sat Aug 29 05:05:29.366917 2026] [security2:error] [pid 1017536:tid 1017691] [client 93.123.109.228:37366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK8-SJcY4fy7tP-rU3mfQAAAi0"] [Sat Aug 29 05:05:29.367455 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.48.251.3:13954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/rem.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhzAAABgs"] [Sat Aug 29 05:05:29.369242 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.196.209.81:12680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/essexec.php"] [unique_id "apK8-TAh5Y1i2tUxg4HhzQAABcc"] [Sat Aug 29 05:05:29.372159 2026] [autoindex:error] [pid 1018003:tid 1018202] [client 45.148.10.62:38648] AH01276: Cannot serve directory /home3/vvrewumy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:29.407339 2026] [security2:error] [pid 1018003:tid 1018197] [client 52.139.37.240:20779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/domains.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh0AAABeY"] [Sat Aug 29 05:05:29.424946 2026] [security2:error] [pid 1018003:tid 1018209] [client 4.232.148.111:32704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/php.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh0wAABfI"] [Sat Aug 29 05:05:29.437374 2026] [security2:error] [pid 1017536:tid 1017703] [client 74.248.24.12:31561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/theme.php"] [unique_id "apK8-SJcY4fy7tP-rU3mhAAAAjk"] [Sat Aug 29 05:05:29.441886 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.104.18.15:8135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/av.php"] [unique_id "apK8-SJcY4fy7tP-rU3mhQAAAlw"] [Sat Aug 29 05:05:29.459853 2026] [security2:error] [pid 1018003:tid 1018260] [client 20.104.104.62:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/k8.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh1AAABiQ"] [Sat Aug 29 05:05:29.465213 2026] [security2:error] [pid 1018003:tid 1018150] [client 93.123.109.228:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/aws.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh1QAABbc"] [Sat Aug 29 05:05:29.473026 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.251.3:28444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/doc.php"] [unique_id "apK8-SJcY4fy7tP-rU3migAAAkA"] [Sat Aug 29 05:05:29.474519 2026] [security2:error] [pid 1017536:tid 1017771] [client 195.178.110.247:11606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.landonrian.com"] [uri "/index.php"] [unique_id "apK8-SJcY4fy7tP-rU3mjAAAAn0"] [Sat Aug 29 05:05:29.496604 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.160.90:63549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/jw.php"] [unique_id "apK8-SJcY4fy7tP-rU3mkAAAAjo"] [Sat Aug 29 05:05:29.511722 2026] [security2:error] [pid 1018003:tid 1018246] [client 4.205.62.107:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/dd.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh2AAABhY"] [Sat Aug 29 05:05:29.513037 2026] [security2:error] [pid 1018003:tid 1018247] [client 185.104.184.230:55978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK8-TAh5Y1i2tUxg4Hh2QAABhc"] [Sat Aug 29 05:05:29.517072 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.104.104.62:15320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/mh.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh2gAABhU"] [Sat Aug 29 05:05:29.523032 2026] [security2:error] [pid 1018003:tid 1018179] [client 45.148.10.62:38648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/.env"] [unique_id "apK8-TAh5Y1i2tUxg4Hh2wAABdQ"] [Sat Aug 29 05:05:29.542101 2026] [security2:error] [pid 1018003:tid 1018271] [client 168.107.94.195:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh3AAABi8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:29.554690 2026] [security2:error] [pid 1018003:tid 1018153] [client 68.155.159.216:50260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/lv.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh3QAABbo"] [Sat Aug 29 05:05:29.554690 2026] [security2:error] [pid 1017536:tid 1017740] [client 93.123.109.228:37312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/config.inc.php"] [unique_id "apK8-SJcY4fy7tP-rU3mkgAAAl4"] [Sat Aug 29 05:05:29.563506 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.104.104.62:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/f2r4.php"] [unique_id "apK8-SJcY4fy7tP-rU3mkwAAAo0"] [Sat Aug 29 05:05:29.566734 2026] [security2:error] [pid 1018003:tid 1018238] [client 35.198.240.194:51974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/root/.ssh/id_rsa"] [unique_id "apK8-TAh5Y1i2tUxg4Hh3gAABg4"] [Sat Aug 29 05:05:29.567789 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.104.104.62:10453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/155.php"] [unique_id "apK8-SJcY4fy7tP-rU3mlAAAAmQ"] [Sat Aug 29 05:05:29.567867 2026] [security2:error] [pid 1017536:tid 1017728] [client 35.198.240.194:51988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.omni-staffing.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK8-SJcY4fy7tP-rU3mlQAAAlI"] [Sat Aug 29 05:05:29.567972 2026] [security2:error] [pid 1017536:tid 1017728] [client 35.198.240.194:51988] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.omni-staffing.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK8-SJcY4fy7tP-rU3mlQAAAlI"] [Sat Aug 29 05:05:29.569558 2026] [security2:error] [pid 1018003:tid 1018188] [client 35.198.240.194:51982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK8-TAh5Y1i2tUxg4Hh3wAABd0"] [Sat Aug 29 05:05:29.570667 2026] [security2:error] [pid 1017536:tid 1017707] [client 35.198.240.194:52006] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.omni-staffing.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apK8-SJcY4fy7tP-rU3mmAAAAj0"] [Sat Aug 29 05:05:29.572226 2026] [security2:error] [pid 1017536:tid 1017705] [client 35.198.240.194:52028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.omni-staffing.com"] [uri "/@fs/../../../../../app/.env"] [unique_id "apK8-SJcY4fy7tP-rU3mmgAAAjs"] [Sat Aug 29 05:05:29.573841 2026] [core:error] [pid 1018003:tid 1018180] [client 35.198.240.194:52048] AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) [Sat Aug 29 05:05:29.574175 2026] [security2:error] [pid 1018003:tid 1018231] [client 35.198.240.194:52098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/@fs/home/ubuntu/.azure/credentials"] [unique_id "apK8-TAh5Y1i2tUxg4Hh5QAABgc"] [Sat Aug 29 05:05:29.576269 2026] [security2:error] [pid 1017536:tid 1017695] [client 35.198.240.194:52034] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.omni-staffing.com"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apK8-SJcY4fy7tP-rU3mngAAAjE"] [Sat Aug 29 05:05:29.581543 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.63.219.114:1190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/disagraeed.php"] [unique_id "apK8-SJcY4fy7tP-rU3mpAAAAm8"] [Sat Aug 29 05:05:29.582190 2026] [security2:error] [pid 1018003:tid 1018259] [client 4.205.62.107:55371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/saml.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh6wAABiM"] [Sat Aug 29 05:05:29.586216 2026] [security2:error] [pid 1017536:tid 1017774] [client 20.104.18.15:8083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/images.php"] [unique_id "apK8-SJcY4fy7tP-rU3mqwAAAoA"] [Sat Aug 29 05:05:29.587537 2026] [security2:error] [pid 1017536:tid 1017781] [client 35.198.240.194:52180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK8-SJcY4fy7tP-rU3mpQAAAoc"] [Sat Aug 29 05:05:29.593054 2026] [security2:error] [pid 1017536:tid 1017721] [client 93.123.109.228:37324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/config.php"] [unique_id "apK8-SJcY4fy7tP-rU3mrQAAAks"] [Sat Aug 29 05:05:29.603564 2026] [security2:error] [pid 1018003:tid 1018185] [client 52.139.37.240:21153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/dropdown.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh7QAABdo"] [Sat Aug 29 05:05:29.608545 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.104.62:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/alog.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh7gAABcU"] [Sat Aug 29 05:05:29.613450 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.48.251.3:28429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/css.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh7wAABf8"] [Sat Aug 29 05:05:29.615904 2026] [security2:error] [pid 1017536:tid 1017766] [client 192.145.125.70:35458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK8-SJcY4fy7tP-rU3msQAAAng"] [Sat Aug 29 05:05:29.617600 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.48.251.3:14296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/min.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh8AAABhI"] [Sat Aug 29 05:05:29.629784 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.63.219.114:1535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/wxo.php"] [unique_id "apK8-SJcY4fy7tP-rU3msgAAAo8"] [Sat Aug 29 05:05:29.634583 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.49.130:42233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/zoo2.php"] [unique_id "apK8-SJcY4fy7tP-rU3mswAAAic"] [Sat Aug 29 05:05:29.648605 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.160.90:62622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/or.php"] [unique_id "apK8-SJcY4fy7tP-rU3mtAAAAmI"] [Sat Aug 29 05:05:29.663165 2026] [security2:error] [pid 1017536:tid 1017769] [client 158.23.147.79:30657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK8-SJcY4fy7tP-rU3mtQAAAns"] [Sat Aug 29 05:05:29.666037 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.104.104.62:14366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/f2r4.php"] [unique_id "apK8-SJcY4fy7tP-rU3mtgAAAlA"] [Sat Aug 29 05:05:29.675157 2026] [security2:error] [pid 1018003:tid 1018173] [client 45.148.10.62:38648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/.env"] [unique_id "apK8-TAh5Y1i2tUxg4Hh8gAABc4"] [Sat Aug 29 05:05:29.693226 2026] [security2:error] [pid 1018003:tid 1018191] [client 93.123.109.228:36624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/env.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh8wAABeA"] [Sat Aug 29 05:05:29.698607 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.104.62:44601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/mcd.php"] [unique_id "apK8-SJcY4fy7tP-rU3mtwAAAoY"] [Sat Aug 29 05:05:29.700283 2026] [security2:error] [pid 1017536:tid 1017723] [client 68.155.159.216:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/dropdown.php"] [unique_id "apK8-SJcY4fy7tP-rU3muAAAAk0"] [Sat Aug 29 05:05:29.706074 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.104.104.62:13728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/sadis.php"] [unique_id "apK8-SJcY4fy7tP-rU3mugAAAmU"] [Sat Aug 29 05:05:29.706706 2026] [security2:error] [pid 1018003:tid 1018263] [client 4.205.62.107:22214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/snq.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh9AAABic"] [Sat Aug 29 05:05:29.718319 2026] [security2:error] [pid 1017536:tid 1017755] [client 93.123.109.228:37240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/nexmo.php"] [unique_id "apK8-SJcY4fy7tP-rU3muwAAAm0"] [Sat Aug 29 05:05:29.721473 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.104.49.130:52320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/term.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh9gAABg8"] [Sat Aug 29 05:05:29.722078 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.196.209.81:9010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK8-SJcY4fy7tP-rU3mvAAAAmg"] [Sat Aug 29 05:05:29.722931 2026] [security2:error] [pid 1017536:tid 1017712] [client 93.123.109.228:36616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/module.config.php"] [unique_id "apK8-SJcY4fy7tP-rU3mvQAAAkI"] [Sat Aug 29 05:05:29.734506 2026] [security2:error] [pid 1017536:tid 1017702] [client 74.248.24.12:21811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/php.php"] [unique_id "apK8-SJcY4fy7tP-rU3mvgAAAjg"] [Sat Aug 29 05:05:29.737721 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.147.79:23267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ridetimewinnipegservicetiresrims.ca"] [uri "/first.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh9wAABcg"] [Sat Aug 29 05:05:29.739510 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.147.79:48266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/chosen.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh-AAABbk"] [Sat Aug 29 05:05:29.740822 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.18.15:8147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ops.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh-QAABgo"] [Sat Aug 29 05:05:29.742283 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.104.62:20832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/arab.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh-gAABhQ"] [Sat Aug 29 05:05:29.759732 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.196.209.81:15805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/class_api.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh-wAABjY"] [Sat Aug 29 05:05:29.761123 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.104.62:41621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/adin.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh_QAABfw"] [Sat Aug 29 05:05:29.765214 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.48.251.3:27142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/php_info.php"] [unique_id "apK8-TAh5Y1i2tUxg4Hh_gAABb4"] [Sat Aug 29 05:05:29.778501 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.160.90:28584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/ile56.php"] [unique_id "apK8-SJcY4fy7tP-rU3mwQAAAjk"] [Sat Aug 29 05:05:29.779031 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.196.209.81:4503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/hello.php"] [unique_id "apK8-SJcY4fy7tP-rU3mwgAAAi8"] [Sat Aug 29 05:05:29.794767 2026] [security2:error] [pid 1018003:tid 1018211] [client 4.232.148.111:35107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/alfa-rex.php7"] [unique_id "apK8-TAh5Y1i2tUxg4Hh_wAABfQ"] [Sat Aug 29 05:05:29.807193 2026] [security2:error] [pid 1017536:tid 1017745] [client 158.23.147.79:25597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK8-SJcY4fy7tP-rU3mxAAAAmM"] [Sat Aug 29 05:05:29.807698 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.104.62:14389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/sadis.php"] [unique_id "apK8-SJcY4fy7tP-rU3mxQAAAmE"] [Sat Aug 29 05:05:29.809968 2026] [security2:error] [pid 1017536:tid 1017670] [client 185.104.184.230:55988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK8-SJcY4fy7tP-rU3mxwAAAhg"] [Sat Aug 29 05:05:29.813943 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.251.3:13970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/saiga.php"] [unique_id "apK8-SJcY4fy7tP-rU3myQAAAkQ"] [Sat Aug 29 05:05:29.816527 2026] [security2:error] [pid 1018003:tid 1018182] [client 107.150.120.129:45044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.development.dubeyko.com"] [uri "/"] [unique_id "apK8-TAh5Y1i2tUxg4HiAAAABdc"] [Sat Aug 29 05:05:29.817735 2026] [security2:error] [pid 1018003:tid 1018268] [client 4.205.62.107:53364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/ws62.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiAQAABiw"] [Sat Aug 29 05:05:29.821587 2026] [security2:error] [pid 1017536:tid 1017696] [client 52.139.37.240:21120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/files/index.php"] [unique_id "apK8-SJcY4fy7tP-rU3mywAAAjI"] [Sat Aug 29 05:05:29.828512 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.104.104.62:44554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/waw.php"] [unique_id "apK8-SJcY4fy7tP-rU3mzAAAAn0"] [Sat Aug 29 05:05:29.837812 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.104.104.62:13569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/xcre1.php"] [unique_id "apK8-SJcY4fy7tP-rU3mzQAAAkM"] [Sat Aug 29 05:05:29.849854 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK8-SJcY4fy7tP-rU3mzgAAAjo"] [Sat Aug 29 05:05:29.862521 2026] [security2:error] [pid 1017536:tid 1017779] [client 158.23.147.79:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK8-SJcY4fy7tP-rU3mzwAAAoU"] [Sat Aug 29 05:05:29.890631 2026] [security2:error] [pid 1017536:tid 1017720] [client 4.205.62.107:22325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/infos.php"] [unique_id "apK8-SJcY4fy7tP-rU3m0wAAAko"] [Sat Aug 29 05:05:29.899572 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.48.251.3:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/session.php"] [unique_id "apK8-SJcY4fy7tP-rU3m1AAAAkU"] [Sat Aug 29 05:05:29.911111 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.104.62:41606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/sf9.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiBAAABjU"] [Sat Aug 29 05:05:29.912869 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.23.147.79:38766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiBgAABio"] [Sat Aug 29 05:05:29.915678 2026] [security2:error] [pid 1018003:tid 1018270] [client 172.97.247.204:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutihomes.com"] [uri "/boats"] [unique_id "apK8-TAh5Y1i2tUxg4HiBQAABi4"], referer: https://www.djiboutihomes.com/ [Sat Aug 29 05:05:29.920685 2026] [security2:error] [pid 1018003:tid 1018241] [client 93.123.109.228:37394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/config/stripe.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiBwAABhE"] [Sat Aug 29 05:05:29.923492 2026] [security2:error] [pid 1018003:tid 1018213] [client 168.107.94.195:49563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiCAAABfY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:29.923513 2026] [security2:error] [pid 1018003:tid 1018165] [client 4.205.62.107:65427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/kerang.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiCQAABcY"] [Sat Aug 29 05:05:29.927480 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.158.54.35:10870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/lite.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiCgAABfk"] [Sat Aug 29 05:05:29.929955 2026] [security2:error] [pid 1017536:tid 1017742] [client 61.9.8.223:64173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK8-SJcY4fy7tP-rU3m3QAAAmA"] [Sat Aug 29 05:05:29.930076 2026] [security2:error] [pid 1017536:tid 1017742] [client 61.9.8.223:64173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK8-SJcY4fy7tP-rU3m3QAAAmA"] [Sat Aug 29 05:05:29.936319 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.160.90:63531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/emmh.php"] [unique_id "apK8-SJcY4fy7tP-rU3m3gAAAoc"] [Sat Aug 29 05:05:29.937275 2026] [security2:error] [pid 1017536:tid 1017760] [client 4.232.148.111:11014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/init.php"] [unique_id "apK8-SJcY4fy7tP-rU3m3wAAAnI"] [Sat Aug 29 05:05:29.941078 2026] [security2:error] [pid 1018003:tid 1018265] [client 209.50.181.31:13101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.181.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiAwAABik"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:29.941669 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.18.15:8187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/coffexium.php"] [unique_id "apK8-SJcY4fy7tP-rU3m4QAAAow"] [Sat Aug 29 05:05:29.945597 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.104.62:14798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/xcre1.php"] [unique_id "apK8-SJcY4fy7tP-rU3m4gAAAks"] [Sat Aug 29 05:05:29.948085 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.63.219.114:1214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/add_actualites.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiCwAABbw"] [Sat Aug 29 05:05:29.951802 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.49.130:48515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/srontol.php"] [unique_id "apK8-SJcY4fy7tP-rU3m4wAAApA"] [Sat Aug 29 05:05:29.959417 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.104.62:10443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/x23.php"] [unique_id "apK8-SJcY4fy7tP-rU3m5QAAAis"] [Sat Aug 29 05:05:29.966877 2026] [security2:error] [pid 1017536:tid 1017773] [client 4.205.62.107:2639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/aws.php"] [unique_id "apK8-SJcY4fy7tP-rU3m5wAAAn8"] [Sat Aug 29 05:05:29.971134 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.104.62:13598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/motu.php"] [unique_id "apK8-SJcY4fy7tP-rU3m6AAAAiE"] [Sat Aug 29 05:05:29.979980 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.251.3:13966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/ammika.php"] [unique_id "apK8-TAh5Y1i2tUxg4HiDQAABd8"] [Sat Aug 29 05:05:29.991106 2026] [autoindex:error] [pid 1018003:tid 1018199] [client 45.148.10.62:38648] AH01276: Cannot serve directory /home3/vvrewumy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:30.022619 2026] [security2:error] [pid 1018003:tid 1018181] [client 52.139.37.240:21388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gp3llc.com"] [uri "/flower.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiEAAABdY"] [Sat Aug 29 05:05:30.023861 2026] [security2:error] [pid 1017536:tid 1017678] [client 74.248.24.12:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/classwithtostring.php"] [unique_id "apK8-iJcY4fy7tP-rU3m7AAAAiA"] [Sat Aug 29 05:05:30.027763 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.251.3:28538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/h.php"] [unique_id "apK8-iJcY4fy7tP-rU3m7QAAAjQ"] [Sat Aug 29 05:05:30.030924 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.63.219.114:7463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/as.php"] [unique_id "apK8-iJcY4fy7tP-rU3m7gAAAmc"] [Sat Aug 29 05:05:30.040591 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.104.104.62:41652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/lte7.php"] [unique_id "apK8-iJcY4fy7tP-rU3m8AAAAns"] [Sat Aug 29 05:05:30.079021 2026] [security2:error] [pid 1017536:tid 1017719] [client 68.155.159.216:16234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/ans.php"] [unique_id "apK8-iJcY4fy7tP-rU3m8wAAAkk"] [Sat Aug 29 05:05:30.085636 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.104.18.15:8159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/BDKR28WP.php"] [unique_id "apK8-iJcY4fy7tP-rU3m9AAAAjY"] [Sat Aug 29 05:05:30.088969 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.104.62:14390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/motu.php"] [unique_id "apK8-iJcY4fy7tP-rU3m9QAAAoM"] [Sat Aug 29 05:05:30.090066 2026] [security2:error] [pid 1017536:tid 1017780] [client 68.155.159.216:57411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK8-iJcY4fy7tP-rU3m9gAAAoY"] [Sat Aug 29 05:05:30.109876 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.104.104.62:48690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/shelp.php"] [unique_id "apK8-iJcY4fy7tP-rU3m9wAAAnY"] [Sat Aug 29 05:05:30.116900 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.196.209.81:10678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/languages/index.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiFQAABeY"] [Sat Aug 29 05:05:30.128897 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.104.62:10456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/ws66.php"] [unique_id "apK8-iJcY4fy7tP-rU3m-AAAAkI"] [Sat Aug 29 05:05:30.131336 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.104.62:13568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/wefile.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiGwAABgc"] [Sat Aug 29 05:05:30.142888 2026] [security2:error] [pid 1017536:tid 1017731] [client 185.104.184.230:55998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK8-iJcY4fy7tP-rU3m-gAAAlU"] [Sat Aug 29 05:05:30.146154 2026] [security2:error] [pid 1017536:tid 1017691] [client 68.155.159.216:12168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/sad/about.php"] [unique_id "apK8-iJcY4fy7tP-rU3m_AAAAi0"] [Sat Aug 29 05:05:30.156488 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.251.3:28432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/bootstrap.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiHgAABeU"] [Sat Aug 29 05:05:30.156521 2026] [security2:error] [pid 1018003:tid 1018223] [client 20.48.251.3:13973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aws_config.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiHwAABgA"] [Sat Aug 29 05:05:30.166025 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.48.160.90:63540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/em.php"] [unique_id "apK8-iJcY4fy7tP-rU3nAAAAAlw"] [Sat Aug 29 05:05:30.174113 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.196.209.81:15746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/aksinet.php"] [unique_id "apK8-iJcY4fy7tP-rU3nAQAAAlA"] [Sat Aug 29 05:05:30.175909 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.104.104.62:41636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/tanjiro.php"] [unique_id "apK8-iJcY4fy7tP-rU3nAgAAAho"] [Sat Aug 29 05:05:30.184102 2026] [security2:error] [pid 1018003:tid 1018264] [client 149.34.210.141:57410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiIgAABig"] [Sat Aug 29 05:05:30.184194 2026] [security2:error] [pid 1018003:tid 1018264] [client 149.34.210.141:57410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiIgAABig"] [Sat Aug 29 05:05:30.222941 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.18.15:8148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/sf.php"] [unique_id "apK8-iJcY4fy7tP-rU3nBQAAAjI"] [Sat Aug 29 05:05:30.223089 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:14363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/wefile.php"] [unique_id "apK8-iJcY4fy7tP-rU3nBgAAAlo"] [Sat Aug 29 05:05:30.224678 2026] [security2:error] [pid 1018003:tid 1018164] [client 68.155.159.216:16249] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "familytrade.ca"] [uri "/1.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiJQAABcU"] [Sat Aug 29 05:05:30.224720 2026] [security2:error] [pid 1018003:tid 1018251] [client 192.145.125.70:35460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK8-jAh5Y1i2tUxg4HiJgAABhs"] [Sat Aug 29 05:05:30.224775 2026] [security2:error] [pid 1018003:tid 1018164] [client 68.155.159.216:16249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/1.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiJQAABcU"] [Sat Aug 29 05:05:30.233609 2026] [security2:error] [pid 1018003:tid 1018254] [client 103.171.189.88:50992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiJwAABh4"] [Sat Aug 29 05:05:30.233753 2026] [security2:error] [pid 1018003:tid 1018254] [client 103.171.189.88:50992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiJwAABh4"] [Sat Aug 29 05:05:30.259486 2026] [security2:error] [pid 1017536:tid 1017732] [client 74.248.24.12:21807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/init.php"] [unique_id "apK8-iJcY4fy7tP-rU3nCQAAAlY"] [Sat Aug 29 05:05:30.268779 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.104.62:13320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/EM.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiKwAABeE"] [Sat Aug 29 05:05:30.269792 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.104.62:44558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/Cok.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiLAAABew"] [Sat Aug 29 05:05:30.275575 2026] [security2:error] [pid 1018003:tid 1018179] [client 4.232.148.111:24931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiLQAABdQ"] [Sat Aug 29 05:05:30.278934 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.196.209.81:12720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/fi2.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiLgAABd0"] [Sat Aug 29 05:05:30.285443 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.251.3:27174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/333.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiLwAABfs"] [Sat Aug 29 05:05:30.297186 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.104.62:20807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/bd.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiMQAABeA"] [Sat Aug 29 05:05:30.298083 2026] [security2:error] [pid 1018003:tid 1018263] [client 45.148.10.62:38648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/api/.env"] [unique_id "apK8-jAh5Y1i2tUxg4HiMAAABic"] [Sat Aug 29 05:05:30.302443 2026] [security2:error] [pid 1018003:tid 1018269] [client 168.107.94.195:49919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiMgAABi0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:30.315200 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.104.62:41655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/Rk41.php"] [unique_id "apK8-iJcY4fy7tP-rU3nCgAAAmY"] [Sat Aug 29 05:05:30.320728 2026] [security2:error] [pid 1018003:tid 1018239] [client 68.155.159.216:33735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/goods.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiMwAABg8"] [Sat Aug 29 05:05:30.347450 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.48.160.90:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/dvve.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiNQAABbk"] [Sat Aug 29 05:05:30.357490 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.63.219.114:1422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/alfanew.php7"] [unique_id "apK8-iJcY4fy7tP-rU3nDwAAAn0"] [Sat Aug 29 05:05:30.360255 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.104.104.62:14396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/EM.php"] [unique_id "apK8-iJcY4fy7tP-rU3nEAAAAn0"] [Sat Aug 29 05:05:30.374017 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.18.15:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/132.php"] [unique_id "apK8-iJcY4fy7tP-rU3nEgAAAoc"] [Sat Aug 29 05:05:30.375563 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.158.54.35:21809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/term.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiOQAABf8"] [Sat Aug 29 05:05:30.376905 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.18.15:7003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/nox.php"] [unique_id "apK8-iJcY4fy7tP-rU3nFQAAAks"] [Sat Aug 29 05:05:30.377119 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.18.15:8187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/k.php"] [unique_id "apK8-iJcY4fy7tP-rU3nFAAAAow"] [Sat Aug 29 05:05:30.386980 2026] [security2:error] [pid 1017536:tid 1017788] [client 93.123.109.228:37338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nGwAAAo4"] [Sat Aug 29 05:05:30.400091 2026] [security2:error] [pid 1017536:tid 1017668] [client 93.123.109.228:37292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nHQAAAhY"] [Sat Aug 29 05:05:30.402481 2026] [security2:error] [pid 1017536:tid 1017668] [client 93.123.109.228:36610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nHgAAAhY"] [Sat Aug 29 05:05:30.403404 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.104.62:44564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/X7T6.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiOwAABds"] [Sat Aug 29 05:05:30.406640 2026] [security2:error] [pid 1018003:tid 1018178] [client 20.104.104.62:13627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/ca4.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiPAAABdM"] [Sat Aug 29 05:05:30.417555 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.251.3:27167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/G-in.php"] [unique_id "apK8-iJcY4fy7tP-rU3nHwAAAmw"] [Sat Aug 29 05:05:30.418213 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.63.219.114:1697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/room.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiPgAABc4"] [Sat Aug 29 05:05:30.419161 2026] [security2:error] [pid 1017536:tid 1017773] [client 93.123.109.228:37264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nIAAAAn8"] [Sat Aug 29 05:05:30.423560 2026] [security2:error] [pid 1018003:tid 1018255] [client 4.232.148.111:24818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiQQAABh8"] [Sat Aug 29 05:05:30.424639 2026] [security2:error] [pid 1017536:tid 1017679] [client 93.123.109.228:36644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nIQAAAiE"] [Sat Aug 29 05:05:30.433889 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.18.15:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/m.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiQgAABcQ"] [Sat Aug 29 05:05:30.452369 2026] [security2:error] [pid 1017536:tid 1017793] [client 185.104.184.230:56004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK8-iJcY4fy7tP-rU3nIwAAApM"] [Sat Aug 29 05:05:30.455263 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.104.62:48655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/13ede.php"] [unique_id "apK8-iJcY4fy7tP-rU3nJAAAAic"] [Sat Aug 29 05:05:30.455960 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.104.62:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/7logs.php"] [unique_id "apK8-iJcY4fy7tP-rU3nJQAAAig"] [Sat Aug 29 05:05:30.460016 2026] [security2:error] [pid 1018003:tid 1018198] [client 45.148.10.62:38648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/.env.bak"] [unique_id "apK8-jAh5Y1i2tUxg4HiRAAABec"] [Sat Aug 29 05:05:30.463246 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.104.18.15:23432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/m.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiRQAABhE"] [Sat Aug 29 05:05:30.489000 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.104.18.15:36698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/ws85.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiRgAABfI"] [Sat Aug 29 05:05:30.490784 2026] [security2:error] [pid 1018003:tid 1018193] [client 93.123.109.228:36682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK8-jAh5Y1i2tUxg4HiRwAABeI"] [Sat Aug 29 05:05:30.491307 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.48.160.90:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/doo.php"] [unique_id "apK8-iJcY4fy7tP-rU3nJgAAAoM"] [Sat Aug 29 05:05:30.493512 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.104.62:15298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/ca4.php"] [unique_id "apK8-iJcY4fy7tP-rU3nKAAAAiI"] [Sat Aug 29 05:05:30.495140 2026] [security2:error] [pid 1017536:tid 1017780] [client 93.123.109.228:36690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nJwAAAoY"] [Sat Aug 29 05:05:30.495351 2026] [security2:error] [pid 1017536:tid 1017755] [client 93.123.109.228:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nKQAAAm0"] [Sat Aug 29 05:05:30.517747 2026] [security2:error] [pid 1018003:tid 1018211] [client 20.196.209.81:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/languages/min.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiSAAABfQ"] [Sat Aug 29 05:05:30.542956 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.104.104.62:10863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/see.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiTAAABfg"] [Sat Aug 29 05:05:30.543514 2026] [security2:error] [pid 1018003:tid 1018247] [client 20.104.104.62:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/x0x.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiTQAABhc"] [Sat Aug 29 05:05:30.544486 2026] [security2:error] [pid 1018003:tid 1018157] [client 65.111.3.82:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiSQAABb4"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:30.544587 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.48.251.3:13960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/phpinfo01.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiTgAABhU"] [Sat Aug 29 05:05:30.549166 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.104.18.15:7073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/akismet.php"] [unique_id "apK8-iJcY4fy7tP-rU3nLQAAAlU"] [Sat Aug 29 05:05:30.550492 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.104.18.15:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/v22.php"] [unique_id "apK8-iJcY4fy7tP-rU3nLgAAAoo"] [Sat Aug 29 05:05:30.551690 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.251.3:28477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/apikeys.php"] [unique_id "apK8-iJcY4fy7tP-rU3nMAAAAj4"] [Sat Aug 29 05:05:30.564605 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.104.18.15:13251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/fling.php"] [unique_id "apK8-iJcY4fy7tP-rU3nMgAAAlQ"] [Sat Aug 29 05:05:30.584591 2026] [security2:error] [pid 1017536:tid 1017742] [client 74.248.24.12:33172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/news.php"] [unique_id "apK8-iJcY4fy7tP-rU3nNQAAAmA"] [Sat Aug 29 05:05:30.587037 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.104.104.62:22704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/sf.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiUgAABeY"] [Sat Aug 29 05:05:30.596085 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.196.209.81:15791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/alfa-rex1.php"] [unique_id "apK8-iJcY4fy7tP-rU3nNgAAAhc"] [Sat Aug 29 05:05:30.596494 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.18.15:8102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/82.php"] [unique_id "apK8-iJcY4fy7tP-rU3nNwAAAmM"] [Sat Aug 29 05:05:30.598296 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.104.18.15:23490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/fling.php"] [unique_id "apK8-iJcY4fy7tP-rU3nOAAAAk8"] [Sat Aug 29 05:05:30.624057 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.160.90:28618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/adminer-4.6.6.php"] [unique_id "apK8-iJcY4fy7tP-rU3nOQAAAlo"] [Sat Aug 29 05:05:30.639407 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.104.62:40215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/komet.php"] [unique_id "apK8-iJcY4fy7tP-rU3nPQAAAkE"] [Sat Aug 29 05:05:30.642521 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.104.104.62:15268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/x0x.php"] [unique_id "apK8-iJcY4fy7tP-rU3nPgAAAkQ"] [Sat Aug 29 05:05:30.674247 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.104.104.62:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/horeg.php"] [unique_id "apK8-iJcY4fy7tP-rU3nQwAAAjo"] [Sat Aug 29 05:05:30.674677 2026] [security2:error] [pid 1018003:tid 1018251] [client 68.155.159.216:50298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiVQAABhs"] [Sat Aug 29 05:05:30.680112 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.196.209.81:21092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/1p.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiVgAABg4"] [Sat Aug 29 05:05:30.680585 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.251.3:57843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/motu.php"] [unique_id "apK8-iJcY4fy7tP-rU3nRAAAAmQ"] [Sat Aug 29 05:05:30.681152 2026] [security2:error] [pid 1018003:tid 1018254] [client 20.104.104.62:13586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahrice-co-uk.glowt-shirt.com"] [uri "/fesa.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiVwAABh4"] [Sat Aug 29 05:05:30.681157 2026] [security2:error] [pid 1017536:tid 1017728] [client 158.23.147.79:53963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK8-iJcY4fy7tP-rU3nRQAAAlI"] [Sat Aug 29 05:05:30.685150 2026] [security2:error] [pid 1017536:tid 1017694] [client 168.107.94.195:50259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8-iJcY4fy7tP-rU3nRgAAAjA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:30.694092 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.18.15:7051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ajax.php"] [unique_id "apK8-iJcY4fy7tP-rU3nRwAAAkU"] [Sat Aug 29 05:05:30.709333 2026] [security2:error] [pid 1017536:tid 1017690] [client 4.205.62.107:61208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/wp-tem.php"] [unique_id "apK8-iJcY4fy7tP-rU3nSQAAAiw"] [Sat Aug 29 05:05:30.711523 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.18.15:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/btyuio.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiWQAABgk"] [Sat Aug 29 05:05:30.716631 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.104.62:22681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/super.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiWwAABb0"] [Sat Aug 29 05:05:30.717161 2026] [security2:error] [pid 1018003:tid 1018195] [client 93.123.109.228:36714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK8-jAh5Y1i2tUxg4HiWgAABeQ"] [Sat Aug 29 05:05:30.717575 2026] [security2:error] [pid 1018003:tid 1018253] [client 4.205.62.107:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/aws_settings.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiXAAABh0"] [Sat Aug 29 05:05:30.720233 2026] [security2:error] [pid 1017536:tid 1017772] [client 93.123.109.228:37302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK8-iJcY4fy7tP-rU3nSgAAAn4"] [Sat Aug 29 05:05:30.721450 2026] [security2:error] [pid 1017536:tid 1017753] [client 93.123.109.228:37338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nSwAAAms"] [Sat Aug 29 05:05:30.725517 2026] [security2:error] [pid 1017536:tid 1017707] [client 93.123.109.228:37292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nTAAAAj0"] [Sat Aug 29 05:05:30.727284 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.63.219.114:1588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/xmlrpc.php0"] [unique_id "apK8-jAh5Y1i2tUxg4HiXQAABcA"] [Sat Aug 29 05:05:30.749189 2026] [security2:error] [pid 1018003:tid 1018196] [client 4.232.148.111:24936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/upload.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiXwAABeU"] [Sat Aug 29 05:05:30.754788 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.18.15:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/ffs.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiYQAABdQ"] [Sat Aug 29 05:05:30.759215 2026] [security2:error] [pid 1017536:tid 1017790] [client 185.104.184.230:56016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK8-iJcY4fy7tP-rU3nTwAAApA"] [Sat Aug 29 05:05:30.759792 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.104.18.15:8090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/dex.php"] [unique_id "apK8-iJcY4fy7tP-rU3nUAAAAo4"] [Sat Aug 29 05:05:30.761745 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.18.15:47005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-activate.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiYwAABfs"] [Sat Aug 29 05:05:30.763011 2026] [security2:error] [pid 1018003:tid 1018191] [client 93.123.109.228:36682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK8-jAh5Y1i2tUxg4HiZAAABeA"] [Sat Aug 29 05:05:30.766781 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.48.160.90:64713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/gelap1.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiZQAABic"] [Sat Aug 29 05:05:30.768585 2026] [security2:error] [pid 1017536:tid 1017689] [client 93.123.109.228:37264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nUQAAAis"] [Sat Aug 29 05:05:30.774111 2026] [security2:error] [pid 1018003:tid 1018239] [client 158.23.147.79:30681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiZgAABg8"] [Sat Aug 29 05:05:30.779376 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.104.104.62:14367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.vistacounselingcolorado.com"] [uri "/fesa.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiZwAABfc"] [Sat Aug 29 05:05:30.788033 2026] [security2:error] [pid 1017536:tid 1017775] [client 74.248.24.12:28218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "apK8-iJcY4fy7tP-rU3nUgAAAoE"] [Sat Aug 29 05:05:30.810405 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.104.62:44600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/basic.php"] [unique_id "apK8-jAh5Y1i2tUxg4HiagAABhQ"] [Sat Aug 29 05:05:30.811471 2026] [security2:error] [pid 1018003:tid 1018194] [client 192.145.125.70:35472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK8-jAh5Y1i2tUxg4HibAAABeM"] [Sat Aug 29 05:05:30.813328 2026] [security2:error] [pid 1018003:tid 1018164] [client 158.158.54.35:15890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/config.php"] [unique_id "apK8-jAh5Y1i2tUxg4HibQAABcU"] [Sat Aug 29 05:05:30.818206 2026] [security2:error] [pid 1018003:tid 1018278] [client 64.89.161.160:55325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thedesignfit.com"] [uri "/assets/js/file-uploader/server/php/index.php"] [unique_id "apK8-jAh5Y1i2tUxg4HibwAABjY"] [Sat Aug 29 05:05:30.819616 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.251.3:28430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/public/mah.php.php"] [unique_id "apK8-jAh5Y1i2tUxg4HicAAABgw"] [Sat Aug 29 05:05:30.820089 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.18.15:23512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/btyuio.php"] [unique_id "apK8-iJcY4fy7tP-rU3nVgAAAhw"] [Sat Aug 29 05:05:30.820609 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.104.62:48654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/k8.php"] [unique_id "apK8-jAh5Y1i2tUxg4HicQAABfA"] [Sat Aug 29 05:05:30.822993 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.63.219.114:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/class-wp-cmd.php"] [unique_id "apK8-iJcY4fy7tP-rU3nVwAAAoU"] [Sat Aug 29 05:05:30.824764 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.18.15:7123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/atomlib.php"] [unique_id "apK8-iJcY4fy7tP-rU3nWAAAAlc"] [Sat Aug 29 05:05:30.838307 2026] [security2:error] [pid 1017536:tid 1017766] [client 4.205.62.107:21927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/aws_credentials.php"] [unique_id "apK8-iJcY4fy7tP-rU3nWgAAAng"] [Sat Aug 29 05:05:30.844853 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.18.15:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/dehnl.php"] [unique_id "apK8-jAh5Y1i2tUxg4HicgAABds"] [Sat Aug 29 05:05:30.845554 2026] [security2:error] [pid 1018003:tid 1018178] [client 68.155.159.216:51482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/sad/about.php"] [unique_id "apK8-jAh5Y1i2tUxg4HicwAABdM"] [Sat Aug 29 05:05:30.856351 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.104.62:22701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/lufix1.php"] [unique_id "apK8-jAh5Y1i2tUxg4HidAAABh8"] [Sat Aug 29 05:05:30.864810 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.104.62:20808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/1337.php"] [unique_id "apK8-iJcY4fy7tP-rU3nWwAAAik"] [Sat Aug 29 05:05:30.875403 2026] [security2:error] [pid 1017536:tid 1017686] [client 158.23.147.79:48296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/goods.php"] [unique_id "apK8-iJcY4fy7tP-rU3nXgAAAig"] [Sat Aug 29 05:05:30.877121 2026] [security2:error] [pid 1017536:tid 1017667] [client 93.123.109.228:37338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/info.php"] [unique_id "apK8-iJcY4fy7tP-rU3nYAAAAhU"] [Sat Aug 29 05:05:30.881385 2026] [security2:error] [pid 1018003:tid 1018257] [client 68.155.159.216:62892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK8-jAh5Y1i2tUxg4HidwAABiE"] [Sat Aug 29 05:05:30.892684 2026] [security2:error] [pid 1018003:tid 1018221] [client 93.123.109.228:37390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/infos.php"] [unique_id "apK8-jAh5Y1i2tUxg4HieQAABf4"] [Sat Aug 29 05:05:30.895033 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.251.3:14333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/oiko6u.php"] [unique_id "apK8-iJcY4fy7tP-rU3nYQAAAmc"] [Sat Aug 29 05:05:30.904880 2026] [security2:error] [pid 1017536:tid 1017769] [client 93.123.109.228:36690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/infophp.php"] [unique_id "apK8-iJcY4fy7tP-rU3nYgAAAns"] [Sat Aug 29 05:05:30.911592 2026] [security2:error] [pid 1017536:tid 1017681] [client 127.0.0.1:52374] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "apK8-iJcY4fy7tP-rU3nVQAAAiM"] [Sat Aug 29 05:05:30.913000 2026] [security2:error] [pid 1017536:tid 1017777] [client 158.23.147.79:25494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/file.php"] [unique_id "apK8-iJcY4fy7tP-rU3nZQAAAoM"] [Sat Aug 29 05:05:30.922475 2026] [security2:error] [pid 1018003:tid 1018269] [client 74.7.244.42:58066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.pee.bbn.mybluehost.me"] [uri "/robots.txt"] [unique_id "apK8-jAh5Y1i2tUxg4HibgAGLU8"] [Sat Aug 29 05:05:30.923757 2026] [security2:error] [pid 1017536:tid 1017675] [client 93.123.109.228:37264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK8-iJcY4fy7tP-rU3nawAAAh0"] [Sat Aug 29 05:05:30.924426 2026] [security2:error] [pid 1017536:tid 1017735] [client 20.196.209.81:4707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/languages/pk.php"] [unique_id "apK8-iJcY4fy7tP-rU3nbAAAAlk"] [Sat Aug 29 05:05:30.926010 2026] [security2:error] [pid 1018003:tid 1018162] [client 93.123.109.228:36612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK8-jAh5Y1i2tUxg4HifQAABcM"] [Sat Aug 29 05:05:30.931012 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.48.160.90:63538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/rsjlrria.php"] [unique_id "apK8-jAh5Y1i2tUxg4HifgAABhE"] [Sat Aug 29 05:05:30.943044 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.104.104.62:44545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/monso.php"] [unique_id "apK8-iJcY4fy7tP-rU3nbwAAAnY"] [Sat Aug 29 05:05:30.945890 2026] [security2:error] [pid 1018003:tid 1018213] [client 45.148.10.62:38648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/stripe/.env"] [unique_id "apK8-jAh5Y1i2tUxg4HifwAABfY"] [Sat Aug 29 05:05:30.953045 2026] [security2:error] [pid 1017536:tid 1017680] [client 4.205.62.107:53345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wp-class.php"] [unique_id "apK8-iJcY4fy7tP-rU3ncAAAAiI"] [Sat Aug 29 05:05:30.955079 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.104.18.15:23511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/dehnl.php"] [unique_id "apK8-jAh5Y1i2tUxg4HigAAABcE"] [Sat Aug 29 05:05:30.957077 2026] [security2:error] [pid 1018003:tid 1018265] [client 93.123.109.228:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK8-jAh5Y1i2tUxg4HigQAABik"] [Sat Aug 29 05:05:30.959431 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.18.15:46913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-trackback.php"] [unique_id "apK8-iJcY4fy7tP-rU3ncQAAAmg"] [Sat Aug 29 05:05:30.976179 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.251.3:28454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/zaza.php"] [unique_id "apK8-jAh5Y1i2tUxg4HigwAABes"] [Sat Aug 29 05:05:30.977334 2026] [security2:error] [pid 1018003:tid 1018190] [client 158.23.147.79:24573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK8-jAh5Y1i2tUxg4HihAAABd8"] [Sat Aug 29 05:05:30.982420 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.104.18.15:8191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/inso.php"] [unique_id "apK8-jAh5Y1i2tUxg4HihQAABgQ"] [Sat Aug 29 05:05:30.987351 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.104.104.62:41628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/hack.php"] [unique_id "apK8-jAh5Y1i2tUxg4HihgAABeg"] [Sat Aug 29 05:05:31.001133 2026] [security2:error] [pid 1018003:tid 1018205] [client 20.104.18.15:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/zoo2.php"] [unique_id "apK8-zAh5Y1i2tUxg4HihwAABe4"] [Sat Aug 29 05:05:31.006453 2026] [autoindex:error] [pid 1018003:tid 1018203] [client 4.232.148.111:20997] AH01276: Cannot serve directory /home4/ehfields/public_html/tiaandephraim/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:31.021084 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.196.209.81:15783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/headerg.php"] [unique_id "apK8-yJcY4fy7tP-rU3ncwAAAoQ"] [Sat Aug 29 05:05:31.026215 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.18.15:7058] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "moderntechservices.com"] [uri "/1.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiiQAABe8"] [Sat Aug 29 05:05:31.026310 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.18.15:7058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/1.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiiQAABe8"] [Sat Aug 29 05:05:31.026986 2026] [security2:error] [pid 1018003:tid 1018250] [client 4.205.62.107:22329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/vx.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiigAABho"] [Sat Aug 29 05:05:31.031965 2026] [security2:error] [pid 1017536:tid 1017784] [client 158.23.147.79:63035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/dropdown.php"] [unique_id "apK8-yJcY4fy7tP-rU3ndAAAAoo"] [Sat Aug 29 05:05:31.036633 2026] [security2:error] [pid 1018003:tid 1018262] [client 93.123.109.228:36714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HiiwAABiY"] [Sat Aug 29 05:05:31.050010 2026] [security2:error] [pid 1018003:tid 1018240] [client 93.123.109.228:36762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HijAAABhA"] [Sat Aug 29 05:05:31.055772 2026] [security2:error] [pid 1018003:tid 1018215] [client 4.205.62.107:65409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/rem.php"] [unique_id "apK8-zAh5Y1i2tUxg4HijQAABfg"] [Sat Aug 29 05:05:31.065294 2026] [security2:error] [pid 1018003:tid 1018247] [client 93.123.109.228:36654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HijgAABhc"] [Sat Aug 29 05:05:31.065987 2026] [security2:error] [pid 1018003:tid 1018245] [client 168.107.94.195:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8-zAh5Y1i2tUxg4HijwAABhU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:31.066771 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.48.160.90:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/AxAo.php"] [unique_id "apK8-yJcY4fy7tP-rU3neAAAAkw"] [Sat Aug 29 05:05:31.068910 2026] [security2:error] [pid 1017536:tid 1017670] [client 185.104.184.230:56030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK8-yJcY4fy7tP-rU3negAAAhg"] [Sat Aug 29 05:05:31.075195 2026] [security2:error] [pid 1018003:tid 1018157] [client 93.123.109.228:36754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HikAAABb4"] [Sat Aug 29 05:05:31.077619 2026] [security2:error] [pid 1018003:tid 1018226] [client 93.123.109.228:36612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HikQAABgM"] [Sat Aug 29 05:05:31.078410 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.104.104.62:10444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/rce.php"] [unique_id "apK8-zAh5Y1i2tUxg4HikgAABbo"] [Sat Aug 29 05:05:31.082563 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.63.219.114:18404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/content.php"] [unique_id "apK8-yJcY4fy7tP-rU3nfgAAAjg"] [Sat Aug 29 05:05:31.086264 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.196.209.81:21084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/Njima.php"] [unique_id "apK8-zAh5Y1i2tUxg4HikwAABfk"] [Sat Aug 29 05:05:31.096156 2026] [security2:error] [pid 1017536:tid 1017716] [client 104.207.40.179:41041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.40.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8-yJcY4fy7tP-rU3newAAAkY"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:31.097234 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.104.18.15:23435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/zoo2.php"] [unique_id "apK8-zAh5Y1i2tUxg4HilQAABcs"] [Sat Aug 29 05:05:31.099236 2026] [security2:error] [pid 1018003:tid 1018223] [client 4.205.62.107:2994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/05.php"] [unique_id "apK8-zAh5Y1i2tUxg4HilgAABgA"] [Sat Aug 29 05:05:31.102644 2026] [security2:error] [pid 1018003:tid 1018276] [client 93.123.109.228:36682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HilwAABjQ"] [Sat Aug 29 05:05:31.103451 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.104.62:40206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/backd00r.php"] [unique_id "apK8-yJcY4fy7tP-rU3ngAAAAkE"] [Sat Aug 29 05:05:31.104182 2026] [security2:error] [pid 1018003:tid 1018264] [client 93.123.109.228:37266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HimAAABig"] [Sat Aug 29 05:05:31.104211 2026] [security2:error] [pid 1017536:tid 1017714] [client 93.123.109.228:36610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK8-yJcY4fy7tP-rU3ngQAAAkQ"] [Sat Aug 29 05:05:31.108139 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.48.251.3:28463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/u88.php"] [unique_id "apK8-zAh5Y1i2tUxg4HimQAABc8"] [Sat Aug 29 05:05:31.110210 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.18.15:47046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/pri.php"] [unique_id "apK8-yJcY4fy7tP-rU3nggAAAhs"] [Sat Aug 29 05:05:31.111495 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.48.250.41:27601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/f35.php"] [unique_id "apK8-yJcY4fy7tP-rU3ngwAAAl0"] [Sat Aug 29 05:05:31.113953 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.104.104.62:41617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/155.php"] [unique_id "apK8-yJcY4fy7tP-rU3nhAAAAjo"] [Sat Aug 29 05:05:31.128834 2026] [security2:error] [pid 1017536:tid 1017671] [client 74.248.24.12:35491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/about/function.php"] [unique_id "apK8-yJcY4fy7tP-rU3nhgAAAhk"] [Sat Aug 29 05:05:31.132671 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.251.3:14297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/fraro.php"] [unique_id "apK8-yJcY4fy7tP-rU3nhwAAAj8"] [Sat Aug 29 05:05:31.139917 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.18.15:8077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/aa.php"] [unique_id "apK8-yJcY4fy7tP-rU3niAAAAko"] [Sat Aug 29 05:05:31.143623 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.18.15:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/zoo1.php"] [unique_id "apK8-yJcY4fy7tP-rU3niQAAAkU"] [Sat Aug 29 05:05:31.152025 2026] [security2:error] [pid 1018003:tid 1018184] [client 93.123.109.228:36660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HimwAABdk"] [Sat Aug 29 05:05:31.152566 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.18.15:36839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/nano.php"] [unique_id "apK8-yJcY4fy7tP-rU3nigAAAjE"] [Sat Aug 29 05:05:31.159636 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.104.104.62:48746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/alog.php"] [unique_id "apK8-yJcY4fy7tP-rU3niwAAAiw"] [Sat Aug 29 05:05:31.166566 2026] [security2:error] [pid 1017536:tid 1017707] [client 93.123.109.228:36644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK8-yJcY4fy7tP-rU3njQAAAj0"] [Sat Aug 29 05:05:31.175104 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.18.15:7146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/samll.php"] [unique_id "apK8-zAh5Y1i2tUxg4HingAABb0"] [Sat Aug 29 05:05:31.188806 2026] [security2:error] [pid 1018003:tid 1018253] [client 68.155.159.216:16141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/worksec.php"] [unique_id "apK8-zAh5Y1i2tUxg4HioAAABh0"] [Sat Aug 29 05:05:31.197262 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.63.219.114:10105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/disagreed.php"] [unique_id "apK8-yJcY4fy7tP-rU3nkAAAAi8"] [Sat Aug 29 05:05:31.206958 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.104.62:10478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/exec.php"] [unique_id "apK8-yJcY4fy7tP-rU3nkwAAAhY"] [Sat Aug 29 05:05:31.224378 2026] [autoindex:error] [pid 1017536:tid 1017689] [client 4.232.148.111:0] AH01276: Cannot serve directory /home4/ehfields/public_html/tiaandephraim/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:31.224762 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.160.90:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/class17.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiowAABeU"] [Sat Aug 29 05:05:31.226032 2026] [security2:error] [pid 1018003:tid 1018179] [client 93.123.109.228:36612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HipAAABdQ"] [Sat Aug 29 05:05:31.229428 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.18.15:23531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/zoo1.php"] [unique_id "apK8-yJcY4fy7tP-rU3nlgAAAlc"] [Sat Aug 29 05:05:31.236123 2026] [security2:error] [pid 1017536:tid 1017766] [client 93.123.109.228:36778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK8-yJcY4fy7tP-rU3nmAAAAng"] [Sat Aug 29 05:05:31.238708 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.48.251.3:28491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/config/laravolt/css/index.php"] [unique_id "apK8-yJcY4fy7tP-rU3nmgAAAik"] [Sat Aug 29 05:05:31.246233 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.104.104.62:22676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/mcd.php"] [unique_id "apK8-zAh5Y1i2tUxg4HipgAABbg"] [Sat Aug 29 05:05:31.266227 2026] [security2:error] [pid 1017536:tid 1017746] [client 158.158.54.35:10827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK8-yJcY4fy7tP-rU3nngAAAmQ"] [Sat Aug 29 05:05:31.267821 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.250.41:23480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/users.php"] [unique_id "apK8-yJcY4fy7tP-rU3nnwAAAig"] [Sat Aug 29 05:05:31.269743 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.48.250.41:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/amp.php"] [unique_id "apK8-yJcY4fy7tP-rU3noAAAAhU"] [Sat Aug 29 05:05:31.277221 2026] [security2:error] [pid 1017536:tid 1017588] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/app/.env"] [unique_id "apK8-yJcY4fy7tP-rU3npQACcjM"] [Sat Aug 29 05:05:31.279233 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.18.15:13230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/radio.php"] [unique_id "apK8-yJcY4fy7tP-rU3npgAAAnk"] [Sat Aug 29 05:05:31.280643 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.104.18.15:8185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/img.php"] [unique_id "apK8-yJcY4fy7tP-rU3npwAAAmI"] [Sat Aug 29 05:05:31.284384 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.18.15:46974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp_blog_footer.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiqgAABbk"] [Sat Aug 29 05:05:31.287529 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.250.41:12375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/s1.php"] [unique_id "apK8-yJcY4fy7tP-rU3nqgAAAk4"] [Sat Aug 29 05:05:31.311386 2026] [core:error] [pid 1017536:tid 1017694] [client 74.248.24.12:16573] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.311411 2026] [core:error] [pid 1017536:tid 1017694] [client 74.248.24.12:16573] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.321677 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.196.209.81:4711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carolinashooter.lowfatdinnermenus.com"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK8-zAh5Y1i2tUxg4HirAAABhI"] [Sat Aug 29 05:05:31.330969 2026] [security2:error] [pid 1018003:tid 1018278] [client 68.155.159.216:16248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/ws.php"] [unique_id "apK8-zAh5Y1i2tUxg4HirgAABjY"] [Sat Aug 29 05:05:31.335633 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.251.3:13969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/thui.php"] [unique_id "apK8-yJcY4fy7tP-rU3nsAAAAos"] [Sat Aug 29 05:05:31.336640 2026] [security2:error] [pid 1017536:tid 1017776] [client 127.0.0.1:52396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "apK8-yJcY4fy7tP-rU3nnQAAAoI"] [Sat Aug 29 05:05:31.336724 2026] [security2:error] [pid 1017536:tid 1017793] [client 127.0.0.1:52392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.macaromedia.com"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "apK8-yJcY4fy7tP-rU3nnAAAApM"] [Sat Aug 29 05:05:31.337143 2026] [security2:error] [pid 1017536:tid 1017741] [client 74.7.228.1:44172] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.macaromedia.com"] [uri "/robots.txt"] [unique_id "apK8-yJcY4fy7tP-rU3nmwACXzI"] [Sat Aug 29 05:05:31.337955 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.104.62:48454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/adin.php"] [unique_id "apK8-yJcY4fy7tP-rU3nsQAAAiI"] [Sat Aug 29 05:05:31.344567 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.104.18.15:7135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/she11.php"] [unique_id "apK8-yJcY4fy7tP-rU3nsgAAAns"] [Sat Aug 29 05:05:31.345441 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.104.62:40231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/backdoor.php"] [unique_id "apK8-yJcY4fy7tP-rU3nswAAAoY"] [Sat Aug 29 05:05:31.346853 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.104.62:10484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/dbc.php"] [unique_id "apK8-zAh5Y1i2tUxg4HirwAABgw"] [Sat Aug 29 05:05:31.350144 2026] [security2:error] [pid 1017536:tid 1017758] [client 20.104.18.15:36838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/ano.php"] [unique_id "apK8-yJcY4fy7tP-rU3ntQAAAnA"] [Sat Aug 29 05:05:31.352810 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.48.250.41:27580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wen.php"] [unique_id "apK8-yJcY4fy7tP-rU3ntgAAAlE"] [Sat Aug 29 05:05:31.369589 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.251.3:27171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/87.php"] [unique_id "apK8-yJcY4fy7tP-rU3ntwAAAk0"] [Sat Aug 29 05:05:31.373698 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.160.90:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/okxoby.php"] [unique_id "apK8-yJcY4fy7tP-rU3nuAAAAmk"] [Sat Aug 29 05:05:31.378461 2026] [security2:error] [pid 1017536:tid 1017708] [client 185.104.184.230:56046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK8-yJcY4fy7tP-rU3nuQAAAj4"] [Sat Aug 29 05:05:31.383656 2026] [security2:error] [pid 1018003:tid 1018207] [client 4.232.148.111:20997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-content/admin.php"] [unique_id "apK8-zAh5Y1i2tUxg4HisAAABfA"] [Sat Aug 29 05:05:31.383862 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.18.15:23534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/radio.php"] [unique_id "apK8-yJcY4fy7tP-rU3nuwAAAok"] [Sat Aug 29 05:05:31.385467 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.104.62:41624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/waw.php"] [unique_id "apK8-yJcY4fy7tP-rU3nvQAAAi0"] [Sat Aug 29 05:05:31.387995 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.250.41:57683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/Geforce.php"] [unique_id "apK8-yJcY4fy7tP-rU3nvwAAAjk"] [Sat Aug 29 05:05:31.391910 2026] [security2:error] [pid 1017536:tid 1017601] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/frontend/.env"] [unique_id "apK8-yJcY4fy7tP-rU3nwAACF0A"] [Sat Aug 29 05:05:31.409137 2026] [security2:error] [pid 1017536:tid 1017787] [client 192.145.125.70:35480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK8-yJcY4fy7tP-rU3nwgAAAo0"] [Sat Aug 29 05:05:31.413976 2026] [security2:error] [pid 1017536:tid 1017551] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/server/.env"] [unique_id "apK8-yJcY4fy7tP-rU3nxQACYA4"] [Sat Aug 29 05:05:31.416240 2026] [security2:error] [pid 1017536:tid 1017717] [client 45.148.10.59:57668] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "theverystuff.com"] [uri "/wp/"] [unique_id "apK8-yJcY4fy7tP-rU3nxwAAAkc"] [Sat Aug 29 05:05:31.421511 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.18.15:47032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/sushi.php"] [unique_id "apK8-yJcY4fy7tP-rU3nyAAAAmM"] [Sat Aug 29 05:05:31.422129 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.48.250.41:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/cc13.php"] [unique_id "apK8-yJcY4fy7tP-rU3nyQAAAkY"] [Sat Aug 29 05:05:31.422761 2026] [security2:error] [pid 1017536:tid 1017711] [client 68.155.159.216:33762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK8-yJcY4fy7tP-rU3nygAAAkE"] [Sat Aug 29 05:05:31.427983 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.104.18.15:13198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/one.php"] [unique_id "apK8-zAh5Y1i2tUxg4HitQAABdU"] [Sat Aug 29 05:05:31.428840 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.48.250.41:12433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/0byte.php"] [unique_id "apK8-zAh5Y1i2tUxg4HitgAABc4"] [Sat Aug 29 05:05:31.435536 2026] [security2:error] [pid 1018003:tid 1018187] [client 45.148.10.246:23456] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "eastsidepride.com"] [uri "/blog/"] [unique_id "apK8-zAh5Y1i2tUxg4HitwAABdw"] [Sat Aug 29 05:05:31.442041 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.63.219.114:1673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/wxo.php"] [unique_id "apK8-yJcY4fy7tP-rU3nywAAAm4"] [Sat Aug 29 05:05:31.445504 2026] [security2:error] [pid 1018003:tid 1018257] [client 168.107.94.195:50997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiuQAABiE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:31.445551 2026] [security2:error] [pid 1018003:tid 1018230] [client 93.123.109.228:36754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/php-info.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiuAAABgY"] [Sat Aug 29 05:05:31.448309 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.196.209.81:25036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/meta.php"] [unique_id "apK8-yJcY4fy7tP-rU3nzAAAAiA"] [Sat Aug 29 05:05:31.453969 2026] [security2:error] [pid 1017536:tid 1017671] [client 20.104.18.15:8153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/222.php"] [unique_id "apK8-yJcY4fy7tP-rU3nzQAAAhk"] [Sat Aug 29 05:05:31.457991 2026] [security2:error] [pid 1018003:tid 1018275] [client 93.123.109.228:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/php.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiuwAABjM"] [Sat Aug 29 05:05:31.459910 2026] [security2:error] [pid 1017536:tid 1017709] [client 93.123.109.228:36610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/php_info.php"] [unique_id "apK8-yJcY4fy7tP-rU3nzgAAAj8"] [Sat Aug 29 05:05:31.460687 2026] [security2:error] [pid 1018003:tid 1018221] [client 93.123.109.228:36682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/phpinfo.php"] [unique_id "apK8-zAh5Y1i2tUxg4HivAAABf4"] [Sat Aug 29 05:05:31.474928 2026] [security2:error] [pid 1017536:tid 1017596] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/src/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n0AACSjs"] [Sat Aug 29 05:05:31.484746 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.48.250.41:27646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/inc.php"] [unique_id "apK8-yJcY4fy7tP-rU3n0QAAAn4"] [Sat Aug 29 05:05:31.485105 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.196.209.81:12689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/configs.php"] [unique_id "apK8-yJcY4fy7tP-rU3n0gAAAoo"] [Sat Aug 29 05:05:31.496069 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:23433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/bzjdlofz.php"] [unique_id "apK8-yJcY4fy7tP-rU3n0wAAAj0"] [Sat Aug 29 05:05:31.498735 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.104.104.62:44594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/wp-wlx.php"] [unique_id "apK8-yJcY4fy7tP-rU3n1AAAAn0"] [Sat Aug 29 05:05:31.499051 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.251.3:27146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/plss3.php"] [unique_id "apK8-yJcY4fy7tP-rU3n1QAAAnc"] [Sat Aug 29 05:05:31.503323 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.104.18.15:36783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/mgrr.php"] [unique_id "apK8-yJcY4fy7tP-rU3n1wAAAi8"] [Sat Aug 29 05:05:31.503344 2026] [security2:error] [pid 1018003:tid 1018172] [client 93.123.109.228:36660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HivQAABc0"] [Sat Aug 29 05:05:31.509546 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.18.15:7084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/kerang.php"] [unique_id "apK8-yJcY4fy7tP-rU3n2AAAAhY"] [Sat Aug 29 05:05:31.514310 2026] [security2:error] [pid 1018003:tid 1018189] [client 103.162.125.59:50869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK8-zAh5Y1i2tUxg4HivgAABd4"] [Sat Aug 29 05:05:31.514430 2026] [security2:error] [pid 1018003:tid 1018189] [client 103.162.125.59:50869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK8-zAh5Y1i2tUxg4HivgAABd4"] [Sat Aug 29 05:05:31.518948 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.104.104.62:22690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/x23.php"] [unique_id "apK8-zAh5Y1i2tUxg4HivwAABi0"] [Sat Aug 29 05:05:31.519956 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.18.15:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/one.php"] [unique_id "apK8-yJcY4fy7tP-rU3n2QAAAoE"] [Sat Aug 29 05:05:31.524037 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.160.90:62628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/esuutzzx.php"] [unique_id "apK8-yJcY4fy7tP-rU3n2gAAAmw"] [Sat Aug 29 05:05:31.555882 2026] [security2:error] [pid 1017536:tid 1017541] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/docker/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n3QACXgQ"] [Sat Aug 29 05:05:31.556059 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.48.251.3:13957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/lala.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiwQAABi4"] [Sat Aug 29 05:05:31.559300 2026] [security2:error] [pid 1017536:tid 1017725] [client 93.123.109.228:37366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n3gAAAk8"] [Sat Aug 29 05:05:31.563536 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.250.41:12374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/xr.php"] [unique_id "apK8-yJcY4fy7tP-rU3n3wAAAiU"] [Sat Aug 29 05:05:31.564234 2026] [security2:error] [pid 1017536:tid 1017761] [client 4.232.148.111:5896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-content/file.php"] [unique_id "apK8-yJcY4fy7tP-rU3n4AAAAnM"] [Sat Aug 29 05:05:31.564503 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.49.130:30239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/worksec.php"] [unique_id "apK8-yJcY4fy7tP-rU3n4QAAAig"] [Sat Aug 29 05:05:31.565288 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.63.219.114:1545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/class_api.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiwgAABh8"] [Sat Aug 29 05:05:31.566618 2026] [security2:error] [pid 1017536:tid 1017653] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/production/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n4wACeXQ"] [Sat Aug 29 05:05:31.576224 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:13203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/503.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiwwAABec"] [Sat Aug 29 05:05:31.578908 2026] [security2:error] [pid 1018003:tid 1018241] [client 93.123.109.228:36654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HixAAABhE"] [Sat Aug 29 05:05:31.582883 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.48.250.41:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/aa.php"] [unique_id "apK8-yJcY4fy7tP-rU3n5QAAAkk"] [Sat Aug 29 05:05:31.588416 2026] [security2:error] [pid 1017536:tid 1017734] [client 93.123.109.228:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n5gAAAlg"] [Sat Aug 29 05:05:31.594110 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.250.41:61793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/click.php"] [unique_id "apK8-yJcY4fy7tP-rU3n5wAAAjA"] [Sat Aug 29 05:05:31.597040 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.18.15:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/manga.php"] [unique_id "apK8-zAh5Y1i2tUxg4HixgAABjU"] [Sat Aug 29 05:05:31.598489 2026] [security2:error] [pid 1018003:tid 1018160] [client 45.148.10.62:38648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/backend/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HixwAABcE"] [Sat Aug 29 05:05:31.601284 2026] [security2:error] [pid 1017536:tid 1017561] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/staging/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n6AACZRg"] [Sat Aug 29 05:05:31.606563 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.18.15:8073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/key.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiyAAABbw"] [Sat Aug 29 05:05:31.607594 2026] [security2:error] [pid 1018003:tid 1018224] [client 93.123.109.228:36714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HiyQAABgE"] [Sat Aug 29 05:05:31.613523 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.104.104.62:47595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/andela.php"] [unique_id "apK8-yJcY4fy7tP-rU3n6gAAAl8"] [Sat Aug 29 05:05:31.623932 2026] [security2:error] [pid 1017536:tid 1017755] [client 20.48.250.41:27519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/6bcwiqwj.php"] [unique_id "apK8-yJcY4fy7tP-rU3n7AAAAm0"] [Sat Aug 29 05:05:31.626316 2026] [security2:error] [pid 1018003:tid 1018199] [client 93.123.109.228:36728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK8-zAh5Y1i2tUxg4HiygAABeg"] [Sat Aug 29 05:05:31.626780 2026] [security2:error] [pid 1017536:tid 1017666] [client 20.48.251.3:57848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws.php"] [unique_id "apK8-yJcY4fy7tP-rU3n7QAAAhQ"] [Sat Aug 29 05:05:31.630740 2026] [security2:error] [pid 1017536:tid 1017688] [client 93.123.109.228:37302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/public/phpinfo.php"] [unique_id "apK8-yJcY4fy7tP-rU3n7wAAAio"] [Sat Aug 29 05:05:31.632066 2026] [security2:error] [pid 1017536:tid 1017758] [client 93.123.109.228:36702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n7gAAAnA"] [Sat Aug 29 05:05:31.641009 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.104.104.62:10476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/attack.php"] [unique_id "apK8-yJcY4fy7tP-rU3n8AAAAi4"] [Sat Aug 29 05:05:31.647765 2026] [security2:error] [pid 1018003:tid 1018205] [client 20.104.18.15:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/m.php"] [unique_id "apK8-zAh5Y1i2tUxg4HiywAABe4"] [Sat Aug 29 05:05:31.658522 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.48.160.90:63542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/replace.php"] [unique_id "apK8-zAh5Y1i2tUxg4HizQAABhg"] [Sat Aug 29 05:05:31.665217 2026] [security2:error] [pid 1017536:tid 1017753] [client 93.123.109.228:37264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n8QAAAms"] [Sat Aug 29 05:05:31.669289 2026] [security2:error] [pid 1017536:tid 1017589] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/apps/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n8wACVTQ"] [Sat Aug 29 05:05:31.671321 2026] [core:error] [pid 1017536:tid 1017774] [client 74.248.24.12:5302] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.671333 2026] [core:error] [pid 1017536:tid 1017774] [client 74.248.24.12:5302] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.671958 2026] [security2:error] [pid 1018003:tid 1018220] [client 185.104.184.230:56056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.mcdcomputers.net"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK8-zAh5Y1i2tUxg4Hi0AAABf0"] [Sat Aug 29 05:05:31.679142 2026] [security2:error] [pid 1018003:tid 1018252] [client 45.3.47.190:62731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8-zAh5Y1i2tUxg4HizAAABhw"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:31.683376 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.48.250.41:23425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/selesai.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi0wAABdY"] [Sat Aug 29 05:05:31.697745 2026] [security2:error] [pid 1018003:tid 1018260] [client 20.104.18.15:36751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/mac.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi1AAABiQ"] [Sat Aug 29 05:05:31.699267 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.18.15:23433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/503.php"] [unique_id "apK8-yJcY4fy7tP-rU3n9gAAAmk"] [Sat Aug 29 05:05:31.699374 2026] [security2:error] [pid 1018003:tid 1018154] [client 158.158.54.35:23950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-good.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi1QAABbs"] [Sat Aug 29 05:05:31.700220 2026] [security2:error] [pid 1017536:tid 1017708] [client 93.123.109.228:36644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK8-yJcY4fy7tP-rU3n9QAAAj4"] [Sat Aug 29 05:05:31.701063 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.104.62:48598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/sf9.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi1gAABfo"] [Sat Aug 29 05:05:31.705919 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.104.62:54539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/ws66.php"] [unique_id "apK8-yJcY4fy7tP-rU3n9wAAAi0"] [Sat Aug 29 05:05:31.709495 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.18.15:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/504.php"] [unique_id "apK8-yJcY4fy7tP-rU3n-AAAAhc"] [Sat Aug 29 05:05:31.710734 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.250.41:12312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/h02ugyh.php"] [unique_id "apK8-yJcY4fy7tP-rU3n-QAAAoc"] [Sat Aug 29 05:05:31.720852 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.48.250.41:64933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/s1.php"] [unique_id "apK8-yJcY4fy7tP-rU3n-wAAAn8"] [Sat Aug 29 05:05:31.725297 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.250.41:57665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/ms.php"] [unique_id "apK8-yJcY4fy7tP-rU3n_AAAAmA"] [Sat Aug 29 05:05:31.736987 2026] [security2:error] [pid 1017536:tid 1017737] [client 68.155.159.216:12250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/admin.php"] [unique_id "apK8-yJcY4fy7tP-rU3n_QAAAls"] [Sat Aug 29 05:05:31.747242 2026] [security2:error] [pid 1018003:tid 1018157] [client 45.148.10.62:38648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/test.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi2gAABb4"] [Sat Aug 29 05:05:31.747960 2026] [security2:error] [pid 1017536:tid 1017557] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/v1/.env"] [unique_id "apK8-yJcY4fy7tP-rU3oAQACQRQ"] [Sat Aug 29 05:05:31.755665 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.251.3:27162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/app.default.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi2wAABgM"] [Sat Aug 29 05:05:31.759295 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.250.41:26884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/easy.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi3AAABfU"] [Sat Aug 29 05:05:31.770858 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.104.62:10455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/file66.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi3gAABis"] [Sat Aug 29 05:05:31.780240 2026] [security2:error] [pid 1017536:tid 1017704] [client 45.148.10.59:57668] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "theverystuff.com"] [uri "/wordpress/"] [unique_id "apK8-yJcY4fy7tP-rU3oAgAAAjo"] [Sat Aug 29 05:05:31.784381 2026] [security2:error] [pid 1017536:tid 1017671] [client 68.155.159.216:50206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/content.php"] [unique_id "apK8-yJcY4fy7tP-rU3oBAAAAhk"] [Sat Aug 29 05:05:31.786091 2026] [security2:error] [pid 1017536:tid 1017715] [client 158.23.147.79:58880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/ans.php"] [unique_id "apK8-yJcY4fy7tP-rU3oBQAAAkU"] [Sat Aug 29 05:05:31.789200 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.160.90:64744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/gulu.php"] [unique_id "apK8-yJcY4fy7tP-rU3oBgAAAjE"] [Sat Aug 29 05:05:31.792319 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.48.251.3:13985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wsws.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi4QAABgk"] [Sat Aug 29 05:05:31.804074 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.104.18.15:7095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/fling.php"] [unique_id "apK8-yJcY4fy7tP-rU3oCAAAAn0"] [Sat Aug 29 05:05:31.809809 2026] [security2:error] [pid 1017536:tid 1017562] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/old/.env"] [unique_id "apK8-yJcY4fy7tP-rU3oCgACdxk"] [Sat Aug 29 05:05:31.814172 2026] [security2:error] [pid 1017536:tid 1017558] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/dev/.env"] [unique_id "apK8-yJcY4fy7tP-rU3oDQACFhU"] [Sat Aug 29 05:05:31.822088 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.18.15:8076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/chosen.php"] [unique_id "apK8-yJcY4fy7tP-rU3oDgAAAks"] [Sat Aug 29 05:05:31.825171 2026] [security2:error] [pid 1017536:tid 1017786] [client 168.107.94.195:51444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8-yJcY4fy7tP-rU3oEAAAAow"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:31.825733 2026] [security2:error] [pid 1017536:tid 1017595] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/portal/.env"] [unique_id "apK8-yJcY4fy7tP-rU3oDwACUzo"] [Sat Aug 29 05:05:31.836916 2026] [core:error] [pid 1018003:tid 1018203] [client 74.248.24.12:21785] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.836936 2026] [core:error] [pid 1018003:tid 1018203] [client 74.248.24.12:21785] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.840402 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.48.250.41:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/xxw.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi6AAABeA"] [Sat Aug 29 05:05:31.841402 2026] [security2:error] [pid 1017536:tid 1017567] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/v2/.env"] [unique_id "apK8-yJcY4fy7tP-rU3oEwACVx4"] [Sat Aug 29 05:05:31.841574 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.104.62:22713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/Cok.php"] [unique_id "apK8-yJcY4fy7tP-rU3oFAAAAiE"] [Sat Aug 29 05:05:31.843187 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.18.15:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/admin.php"] [unique_id "apK8-yJcY4fy7tP-rU3oFQAAAik"] [Sat Aug 29 05:05:31.844504 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.63.219.114:1693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/as.php"] [unique_id "apK8-yJcY4fy7tP-rU3oFgAAAlw"] [Sat Aug 29 05:05:31.846047 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.196.209.81:25058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/dxc.php"] [unique_id "apK8-yJcY4fy7tP-rU3oFwAAAkw"] [Sat Aug 29 05:05:31.852845 2026] [security2:error] [pid 1018003:tid 1018239] [client 4.205.62.107:64923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/wp-konfig.backup.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi6QAABg8"] [Sat Aug 29 05:05:31.867981 2026] [security2:error] [pid 1017536:tid 1017670] [client 34.12.38.134:40670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/web.config"] [unique_id "apK8-yJcY4fy7tP-rU3oGgAAAhg"] [Sat Aug 29 05:05:31.869275 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.104.18.15:47099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/asdfghj.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi6gAABic"] [Sat Aug 29 05:05:31.869885 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.104.62:20848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/jkt48.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi6wAABhY"] [Sat Aug 29 05:05:31.872088 2026] [security2:error] [pid 1017536:tid 1017746] [client 4.205.62.107:54456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/txets.php"] [unique_id "apK8-yJcY4fy7tP-rU3oGwAAAmQ"] [Sat Aug 29 05:05:31.880249 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.250.41:23514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/shlo.php"] [unique_id "apK8-yJcY4fy7tP-rU3oIQAAAjQ"] [Sat Aug 29 05:05:31.884499 2026] [core:error] [pid 1017536:tid 1017787] [client 34.12.38.134:40678] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.884514 2026] [core:error] [pid 1017536:tid 1017787] [client 34.12.38.134:40678] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.886291 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.196.209.81:21108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/disagraeed.php"] [unique_id "apK8-yJcY4fy7tP-rU3oJAAAAho"] [Sat Aug 29 05:05:31.892463 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.104.18.15:23517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/504.php"] [unique_id "apK8-yJcY4fy7tP-rU3oJwAAAmc"] [Sat Aug 29 05:05:31.896028 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.48.251.3:27158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/app_local.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi8gAABeM"] [Sat Aug 29 05:05:31.896066 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.18.15:36777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/simple.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi8wAABd0"] [Sat Aug 29 05:05:31.899161 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.48.250.41:58518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/zxekqlxb.php"] [unique_id "apK8-yJcY4fy7tP-rU3oKgAAAic"] [Sat Aug 29 05:05:31.900342 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.104.62:44607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/zafir1.php"] [unique_id "apK8-yJcY4fy7tP-rU3oLAAAAjA"] [Sat Aug 29 05:05:31.903670 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.250.41:26938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/fresh3.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi9AAABcU"] [Sat Aug 29 05:05:31.906722 2026] [core:error] [pid 1017536:tid 1017777] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.906747 2026] [core:error] [pid 1017536:tid 1017777] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.916424 2026] [security2:error] [pid 1018003:tid 1018170] [client 34.12.38.134:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.38.12.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/configuration.php.bak"] [unique_id "apK8-zAh5Y1i2tUxg4Hi-gAABcs"] [Sat Aug 29 05:05:31.917786 2026] [security2:error] [pid 1017536:tid 1017783] [client 4.232.148.111:32737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-configs.php"] [unique_id "apK8-yJcY4fy7tP-rU3oLQAAAok"] [Sat Aug 29 05:05:31.922400 2026] [core:error] [pid 1018003:tid 1018223] [client 34.12.38.134:40782] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.922431 2026] [core:error] [pid 1018003:tid 1018223] [client 34.12.38.134:40782] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.922630 2026] [core:error] [pid 1017536:tid 1017777] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.922643 2026] [core:error] [pid 1017536:tid 1017777] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.922789 2026] [security2:error] [pid 1017536:tid 1017606] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/site/.env"] [unique_id "apK8-yJcY4fy7tP-rU3oLwACbUU"] [Sat Aug 29 05:05:31.934506 2026] [core:error] [pid 1017536:tid 1017710] [client 34.12.38.134:40788] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.934532 2026] [core:error] [pid 1017536:tid 1017710] [client 34.12.38.134:40788] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.936108 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.250.41:64988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/0byte.php"] [unique_id "apK8-yJcY4fy7tP-rU3oNQAAAiM"] [Sat Aug 29 05:05:31.939495 2026] [core:error] [pid 1018003:tid 1018222] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.939516 2026] [core:error] [pid 1018003:tid 1018222] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.950046 2026] [core:error] [pid 1018003:tid 1018197] [client 34.12.38.134:40768] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.950071 2026] [core:error] [pid 1018003:tid 1018197] [client 34.12.38.134:40768] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.950822 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.48.160.90:63544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/gtghklk.php"] [unique_id "apK8-yJcY4fy7tP-rU3oOAAAAoQ"] [Sat Aug 29 05:05:31.954338 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.251.3:13993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/localconf.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi_QAABds"] [Sat Aug 29 05:05:31.954902 2026] [core:error] [pid 1017536:tid 1017769] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.954922 2026] [core:error] [pid 1017536:tid 1017769] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.957010 2026] [core:error] [pid 1017536:tid 1017772] [client 34.12.38.134:40800] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.957026 2026] [core:error] [pid 1017536:tid 1017772] [client 34.12.38.134:40800] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.958323 2026] [security2:error] [pid 1017536:tid 1017710] [client 34.12.38.134:40788] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK8-yJcY4fy7tP-rU3oMQAAAkA"] [Sat Aug 29 05:05:31.962940 2026] [core:error] [pid 1017536:tid 1017739] [client 34.12.38.134:40790] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.962961 2026] [core:error] [pid 1017536:tid 1017739] [client 34.12.38.134:40790] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.963239 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.63.219.114:1695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/aksinet.php"] [unique_id "apK8-yJcY4fy7tP-rU3oPQAAAm8"] [Sat Aug 29 05:05:31.964973 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.104.18.15:7161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/btyuio.php"] [unique_id "apK8-yJcY4fy7tP-rU3oPwAAAlE"] [Sat Aug 29 05:05:31.966951 2026] [core:error] [pid 1017536:tid 1017683] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.966968 2026] [core:error] [pid 1017536:tid 1017683] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.967061 2026] [core:error] [pid 1017536:tid 1017764] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.967073 2026] [core:error] [pid 1017536:tid 1017764] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.967191 2026] [security2:error] [pid 1017536:tid 1017764] [client 34.12.38.134:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK8-yJcY4fy7tP-rU3oPgAAAnY"] [Sat Aug 29 05:05:31.970890 2026] [core:error] [pid 1017536:tid 1017731] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.970906 2026] [core:error] [pid 1017536:tid 1017731] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.972537 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.104.18.15:8173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/file1221.php"] [unique_id "apK8-yJcY4fy7tP-rU3oQQAAAjY"] [Sat Aug 29 05:05:31.973373 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.104.62:41651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/X7T6.php"] [unique_id "apK8-yJcY4fy7tP-rU3oQgAAAmE"] [Sat Aug 29 05:05:31.973446 2026] [security2:error] [pid 1017536:tid 1017717] [client 34.12.38.134:40724] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/ssl/server.key"] [unique_id "apK8-yJcY4fy7tP-rU3oJgAAAkc"] [Sat Aug 29 05:05:31.973735 2026] [security2:error] [pid 1018003:tid 1018035] [remote 162.55.89.48:36626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dmisner.net"] [uri "/wp-login.php"] [unique_id "apK8-zAh5Y1i2tUxg4Hi_gAFvQ4"] [Sat Aug 29 05:05:31.978427 2026] [security2:error] [pid 1017536:tid 1017716] [client 4.205.62.107:21872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/v1.php"] [unique_id "apK8-yJcY4fy7tP-rU3oRQAAAkY"] [Sat Aug 29 05:05:31.978499 2026] [security2:error] [pid 1017536:tid 1017792] [client 145.239.10.137:47353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "woosigns.com"] [uri "/ultra-enc.php"] [unique_id "apK8-yJcY4fy7tP-rU3oRgAAApI"], referer: http://woosigns.com/ultra-enc.php [Sat Aug 29 05:05:31.982210 2026] [core:error] [pid 1017536:tid 1017737] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.982226 2026] [core:error] [pid 1017536:tid 1017737] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:31.986125 2026] [security2:error] [pid 1018003:tid 1018257] [client 158.23.147.79:48172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK8-zAh5Y1i2tUxg4HjAAAABiE"] [Sat Aug 29 05:05:31.987131 2026] [security2:error] [pid 1017536:tid 1017756] [client 68.155.159.216:62882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK8-yJcY4fy7tP-rU3oSAAAAm4"] [Sat Aug 29 05:05:31.988063 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.104.18.15:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ws85.php"] [unique_id "apK8-yJcY4fy7tP-rU3oSQAAAiY"] [Sat Aug 29 05:05:31.996224 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.48.250.41:12354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/bolt.php"] [unique_id "apK8-yJcY4fy7tP-rU3oSgAAAkU"] [Sat Aug 29 05:05:31.998988 2026] [security2:error] [pid 1017536:tid 1017703] [client 192.145.125.70:35496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK8-yJcY4fy7tP-rU3oSwAAAjk"] [Sat Aug 29 05:05:32.018629 2026] [security2:error] [pid 1017536:tid 1017771] [client 158.23.147.79:25537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/file17.php"] [unique_id "apK8_CJcY4fy7tP-rU3oTgAAAn0"] [Sat Aug 29 05:05:32.025166 2026] [security2:error] [pid 1017536:tid 1017748] [client 111.235.68.106:53633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK8_CJcY4fy7tP-rU3oTwAAAmY"] [Sat Aug 29 05:05:32.025291 2026] [security2:error] [pid 1017536:tid 1017748] [client 111.235.68.106:53633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK8_CJcY4fy7tP-rU3oTwAAAmY"] [Sat Aug 29 05:05:32.026319 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.251.3:27151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/ws62.php"] [unique_id "apK8_CJcY4fy7tP-rU3oUAAAAlY"] [Sat Aug 29 05:05:32.041794 2026] [security2:error] [pid 1017536:tid 1017693] [client 93.123.109.228:36644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK8_CJcY4fy7tP-rU3oUQAAAi8"] [Sat Aug 29 05:05:32.042055 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.104.62:44553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/console.php"] [unique_id "apK8_CJcY4fy7tP-rU3oUgAAAlc"] [Sat Aug 29 05:05:32.043270 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.104.62:20702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/gaza.php"] [unique_id "apK8_CJcY4fy7tP-rU3oUwAAAiE"] [Sat Aug 29 05:05:32.043656 2026] [security2:error] [pid 1018003:tid 1018161] [client 4.232.148.111:32354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/files.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjBQAABcI"] [Sat Aug 29 05:05:32.048115 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.18.15:23476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/admin.php"] [unique_id "apK8_CJcY4fy7tP-rU3oVQAAAjs"] [Sat Aug 29 05:05:32.059134 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.250.41:23364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/asax.php"] [unique_id "apK8_CJcY4fy7tP-rU3oVgAAAoE"] [Sat Aug 29 05:05:32.066330 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.18.15:47022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/dragonshell.php"] [unique_id "apK8_CJcY4fy7tP-rU3oVwAAAjQ"] [Sat Aug 29 05:05:32.074435 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.250.41:27594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/bgymj.php"] [unique_id "apK8_CJcY4fy7tP-rU3oWAAAAmc"] [Sat Aug 29 05:05:32.087554 2026] [security2:error] [pid 1017536:tid 1017694] [client 158.23.147.79:24547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-login.php"] [unique_id "apK8_CJcY4fy7tP-rU3oWQAAAjA"] [Sat Aug 29 05:05:32.091086 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.48.251.3:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/bengi.php"] [unique_id "apK8_CJcY4fy7tP-rU3oWgAAApM"] [Sat Aug 29 05:05:32.094228 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.18.15:36704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/xty.php"] [unique_id "apK8_CJcY4fy7tP-rU3oWwAAAok"] [Sat Aug 29 05:05:32.100659 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.250.41:58540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/init.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjCAAABh8"] [Sat Aug 29 05:05:32.101288 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.160.90:62636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/comand.php"] [unique_id "apK8_CJcY4fy7tP-rU3oXQAAAiM"] [Sat Aug 29 05:05:32.102929 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.104.104.62:41637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/see.php"] [unique_id "apK8_CJcY4fy7tP-rU3oXgAAAi4"] [Sat Aug 29 05:05:32.120024 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.18.15:8164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/nox.php"] [unique_id "apK8_CJcY4fy7tP-rU3oYAAAAk0"] [Sat Aug 29 05:05:32.121059 2026] [security2:error] [pid 1017536:tid 1017751] [client 4.205.62.107:53425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/hosty.php"] [unique_id "apK8_CJcY4fy7tP-rU3oYQAAAmk"] [Sat Aug 29 05:05:32.127923 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.48.250.41:12423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/rtx.php"] [unique_id "apK8_CJcY4fy7tP-rU3oYgAAAns"] [Sat Aug 29 05:05:32.132931 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.18.15:13209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ffs.php"] [unique_id "apK8_CJcY4fy7tP-rU3oZAAAAiU"] [Sat Aug 29 05:05:32.142911 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.18.15:7056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/dehnl.php"] [unique_id "apK8_CJcY4fy7tP-rU3oZQAAAkk"] [Sat Aug 29 05:05:32.146607 2026] [security2:error] [pid 1017536:tid 1017720] [client 158.158.54.35:11043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "apK8_CJcY4fy7tP-rU3oZgAAAko"] [Sat Aug 29 05:05:32.149141 2026] [security2:error] [pid 1017536:tid 1017758] [client 158.23.147.79:63847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/sad/about.php"] [unique_id "apK8_CJcY4fy7tP-rU3oZwAAAnA"] [Sat Aug 29 05:05:32.153792 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.251.3:28462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/grsiuk.php"] [unique_id "apK8_CJcY4fy7tP-rU3oaAAAAk4"] [Sat Aug 29 05:05:32.154508 2026] [security2:error] [pid 1017536:tid 1017696] [client 66.248.203.2:52442] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2011/07/11/moving-right-along/"] [unique_id "apK8_CJcY4fy7tP-rU3oaQAAAjI"] [Sat Aug 29 05:05:32.166653 2026] [security2:error] [pid 1017536:tid 1017742] [client 4.205.62.107:21843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/radio.php"] [unique_id "apK8_CJcY4fy7tP-rU3obAAAAmA"] [Sat Aug 29 05:05:32.167982 2026] [security2:error] [pid 1017536:tid 1017776] [client 93.123.109.228:36702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK8_CJcY4fy7tP-rU3oawAAAoI"] [Sat Aug 29 05:05:32.168694 2026] [security2:error] [pid 1018003:tid 1018193] [client 93.123.109.228:36692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK8_DAh5Y1i2tUxg4HjDAAABeI"] [Sat Aug 29 05:05:32.174152 2026] [security2:error] [pid 1017536:tid 1017737] [client 45.148.10.59:57668] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "theverystuff.com"] [uri "/blog/"] [unique_id "apK8_CJcY4fy7tP-rU3obQAAAls"] [Sat Aug 29 05:05:32.179231 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:44551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/blnux.php"] [unique_id "apK8_CJcY4fy7tP-rU3obwAAAlo"] [Sat Aug 29 05:05:32.185501 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.48.250.41:62218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/xr.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjDwAABe8"] [Sat Aug 29 05:05:32.192990 2026] [security2:error] [pid 1017536:tid 1017726] [client 74.248.24.12:8966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/admin.php"] [unique_id "apK8_CJcY4fy7tP-rU3ocQAAAlA"] [Sat Aug 29 05:05:32.197588 2026] [security2:error] [pid 1017536:tid 1017615] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/.docker/.env"] [unique_id "apK8_CJcY4fy7tP-rU3ocgACIE4"] [Sat Aug 29 05:05:32.201288 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.63.219.114:10055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/room.php"] [unique_id "apK8_CJcY4fy7tP-rU3odQAAAnM"] [Sat Aug 29 05:05:32.201335 2026] [security2:error] [pid 1017536:tid 1017709] [client 93.123.109.228:37378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK8_CJcY4fy7tP-rU3ocwAAAj8"] [Sat Aug 29 05:05:32.201695 2026] [security2:error] [pid 1017536:tid 1017715] [client 4.205.62.107:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/min.php"] [unique_id "apK8_CJcY4fy7tP-rU3odwAAAkU"] [Sat Aug 29 05:05:32.203502 2026] [security2:error] [pid 1017536:tid 1017571] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/env.old"] [unique_id "apK8_CJcY4fy7tP-rU3odgACJiI"] [Sat Aug 29 05:05:32.204628 2026] [security2:error] [pid 1017536:tid 1017564] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/.env.production.bak"] [unique_id "apK8_CJcY4fy7tP-rU3oeAACJhs"] [Sat Aug 29 05:05:32.207130 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.104.62:40215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/injection.php"] [unique_id "apK8_CJcY4fy7tP-rU3oeQAAAjE"] [Sat Aug 29 05:05:32.207493 2026] [security2:error] [pid 1018003:tid 1018252] [client 168.107.94.195:51833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjEAAABhw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:32.208254 2026] [security2:error] [pid 1017536:tid 1017548] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/api/.env.bak"] [unique_id "apK8_CJcY4fy7tP-rU3oegACJgs"] [Sat Aug 29 05:05:32.208990 2026] [security2:error] [pid 1017536:tid 1017664] [remote 34.138.108.56:53920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/env.bak"] [unique_id "apK8_CJcY4fy7tP-rU3oewACJn8"] [Sat Aug 29 05:05:32.210503 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.250.41:23528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/fetch.php"] [unique_id "apK8_CJcY4fy7tP-rU3ofQAAAjk"] [Sat Aug 29 05:05:32.223881 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.104.18.15:23441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ws85.php"] [unique_id "apK8_CJcY4fy7tP-rU3ogAAAAog"] [Sat Aug 29 05:05:32.228705 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.18.15:47015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-safe.php"] [unique_id "apK8_CJcY4fy7tP-rU3ogQAAAnc"] [Sat Aug 29 05:05:32.234446 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.104.62:22659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/horeg.php"] [unique_id "apK8_CJcY4fy7tP-rU3oggAAAmY"] [Sat Aug 29 05:05:32.236185 2026] [security2:error] [pid 1017536:tid 1017690] [client 4.205.62.107:2510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/xmy.php"] [unique_id "apK8_CJcY4fy7tP-rU3ogwAAAiw"] [Sat Aug 29 05:05:32.237157 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.48.251.3:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/i.php"] [unique_id "apK8_CJcY4fy7tP-rU3ohAAAAks"] [Sat Aug 29 05:05:32.240363 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.48.160.90:63520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apK8_CJcY4fy7tP-rU3ohQAAApA"] [Sat Aug 29 05:05:32.240444 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.196.209.81:25075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/wp-2019.php"] [unique_id "apK8_CJcY4fy7tP-rU3ohgAAAiI"] [Sat Aug 29 05:05:32.240772 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.48.250.41:27596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ws69.php"] [unique_id "apK8_CJcY4fy7tP-rU3ohwAAAlM"] [Sat Aug 29 05:05:32.248279 2026] [security2:error] [pid 1017536:tid 1017786] [client 57.141.14.71:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK8_CJcY4fy7tP-rU3oiAAAAow"] [Sat Aug 29 05:05:32.252567 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.48.250.41:12468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/ckk.php"] [unique_id "apK8_CJcY4fy7tP-rU3oiwAAAlw"] [Sat Aug 29 05:05:32.253186 2026] [security2:error] [pid 1017536:tid 1017687] [client 68.155.159.216:57449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/.well-knownold/index.php"] [unique_id "apK8_CJcY4fy7tP-rU3ojAAAAik"] [Sat Aug 29 05:05:32.256175 2026] [security2:error] [pid 1017536:tid 1017755] [client 45.148.10.62:38658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/.env.backup"] [unique_id "apK8_CJcY4fy7tP-rU3ojQAAAm0"] [Sat Aug 29 05:05:32.258699 2026] [security2:error] [pid 1017536:tid 1017746] [client 45.3.34.110:28763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8_CJcY4fy7tP-rU3ofAAAAmQ"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:32.264605 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.48.250.41:61753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/term.php"] [unique_id "apK8_CJcY4fy7tP-rU3ojgAAAiE"] [Sat Aug 29 05:05:32.266175 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.18.15:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/nano.php"] [unique_id "apK8_CJcY4fy7tP-rU3ojwAAAiE"] [Sat Aug 29 05:05:32.278626 2026] [security2:error] [pid 1017536:tid 1017672] [client 68.155.159.216:14314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-mail.php"] [unique_id "apK8_CJcY4fy7tP-rU3okQAAAho"] [Sat Aug 29 05:05:32.285845 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.251.3:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/paypal.php"] [unique_id "apK8_CJcY4fy7tP-rU3okgAAAnk"] [Sat Aug 29 05:05:32.287560 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.196.209.81:21115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/add_actualites.php"] [unique_id "apK8_CJcY4fy7tP-rU3okwAAAjg"] [Sat Aug 29 05:05:32.290619 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.18.15:8167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/akismet.php"] [unique_id "apK8_CJcY4fy7tP-rU3olAAAAlg"] [Sat Aug 29 05:05:32.292007 2026] [security2:error] [pid 1017536:tid 1017780] [client 52.139.37.240:65163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/aged.php"] [unique_id "apK8_CJcY4fy7tP-rU3olQAAAoY"] [Sat Aug 29 05:05:32.319236 2026] [security2:error] [pid 1017536:tid 1017666] [client 93.123.109.228:36702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK8_CJcY4fy7tP-rU3omAAAAhQ"] [Sat Aug 29 05:05:32.319548 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.63.219.114:1665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/alfa-rex1.php"] [unique_id "apK8_CJcY4fy7tP-rU3omQAAAis"] [Sat Aug 29 05:05:32.324146 2026] [security2:error] [pid 1018003:tid 1018271] [client 93.123.109.228:36692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK8_DAh5Y1i2tUxg4HjFwAABi8"] [Sat Aug 29 05:05:32.329421 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.104.62:44580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/pentest.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjGAAABb4"] [Sat Aug 29 05:05:32.358981 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.104.18.15:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/zoo2.php"] [unique_id "apK8_CJcY4fy7tP-rU3omwAAAnY"] [Sat Aug 29 05:05:32.362404 2026] [security2:error] [pid 1017536:tid 1017704] [client 74.248.24.12:3573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-content/admin.php"] [unique_id "apK8_CJcY4fy7tP-rU3onAAAAjo"] [Sat Aug 29 05:05:32.365315 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.18.15:23498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ffs.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjGQAABgc"] [Sat Aug 29 05:05:32.366197 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.18.15:46988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/gjewuagf.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjGgAABfU"] [Sat Aug 29 05:05:32.366807 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.48.250.41:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/h02ugyh.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjGwAABek"] [Sat Aug 29 05:05:32.380401 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.104.62:41630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/basic.php"] [unique_id "apK8_CJcY4fy7tP-rU3ongAAAoc"] [Sat Aug 29 05:05:32.382478 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.48.250.41:12448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "employedlawyer.com"] [uri "/R57.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjHQAABig"] [Sat Aug 29 05:05:32.394083 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.48.160.90:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apK8_CJcY4fy7tP-rU3ooAAAAjI"] [Sat Aug 29 05:05:32.394572 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.104.18.15:13311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ano.php"] [unique_id "apK8_CJcY4fy7tP-rU3ooQAAAjY"] [Sat Aug 29 05:05:32.394949 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.232.148.111:3030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-includes/index.php"] [unique_id "apK8_CJcY4fy7tP-rU3oogAAAlY"] [Sat Aug 29 05:05:32.406004 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.251.3:14330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/guk.php"] [unique_id "apK8_CJcY4fy7tP-rU3opAAAAlU"] [Sat Aug 29 05:05:32.407084 2026] [security2:error] [pid 1017536:tid 1017792] [client 45.148.10.62:38658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/.env.old"] [unique_id "apK8_CJcY4fy7tP-rU3opQAAApI"] [Sat Aug 29 05:05:32.411909 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.48.250.41:57686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/aaa.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjHgAABdg"] [Sat Aug 29 05:05:32.413371 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.104.104.62:48475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/lte7.php"] [unique_id "apK8_CJcY4fy7tP-rU3opgAAAmA"] [Sat Aug 29 05:05:32.415753 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.250.41:23530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/vx.php"] [unique_id "apK8_CJcY4fy7tP-rU3opwAAAoI"] [Sat Aug 29 05:05:32.429308 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.48.251.3:57915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/userfuns.php"] [unique_id "apK8_CJcY4fy7tP-rU3oqAAAAhs"] [Sat Aug 29 05:05:32.429998 2026] [security2:error] [pid 1018003:tid 1018235] [client 93.123.109.228:36654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK8_DAh5Y1i2tUxg4HjIAAABgs"] [Sat Aug 29 05:05:32.436032 2026] [security2:error] [pid 1017536:tid 1017726] [client 93.123.109.228:37292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK8_CJcY4fy7tP-rU3oqQAAAlA"] [Sat Aug 29 05:05:32.437066 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.48.250.41:26932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ccs.php"] [unique_id "apK8_CJcY4fy7tP-rU3oqwAAAiA"] [Sat Aug 29 05:05:32.451708 2026] [security2:error] [pid 1017536:tid 1017604] [remote 34.138.108.56:53920] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "proppastie.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK8_CJcY4fy7tP-rU3orQACRUM"] [Sat Aug 29 05:05:32.452768 2026] [security2:error] [pid 1018003:tid 1018253] [client 68.155.159.216:16316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/css/index.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjIQAABh0"] [Sat Aug 29 05:05:32.462961 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.18.15:8092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ajax.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjIwAABdQ"] [Sat Aug 29 05:05:32.464385 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.104.104.62:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/6y7t.php"] [unique_id "apK8_CJcY4fy7tP-rU3orgAAAiY"] [Sat Aug 29 05:05:32.475627 2026] [security2:error] [pid 1018003:tid 1018192] [client 68.155.159.216:51515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/admin.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjJAAABeE"] [Sat Aug 29 05:05:32.479992 2026] [security2:error] [pid 1017536:tid 1017737] [client 52.139.37.240:37934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/essexec.php"] [unique_id "apK8_CJcY4fy7tP-rU3osQAAAls"] [Sat Aug 29 05:05:32.502316 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.18.15:23379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/nano.php"] [unique_id "apK8_CJcY4fy7tP-rU3otAAAAmY"] [Sat Aug 29 05:05:32.503228 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.104.104.62:64723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/bejak.php"] [unique_id "apK8_CJcY4fy7tP-rU3otQAAAiw"] [Sat Aug 29 05:05:32.505023 2026] [security2:error] [pid 1018003:tid 1018191] [client 93.123.109.228:36728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK8_DAh5Y1i2tUxg4HjJgAABeA"] [Sat Aug 29 05:05:32.517147 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.104.62:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/monso.php"] [unique_id "apK8_CJcY4fy7tP-rU3ouAAAAl4"] [Sat Aug 29 05:05:32.530249 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.160.90:28671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/edit.php"] [unique_id "apK8_CJcY4fy7tP-rU3ouQAAAow"] [Sat Aug 29 05:05:32.531284 2026] [security2:error] [pid 1017536:tid 1017784] [client 68.155.159.216:33779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK8_CJcY4fy7tP-rU3ougAAAoo"] [Sat Aug 29 05:05:32.532653 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.250.41:64253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/xxw.php"] [unique_id "apK8_CJcY4fy7tP-rU3ovQAAAow"] [Sat Aug 29 05:05:32.532695 2026] [security2:error] [pid 1017536:tid 1017719] [client 4.232.148.111:19618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/o.php"] [unique_id "apK8_CJcY4fy7tP-rU3ovAAAAkk"] [Sat Aug 29 05:05:32.541423 2026] [security2:error] [pid 1017536:tid 1017643] [remote 45.148.10.166:42896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "waysidebaptistmission.lifesosweet.com"] [uri "/wp-json/batch/v1"] [unique_id "apK8_CJcY4fy7tP-rU3ovgACcGo"] [Sat Aug 29 05:05:32.547008 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.104.104.62:32840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jen.chow-s.com"] [uri "/new4.php"] [unique_id "apK8_CJcY4fy7tP-rU3owAAAAkw"] [Sat Aug 29 05:05:32.550521 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.18.15:13286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/mgrr.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjKQAABbk"] [Sat Aug 29 05:05:32.553858 2026] [security2:error] [pid 1017536:tid 1017671] [client 20.63.219.114:10074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/class-wp-cmd.php"] [unique_id "apK8_CJcY4fy7tP-rU3owgAAAhk"] [Sat Aug 29 05:05:32.556448 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.104.18.15:7131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/zoo1.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjKgAABeM"] [Sat Aug 29 05:05:32.558606 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.250.41:61750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/xsox.php"] [unique_id "apK8_CJcY4fy7tP-rU3oxAAAAjQ"] [Sat Aug 29 05:05:32.558674 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.48.251.3:27195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/mamzi.php"] [unique_id "apK8_CJcY4fy7tP-rU3oxQAAAo0"] [Sat Aug 29 05:05:32.570975 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.147.79:50062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjKwAABd0"] [Sat Aug 29 05:05:32.573085 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.104.18.15:36758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/sallu.php"] [unique_id "apK8_CJcY4fy7tP-rU3oxwAAAjg"] [Sat Aug 29 05:05:32.579389 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.48.251.3:13975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/config_dev.php"] [unique_id "apK8_CJcY4fy7tP-rU3oyAAAAlg"] [Sat Aug 29 05:05:32.588456 2026] [security2:error] [pid 1018003:tid 1018244] [client 168.107.94.195:52172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjLgAABhQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:32.598822 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.104.18.15:46967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/tnglzqmv.php"] [unique_id "apK8_CJcY4fy7tP-rU3oywAAAi4"] [Sat Aug 29 05:05:32.604345 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.250.41:23465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/global.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjLwAABcs"] [Sat Aug 29 05:05:32.604619 2026] [security2:error] [pid 1018003:tid 1018251] [client 158.158.54.35:10872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/abcd.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjMAAABhs"] [Sat Aug 29 05:05:32.606048 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.104.62:44557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/0xs.php"] [unique_id "apK8_CJcY4fy7tP-rU3ozQAAAms"] [Sat Aug 29 05:05:32.608351 2026] [security2:error] [pid 1017536:tid 1017710] [client 192.145.125.70:35512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK8_CJcY4fy7tP-rU3ozgAAAkA"] [Sat Aug 29 05:05:32.635574 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.250.41:26886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/mar.php"] [unique_id "apK8_CJcY4fy7tP-rU3ozwAAAm8"] [Sat Aug 29 05:05:32.637456 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.104.18.15:8105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/atomlib.php"] [unique_id "apK8_CJcY4fy7tP-rU3o0AAAAo8"] [Sat Aug 29 05:05:32.638088 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.18.15:23468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ano.php"] [unique_id "apK8_CJcY4fy7tP-rU3o0QAAAoM"] [Sat Aug 29 05:05:32.666615 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.160.90:28547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/tqkdqbbv.php"] [unique_id "apK8_CJcY4fy7tP-rU3o1gAAAiU"] [Sat Aug 29 05:05:32.673250 2026] [security2:error] [pid 1017536:tid 1017793] [client 52.139.37.240:54170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/fw.php"] [unique_id "apK8_CJcY4fy7tP-rU3o2AAAApM"] [Sat Aug 29 05:05:32.675225 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.63.219.114:18478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/headerg.php"] [unique_id "apK8_CJcY4fy7tP-rU3o2QAAAk8"] [Sat Aug 29 05:05:32.676215 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.250.41:64954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/bolt.php"] [unique_id "apK8_CJcY4fy7tP-rU3o2gAAAlY"] [Sat Aug 29 05:05:32.677114 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.104.62:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/rce.php"] [unique_id "apK8_CJcY4fy7tP-rU3o2wAAAko"] [Sat Aug 29 05:05:32.677862 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.18.15:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/mac.php"] [unique_id "apK8_CJcY4fy7tP-rU3o3AAAApI"] [Sat Aug 29 05:05:32.677935 2026] [security2:error] [pid 1018003:tid 1018222] [client 93.123.109.228:36714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK8_DAh5Y1i2tUxg4HjMQAABf8"] [Sat Aug 29 05:05:32.682309 2026] [security2:error] [pid 1017536:tid 1017742] [client 93.123.109.228:36702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK8_CJcY4fy7tP-rU3o3QAAAmA"] [Sat Aug 29 05:05:32.683652 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.196.209.81:4509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/alfanew.php7"] [unique_id "apK8_CJcY4fy7tP-rU3o3gAAAi8"] [Sat Aug 29 05:05:32.684833 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.250.41:61729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/lkui.php"] [unique_id "apK8_CJcY4fy7tP-rU3o4AAAAkQ"] [Sat Aug 29 05:05:32.690155 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.48.251.3:27155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/public/rip.php.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjNwAABeY"] [Sat Aug 29 05:05:32.694507 2026] [security2:error] [pid 1017536:tid 1017726] [client 93.123.109.228:36742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK8_CJcY4fy7tP-rU3o5AAAAlA"] [Sat Aug 29 05:05:32.695938 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.18.15:7111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/radio.php"] [unique_id "apK8_CJcY4fy7tP-rU3o5QAAAiA"] [Sat Aug 29 05:05:32.709446 2026] [security2:error] [pid 1017536:tid 1017684] [client 45.148.10.62:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/.env.php.bak"] [unique_id "apK8_CJcY4fy7tP-rU3o5wAAAiY"] [Sat Aug 29 05:05:32.710589 2026] [security2:error] [pid 1017536:tid 1017745] [client 93.123.109.228:36632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK8_CJcY4fy7tP-rU3o6AAAAmM"] [Sat Aug 29 05:05:32.720234 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.18.15:36697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/codex.php"] [unique_id "apK8_CJcY4fy7tP-rU3o6gAAAls"] [Sat Aug 29 05:05:32.727145 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.18.15:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wefile.php"] [unique_id "apK8_CJcY4fy7tP-rU3o6wAAAkY"] [Sat Aug 29 05:05:32.728404 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.251.3:14295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aws_credentials.php"] [unique_id "apK8_CJcY4fy7tP-rU3o7AAAAj0"] [Sat Aug 29 05:05:32.740263 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.104.62:10471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/waf.php"] [unique_id "apK8_CJcY4fy7tP-rU3o7gAAAks"] [Sat Aug 29 05:05:32.743025 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.104.104.62:33287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jen.chow-s.com"] [uri "/pouhg.php"] [unique_id "apK8_CJcY4fy7tP-rU3o7wAAAlU"] [Sat Aug 29 05:05:32.745130 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.196.209.81:25025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/menu.php"] [unique_id "apK8_CJcY4fy7tP-rU3o8AAAAkI"] [Sat Aug 29 05:05:32.757780 2026] [security2:error] [pid 1017536:tid 1017738] [client 93.123.109.228:37292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK8_CJcY4fy7tP-rU3o8wAAAlw"] [Sat Aug 29 05:05:32.760929 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.104.62:20803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/idca_shell.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjPAAABgI"] [Sat Aug 29 05:05:32.769990 2026] [core:error] [pid 1017536:tid 1017679] [client 74.248.24.12:33215] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:32.770007 2026] [core:error] [pid 1017536:tid 1017679] [client 74.248.24.12:33215] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:32.780042 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.104.18.15:23458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/mgrr.php"] [unique_id "apK8_CJcY4fy7tP-rU3o9QAAAoo"] [Sat Aug 29 05:05:32.797877 2026] [security2:error] [pid 1017536:tid 1017755] [client 20.48.160.90:62640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/kjyehoxl.php"] [unique_id "apK8_CJcY4fy7tP-rU3o-gAAAm0"] [Sat Aug 29 05:05:32.812217 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.104.62:22659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/exec.php"] [unique_id "apK8_CJcY4fy7tP-rU3o-wAAAig"] [Sat Aug 29 05:05:32.813993 2026] [security2:error] [pid 1017536:tid 1017713] [client 209.50.167.72:53829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.167.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8_CJcY4fy7tP-rU3o9gAAAkM"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:32.825184 2026] [security2:error] [pid 1017536:tid 1017667] [client 213.202.253.4:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/delpaths.php"] [unique_id "apK8_CJcY4fy7tP-rU3o_QAAAhU"], referer: www.google.com [Sat Aug 29 05:05:32.830464 2026] [security2:error] [pid 1017536:tid 1017702] [client 20.104.18.15:6977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/one.php"] [unique_id "apK8_CJcY4fy7tP-rU3o_gAAAjg"] [Sat Aug 29 05:05:32.833592 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.48.250.41:64942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/rtx.php"] [unique_id "apK8_CJcY4fy7tP-rU3o_wAAAic"] [Sat Aug 29 05:05:32.844029 2026] [security2:error] [pid 1017536:tid 1017735] [client 20.48.250.41:23539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/fs.php"] [unique_id "apK8_CJcY4fy7tP-rU3pAgAAAlk"] [Sat Aug 29 05:05:32.845646 2026] [security2:error] [pid 1017536:tid 1017747] [client 68.155.159.216:12226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/admin.php"] [unique_id "apK8_CJcY4fy7tP-rU3pAwAAAmU"] [Sat Aug 29 05:05:32.849551 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.18.15:13154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/simple.php"] [unique_id "apK8_CJcY4fy7tP-rU3pBAAAAjA"] [Sat Aug 29 05:05:32.851864 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.250.41:26930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ccu.php"] [unique_id "apK8_CJcY4fy7tP-rU3pBQAAAiM"] [Sat Aug 29 05:05:32.852886 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.48.251.3:27188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/environment.php"] [unique_id "apK8_CJcY4fy7tP-rU3pBwAAAoQ"] [Sat Aug 29 05:05:32.864658 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:8143] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "canistermachine.com"] [uri "/1.php"] [unique_id "apK8_CJcY4fy7tP-rU3pCQAAAkA"] [Sat Aug 29 05:05:32.864762 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:8143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/1.php"] [unique_id "apK8_CJcY4fy7tP-rU3pCQAAAkA"] [Sat Aug 29 05:05:32.867714 2026] [security2:error] [pid 1018003:tid 1018257] [client 93.123.109.228:36692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK8_DAh5Y1i2tUxg4HjQgAABiE"] [Sat Aug 29 05:05:32.868639 2026] [security2:error] [pid 1017536:tid 1017698] [client 52.139.37.240:37919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/zwso.php"] [unique_id "apK8_CJcY4fy7tP-rU3pCgAAAjQ"] [Sat Aug 29 05:05:32.874983 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.104.62:10447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/bnnof6.php"] [unique_id "apK8_CJcY4fy7tP-rU3pCwAAAis"] [Sat Aug 29 05:05:32.881005 2026] [security2:error] [pid 1017536:tid 1017675] [client 74.248.24.12:31723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-configs.php"] [unique_id "apK8_CJcY4fy7tP-rU3pDQAAAh0"] [Sat Aug 29 05:05:32.886020 2026] [security2:error] [pid 1018003:tid 1018226] [client 93.123.109.228:36660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/test.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjQwAABgM"] [Sat Aug 29 05:05:32.889124 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.250.41:58563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK8_CJcY4fy7tP-rU3pDwAAAk0"] [Sat Aug 29 05:05:32.889827 2026] [security2:error] [pid 1018003:tid 1018221] [client 93.123.109.228:36612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK8_DAh5Y1i2tUxg4HjRAAABf4"] [Sat Aug 29 05:05:32.894416 2026] [security2:error] [pid 1018003:tid 1018274] [client 4.232.148.111:14462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-admin/a.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjRQAABjI"] [Sat Aug 29 05:05:32.894477 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.104.18.15:36678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/5656.php"] [unique_id "apK8_CJcY4fy7tP-rU3pEAAAAj4"] [Sat Aug 29 05:05:32.896647 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.18.15:47077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/blog.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjRgAABcQ"] [Sat Aug 29 05:05:32.911204 2026] [security2:error] [pid 1017536:tid 1017703] [client 68.155.159.216:50239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK8_CJcY4fy7tP-rU3pFAAAAjk"] [Sat Aug 29 05:05:32.914067 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.251.3:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aws-credentials.php"] [unique_id "apK8_CJcY4fy7tP-rU3pFQAAAmo"] [Sat Aug 29 05:05:32.915381 2026] [access_compat:error] [pid 1017536:tid 1017688] [client 67.20.76.220:22342] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:05:32.920157 2026] [security2:error] [pid 1018003:tid 1018208] [client 93.123.109.228:36762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK8_DAh5Y1i2tUxg4HjSAAABfE"] [Sat Aug 29 05:05:32.921628 2026] [security2:error] [pid 1017536:tid 1017671] [client 20.63.219.114:1727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/disagreed.php"] [unique_id "apK8_CJcY4fy7tP-rU3pFgAAAhk"] [Sat Aug 29 05:05:32.944962 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.160.90:62673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/llyuxaqd.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjSQAABd8"] [Sat Aug 29 05:05:32.954273 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.104.62:22710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/dbc.php"] [unique_id "apK8_CJcY4fy7tP-rU3pGAAAAn8"] [Sat Aug 29 05:05:32.957173 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.104.18.15:23504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/mac.php"] [unique_id "apK8_CJcY4fy7tP-rU3pGQAAAm4"] [Sat Aug 29 05:05:32.966859 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.104.18.15:7044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/503.php"] [unique_id "apK8_CJcY4fy7tP-rU3pGwAAAkc"] [Sat Aug 29 05:05:32.968621 2026] [security2:error] [pid 1018003:tid 1018189] [client 168.107.94.195:52530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8_DAh5Y1i2tUxg4HjSgAABd4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:32.986270 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.250.41:23489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ioxi.php"] [unique_id "apK8_CJcY4fy7tP-rU3pHAAAAkE"] [Sat Aug 29 05:05:32.990706 2026] [security2:error] [pid 1017536:tid 1017716] [client 4.205.62.107:64240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/packed.php"] [unique_id "apK8_CJcY4fy7tP-rU3pHQAAAkY"] [Sat Aug 29 05:05:32.996909 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.250.41:27394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ak.php"] [unique_id "apK8_CJcY4fy7tP-rU3pHgAAAnc"] [Sat Aug 29 05:05:33.003735 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.251.3:57813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws_secret_config.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjSwAABcM"] [Sat Aug 29 05:05:33.007633 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.48.250.41:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/ckk.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjTAAABi0"] [Sat Aug 29 05:05:33.013174 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.104.62:10626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/ah24.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjTQAABec"] [Sat Aug 29 05:05:33.018948 2026] [security2:error] [pid 1017536:tid 1017783] [client 4.232.148.111:24122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/file2.php"] [unique_id "apK8_SJcY4fy7tP-rU3pHwAAAok"] [Sat Aug 29 05:05:33.020170 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.48.250.41:61748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/motu.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjTgAABhE"] [Sat Aug 29 05:05:33.020300 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.104.18.15:8097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/samll.php"] [unique_id "apK8_SJcY4fy7tP-rU3pIQAAAiw"] [Sat Aug 29 05:05:33.020690 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.18.15:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/xty.php"] [unique_id "apK8_SJcY4fy7tP-rU3pIgAAAks"] [Sat Aug 29 05:05:33.021851 2026] [security2:error] [pid 1018003:tid 1018213] [client 93.123.109.228:36714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK8_TAh5Y1i2tUxg4HjTwAABfY"] [Sat Aug 29 05:05:33.023691 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:33434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jen.chow-s.com"] [uri "/sbhu.php"] [unique_id "apK8_SJcY4fy7tP-rU3pJAAAAnM"] [Sat Aug 29 05:05:33.031414 2026] [security2:error] [pid 1018003:tid 1018277] [client 93.123.109.228:36728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK8_TAh5Y1i2tUxg4HjUAAABjU"] [Sat Aug 29 05:05:33.038044 2026] [security2:error] [pid 1017536:tid 1017746] [client 93.123.109.228:37366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK8_SJcY4fy7tP-rU3pJgAAAmQ"] [Sat Aug 29 05:05:33.041028 2026] [security2:error] [pid 1017536:tid 1017687] [client 4.205.62.107:57849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/time.php"] [unique_id "apK8_SJcY4fy7tP-rU3pJwAAAik"] [Sat Aug 29 05:05:33.045474 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.18.15:46943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apK8_SJcY4fy7tP-rU3pKQAAAoY"] [Sat Aug 29 05:05:33.063345 2026] [security2:error] [pid 1017536:tid 1017741] [client 52.139.37.240:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/admin/function.php"] [unique_id "apK8_SJcY4fy7tP-rU3pLAAAAl8"] [Sat Aug 29 05:05:33.064978 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.63.219.114:10050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/meta.php"] [unique_id "apK8_SJcY4fy7tP-rU3pLQAAAko"] [Sat Aug 29 05:05:33.067072 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.104.18.15:36846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/w3lls.php"] [unique_id "apK8_SJcY4fy7tP-rU3pLgAAAlE"] [Sat Aug 29 05:05:33.083948 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.104.104.62:41626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/wp-wlx.php"] [unique_id "apK8_SJcY4fy7tP-rU3pMgAAAhg"] [Sat Aug 29 05:05:33.084182 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.158.54.35:9471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-access.php"] [unique_id "apK8_SJcY4fy7tP-rU3pMQAAAoc"] [Sat Aug 29 05:05:33.090594 2026] [security2:error] [pid 1018003:tid 1018205] [client 158.23.147.79:30600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjVQAABe4"] [Sat Aug 29 05:05:33.090627 2026] [security2:error] [pid 1018003:tid 1018193] [client 20.48.160.90:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/nbwxolou.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjVgAABeI"] [Sat Aug 29 05:05:33.112053 2026] [security2:error] [pid 1017536:tid 1017739] [client 20.104.18.15:7061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/504.php"] [unique_id "apK8_SJcY4fy7tP-rU3pNAAAAl0"] [Sat Aug 29 05:05:33.115575 2026] [security2:error] [pid 1017536:tid 1017702] [client 4.205.62.107:22313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/olfclass.php"] [unique_id "apK8_SJcY4fy7tP-rU3pNgAAAjg"] [Sat Aug 29 05:05:33.121504 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.18.15:23456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/simple.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjWAAABe8"] [Sat Aug 29 05:05:33.123334 2026] [security2:error] [pid 1017536:tid 1017747] [client 158.23.147.79:25593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/file5.php"] [unique_id "apK8_SJcY4fy7tP-rU3pOQAAAmU"] [Sat Aug 29 05:05:33.128867 2026] [proxy_http:error] [pid 1018003:tid 1018275] (20014)Internal error (specific information not available): [client 34.21.253.104:28416] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:33.128886 2026] [proxy:error] [pid 1018003:tid 1018275] [client 34.21.253.104:28416] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.aws/sso/cache/ [Sat Aug 29 05:05:33.130074 2026] [security2:error] [pid 1017536:tid 1017673] [client 34.21.253.104:28478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/app/terraform.tfstate"] [unique_id "apK8_SJcY4fy7tP-rU3pPwAAAhs"] [Sat Aug 29 05:05:33.134967 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.104.104.62:64742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/idca.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjWgAABhw"] [Sat Aug 29 05:05:33.138282 2026] [proxy_http:error] [pid 1017536:tid 1017725] (20014)Internal error (specific information not available): [client 34.21.253.104:28482] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:33.138296 2026] [proxy:error] [pid 1017536:tid 1017725] [client 34.21.253.104:28482] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/terraform.tfstate [Sat Aug 29 05:05:33.139997 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.251.3:28494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/snq.php"] [unique_id "apK8_SJcY4fy7tP-rU3pQQAAAmg"] [Sat Aug 29 05:05:33.140111 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.196.209.81:9506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/alfa.php"] [unique_id "apK8_SJcY4fy7tP-rU3pQgAAAhY"] [Sat Aug 29 05:05:33.146134 2026] [security2:error] [pid 1018003:tid 1018025] [remote 45.148.10.166:42904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "waysidebaptistmission.lifesosweet.com"] [uri "/"] [unique_id "apK8_TAh5Y1i2tUxg4HjWwAGLgQ"] [Sat Aug 29 05:05:33.146853 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.104.104.62:10460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/ztv.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjXQAABfg"] [Sat Aug 29 05:05:33.149925 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.48.250.41:23507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/bootstrap.php"] [unique_id "apK8_SJcY4fy7tP-rU3pQwAAAo8"] [Sat Aug 29 05:05:33.150308 2026] [proxy_http:error] [pid 1017536:tid 1017714] (20014)Internal error (specific information not available): [client 34.21.253.104:28464] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:33.150317 2026] [proxy:error] [pid 1017536:tid 1017714] [client 34.21.253.104:28464] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/var/www/.env [Sat Aug 29 05:05:33.155040 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.104.18.15:13301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/sallu.php"] [unique_id "apK8_SJcY4fy7tP-rU3pRAAAAjY"] [Sat Aug 29 05:05:33.161405 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.196.209.81:21058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/xmlrpc.php0"] [unique_id "apK8_SJcY4fy7tP-rU3pRwAAAl4"] [Sat Aug 29 05:05:33.165841 2026] [proxy_http:error] [pid 1017536:tid 1017707] (20014)Internal error (specific information not available): [client 34.21.253.104:28522] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:33.165854 2026] [proxy:error] [pid 1017536:tid 1017707] [client 34.21.253.104:28522] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/app/aws-exports.js [Sat Aug 29 05:05:33.192132 2026] [security2:error] [pid 1017536:tid 1017679] [client 45.148.10.62:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/.env.php"] [unique_id "apK8_SJcY4fy7tP-rU3pTgAAAiE"] [Sat Aug 29 05:05:33.196421 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.48.250.41:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/lib.php"] [unique_id "apK8_SJcY4fy7tP-rU3pUQAAAiY"] [Sat Aug 29 05:05:33.201582 2026] [security2:error] [pid 1018003:tid 1018216] [client 93.123.109.228:36692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK8_TAh5Y1i2tUxg4HjYAAABfk"] [Sat Aug 29 05:05:33.201899 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.104.62:48685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/tanjiro.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjYQAABgc"] [Sat Aug 29 05:05:33.211081 2026] [security2:error] [pid 1018003:tid 1018212] [client 93.123.109.228:36612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK8_TAh5Y1i2tUxg4HjYgAABfU"] [Sat Aug 29 05:05:33.219040 2026] [security2:error] [pid 1018003:tid 1018150] [client 20.104.104.62:33336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jen.chow-s.com"] [uri "/sf.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjYwAABbc"] [Sat Aug 29 05:05:33.221027 2026] [security2:error] [pid 1018003:tid 1018195] [client 192.145.125.70:35516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK8_TAh5Y1i2tUxg4HjZQAABeQ"] [Sat Aug 29 05:05:33.221103 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.104.62:22683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/attack.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjZAAABis"] [Sat Aug 29 05:05:33.230405 2026] [security2:error] [pid 1017536:tid 1017783] [client 93.123.109.228:36632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK8_SJcY4fy7tP-rU3pVQAAAok"] [Sat Aug 29 05:05:33.230919 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.48.160.90:63575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/nsxeubyv.php"] [unique_id "apK8_SJcY4fy7tP-rU3pVgAAAiw"] [Sat Aug 29 05:05:33.231337 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.23.147.79:48268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK8_SJcY4fy7tP-rU3pVwAAAkI"] [Sat Aug 29 05:05:33.254869 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.48.250.41:61757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/Ov-Simple1.php"] [unique_id "apK8_SJcY4fy7tP-rU3pWQAAAlw"] [Sat Aug 29 05:05:33.257034 2026] [security2:error] [pid 1018003:tid 1018153] [client 52.139.37.240:37924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/zoom1.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjZwAABbo"] [Sat Aug 29 05:05:33.258981 2026] [security2:error] [pid 1017536:tid 1017731] [client 4.205.62.107:53343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/temp.php"] [unique_id "apK8_SJcY4fy7tP-rU3pWgAAAlU"] [Sat Aug 29 05:05:33.261132 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.48.250.41:65419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sistamp.com"] [uri "/R57.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjaAAABc8"] [Sat Aug 29 05:05:33.268725 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.251.3:27194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-access.php"] [unique_id "apK8_SJcY4fy7tP-rU3pXAAAAjE"] [Sat Aug 29 05:05:33.276368 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.63.219.114:18395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/class_api.php"] [unique_id "apK8_SJcY4fy7tP-rU3pXgAAAnw"] [Sat Aug 29 05:05:33.282034 2026] [security2:error] [pid 1017536:tid 1017672] [client 34.7.216.49:37064] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/config.js"] [unique_id "apK8_SJcY4fy7tP-rU3pYgAAAho"] [Sat Aug 29 05:05:33.283300 2026] [security2:error] [pid 1017536:tid 1017774] [client 34.7.216.49:37108] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/app-config.json"] [unique_id "apK8_SJcY4fy7tP-rU3pZQAAAoA"] [Sat Aug 29 05:05:33.285223 2026] [security2:error] [pid 1018003:tid 1018217] [client 34.7.216.49:37232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/__/firebase/init.json"] [unique_id "apK8_TAh5Y1i2tUxg4HjcAAABfo"] [Sat Aug 29 05:05:33.286775 2026] [security2:error] [pid 1017536:tid 1017758] [client 20.104.104.62:10449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/kure.php"] [unique_id "apK8_SJcY4fy7tP-rU3pZwAAAnA"] [Sat Aug 29 05:05:33.296742 2026] [security2:error] [pid 1017536:tid 1017764] [client 34.7.216.49:37302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/.ssh/id_ed25519"] [unique_id "apK8_SJcY4fy7tP-rU3pdQAAAnY"] [Sat Aug 29 05:05:33.303559 2026] [security2:error] [pid 1017536:tid 1017719] [client 4.205.62.107:22314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/BDKR28WP.php"] [unique_id "apK8_SJcY4fy7tP-rU3peQAAAkk"] [Sat Aug 29 05:05:33.316378 2026] [security2:error] [pid 1018003:tid 1018253] [client 20.48.250.41:23426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/export.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjcwAABh0"] [Sat Aug 29 05:05:33.316662 2026] [security2:error] [pid 1017536:tid 1017667] [client 74.248.24.12:35485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/lock360.php"] [unique_id "apK8_SJcY4fy7tP-rU3pegAAAhU"] [Sat Aug 29 05:05:33.334610 2026] [security2:error] [pid 1018003:tid 1018157] [client 104.207.42.91:35089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjdAAABb4"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:33.339962 2026] [security2:error] [pid 1018003:tid 1018218] [client 4.205.62.107:65434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/saiga.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjdgAABfs"] [Sat Aug 29 05:05:33.345694 2026] [security2:error] [pid 1018003:tid 1018196] [client 68.155.159.216:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/x.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjdwAABeU"] [Sat Aug 29 05:05:33.348996 2026] [security2:error] [pid 1018003:tid 1018203] [client 68.155.159.216:58260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjeQAABew"] [Sat Aug 29 05:05:33.349758 2026] [security2:error] [pid 1018003:tid 1018151] [client 168.107.94.195:52875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjegAABbg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:33.356584 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.104.62:54985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/file66.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjfAAABbk"] [Sat Aug 29 05:05:33.373617 2026] [security2:error] [pid 1017536:tid 1017735] [client 20.48.250.41:27595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wp-style.php"] [unique_id "apK8_SJcY4fy7tP-rU3pfwAAAlk"] [Sat Aug 29 05:05:33.376007 2026] [security2:error] [pid 1017536:tid 1017747] [client 4.205.62.107:2902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/wp-blog.php"] [unique_id "apK8_SJcY4fy7tP-rU3pgAAAAmU"] [Sat Aug 29 05:05:33.378063 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.48.160.90:63613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/zfqipfss.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjgAAABd0"] [Sat Aug 29 05:05:33.384862 2026] [security2:error] [pid 1017536:tid 1017694] [client 93.123.109.228:36632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK8_SJcY4fy7tP-rU3pggAAAjA"] [Sat Aug 29 05:05:33.395783 2026] [security2:error] [pid 1017536:tid 1017748] [client 74.248.24.12:21789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-includes/index.php"] [unique_id "apK8_SJcY4fy7tP-rU3phQAAAmY"] [Sat Aug 29 05:05:33.396606 2026] [security2:error] [pid 1017536:tid 1017734] [client 93.123.109.228:36702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.elisefairweather.com"] [uri "/wp-config.php"] [unique_id "apK8_SJcY4fy7tP-rU3phAAAAlg"] [Sat Aug 29 05:05:33.398113 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.48.251.3:57836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/otuz1.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjgQAABfw"] [Sat Aug 29 05:05:33.401893 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.104.62:64733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/indoxploit_shell.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjggAABgw"] [Sat Aug 29 05:05:33.402462 2026] [security2:error] [pid 1017536:tid 1017685] [client 93.123.109.228:36674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.elisefairweather.com"] [uri "/wp-config.php.bak"] [unique_id "apK8_SJcY4fy7tP-rU3phgAAAic"] [Sat Aug 29 05:05:33.405045 2026] [security2:error] [pid 1018003:tid 1018222] [client 93.123.109.228:36762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.elisefairweather.com"] [uri "/wp-config.php.new"] [unique_id "apK8_TAh5Y1i2tUxg4HjgwAABf8"] [Sat Aug 29 05:05:33.417263 2026] [security2:error] [pid 1017536:tid 1017750] [client 93.123.109.228:37378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.elisefairweather.com"] [uri "/wp-config.php.old"] [unique_id "apK8_SJcY4fy7tP-rU3phwAAAmg"] [Sat Aug 29 05:05:33.421238 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.63.219.114:18372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/dxc.php"] [unique_id "apK8_SJcY4fy7tP-rU3piAAAAoo"] [Sat Aug 29 05:05:33.427244 2026] [security2:error] [pid 1017536:tid 1017610] [remote 34.138.108.56:53934] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "proppastie.com"] [uri "/_image"] [unique_id "apK8_SJcY4fy7tP-rU3pjAACVkk"] [Sat Aug 29 05:05:33.429756 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.104.104.62:44546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/cafe.php"] [unique_id "apK8_SJcY4fy7tP-rU3pjQAAAk4"] [Sat Aug 29 05:05:33.448219 2026] [security2:error] [pid 1017536:tid 1017766] [client 20.48.250.41:23511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/gk.php"] [unique_id "apK8_SJcY4fy7tP-rU3pkgAAAng"] [Sat Aug 29 05:05:33.450331 2026] [security2:error] [pid 1018003:tid 1018214] [client 93.123.109.228:36654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.elisefairweather.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK8_TAh5Y1i2tUxg4HjhQAABfc"] [Sat Aug 29 05:05:33.452254 2026] [security2:error] [pid 1018003:tid 1018251] [client 52.139.37.240:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/about.php7"] [unique_id "apK8_TAh5Y1i2tUxg4HjhgAABhs"] [Sat Aug 29 05:05:33.484467 2026] [autoindex:error] [pid 1017536:tid 1017726] [client 4.232.148.111:0] AH01276: Cannot serve directory /home4/ehfields/public_html/tiaandephraim/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:33.497873 2026] [security2:error] [pid 1018003:tid 1018192] [client 4.232.148.111:19634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjiQAABeE"] [Sat Aug 29 05:05:33.506334 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.104.62:22685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/zafir1.php"] [unique_id "apK8_SJcY4fy7tP-rU3plwAAAiE"] [Sat Aug 29 05:05:33.509903 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.48.160.90:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stampstudios.glowt-shirt.com"] [uri "/zrjuyoos.php"] [unique_id "apK8_SJcY4fy7tP-rU3pmAAAAiY"] [Sat Aug 29 05:05:33.511821 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.48.250.41:27642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/browse.php"] [unique_id "apK8_SJcY4fy7tP-rU3pmQAAAnI"] [Sat Aug 29 05:05:33.513878 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.251.3:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/xda.php"] [unique_id "apK8_SJcY4fy7tP-rU3pmgAAAhw"] [Sat Aug 29 05:05:33.523508 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.48.250.41:58623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/wp-blogs.php"] [unique_id "apK8_SJcY4fy7tP-rU3pnQAAAkU"] [Sat Aug 29 05:05:33.529124 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.251.3:28565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/update.php"] [unique_id "apK8_SJcY4fy7tP-rU3pngAAAnc"] [Sat Aug 29 05:05:33.544269 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.196.209.81:15762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK8_SJcY4fy7tP-rU3pnwAAAoI"] [Sat Aug 29 05:05:33.550234 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.104.62:48476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/Rk41.php"] [unique_id "apK8_SJcY4fy7tP-rU3poAAAAks"] [Sat Aug 29 05:05:33.551121 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.104.62:32874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jen.chow-s.com"] [uri "/wp-content/plugins/cp-pro/js.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjjAAABhI"] [Sat Aug 29 05:05:33.561925 2026] [security2:error] [pid 1018003:tid 1018158] [client 68.155.159.216:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjjQAABb8"] [Sat Aug 29 05:05:33.566086 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.104.104.62:10451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/eval.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjjgAABdU"] [Sat Aug 29 05:05:33.582316 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.158.54.35:35961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/uploads/min.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjjwAABdA"] [Sat Aug 29 05:05:33.584955 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.250.41:23440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/logs1.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjkAAABdc"] [Sat Aug 29 05:05:33.637722 2026] [security2:error] [pid 1017536:tid 1017770] [client 68.155.159.216:33739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/file.php"] [unique_id "apK8_SJcY4fy7tP-rU3powAAAnw"] [Sat Aug 29 05:05:33.642470 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.196.209.81:21070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/content.php"] [unique_id "apK8_SJcY4fy7tP-rU3ppAAAAm4"] [Sat Aug 29 05:05:33.646878 2026] [security2:error] [pid 1017536:tid 1017716] [client 52.139.37.240:54168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/cron.php"] [unique_id "apK8_SJcY4fy7tP-rU3ppQAAAkY"] [Sat Aug 29 05:05:33.649981 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.104.104.62:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/console.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjkQAABjI"] [Sat Aug 29 05:05:33.651046 2026] [security2:error] [pid 1017536:tid 1017687] [client 4.232.148.111:18134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK8_SJcY4fy7tP-rU3ppgAAAik"] [Sat Aug 29 05:05:33.654890 2026] [security2:error] [pid 1017536:tid 1017774] [client 20.104.104.62:64754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/sbh.php"] [unique_id "apK8_SJcY4fy7tP-rU3ppwAAAoA"] [Sat Aug 29 05:05:33.657218 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.63.219.114:10110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/aksinet.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjkgAABiw"] [Sat Aug 29 05:05:33.659180 2026] [security2:error] [pid 1018003:tid 1018208] [client 20.48.251.3:28453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/channels.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjkwAABfE"] [Sat Aug 29 05:05:33.663105 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:51821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/admin.php"] [unique_id "apK8_SJcY4fy7tP-rU3pqAAAAms"] [Sat Aug 29 05:05:33.676231 2026] [security2:error] [pid 1017536:tid 1017764] [client 158.23.147.79:50066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK8_SJcY4fy7tP-rU3pqQAAAnY"] [Sat Aug 29 05:05:33.677305 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.48.250.41:26942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/zoo.php"] [unique_id "apK8_SJcY4fy7tP-rU3pqgAAAlQ"] [Sat Aug 29 05:05:33.700159 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.104.104.62:10468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/sao.php"] [unique_id "apK8_SJcY4fy7tP-rU3pqwAAAlE"] [Sat Aug 29 05:05:33.713942 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.250.41:61765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/mini.php"] [unique_id "apK8_SJcY4fy7tP-rU3prAAAAkA"] [Sat Aug 29 05:05:33.729000 2026] [security2:error] [pid 1018003:tid 1018213] [client 168.107.94.195:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjlAAABfY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:33.732872 2026] [security2:error] [pid 1017536:tid 1017755] [client 20.48.250.41:23470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/inege.php"] [unique_id "apK8_SJcY4fy7tP-rU3prQAAAm0"] [Sat Aug 29 05:05:33.744773 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.104.62:33316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jen.chow-s.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjlQAABcI"] [Sat Aug 29 05:05:33.776268 2026] [security2:error] [pid 1017536:tid 1017758] [client 20.63.219.114:1551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/wp-2019.php"] [unique_id "apK8_SJcY4fy7tP-rU3psAAAAnA"] [Sat Aug 29 05:05:33.782896 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.23.147.79:62995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/admin.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjlgAABgE"] [Sat Aug 29 05:05:33.788587 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.48.251.3:27185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/zz.php"] [unique_id "apK8_SJcY4fy7tP-rU3psgAAAoQ"] [Sat Aug 29 05:05:33.796765 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.104.62:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/blnux.php"] [unique_id "apK8_SJcY4fy7tP-rU3pswAAAhs"] [Sat Aug 29 05:05:33.826982 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.49.130:53859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/kj.php"] [unique_id "apK8_SJcY4fy7tP-rU3ptQAAAk0"] [Sat Aug 29 05:05:33.833172 2026] [security2:error] [pid 1018003:tid 1018225] [client 192.145.125.70:35532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK8_TAh5Y1i2tUxg4HjlwAABgI"] [Sat Aug 29 05:05:33.847518 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.48.250.41:27618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/elp.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjmAAABcc"] [Sat Aug 29 05:05:33.854869 2026] [security2:error] [pid 1017536:tid 1017751] [client 52.139.37.240:65297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/wp-2019.php"] [unique_id "apK8_SJcY4fy7tP-rU3ptwAAAmk"] [Sat Aug 29 05:05:33.869239 2026] [security2:error] [pid 1017536:tid 1017720] [client 65.111.4.250:21523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.4.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8_SJcY4fy7tP-rU3ptgAAAko"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:33.884679 2026] [security2:error] [pid 1018003:tid 1018255] [client 74.248.24.12:23825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-conflg.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjmQAABh8"] [Sat Aug 29 05:05:33.888910 2026] [security2:error] [pid 1017536:tid 1017611] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/.env"] [unique_id "apK8_SJcY4fy7tP-rU3puAACk0o"] [Sat Aug 29 05:05:33.889116 2026] [security2:error] [pid 1017536:tid 1017565] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/.env"] [unique_id "apK8_SJcY4fy7tP-rU3puwACkxw"] [Sat Aug 29 05:05:33.891099 2026] [security2:error] [pid 1017536:tid 1017646] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/.env"] [unique_id "apK8_SJcY4fy7tP-rU3pvQACk20"] [Sat Aug 29 05:05:33.891506 2026] [security2:error] [pid 1017536:tid 1017634] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/api/.env/public/.env"] [unique_id "apK8_SJcY4fy7tP-rU3pvAACk2E"] [Sat Aug 29 05:05:33.891570 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.48.250.41:58507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/amp.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjmgAABeg"] [Sat Aug 29 05:05:33.913167 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.250.41:23433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wp-link10.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjmwAABgY"] [Sat Aug 29 05:05:33.919950 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.147.79:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/worksec.php"] [unique_id "apK8_TAh5Y1i2tUxg4HjnAAABjM"] [Sat Aug 29 05:05:33.926683 2026] [security2:error] [pid 1017536:tid 1017739] [client 74.248.24.12:21327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-admin/a.php"] [unique_id "apK8_SJcY4fy7tP-rU3pwAAAAl0"] [Sat Aug 29 05:05:33.952187 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.251.3:27136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/test.php"] [unique_id "apK8_SJcY4fy7tP-rU3pxgAAAjo"] [Sat Aug 29 05:05:33.980715 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:27459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/666.php"] [unique_id "apK8_SJcY4fy7tP-rU3pygAAAj0"] [Sat Aug 29 05:05:33.981824 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.49.130:57522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/kj.php"] [unique_id "apK8_SJcY4fy7tP-rU3pywAAAi0"] [Sat Aug 29 05:05:34.004596 2026] [security2:error] [pid 1017536:tid 1017784] [client 4.232.148.111:19603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/xda.php"] [unique_id "apK8_iJcY4fy7tP-rU3pzAAAAoo"] [Sat Aug 29 05:05:34.018293 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.63.219.114:1724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/alfa-rex1.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjnQAABe8"] [Sat Aug 29 05:05:34.023993 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.49.130:51109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/sxxb.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjngAABfU"] [Sat Aug 29 05:05:34.026107 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.48.251.3:14276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/pinfo.php"] [unique_id "apK8_iJcY4fy7tP-rU3pzQAAAoU"] [Sat Aug 29 05:05:34.029092 2026] [security2:error] [pid 1017536:tid 1017746] [client 68.155.159.216:50183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/goat.php"] [unique_id "apK8_iJcY4fy7tP-rU3pzgAAAmQ"] [Sat Aug 29 05:05:34.030264 2026] [security2:error] [pid 1018003:tid 1018205] [client 158.158.54.35:9457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjnwAABe4"] [Sat Aug 29 05:05:34.042012 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.196.209.81:21100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/wxo.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjoAAABhg"] [Sat Aug 29 05:05:34.052940 2026] [security2:error] [pid 1017536:tid 1017709] [client 52.139.37.240:65306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/gecko-new.php"] [unique_id "apK8_iJcY4fy7tP-rU3p0AAAAj8"] [Sat Aug 29 05:05:34.065173 2026] [security2:error] [pid 1017536:tid 1017593] [remote 103.74.116.219:42506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ujwonline.org"] [uri "/wp-login.php"] [unique_id "apK8_iJcY4fy7tP-rU3pzwACiTg"] [Sat Aug 29 05:05:34.074912 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.196.209.81:15787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/inputs.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjoQAABfg"] [Sat Aug 29 05:05:34.080181 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.48.250.41:61779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/cc13.php"] [unique_id "apK8_iJcY4fy7tP-rU3p0gAAAjI"] [Sat Aug 29 05:05:34.082794 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.251.3:27199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/cloud.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjogAABbo"] [Sat Aug 29 05:05:34.091514 2026] [security2:error] [pid 1017536:tid 1017725] [client 87.219.197.128:50784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK8_iJcY4fy7tP-rU3p0wAAAk8"] [Sat Aug 29 05:05:34.091616 2026] [security2:error] [pid 1017536:tid 1017725] [client 87.219.197.128:50784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK8_iJcY4fy7tP-rU3p0wAAAk8"] [Sat Aug 29 05:05:34.108448 2026] [security2:error] [pid 1018003:tid 1018185] [client 168.107.94.195:53504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjowAABdo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:34.110768 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.48.250.41:23377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ww.php"] [unique_id "apK8_iJcY4fy7tP-rU3p1QAAAiw"] [Sat Aug 29 05:05:34.126764 2026] [security2:error] [pid 1017536:tid 1017706] [client 4.205.62.107:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/wp-info.php"] [unique_id "apK8_iJcY4fy7tP-rU3p2AAAAjw"] [Sat Aug 29 05:05:34.142629 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.48.250.41:27528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/knmt.php"] [unique_id "apK8_iJcY4fy7tP-rU3p2gAAAnM"] [Sat Aug 29 05:05:34.142890 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.63.219.114:1685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/menu.php"] [unique_id "apK8_iJcY4fy7tP-rU3p2wAAAl4"] [Sat Aug 29 05:05:34.142967 2026] [security2:error] [pid 1017536:tid 1017692] [client 4.232.148.111:32901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiaandephraim.com"] [uri "/wp-admin.php"] [unique_id "apK8_iJcY4fy7tP-rU3p3AAAAi4"] [Sat Aug 29 05:05:34.208458 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.23.147.79:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK8_iJcY4fy7tP-rU3p3gAAAms"] [Sat Aug 29 05:05:34.212034 2026] [security2:error] [pid 1018003:tid 1018221] [client 103.185.242.143:59587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjpQAABf4"] [Sat Aug 29 05:05:34.212559 2026] [security2:error] [pid 1018003:tid 1018221] [client 103.185.242.143:59587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjpQAABf4"] [Sat Aug 29 05:05:34.214366 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.48.251.3:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/asdf.php"] [unique_id "apK8_iJcY4fy7tP-rU3p4AAAAl8"] [Sat Aug 29 05:05:34.219682 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.48.250.41:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/aa.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjpgAABiY"] [Sat Aug 29 05:05:34.229191 2026] [security2:error] [pid 1017536:tid 1017666] [client 4.205.62.107:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/doc.php"] [unique_id "apK8_iJcY4fy7tP-rU3p4wAAAhQ"] [Sat Aug 29 05:05:34.234986 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.23.147.79:25589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/file88.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjpwAABhM"] [Sat Aug 29 05:05:34.238242 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.250.41:23430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/w1px.php"] [unique_id "apK8_iJcY4fy7tP-rU3p5gAAAos"] [Sat Aug 29 05:05:34.245512 2026] [security2:error] [pid 1018003:tid 1018038] [remote 34.138.108.56:53938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:href. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:href"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/_image"] [unique_id "apK8_jAh5Y1i2tUxg4HjqAAGHhE"] [Sat Aug 29 05:05:34.245649 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.147.79:24490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK8_iJcY4fy7tP-rU3p7QAAAoc"] [Sat Aug 29 05:05:34.248587 2026] [security2:error] [pid 1017536:tid 1017716] [client 52.139.37.240:65300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/add_actualites.php"] [unique_id "apK8_iJcY4fy7tP-rU3p7gAAAkY"] [Sat Aug 29 05:05:34.249295 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.251.3:14322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/X57.php"] [unique_id "apK8_iJcY4fy7tP-rU3p7wAAAkA"] [Sat Aug 29 05:05:34.250009 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.49.130:45745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/browse.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjrgAABb4"] [Sat Aug 29 05:05:34.274383 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.250.41:26907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/sbhu.php"] [unique_id "apK8_iJcY4fy7tP-rU3p9AAAAmw"] [Sat Aug 29 05:05:34.326902 2026] [security2:error] [pid 1017536:tid 1017742] [client 4.205.62.107:22359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/abcd.php"] [unique_id "apK8_iJcY4fy7tP-rU3p-QAAAmA"] [Sat Aug 29 05:05:34.350022 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.48.251.3:27154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjsAAABeA"] [Sat Aug 29 05:05:34.370351 2026] [security2:error] [pid 1018003:tid 1018260] [client 20.48.250.41:58605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/s1.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjsQAABiQ"] [Sat Aug 29 05:05:34.397305 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.251.3:14284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/register.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjsgAABcs"] [Sat Aug 29 05:05:34.399332 2026] [security2:error] [pid 1018003:tid 1018232] [client 158.23.147.79:48279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/file.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjswAABgg"] [Sat Aug 29 05:05:34.403545 2026] [security2:error] [pid 1017536:tid 1017719] [client 74.248.24.12:32584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/123.php"] [unique_id "apK8_iJcY4fy7tP-rU3p-wAAAkk"] [Sat Aug 29 05:05:34.403583 2026] [security2:error] [pid 1017536:tid 1017771] [client 20.63.219.114:9229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/headerg.php"] [unique_id "apK8_iJcY4fy7tP-rU3p_AAAAn0"] [Sat Aug 29 05:05:34.406423 2026] [security2:error] [pid 1017536:tid 1017700] [client 4.205.62.107:9000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/php-details.php"] [unique_id "apK8_iJcY4fy7tP-rU3p_QAAAjY"] [Sat Aug 29 05:05:34.419278 2026] [security2:error] [pid 1018003:tid 1018217] [client 192.145.125.70:39858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK8_jAh5Y1i2tUxg4HjtAAABfo"] [Sat Aug 29 05:05:34.438694 2026] [autoindex:error] [pid 1017536:tid 1017694] [client 45.148.10.62:50722] AH01276: Cannot serve directory /home3/vzofmemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:34.441280 2026] [security2:error] [pid 1018003:tid 1018222] [client 4.205.62.107:21876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/_js.jpg..bk.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjtQAABf8"] [Sat Aug 29 05:05:34.443067 2026] [security2:error] [pid 1018003:tid 1018188] [client 52.139.37.240:65280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/browse.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjtgAABd0"] [Sat Aug 29 05:05:34.448347 2026] [core:error] [pid 1017536:tid 1017713] [client 74.248.24.12:25706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:34.448372 2026] [core:error] [pid 1017536:tid 1017713] [client 74.248.24.12:25706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:34.452414 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.196.209.81:10718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/as.php"] [unique_id "apK8_iJcY4fy7tP-rU3qAgAAAhs"] [Sat Aug 29 05:05:34.455336 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.48.250.41:23444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/to.php"] [unique_id "apK8_iJcY4fy7tP-rU3qAwAAAiA"] [Sat Aug 29 05:05:34.461535 2026] [security2:error] [pid 1017536:tid 1017554] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/images../.env"] [unique_id "apK8_iJcY4fy7tP-rU3qBAACZBE"] [Sat Aug 29 05:05:34.462779 2026] [security2:error] [pid 1017536:tid 1017675] [client 216.73.216.199:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origeneshechoamano.sortthru.com"] [uri "/webapp/wp-admin/admin-ajax.php"] [unique_id "apK8_iJcY4fy7tP-rU3qBgAAAh0"] [Sat Aug 29 05:05:34.470961 2026] [security2:error] [pid 1017536:tid 1017723] [client 4.232.148.111:24079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/theme.php"] [unique_id "apK8_iJcY4fy7tP-rU3qBwAAAk0"] [Sat Aug 29 05:05:34.475803 2026] [security2:error] [pid 1017536:tid 1017708] [client 4.205.62.107:65508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ammika.php"] [unique_id "apK8_iJcY4fy7tP-rU3qCAAAAj4"] [Sat Aug 29 05:05:34.482648 2026] [security2:error] [pid 1018003:tid 1018154] [client 158.158.54.35:22481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/bthil.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjvAAABbs"] [Sat Aug 29 05:05:34.484203 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.48.251.3:27153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/hochladen.form.php"] [unique_id "apK8_iJcY4fy7tP-rU3qCgAAAiY"] [Sat Aug 29 05:05:34.485447 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.196.209.81:9505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjvQAABbk"] [Sat Aug 29 05:05:34.487624 2026] [security2:error] [pid 1018003:tid 1018234] [client 168.107.94.195:53914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjvgAABgo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:34.489647 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:27539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/a332.php"] [unique_id "apK8_iJcY4fy7tP-rU3qCwAAAmE"] [Sat Aug 29 05:05:34.499318 2026] [security2:error] [pid 1017536:tid 1017755] [client 104.207.51.70:27249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8_iJcY4fy7tP-rU3qAAAAAm0"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:34.511602 2026] [security2:error] [pid 1017536:tid 1017688] [client 4.205.62.107:2946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/update.php"] [unique_id "apK8_iJcY4fy7tP-rU3qDAAAAio"] [Sat Aug 29 05:05:34.546788 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.48.251.3:13961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/xqq.php"] [unique_id "apK8_iJcY4fy7tP-rU3qDQAAAks"] [Sat Aug 29 05:05:34.548051 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.250.41:58603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/0byte.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjvwAABds"] [Sat Aug 29 05:05:34.573675 2026] [security2:error] [pid 1017536:tid 1017744] [client 68.155.159.216:14149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/cgi-bin/index.php"] [unique_id "apK8_iJcY4fy7tP-rU3qDwAAAmI"] [Sat Aug 29 05:05:34.574208 2026] [security2:error] [pid 1017536:tid 1017645] [remote 103.74.116.219:42506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ujwonline.org"] [uri "/wp-login.php"] [unique_id "apK8_iJcY4fy7tP-rU3qDgACPGw"], referer: https://ujwonline.org/wp-login.php [Sat Aug 29 05:05:34.575409 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.219.114:18380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/alfa.php"] [unique_id "apK8_iJcY4fy7tP-rU3qEAAAAkc"] [Sat Aug 29 05:05:34.575986 2026] [security2:error] [pid 1017536:tid 1017680] [client 45.148.10.62:38672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/wp-config.php"] [unique_id "apK8_iJcY4fy7tP-rU3qEQAAAiI"] [Sat Aug 29 05:05:34.582000 2026] [core:error] [pid 1017536:tid 1017654] [remote 34.148.90.28:42974] AH10244: invalid URI path (/%2e%2e/.env) [Sat Aug 29 05:05:34.582963 2026] [security2:error] [pid 1017536:tid 1017547] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/assets../.env"] [unique_id "apK8_iJcY4fy7tP-rU3qFQACZwo"] [Sat Aug 29 05:05:34.585336 2026] [security2:error] [pid 1017536:tid 1017695] [client 45.148.10.62:50722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/.env"] [unique_id "apK8_iJcY4fy7tP-rU3qFwAAAjE"] [Sat Aug 29 05:05:34.601819 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.48.250.41:23458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/thui.php"] [unique_id "apK8_iJcY4fy7tP-rU3qGAAAAl4"] [Sat Aug 29 05:05:34.623192 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:26920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ws66.php"] [unique_id "apK8_iJcY4fy7tP-rU3qGgAAAnw"] [Sat Aug 29 05:05:34.627067 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.48.251.3:28417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/debuggen.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjxgAABdw"] [Sat Aug 29 05:05:34.660077 2026] [security2:error] [pid 1017536:tid 1017738] [client 52.139.37.240:54197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/contentloader1.php"] [unique_id "apK8_iJcY4fy7tP-rU3qGwAAAlw"] [Sat Aug 29 05:05:34.667085 2026] [security2:error] [pid 1018003:tid 1018180] [client 68.155.159.216:16231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/cong.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjxwAABdU"] [Sat Aug 29 05:05:34.676064 2026] [security2:error] [pid 1017536:tid 1017640] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/uploads../.env"] [unique_id "apK8_iJcY4fy7tP-rU3qHAACa2c"] [Sat Aug 29 05:05:34.734742 2026] [security2:error] [pid 1017536:tid 1017667] [client 45.148.10.62:50722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/.env"] [unique_id "apK8_iJcY4fy7tP-rU3qHgAAAhU"] [Sat Aug 29 05:05:34.743005 2026] [security2:error] [pid 1018003:tid 1018257] [client 68.155.159.216:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/file17.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjyAAABiE"] [Sat Aug 29 05:05:34.752149 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.48.250.41:27614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ws68.php"] [unique_id "apK8_iJcY4fy7tP-rU3qHwAAAkY"] [Sat Aug 29 05:05:34.756692 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.251.3:27163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/pouhg.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjyQAABgM"] [Sat Aug 29 05:05:34.761751 2026] [security2:error] [pid 1018003:tid 1018158] [client 20.63.219.114:18382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/meta.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjzgAABb8"] [Sat Aug 29 05:05:34.764649 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.48.250.41:23520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/Jcrop.php"] [unique_id "apK8_jAh5Y1i2tUxg4HjzwAABcQ"] [Sat Aug 29 05:05:34.774859 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.48.250.41:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/xr.php"] [unique_id "apK8_jAh5Y1i2tUxg4Hj0AAABiw"] [Sat Aug 29 05:05:34.801628 2026] [security2:error] [pid 1017536:tid 1017727] [client 68.155.159.216:51797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK8_iJcY4fy7tP-rU3qIAAAAlE"] [Sat Aug 29 05:05:34.802276 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.147.79:50076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/index.php"] [unique_id "apK8_iJcY4fy7tP-rU3qIQAAAoQ"] [Sat Aug 29 05:05:34.853803 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.104.49.130:54890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/abcd.php"] [unique_id "apK8_jAh5Y1i2tUxg4Hj1gAABi0"] [Sat Aug 29 05:05:34.854106 2026] [security2:error] [pid 1017536:tid 1017702] [client 52.139.37.240:38122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/upfile.php"] [unique_id "apK8_iJcY4fy7tP-rU3qIgAAAjg"] [Sat Aug 29 05:05:34.867061 2026] [security2:error] [pid 1017536:tid 1017668] [client 168.107.94.195:54263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8_iJcY4fy7tP-rU3qIwAAAhY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:34.872759 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.196.209.81:12726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/room.php"] [unique_id "apK8_iJcY4fy7tP-rU3qJAAAAos"] [Sat Aug 29 05:05:34.892578 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.250.41:23541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ws58.php"] [unique_id "apK8_iJcY4fy7tP-rU3qJgAAAmo"] [Sat Aug 29 05:05:34.897247 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.250.41:26922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/users.php"] [unique_id "apK8_iJcY4fy7tP-rU3qJwAAAk4"] [Sat Aug 29 05:05:34.901239 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.23.147.79:63838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/admin.php"] [unique_id "apK8_iJcY4fy7tP-rU3qKAAAAlY"] [Sat Aug 29 05:05:34.902097 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.251.3:33307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/public/vx.php"] [unique_id "apK8_jAh5Y1i2tUxg4Hj1wAABfY"] [Sat Aug 29 05:05:34.903021 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.250.41:58618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/h02ugyh.php"] [unique_id "apK8_jAh5Y1i2tUxg4Hj2AAABcI"] [Sat Aug 29 05:05:34.904279 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.48.251.3:27147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/phpversion.php"] [unique_id "apK8_iJcY4fy7tP-rU3qKQAAAkk"] [Sat Aug 29 05:05:34.906573 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.196.209.81:25080] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.firstcutfilm.com"] [uri "/1.php7"] [unique_id "apK8_jAh5Y1i2tUxg4Hj2QAABhk"] [Sat Aug 29 05:05:34.906674 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.196.209.81:25080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/1.php7"] [unique_id "apK8_jAh5Y1i2tUxg4Hj2QAABhk"] [Sat Aug 29 05:05:34.931821 2026] [security2:error] [pid 1018003:tid 1018274] [client 74.248.24.12:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/yanz.php"] [unique_id "apK8_jAh5Y1i2tUxg4Hj2gAABjI"] [Sat Aug 29 05:05:34.949436 2026] [security2:error] [pid 1017536:tid 1017714] [client 68.155.159.216:12210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK8_iJcY4fy7tP-rU3qKwAAAkQ"] [Sat Aug 29 05:05:34.950237 2026] [security2:error] [pid 1017536:tid 1017775] [client 4.232.148.111:18051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/classwithtostring.php"] [unique_id "apK8_iJcY4fy7tP-rU3qLAAAAoE"] [Sat Aug 29 05:05:34.951217 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.63.219.114:7481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK8_iJcY4fy7tP-rU3qLQAAAoM"] [Sat Aug 29 05:05:34.965703 2026] [security2:error] [pid 1017536:tid 1017704] [client 35.198.240.194:52344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/@fs/var/task/.env"] [unique_id "apK8_iJcY4fy7tP-rU3qMQAAAjo"] [Sat Aug 29 05:05:34.968338 2026] [security2:error] [pid 1017536:tid 1017726] [client 35.198.240.194:52364] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.omni-staffing.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK8_iJcY4fy7tP-rU3qNAAAAlA"] [Sat Aug 29 05:05:34.968631 2026] [security2:error] [pid 1017536:tid 1017726] [client 35.198.240.194:52364] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/403.html"] [unique_id "apK8_iJcY4fy7tP-rU3qNAAAAlA"] [Sat Aug 29 05:05:34.970123 2026] [security2:error] [pid 1017536:tid 1017767] [client 35.198.240.194:52350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK8_iJcY4fy7tP-rU3qNQAAAnk"] [Sat Aug 29 05:05:34.970197 2026] [security2:error] [pid 1017536:tid 1017767] [client 35.198.240.194:52350] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.omni-staffing.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK8_iJcY4fy7tP-rU3qNQAAAnk"] [Sat Aug 29 05:05:34.970302 2026] [security2:error] [pid 1018003:tid 1018265] [client 35.198.240.194:52294] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK8_jAh5Y1i2tUxg4Hj3QAABik"] [Sat Aug 29 05:05:34.970881 2026] [security2:error] [pid 1017536:tid 1017754] [client 74.248.24.12:3520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK8_iJcY4fy7tP-rU3qOQAAAmw"] [Sat Aug 29 05:05:35.020733 2026] [security2:error] [pid 1017536:tid 1017670] [client 192.145.125.70:39872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vickiandgreg.strangeworx.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK8_yJcY4fy7tP-rU3qOgAAAhg"] [Sat Aug 29 05:05:35.028034 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.23.147.79:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/x.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj4QAABh8"] [Sat Aug 29 05:05:35.040204 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.48.251.3:28435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/adminfus.php"] [unique_id "apK8_yJcY4fy7tP-rU3qPAAAAoU"] [Sat Aug 29 05:05:35.046410 2026] [autoindex:error] [pid 1017536:tid 1017673] [client 45.148.10.62:50722] AH01276: Cannot serve directory /home3/vzofmemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:35.048806 2026] [security2:error] [pid 1017536:tid 1017674] [client 52.139.37.240:54176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/form.php"] [unique_id "apK8_yJcY4fy7tP-rU3qPQAAAhw"] [Sat Aug 29 05:05:35.057910 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.48.250.41:23499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/xs.php"] [unique_id "apK8_yJcY4fy7tP-rU3qPgAAAiA"] [Sat Aug 29 05:05:35.074831 2026] [security2:error] [pid 1017536:tid 1017746] [client 158.158.54.35:35939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/cv.php"] [unique_id "apK8_yJcY4fy7tP-rU3qQAAAAmQ"] [Sat Aug 29 05:05:35.075239 2026] [security2:error] [pid 1017536:tid 1017700] [client 45.148.10.62:50738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/wp-config.php.old"] [unique_id "apK8_yJcY4fy7tP-rU3qQQAAAjY"] [Sat Aug 29 05:05:35.078572 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.250.41:61814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/xxw.php"] [unique_id "apK8_yJcY4fy7tP-rU3qQgAAAk0"] [Sat Aug 29 05:05:35.097190 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.48.250.41:26890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/bzjdlofz.php"] [unique_id "apK8_yJcY4fy7tP-rU3qRAAAAiY"] [Sat Aug 29 05:05:35.100211 2026] [security2:error] [pid 1017536:tid 1017693] [client 209.50.182.59:50717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.182.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8_yJcY4fy7tP-rU3qPwAAAi8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:35.100617 2026] [security2:error] [pid 1017536:tid 1017743] [client 68.155.159.216:64866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/nf_tracking.php"] [unique_id "apK8_yJcY4fy7tP-rU3qRQAAAmE"] [Sat Aug 29 05:05:35.115953 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.63.219.114:18421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/dxc.php"] [unique_id "apK8_yJcY4fy7tP-rU3qRgAAAjk"] [Sat Aug 29 05:05:35.134071 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:50227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK8_yJcY4fy7tP-rU3qSAAAAjI"] [Sat Aug 29 05:05:35.136695 2026] [security2:error] [pid 1017536:tid 1017652] [remote 162.55.89.48:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamesmarquiss.com"] [uri "/wp-login.php"] [unique_id "apK8_yJcY4fy7tP-rU3qSQACJXM"] [Sat Aug 29 05:05:35.167419 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.251.3:28439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/avim.php"] [unique_id "apK8_yJcY4fy7tP-rU3qSwAAAmM"] [Sat Aug 29 05:05:35.181878 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.49.130:53706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/az.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj5AAABio"] [Sat Aug 29 05:05:35.188510 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.48.250.41:23531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/zu.php"] [unique_id "apK8_yJcY4fy7tP-rU3qTQAAAiI"] [Sat Aug 29 05:05:35.213699 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.48.250.41:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/bolt.php"] [unique_id "apK8_yJcY4fy7tP-rU3qUAAAAl4"] [Sat Aug 29 05:05:35.218839 2026] [security2:error] [pid 1017536:tid 1017641] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/img../.env"] [unique_id "apK8_yJcY4fy7tP-rU3qUQACkmg"] [Sat Aug 29 05:05:35.220782 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.49.130:52536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/sd.php"] [unique_id "apK8_yJcY4fy7tP-rU3qUgAAAoY"] [Sat Aug 29 05:05:35.245887 2026] [security2:error] [pid 1017536:tid 1017735] [client 52.139.37.240:54171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/wp-sigunq.php"] [unique_id "apK8_yJcY4fy7tP-rU3qVAAAAlk"] [Sat Aug 29 05:05:35.268564 2026] [security2:error] [pid 1017536:tid 1017764] [client 4.205.62.107:61876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/fns.php"] [unique_id "apK8_yJcY4fy7tP-rU3qVgAAAnY"] [Sat Aug 29 05:05:35.269652 2026] [security2:error] [pid 1017536:tid 1017730] [client 168.107.94.195:54614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK8_yJcY4fy7tP-rU3qVwAAAlQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:35.287698 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.250.41:27634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/selesai.php"] [unique_id "apK8_yJcY4fy7tP-rU3qWAAAAoc"] [Sat Aug 29 05:05:35.299496 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.251.3:27150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/nw.php"] [unique_id "apK8_yJcY4fy7tP-rU3qWQAAAow"] [Sat Aug 29 05:05:35.307063 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.219.114:18429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/inputs.php"] [unique_id "apK8_yJcY4fy7tP-rU3qWgAAAkc"] [Sat Aug 29 05:05:35.325380 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.147.79:30713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/simple.php"] [unique_id "apK8_yJcY4fy7tP-rU3qWwAAAoI"] [Sat Aug 29 05:05:35.345220 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.49.130:57720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/memberfuns.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj6wAABgc"] [Sat Aug 29 05:05:35.345765 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.196.209.81:15745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/ds.php"] [unique_id "apK8_yJcY4fy7tP-rU3qXgAAAlU"] [Sat Aug 29 05:05:35.351066 2026] [security2:error] [pid 1017536:tid 1017751] [client 158.23.147.79:25565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/NewFile.php/"] [unique_id "apK8_yJcY4fy7tP-rU3qXwAAAmk"] [Sat Aug 29 05:05:35.351742 2026] [security2:error] [pid 1017536:tid 1017742] [client 45.148.10.62:50722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/api/.env"] [unique_id "apK8_yJcY4fy7tP-rU3qYAAAAmA"] [Sat Aug 29 05:05:35.364389 2026] [security2:error] [pid 1018003:tid 1018247] [client 20.48.250.41:23427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/lanka.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj7AAABhc"] [Sat Aug 29 05:05:35.405834 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.196.209.81:12708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/class-wp-cmd.php"] [unique_id "apK8_yJcY4fy7tP-rU3qYQAAAms"] [Sat Aug 29 05:05:35.424169 2026] [security2:error] [pid 1017536:tid 1017790] [client 4.232.148.111:18062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/news.php"] [unique_id "apK8_yJcY4fy7tP-rU3qYgAAApA"] [Sat Aug 29 05:05:35.434122 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.251.3:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/product.php"] [unique_id "apK8_yJcY4fy7tP-rU3qZAAAAjs"] [Sat Aug 29 05:05:35.442225 2026] [security2:error] [pid 1017536:tid 1017733] [client 52.139.37.240:38089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/07.php"] [unique_id "apK8_yJcY4fy7tP-rU3qZQAAAlc"] [Sat Aug 29 05:05:35.445346 2026] [security2:error] [pid 1018003:tid 1018216] [client 74.248.24.12:41265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/autoload_classmap.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj7QAABfk"] [Sat Aug 29 05:05:35.449715 2026] [security2:error] [pid 1017536:tid 1017714] [client 68.155.159.216:56909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK8_yJcY4fy7tP-rU3qZwAAAkQ"] [Sat Aug 29 05:05:35.452129 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.48.251.3:13990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/ebahvhhh.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj7gAABe8"] [Sat Aug 29 05:05:35.455415 2026] [security2:error] [pid 1017536:tid 1017647] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/@fs/var/task/.env"] [unique_id "apK8_yJcY4fy7tP-rU3qaAACgW4"] [Sat Aug 29 05:05:35.456373 2026] [security2:error] [pid 1017536:tid 1017777] [client 68.155.159.216:16214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-content/x.php"] [unique_id "apK8_yJcY4fy7tP-rU3qaQAAAoM"] [Sat Aug 29 05:05:35.472225 2026] [security2:error] [pid 1017536:tid 1017689] [client 74.248.24.12:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.realestatetrifecta.com"] [uri "/wp-admin.php"] [unique_id "apK8_yJcY4fy7tP-rU3qbAAAAis"] [Sat Aug 29 05:05:35.487320 2026] [security2:error] [pid 1017536:tid 1017729] [client 4.205.62.107:22517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/userfuns.php"] [unique_id "apK8_yJcY4fy7tP-rU3qbQAAAlM"] [Sat Aug 29 05:05:35.492052 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.48.250.41:58498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/rtx.php"] [unique_id "apK8_yJcY4fy7tP-rU3qbgAAAkw"] [Sat Aug 29 05:05:35.494279 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/classsmtps.php"] [unique_id "apK8_yJcY4fy7tP-rU3qcAAAAnk"] [Sat Aug 29 05:05:35.498942 2026] [security2:error] [pid 1017536:tid 1017691] [client 45.148.10.62:50722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/.env.bak"] [unique_id "apK8_yJcY4fy7tP-rU3qcQAAAi0"] [Sat Aug 29 05:05:35.503298 2026] [security2:error] [pid 1017536:tid 1017635] [remote 34.148.90.28:42974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK8_yJcY4fy7tP-rU3qcgACWmI"] [Sat Aug 29 05:05:35.506881 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.147.79:48247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/file17.php"] [unique_id "apK8_yJcY4fy7tP-rU3qcwAAAnc"] [Sat Aug 29 05:05:35.509466 2026] [security2:error] [pid 1017536:tid 1017553] [remote 34.148.90.28:42974] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "hitechgs.com"] [uri "/api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK8_yJcY4fy7tP-rU3qdAAChRA"] [Sat Aug 29 05:05:35.531315 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.158.54.35:9964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/packed.php"] [unique_id "apK8_yJcY4fy7tP-rU3qdQAAAos"] [Sat Aug 29 05:05:35.537648 2026] [security2:error] [pid 1018003:tid 1018200] [client 45.148.10.62:50746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/config.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj7wAABek"] [Sat Aug 29 05:05:35.543771 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.63.219.114:1675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/wp-2019.php"] [unique_id "apK8_yJcY4fy7tP-rU3qdgAAAmo"] [Sat Aug 29 05:05:35.560073 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.250.41:23544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/gettest.php"] [unique_id "apK8_yJcY4fy7tP-rU3qeAAAAmQ"] [Sat Aug 29 05:05:35.580541 2026] [security2:error] [pid 1017536:tid 1017708] [client 4.205.62.107:22223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/setup-config.php"] [unique_id "apK8_yJcY4fy7tP-rU3qeQAAAj4"] [Sat Aug 29 05:05:35.581985 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.251.3:28464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/fun.php"] [unique_id "apK8_yJcY4fy7tP-rU3qegAAAk0"] [Sat Aug 29 05:05:35.597279 2026] [security2:error] [pid 1017536:tid 1017684] [client 4.205.62.107:53337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/ms-edit.php"] [unique_id "apK8_yJcY4fy7tP-rU3qewAAAiY"] [Sat Aug 29 05:05:35.608555 2026] [security2:error] [pid 1017536:tid 1017693] [client 4.205.62.107:65503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/broadcasting.php"] [unique_id "apK8_yJcY4fy7tP-rU3qfAAAAi8"] [Sat Aug 29 05:05:35.629094 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.48.250.41:58600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/ckk.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj9gAABdo"] [Sat Aug 29 05:05:35.648188 2026] [security2:error] [pid 1017536:tid 1017783] [client 4.205.62.107:2632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/fns.php"] [unique_id "apK8_yJcY4fy7tP-rU3qfgAAAok"] [Sat Aug 29 05:05:35.652387 2026] [security2:error] [pid 1018003:tid 1018276] [client 168.107.94.195:54951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj9wAABjQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:35.656199 2026] [security2:error] [pid 1017536:tid 1017709] [client 52.139.37.240:65323] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/c99.php"] [unique_id "apK8_yJcY4fy7tP-rU3qgAAAAj8"] [Sat Aug 29 05:05:35.678271 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.63.219.114:18389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj-QAABeQ"] [Sat Aug 29 05:05:35.679985 2026] [security2:error] [pid 1017536:tid 1017784] [client 65.111.20.229:40409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK8_yJcY4fy7tP-rU3qfwAAAoo"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:35.713118 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:27612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/shlo.php"] [unique_id "apK8_yJcY4fy7tP-rU3qgQAAAmM"] [Sat Aug 29 05:05:35.715663 2026] [security2:error] [pid 1018003:tid 1018253] [client 20.48.251.3:57882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/kedi.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj-gAABh0"] [Sat Aug 29 05:05:35.715851 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.250.41:23512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/35.php"] [unique_id "apK8_yJcY4fy7tP-rU3qggAAAmI"] [Sat Aug 29 05:05:35.721517 2026] [security2:error] [pid 1018003:tid 1018159] [client 68.155.159.216:14304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj-wAABcA"] [Sat Aug 29 05:05:35.751943 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.196.209.81:25055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/GOD.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj_AAABc8"] [Sat Aug 29 05:05:35.789943 2026] [security2:error] [pid 1018003:tid 1018218] [client 68.155.159.216:16374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj_QAABfs"] [Sat Aug 29 05:05:35.817964 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.196.209.81:4520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/disagreed.php"] [unique_id "apK8_yJcY4fy7tP-rU3qhQAAAkU"] [Sat Aug 29 05:05:35.845853 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.251.3:28481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/oc460l3x.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj_gAABcs"] [Sat Aug 29 05:05:35.849750 2026] [security2:error] [pid 1018003:tid 1018232] [client 68.155.159.216:33717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/file5.php"] [unique_id "apK8_zAh5Y1i2tUxg4Hj_wAABgg"] [Sat Aug 29 05:05:35.855996 2026] [security2:error] [pid 1018003:tid 1018196] [client 52.139.37.240:37897] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/c99.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkAAAABeU"] [Sat Aug 29 05:05:35.871440 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.48.250.41:61817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stephanieandstephen.strangeworx.com"] [uri "/R57.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkAgAABfI"] [Sat Aug 29 05:05:35.874122 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.48.250.41:27602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/asax.php"] [unique_id "apK8_yJcY4fy7tP-rU3qhgAAAi4"] [Sat Aug 29 05:05:35.892686 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.48.250.41:23548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/maraz.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkAwAABfA"] [Sat Aug 29 05:05:35.924102 2026] [security2:error] [pid 1017536:tid 1017792] [client 68.155.159.216:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/classwithtostring.php"] [unique_id "apK8_yJcY4fy7tP-rU3qhwAAApI"] [Sat Aug 29 05:05:35.929339 2026] [security2:error] [pid 1017536:tid 1017728] [client 4.232.148.111:20649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/about/function.php"] [unique_id "apK8_yJcY4fy7tP-rU3qiAAAAlI"] [Sat Aug 29 05:05:35.948600 2026] [security2:error] [pid 1017536:tid 1017770] [client 45.148.10.62:50722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/stripe/.env"] [unique_id "apK8_yJcY4fy7tP-rU3qiQAAAnw"] [Sat Aug 29 05:05:35.949978 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.63.219.114:9237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/menu.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkCAAABeA"] [Sat Aug 29 05:05:35.967747 2026] [security2:error] [pid 1018003:tid 1018260] [client 158.158.54.35:23988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/js/index.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkCQAABiQ"] [Sat Aug 29 05:05:35.977890 2026] [security2:error] [pid 1018003:tid 1018243] [client 74.248.24.12:33409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/bi.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkCgAABhM"] [Sat Aug 29 05:05:35.987722 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.49.130:30040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/100.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkCwAABgo"] [Sat Aug 29 05:05:35.994192 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.48.251.3:27166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/drykl.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkDAAABfc"] [Sat Aug 29 05:05:35.995037 2026] [security2:error] [pid 1018003:tid 1018251] [client 158.23.147.79:50069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/mah.php"] [unique_id "apK8_zAh5Y1i2tUxg4HkDQAABhs"] [Sat Aug 29 05:05:36.009674 2026] [security2:error] [pid 1018003:tid 1018223] [client 20.48.250.41:26927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/fetch.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkDgAABgA"] [Sat Aug 29 05:05:36.010792 2026] [security2:error] [pid 1018003:tid 1018164] [client 45.148.10.62:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/config.php.bak"] [unique_id "apK9ADAh5Y1i2tUxg4HkDwAABcU"] [Sat Aug 29 05:05:36.013094 2026] [security2:error] [pid 1018003:tid 1018239] [client 158.23.147.79:38771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkEAAABg8"] [Sat Aug 29 05:05:36.028611 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.251.3:14331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/asa.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkEQAABds"] [Sat Aug 29 05:05:36.032189 2026] [security2:error] [pid 1018003:tid 1018192] [client 168.107.94.195:55331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkEgAABeE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:36.035235 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.48.250.41:23490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/kbfr.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkEwAABjE"] [Sat Aug 29 05:05:36.043966 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.63.219.114:18385] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/1.php7"] [unique_id "apK9ADAh5Y1i2tUxg4HkFAAABf8"] [Sat Aug 29 05:05:36.044022 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.63.219.114:18385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/1.php7"] [unique_id "apK9ADAh5Y1i2tUxg4HkFAAABf8"] [Sat Aug 29 05:05:36.050866 2026] [security2:error] [pid 1018003:tid 1018152] [client 52.139.37.240:65296] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "autodiscover.naturesfragrancelabs.com"] [uri "/c99.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkFQAABbk"] [Sat Aug 29 05:05:36.133476 2026] [security2:error] [pid 1018003:tid 1018190] [client 158.23.147.79:63234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-content/x.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkGQAABd8"] [Sat Aug 29 05:05:36.135107 2026] [security2:error] [pid 1017536:tid 1017698] [client 68.155.159.216:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9ACJcY4fy7tP-rU3qjgAAAjQ"] [Sat Aug 29 05:05:36.147427 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.48.251.3:27176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/rpk.php"] [unique_id "apK9ACJcY4fy7tP-rU3qjwAAAkc"] [Sat Aug 29 05:05:36.151216 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.196.209.81:15750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/ggfi.php"] [unique_id "apK9ACJcY4fy7tP-rU3qkAAAAhc"] [Sat Aug 29 05:05:36.152002 2026] [security2:error] [pid 1018003:tid 1018090] [remote 34.138.108.56:53938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "proppastie.com"] [uri "/.github/.env"] [unique_id "apK9ADAh5Y1i2tUxg4HkGgAFw0U"] [Sat Aug 29 05:05:36.165239 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.250.41:23432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wp-act.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkIAAABfY"] [Sat Aug 29 05:05:36.216282 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.48.251.3:14273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/radio.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkJgAABgQ"] [Sat Aug 29 05:05:36.224582 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.196.209.81:21085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/class_api.php"] [unique_id "apK9ACJcY4fy7tP-rU3qkwAAAoc"] [Sat Aug 29 05:05:36.227460 2026] [security2:error] [pid 1018003:tid 1018256] [client 65.111.10.164:33791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkIgAABiA"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:36.241075 2026] [security2:error] [pid 1017536:tid 1017750] [client 68.155.159.216:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9ACJcY4fy7tP-rU3qlQAAAmg"] [Sat Aug 29 05:05:36.251425 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.48.250.41:27639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/vx.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkKQAABeg"] [Sat Aug 29 05:05:36.274622 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.184.117:27711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.dj/index.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkKgAABhw"] [Sat Aug 29 05:05:36.276184 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.48.251.3:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/saml.php"] [unique_id "apK9ACJcY4fy7tP-rU3qlwAAAko"] [Sat Aug 29 05:05:36.314951 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.63.219.114:9272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/alfa.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkKwAABgI"] [Sat Aug 29 05:05:36.339582 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.48.250.41:23437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/24.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkLAAABjM"] [Sat Aug 29 05:05:36.380659 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.251.3:13984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/ws61.php"] [unique_id "apK9ACJcY4fy7tP-rU3qmAAAAoE"] [Sat Aug 29 05:05:36.399367 2026] [security2:error] [pid 1018003:tid 1018254] [client 66.248.203.2:49290] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2021/03/15/"] [unique_id "apK9ADAh5Y1i2tUxg4HkLgAABh4"] [Sat Aug 29 05:05:36.406819 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.48.251.3:57829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws_settings.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkLwAABgc"] [Sat Aug 29 05:05:36.410066 2026] [security2:error] [pid 1017536:tid 1017726] [client 4.205.62.107:61785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/params.php"] [unique_id "apK9ACJcY4fy7tP-rU3qmgAAAlA"] [Sat Aug 29 05:05:36.410443 2026] [security2:error] [pid 1017536:tid 1017742] [client 158.158.54.35:35931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/core.php"] [unique_id "apK9ACJcY4fy7tP-rU3qmwAAAmA"] [Sat Aug 29 05:05:36.411348 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.63.219.114:14010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/ds.php"] [unique_id "apK9ACJcY4fy7tP-rU3qnAAAAms"] [Sat Aug 29 05:05:36.413195 2026] [security2:error] [pid 1018003:tid 1018193] [client 168.107.94.195:55641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkMAAABeI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:36.419295 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.23.184.117:27703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.info.php"] [unique_id "apK9ACJcY4fy7tP-rU3qnQAAAkQ"] [Sat Aug 29 05:05:36.429322 2026] [security2:error] [pid 1018003:tid 1018206] [client 158.23.147.79:30689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/about.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkMQAABe8"] [Sat Aug 29 05:05:36.531248 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:23535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/155.php"] [unique_id "apK9ACJcY4fy7tP-rU3qoAAAAj0"] [Sat Aug 29 05:05:36.536110 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.48.250.41:27635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/global.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkMwAABjQ"] [Sat Aug 29 05:05:36.540842 2026] [security2:error] [pid 1017536:tid 1017694] [client 45.148.10.62:50722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/backend/.env"] [unique_id "apK9ACJcY4fy7tP-rU3qogAAAjA"] [Sat Aug 29 05:05:36.548694 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.196.209.81:15779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/alfa-rex.php"] [unique_id "apK9ACJcY4fy7tP-rU3qowAAAlM"] [Sat Aug 29 05:05:36.559333 2026] [security2:error] [pid 1017536:tid 1017765] [client 68.155.159.216:12224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/classwithtostring.php"] [unique_id "apK9ACJcY4fy7tP-rU3qpAAAAnc"] [Sat Aug 29 05:05:36.563077 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.184.117:27668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.trash7206/index.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkNQAABbo"] [Sat Aug 29 05:05:36.563589 2026] [security2:error] [pid 1017536:tid 1017785] [client 68.155.159.216:16193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9ACJcY4fy7tP-rU3qpQAAAos"] [Sat Aug 29 05:05:36.564225 2026] [security2:error] [pid 1017536:tid 1017739] [client 74.248.24.12:15176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/cc.php"] [unique_id "apK9ACJcY4fy7tP-rU3qpgAAAl0"] [Sat Aug 29 05:05:36.568314 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.251.3:28562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-konfig.backup.php"] [unique_id "apK9ACJcY4fy7tP-rU3qqQAAAhw"] [Sat Aug 29 05:05:36.592068 2026] [security2:error] [pid 1017536:tid 1017700] [client 4.232.148.111:5911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/admin.php"] [unique_id "apK9ACJcY4fy7tP-rU3qrQAAAjY"] [Sat Aug 29 05:05:36.620716 2026] [security2:error] [pid 1018003:tid 1018220] [client 158.23.147.79:48240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/file5.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkOAAABf0"] [Sat Aug 29 05:05:36.633086 2026] [security2:error] [pid 1017536:tid 1017787] [client 20.196.209.81:21080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/aksinet.php"] [unique_id "apK9ACJcY4fy7tP-rU3qrgAAAo0"] [Sat Aug 29 05:05:36.646656 2026] [security2:error] [pid 1017536:tid 1017688] [client 4.205.62.107:61241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/cache-compat.php"] [unique_id "apK9ACJcY4fy7tP-rU3qsAAAAio"] [Sat Aug 29 05:05:36.648312 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.48.251.3:14318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/ms-edit.php"] [unique_id "apK9ACJcY4fy7tP-rU3qsQAAAjk"] [Sat Aug 29 05:05:36.677848 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.49.130:57622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/xa.php"] [unique_id "apK9ACJcY4fy7tP-rU3qsgAAAjI"] [Sat Aug 29 05:05:36.683137 2026] [security2:error] [pid 1017536:tid 1017783] [client 4.205.62.107:22303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/register.php"] [unique_id "apK9ACJcY4fy7tP-rU3qrwAAAok"] [Sat Aug 29 05:05:36.691746 2026] [security2:error] [pid 1017536:tid 1017721] [client 45.148.10.62:50722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/test.php"] [unique_id "apK9ACJcY4fy7tP-rU3qtAAAAks"] [Sat Aug 29 05:05:36.692516 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.63.219.114:11586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK9ACJcY4fy7tP-rU3qtQAAAhg"] [Sat Aug 29 05:05:36.698893 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.48.251.3:57910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/packed.php"] [unique_id "apK9ACJcY4fy7tP-rU3qtgAAAiw"] [Sat Aug 29 05:05:36.705378 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.184.117:27671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.trash7206/min.php"] [unique_id "apK9ACJcY4fy7tP-rU3qtwAAAn8"] [Sat Aug 29 05:05:36.718522 2026] [security2:error] [pid 1018003:tid 1018238] [client 4.205.62.107:22227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/phpversion.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkOgAABg4"] [Sat Aug 29 05:05:36.724233 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:23543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/file.php"] [unique_id "apK9ACJcY4fy7tP-rU3quAAAAmM"] [Sat Aug 29 05:05:36.749495 2026] [security2:error] [pid 1017536:tid 1017695] [client 4.205.62.107:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/aws_config.php"] [unique_id "apK9ACJcY4fy7tP-rU3qugAAAjE"] [Sat Aug 29 05:05:36.758131 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.48.250.41:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/fs.php"] [unique_id "apK9ACJcY4fy7tP-rU3quwAAAi4"] [Sat Aug 29 05:05:36.759608 2026] [security2:error] [pid 1017536:tid 1017754] [client 102.208.164.205:29547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.164.208.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mikelait.com"] [uri "/xmlrpc.php"] [unique_id "apK9ACJcY4fy7tP-rU3quQAAAmw"] [Sat Aug 29 05:05:36.759728 2026] [security2:error] [pid 1017536:tid 1017754] [client 102.208.164.205:29547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mikelait.com"] [uri "/xmlrpc.php"] [unique_id "apK9ACJcY4fy7tP-rU3quQAAAmw"] [Sat Aug 29 05:05:36.768979 2026] [security2:error] [pid 1017536:tid 1017728] [client 4.205.62.107:9174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/requirements.php"] [unique_id "apK9ACJcY4fy7tP-rU3qvAAAAlI"] [Sat Aug 29 05:05:36.773583 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.63.219.114:1514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/GOD.php"] [unique_id "apK9ACJcY4fy7tP-rU3qvQAAAnI"] [Sat Aug 29 05:05:36.789065 2026] [security2:error] [pid 1018003:tid 1018262] [client 4.205.62.107:2884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/25.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkOwAABiY"] [Sat Aug 29 05:05:36.792578 2026] [security2:error] [pid 1018003:tid 1018157] [client 168.107.94.195:55993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkPAAABb4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:36.794848 2026] [security2:error] [pid 1017536:tid 1017659] [remote 34.148.90.28:50012] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "hitechgs.com"] [uri "/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "apK9ACJcY4fy7tP-rU3qvwACGno"] [Sat Aug 29 05:05:36.801151 2026] [security2:error] [pid 1017536:tid 1017756] [client 20.48.251.3:13968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/lmfi2.php"] [unique_id "apK9ACJcY4fy7tP-rU3qxAAAAm4"] [Sat Aug 29 05:05:36.807308 2026] [security2:error] [pid 1017536:tid 1017708] [client 151.123.177.58:26891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9ACJcY4fy7tP-rU3qvgAAAj4"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:36.826311 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.251.3:27149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-info.php"] [unique_id "apK9ACJcY4fy7tP-rU3qxgAAAow"] [Sat Aug 29 05:05:36.837528 2026] [security2:error] [pid 1017536:tid 1017669] [client 68.155.159.216:14234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/content.php"] [unique_id "apK9ACJcY4fy7tP-rU3qxwAAAhc"] [Sat Aug 29 05:05:36.848534 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.158.54.35:4377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/admin/function.php"] [unique_id "apK9ACJcY4fy7tP-rU3qyQAAAkI"] [Sat Aug 29 05:05:36.850155 2026] [security2:error] [pid 1017536:tid 1017774] [client 158.23.184.117:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known//index.php"] [unique_id "apK9ACJcY4fy7tP-rU3qygAAAoA"] [Sat Aug 29 05:05:36.856070 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.48.250.41:23469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkPQAABew"] [Sat Aug 29 05:05:36.948470 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.196.209.81:9498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/cookie.php"] [unique_id "apK9ACJcY4fy7tP-rU3qywAAAkY"] [Sat Aug 29 05:05:36.950475 2026] [security2:error] [pid 1018003:tid 1018232] [client 158.23.147.79:25546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/dropdown.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkPgAABgg"] [Sat Aug 29 05:05:36.958341 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.49.130:52325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/wp-blog-header.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkPwAABfo"] [Sat Aug 29 05:05:36.968800 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.251.3:28418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/fns.php"] [unique_id "apK9ADAh5Y1i2tUxg4HkQQAABgw"] [Sat Aug 29 05:05:36.976078 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.23.147.79:24526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9ACJcY4fy7tP-rU3qzQAAAlY"] [Sat Aug 29 05:05:36.993774 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.250.41:26887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ioxi.php"] [unique_id "apK9ACJcY4fy7tP-rU3qzwAAAlc"] [Sat Aug 29 05:05:36.994990 2026] [security2:error] [pid 1017536:tid 1017790] [client 57.141.14.32:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/3/"] [unique_id "apK9ACJcY4fy7tP-rU3qzgAAApA"] [Sat Aug 29 05:05:36.997774 2026] [security2:error] [pid 1017536:tid 1017702] [client 158.23.184.117:52491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/about.php"] [unique_id "apK9ACJcY4fy7tP-rU3q0AAAAjg"] [Sat Aug 29 05:05:37.001194 2026] [security2:error] [pid 1017536:tid 1017777] [client 45.148.10.62:50768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "apK9ASJcY4fy7tP-rU3q0QAAAoM"] [Sat Aug 29 05:05:37.008804 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.49.130:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/load.php"] [unique_id "apK9ASJcY4fy7tP-rU3q0gAAAoE"] [Sat Aug 29 05:05:37.021882 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.250.41:23527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/06.php"] [unique_id "apK9ASJcY4fy7tP-rU3q0wAAAmA"] [Sat Aug 29 05:05:37.033520 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.104.49.130:53713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/3.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkQgAABic"] [Sat Aug 29 05:05:37.052988 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.251.3:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wpver.php"] [unique_id "apK9ASJcY4fy7tP-rU3q1AAAAjs"] [Sat Aug 29 05:05:37.077842 2026] [security2:error] [pid 1017536:tid 1017683] [client 68.155.159.216:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/images/index.php"] [unique_id "apK9ASJcY4fy7tP-rU3q1wAAAiU"] [Sat Aug 29 05:05:37.082042 2026] [security2:error] [pid 1017536:tid 1017670] [client 68.155.159.216:51855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/install.php"] [unique_id "apK9ASJcY4fy7tP-rU3q2QAAAhg"] [Sat Aug 29 05:05:37.090279 2026] [security2:error] [pid 1017536:tid 1017720] [client 74.248.24.12:23853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/files/index.php"] [unique_id "apK9ASJcY4fy7tP-rU3q2gAAAko"] [Sat Aug 29 05:05:37.098252 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.251.3:27159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/params.php"] [unique_id "apK9ASJcY4fy7tP-rU3q2wAAAmM"] [Sat Aug 29 05:05:37.104913 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.196.209.81:12721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/alfa-rex1.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkQwAABjY"] [Sat Aug 29 05:05:37.106162 2026] [security2:error] [pid 1017536:tid 1017744] [client 158.23.147.79:49823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-blog-header.php"] [unique_id "apK9ASJcY4fy7tP-rU3q3AAAAmI"] [Sat Aug 29 05:05:37.112501 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.49.130:57689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/static.php"] [unique_id "apK9ASJcY4fy7tP-rU3q3QAAAiI"] [Sat Aug 29 05:05:37.128662 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.48.250.41:26929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/bootstrap.php"] [unique_id "apK9ASJcY4fy7tP-rU3q3gAAAnM"] [Sat Aug 29 05:05:37.132423 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/classwithtostring.php"] [unique_id "apK9ASJcY4fy7tP-rU3q3wAAAjE"] [Sat Aug 29 05:05:37.173135 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.63.219.114:18845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/ggfi.php"] [unique_id "apK9ASJcY4fy7tP-rU3q4QAAAnk"] [Sat Aug 29 05:05:37.176009 2026] [security2:error] [pid 1017536:tid 1017754] [client 168.107.94.195:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ASJcY4fy7tP-rU3q4gAAAmw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:37.190268 2026] [security2:error] [pid 1018003:tid 1018188] [client 45.148.10.62:50780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/.env.backup"] [unique_id "apK9ATAh5Y1i2tUxg4HkRwAABd0"] [Sat Aug 29 05:05:37.201298 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.63.219.114:1858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/inputs.php"] [unique_id "apK9ASJcY4fy7tP-rU3q5AAAAks"] [Sat Aug 29 05:05:37.203423 2026] [core:error] [pid 1017536:tid 1017788] [client 34.12.38.134:16260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.203441 2026] [core:error] [pid 1017536:tid 1017788] [client 34.12.38.134:16260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.204913 2026] [core:error] [pid 1017536:tid 1017691] [client 34.12.38.134:16268] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.204927 2026] [core:error] [pid 1017536:tid 1017691] [client 34.12.38.134:16268] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.207569 2026] [core:error] [pid 1017536:tid 1017734] [client 34.12.38.134:16318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.207582 2026] [core:error] [pid 1017536:tid 1017734] [client 34.12.38.134:16318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.208175 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.48.250.41:23521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/class.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkSQAABf8"] [Sat Aug 29 05:05:37.208555 2026] [security2:error] [pid 1017536:tid 1017779] [client 34.12.38.134:16332] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/bootstrap.properties"] [unique_id "apK9ASJcY4fy7tP-rU3q6AAAAoU"] [Sat Aug 29 05:05:37.208970 2026] [core:error] [pid 1017536:tid 1017707] [client 34.12.38.134:16322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.208978 2026] [core:error] [pid 1017536:tid 1017707] [client 34.12.38.134:16322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.209914 2026] [core:error] [pid 1018003:tid 1018179] [client 34.12.38.134:16312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.209925 2026] [core:error] [pid 1018003:tid 1018179] [client 34.12.38.134:16312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.215053 2026] [core:error] [pid 1017536:tid 1017785] [client 34.12.38.134:16300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.215069 2026] [core:error] [pid 1017536:tid 1017785] [client 34.12.38.134:16300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.219861 2026] [core:error] [pid 1017536:tid 1017674] [client 34.12.38.134:16270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.219873 2026] [core:error] [pid 1017536:tid 1017674] [client 34.12.38.134:16270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.221182 2026] [core:error] [pid 1017536:tid 1017673] [client 34.12.38.134:16286] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.221196 2026] [core:error] [pid 1017536:tid 1017673] [client 34.12.38.134:16286] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.222150 2026] [core:error] [pid 1017536:tid 1017700] [client 34.12.38.134:16330] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.222170 2026] [core:error] [pid 1017536:tid 1017700] [client 34.12.38.134:16330] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.222582 2026] [security2:error] [pid 1017536:tid 1017678] [client 34.12.38.134:16376] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/telescope/requests"] [unique_id "apK9ASJcY4fy7tP-rU3q9QAAAiA"] [Sat Aug 29 05:05:37.226384 2026] [security2:error] [pid 1017536:tid 1017738] [client 158.23.184.117:27662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9ASJcY4fy7tP-rU3q-gAAAlw"] [Sat Aug 29 05:05:37.226838 2026] [core:error] [pid 1018003:tid 1018223] [client 34.12.38.134:16406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.226847 2026] [core:error] [pid 1018003:tid 1018223] [client 34.12.38.134:16406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.226930 2026] [security2:error] [pid 1018003:tid 1018186] [client 34.12.38.134:16498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/.aws/credentials.bak"] [unique_id "apK9ATAh5Y1i2tUxg4HkTwAABds"] [Sat Aug 29 05:05:37.228313 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.251.3:27192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/gjm.php"] [unique_id "apK9ASJcY4fy7tP-rU3q_AAAAow"] [Sat Aug 29 05:05:37.228569 2026] [security2:error] [pid 1017536:tid 1017688] [client 34.12.38.134:16412] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/.aider.conf.yml"] [unique_id "apK9ASJcY4fy7tP-rU3q_QAAAio"] [Sat Aug 29 05:05:37.229057 2026] [core:error] [pid 1018003:tid 1018164] [client 34.12.38.134:16388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.229065 2026] [core:error] [pid 1018003:tid 1018164] [client 34.12.38.134:16388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.229903 2026] [core:error] [pid 1018003:tid 1018239] [client 34.12.38.134:16424] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.229914 2026] [core:error] [pid 1018003:tid 1018239] [client 34.12.38.134:16424] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.230079 2026] [security2:error] [pid 1017536:tid 1017696] [client 34.12.38.134:16452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.38.12.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/config/aws.php"] [unique_id "apK9ASJcY4fy7tP-rU3q_gAAAjI"] [Sat Aug 29 05:05:37.232903 2026] [security2:error] [pid 1017536:tid 1017725] [client 34.12.38.134:16480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/aws/.env"] [unique_id "apK9ASJcY4fy7tP-rU3rAQAAAk8"] [Sat Aug 29 05:05:37.235518 2026] [security2:error] [pid 1017536:tid 1017712] [client 68.155.159.216:52807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9ASJcY4fy7tP-rU3rBgAAAkI"] [Sat Aug 29 05:05:37.236650 2026] [security2:error] [pid 1017536:tid 1017778] [client 4.232.148.111:18071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/lock360.php"] [unique_id "apK9ASJcY4fy7tP-rU3rCgAAAoQ"] [Sat Aug 29 05:05:37.237327 2026] [security2:error] [pid 1017536:tid 1017690] [client 34.12.38.134:16496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/.aws/credentials.old"] [unique_id "apK9ASJcY4fy7tP-rU3rBQAAAiw"] [Sat Aug 29 05:05:37.238294 2026] [core:error] [pid 1017536:tid 1017686] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.238306 2026] [core:error] [pid 1017536:tid 1017686] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.241583 2026] [security2:error] [pid 1017536:tid 1017731] [client 158.23.147.79:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9ASJcY4fy7tP-rU3rDQAAAlU"] [Sat Aug 29 05:05:37.241898 2026] [core:error] [pid 1017536:tid 1017757] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.241907 2026] [core:error] [pid 1017536:tid 1017757] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.242118 2026] [security2:error] [pid 1017536:tid 1017757] [client 34.12.38.134:0] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK9ASJcY4fy7tP-rU3rDAAAAm8"] [Sat Aug 29 05:05:37.244153 2026] [security2:error] [pid 1017536:tid 1017679] [client 34.12.38.134:16392] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/_ignition/health-check"] [unique_id "apK9ASJcY4fy7tP-rU3q6gAAAiE"] [Sat Aug 29 05:05:37.244524 2026] [core:error] [pid 1017536:tid 1017781] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.244538 2026] [core:error] [pid 1017536:tid 1017781] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.244903 2026] [core:error] [pid 1017536:tid 1017776] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.244912 2026] [core:error] [pid 1017536:tid 1017776] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.247647 2026] [core:error] [pid 1018003:tid 1018215] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.247661 2026] [core:error] [pid 1018003:tid 1018215] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.248161 2026] [security2:error] [pid 1018003:tid 1018215] [client 34.12.38.134:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkVQAABfg"] [Sat Aug 29 05:05:37.248447 2026] [core:error] [pid 1017536:tid 1017675] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.248458 2026] [core:error] [pid 1017536:tid 1017675] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.249444 2026] [security2:error] [pid 1017536:tid 1017684] [client 34.12.38.134:16366] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/api/v2/config"] [unique_id "apK9ASJcY4fy7tP-rU3q8AAAAiY"] [Sat Aug 29 05:05:37.251486 2026] [core:error] [pid 1017536:tid 1017668] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.251497 2026] [core:error] [pid 1017536:tid 1017668] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.252112 2026] [core:error] [pid 1018003:tid 1018258] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.252120 2026] [core:error] [pid 1018003:tid 1018258] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.252377 2026] [core:error] [pid 1018003:tid 1018197] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.252393 2026] [core:error] [pid 1018003:tid 1018197] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.253378 2026] [security2:error] [pid 1018003:tid 1018241] [client 68.155.159.216:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wzy.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkWgAABhE"] [Sat Aug 29 05:05:37.254593 2026] [core:error] [pid 1018003:tid 1018189] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.254602 2026] [core:error] [pid 1018003:tid 1018189] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.254657 2026] [core:error] [pid 1017536:tid 1017689] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.254665 2026] [core:error] [pid 1017536:tid 1017689] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.256010 2026] [core:error] [pid 1017536:tid 1017714] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.256021 2026] [core:error] [pid 1017536:tid 1017714] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.258980 2026] [core:error] [pid 1017536:tid 1017742] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.258991 2026] [core:error] [pid 1017536:tid 1017742] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.259065 2026] [security2:error] [pid 1017536:tid 1017742] [client 34.12.38.134:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK9ASJcY4fy7tP-rU3rFAAAAmA"] [Sat Aug 29 05:05:37.268836 2026] [security2:error] [pid 1017536:tid 1017773] [client 34.12.38.134:16486] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/aws/.env.production"] [unique_id "apK9ASJcY4fy7tP-rU3rCAAAAn8"] [Sat Aug 29 05:05:37.303089 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.251.3:33296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/ah25.php"] [unique_id "apK9ASJcY4fy7tP-rU3rFQAAAmM"] [Sat Aug 29 05:05:37.304040 2026] [security2:error] [pid 1017536:tid 1017715] [client 158.158.54.35:6040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/admin/index.php"] [unique_id "apK9ASJcY4fy7tP-rU3rFgAAAkU"] [Sat Aug 29 05:05:37.314223 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.250.41:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/export.php"] [unique_id "apK9ASJcY4fy7tP-rU3rFwAAAmI"] [Sat Aug 29 05:05:37.335305 2026] [security2:error] [pid 1017536:tid 1017770] [client 65.111.14.131:43865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.14.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9ASJcY4fy7tP-rU3rGAAAAnw"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:37.342821 2026] [security2:error] [pid 1018003:tid 1018199] [client 45.148.10.62:50780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/.env.old"] [unique_id "apK9ATAh5Y1i2tUxg4HkXQAABeg"] [Sat Aug 29 05:05:37.348651 2026] [security2:error] [pid 1018003:tid 1018252] [client 68.155.159.216:50281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkXgAABhw"] [Sat Aug 29 05:05:37.358644 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.48.251.3:28478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/configuration.php"] [unique_id "apK9ASJcY4fy7tP-rU3rGQAAAi4"] [Sat Aug 29 05:05:37.363346 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.196.209.81:15788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/NewFile.php"] [unique_id "apK9ASJcY4fy7tP-rU3rGgAAAjQ"] [Sat Aug 29 05:05:37.370830 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.184.117:27704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkXwAABiA"] [Sat Aug 29 05:05:37.373417 2026] [security2:error] [pid 1018003:tid 1018211] [client 20.48.250.41:23551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/8.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkYAAABfQ"] [Sat Aug 29 05:05:37.388250 2026] [security2:error] [pid 1017536:tid 1017687] [client 213.202.253.4:53924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/delpaths.php"] [unique_id "apK9ASJcY4fy7tP-rU3rGwAAAik"], referer: www.google.com [Sat Aug 29 05:05:37.486549 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.48.251.3:28490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/server_info.php"] [unique_id "apK9ASJcY4fy7tP-rU3rHgAAAlE"] [Sat Aug 29 05:05:37.499568 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.250.41:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/gk.php"] [unique_id "apK9ASJcY4fy7tP-rU3rIAAAAj4"] [Sat Aug 29 05:05:37.513468 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.48.250.41:23493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/0x0x.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkYgAABhg"] [Sat Aug 29 05:05:37.540289 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.196.209.81:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/headerg.php"] [unique_id "apK9ASJcY4fy7tP-rU3rIwAAAkI"] [Sat Aug 29 05:05:37.543531 2026] [security2:error] [pid 1017536:tid 1017733] [client 4.205.62.107:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/gjm.php"] [unique_id "apK9ASJcY4fy7tP-rU3rJAAAAlc"] [Sat Aug 29 05:05:37.554247 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.63.219.114:13996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK9ASJcY4fy7tP-rU3rJQAAAoc"] [Sat Aug 29 05:05:37.556030 2026] [security2:error] [pid 1017536:tid 1017693] [client 168.107.94.195:56680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ASJcY4fy7tP-rU3rJgAAAi8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:37.559959 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.63.219.114:14001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/alfa-rex.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkZQAABig"] [Sat Aug 29 05:05:37.565574 2026] [autoindex:error] [pid 1018003:tid 1018106] [remote 45.148.10.62:50782] AH01276: Cannot serve directory /home3/vvrewumy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:37.567027 2026] [security2:error] [pid 1017536:tid 1017764] [client 158.23.147.79:30691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9ASJcY4fy7tP-rU3rJwAAAnY"] [Sat Aug 29 05:05:37.567857 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.48.251.3:13956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/groceries/index.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkZgAABeQ"] [Sat Aug 29 05:05:37.600922 2026] [security2:error] [pid 1017536:tid 1017684] [client 158.23.184.117:27681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9ASJcY4fy7tP-rU3rKAAAAiY"] [Sat Aug 29 05:05:37.619511 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.251.3:57833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/hosty.php"] [unique_id "apK9ASJcY4fy7tP-rU3rKgAAAmk"] [Sat Aug 29 05:05:37.625664 2026] [security2:error] [pid 1018003:tid 1018206] [client 74.248.24.12:8975] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/1.php7"] [unique_id "apK9ATAh5Y1i2tUxg4HkaQAABe8"] [Sat Aug 29 05:05:37.625737 2026] [security2:error] [pid 1018003:tid 1018206] [client 74.248.24.12:8975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/1.php7"] [unique_id "apK9ATAh5Y1i2tUxg4HkaQAABe8"] [Sat Aug 29 05:05:37.639426 2026] [security2:error] [pid 1018003:tid 1018277] [client 45.148.10.62:50780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/.env.php.bak"] [unique_id "apK9ATAh5Y1i2tUxg4HkagAABjU"] [Sat Aug 29 05:05:37.655439 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:23443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/166.php"] [unique_id "apK9ASJcY4fy7tP-rU3rLAAAAmE"] [Sat Aug 29 05:05:37.663649 2026] [security2:error] [pid 1018003:tid 1018267] [client 68.155.159.216:12183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/install.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkawAABis"] [Sat Aug 29 05:05:37.666993 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.104.49.130:29972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/82.php"] [unique_id "apK9ASJcY4fy7tP-rU3rLQAAAlQ"] [Sat Aug 29 05:05:37.680002 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.48.250.41:27557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/logs1.php"] [unique_id "apK9ASJcY4fy7tP-rU3rLgAAAhc"] [Sat Aug 29 05:05:37.685222 2026] [security2:error] [pid 1017536:tid 1017724] [client 68.155.159.216:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/log-mama/function.php"] [unique_id "apK9ASJcY4fy7tP-rU3rLwAAAk4"] [Sat Aug 29 05:05:37.716630 2026] [security2:error] [pid 1017536:tid 1017723] [client 4.232.148.111:20656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-conflg.php"] [unique_id "apK9ASJcY4fy7tP-rU3rMAAAAk0"] [Sat Aug 29 05:05:37.746918 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.23.184.117:52484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "apK9ASJcY4fy7tP-rU3rMQAAAkQ"] [Sat Aug 29 05:05:37.749906 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.48.251.3:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/pass4.php"] [unique_id "apK9ASJcY4fy7tP-rU3rMgAAAoo"] [Sat Aug 29 05:05:37.751044 2026] [security2:error] [pid 1017536:tid 1017775] [client 158.158.54.35:6037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/storage/rip.php"] [unique_id "apK9ASJcY4fy7tP-rU3rMwAAAoE"] [Sat Aug 29 05:05:37.769182 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.147.79:48322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/file88.php"] [unique_id "apK9ASJcY4fy7tP-rU3rNAAAAiU"] [Sat Aug 29 05:05:37.803557 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.196.209.81:9502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/config.php"] [unique_id "apK9ASJcY4fy7tP-rU3rNgAAAis"] [Sat Aug 29 05:05:37.823157 2026] [security2:error] [pid 1017536:tid 1017704] [client 4.205.62.107:22238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/php-info.php"] [unique_id "apK9ASJcY4fy7tP-rU3rOAAAAjo"] [Sat Aug 29 05:05:37.838329 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.48.250.41:23399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/h2a2ck.php"] [unique_id "apK9ASJcY4fy7tP-rU3rOgAAAn4"] [Sat Aug 29 05:05:37.838938 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.250.41:27600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/inege.php"] [unique_id "apK9ASJcY4fy7tP-rU3rOwAAAmc"] [Sat Aug 29 05:05:37.843489 2026] [security2:error] [pid 1017536:tid 1017695] [client 4.205.62.107:61095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/aws_keys.php"] [unique_id "apK9ASJcY4fy7tP-rU3rPQAAAjE"] [Sat Aug 29 05:05:37.856322 2026] [security2:error] [pid 1018003:tid 1018244] [client 4.205.62.107:22216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/hiquido.com/index.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkbwAABhQ"] [Sat Aug 29 05:05:37.876665 2026] [security2:error] [pid 1018003:tid 1018268] [client 197.219.150.206:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkcQAABiw"] [Sat Aug 29 05:05:37.876751 2026] [security2:error] [pid 1018003:tid 1018268] [client 197.219.150.206:56895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkcQAABiw"] [Sat Aug 29 05:05:37.876870 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.251.3:57862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/cu.php"] [unique_id "apK9ASJcY4fy7tP-rU3rQgAAAmw"] [Sat Aug 29 05:05:37.888502 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.23.184.117:52519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/admin.php"] [unique_id "apK9ASJcY4fy7tP-rU3rQwAAAnM"] [Sat Aug 29 05:05:37.902990 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.205.62.107:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/dialog.php"] [unique_id "apK9ASJcY4fy7tP-rU3rSAAAAi0"] [Sat Aug 29 05:05:37.913697 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.63.219.114:15754] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.coveryourauto.com"] [uri "/1.php7"] [unique_id "apK9ASJcY4fy7tP-rU3rSgAAAic"] [Sat Aug 29 05:05:37.913819 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.63.219.114:15754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/1.php7"] [unique_id "apK9ASJcY4fy7tP-rU3rSgAAAic"] [Sat Aug 29 05:05:37.915321 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.63.219.114:15565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/cookie.php"] [unique_id "apK9ASJcY4fy7tP-rU3rSwAAAmM"] [Sat Aug 29 05:05:37.938276 2026] [security2:error] [pid 1017536:tid 1017785] [client 4.205.62.107:2895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/public/vx.php"] [unique_id "apK9ASJcY4fy7tP-rU3rTAAAAos"] [Sat Aug 29 05:05:37.938559 2026] [security2:error] [pid 1018003:tid 1018236] [client 168.107.94.195:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkcwAABgw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:37.952687 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.196.209.81:4532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/meta.php"] [unique_id "apK9ASJcY4fy7tP-rU3rTQAAAmU"] [Sat Aug 29 05:05:37.958792 2026] [security2:error] [pid 1017536:tid 1017783] [client 216.26.253.154:43233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.253.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9ASJcY4fy7tP-rU3rRgAAAok"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:37.961050 2026] [security2:error] [pid 1017536:tid 1017678] [client 4.205.62.107:53379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/hochladen.form.php"] [unique_id "apK9ASJcY4fy7tP-rU3rTwAAAiA"] [Sat Aug 29 05:05:37.970290 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.184.117:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/update/da222.php"] [unique_id "apK9ATAh5Y1i2tUxg4HkdAAABfA"] [Sat Aug 29 05:05:37.976919 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.48.250.41:23523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/error_log.php"] [unique_id "apK9ASJcY4fy7tP-rU3rUgAAAk8"] [Sat Aug 29 05:05:37.990967 2026] [core:error] [pid 1017536:tid 1017778] [client 32.198.11.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:37.990985 2026] [core:error] [pid 1017536:tid 1017778] [client 32.198.11.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:38.012015 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.251.3:28544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/services.php"] [unique_id "apK9AiJcY4fy7tP-rU3rVAAAAm8"] [Sat Aug 29 05:05:38.028109 2026] [security2:error] [pid 1018003:tid 1018107] [remote 45.148.10.62:50782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vvr.ewu.mybluehost.me"] [uri "/wp-login.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkdQAGJ1Y"] [Sat Aug 29 05:05:38.035147 2026] [security2:error] [pid 1017536:tid 1017690] [client 158.23.184.117:27649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/api.php"] [unique_id "apK9AiJcY4fy7tP-rU3rVQAAAiw"] [Sat Aug 29 05:05:38.040599 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.48.250.41:27568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wp-link10.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkdgAABeM"] [Sat Aug 29 05:05:38.085468 2026] [security2:error] [pid 1017536:tid 1017667] [client 158.23.147.79:24549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9AiJcY4fy7tP-rU3rWAAAAhU"] [Sat Aug 29 05:05:38.092588 2026] [core:error] [pid 1017536:tid 1017684] [client 32.198.11.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:38.092605 2026] [core:error] [pid 1017536:tid 1017684] [client 32.198.11.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:38.115179 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.23.184.117:7293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/xmr.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkdwAABdI"] [Sat Aug 29 05:05:38.121068 2026] [security2:error] [pid 1017536:tid 1017728] [client 60.243.207.176:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9AiJcY4fy7tP-rU3rWgAAAlI"] [Sat Aug 29 05:05:38.121151 2026] [security2:error] [pid 1017536:tid 1017728] [client 60.243.207.176:59516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9AiJcY4fy7tP-rU3rWgAAAlI"] [Sat Aug 29 05:05:38.141710 2026] [security2:error] [pid 1017536:tid 1017688] [client 74.248.24.12:41595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/disagraeosc.php"] [unique_id "apK9AiJcY4fy7tP-rU3rWwAAAio"] [Sat Aug 29 05:05:38.149205 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.251.3:27141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/filesystems.php"] [unique_id "apK9AiJcY4fy7tP-rU3rXAAAAk4"] [Sat Aug 29 05:05:38.154502 2026] [core:error] [pid 1017536:tid 1017597] [remote 32.198.11.44:33434] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:38.154517 2026] [core:error] [pid 1017536:tid 1017597] [remote 32.198.11.44:33434] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:38.162552 2026] [security2:error] [pid 1018003:tid 1018167] [client 45.148.10.62:50786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/.env.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkeAAABcg"] [Sat Aug 29 05:05:38.173841 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.49.130:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/read.php"] [unique_id "apK9AiJcY4fy7tP-rU3rXgAAAnc"] [Sat Aug 29 05:05:38.182036 2026] [security2:error] [pid 1017536:tid 1017729] [client 158.23.184.117:27663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/chosen.php"] [unique_id "apK9AiJcY4fy7tP-rU3rXwAAAlM"] [Sat Aug 29 05:05:38.184143 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:23510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/403.php"] [unique_id "apK9AiJcY4fy7tP-rU3rYAAAAls"] [Sat Aug 29 05:05:38.185426 2026] [security2:error] [pid 1017536:tid 1017774] [client 68.155.159.216:57361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9AiJcY4fy7tP-rU3rYQAAAoA"] [Sat Aug 29 05:05:38.191302 2026] [security2:error] [pid 1017536:tid 1017679] [client 4.232.148.111:8433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/123.php"] [unique_id "apK9AiJcY4fy7tP-rU3rYgAAAiE"] [Sat Aug 29 05:05:38.198048 2026] [security2:error] [pid 1018003:tid 1018209] [client 158.158.54.35:16682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/zoom1.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkeQAABfI"] [Sat Aug 29 05:05:38.230318 2026] [security2:error] [pid 1017536:tid 1017703] [client 68.155.159.216:51443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9AiJcY4fy7tP-rU3rYwAAAjk"] [Sat Aug 29 05:05:38.240390 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.23.147.79:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/install.php"] [unique_id "apK9AiJcY4fy7tP-rU3rZAAAAkQ"] [Sat Aug 29 05:05:38.254774 2026] [security2:error] [pid 1018003:tid 1018098] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/@fs/.env"] [unique_id "apK9AjAh5Y1i2tUxg4HkegAGMU0"] [Sat Aug 29 05:05:38.259514 2026] [security2:error] [pid 1017536:tid 1017769] [client 158.23.184.117:7290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9AiJcY4fy7tP-rU3rZQAAAns"] [Sat Aug 29 05:05:38.269000 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.196.209.81:25070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/22.php"] [unique_id "apK9AiJcY4fy7tP-rU3rZgAAAnY"] [Sat Aug 29 05:05:38.280146 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.63.219.114:18839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/NewFile.php"] [unique_id "apK9AiJcY4fy7tP-rU3rZwAAAmA"] [Sat Aug 29 05:05:38.287686 2026] [security2:error] [pid 1017536:tid 1017680] [client 158.23.147.79:49839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9AiJcY4fy7tP-rU3raAAAAiI"] [Sat Aug 29 05:05:38.318557 2026] [security2:error] [pid 1017536:tid 1017695] [client 168.107.94.195:57315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9AiJcY4fy7tP-rU3raQAAAjE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:38.318581 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.251.3:13999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/gnmlc.php"] [unique_id "apK9AiJcY4fy7tP-rU3ragAAAmc"] [Sat Aug 29 05:05:38.321138 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:27495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ww.php"] [unique_id "apK9AiJcY4fy7tP-rU3rawAAAnw"] [Sat Aug 29 05:05:38.321606 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.63.219.114:18824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/ds.php"] [unique_id "apK9AiJcY4fy7tP-rU3rbAAAAmo"] [Sat Aug 29 05:05:38.327406 2026] [security2:error] [pid 1017536:tid 1017715] [client 158.23.184.117:52500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/config.php"] [unique_id "apK9AiJcY4fy7tP-rU3rbQAAAkU"] [Sat Aug 29 05:05:38.348688 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.147.79:55893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/log-mama/function.php"] [unique_id "apK9AiJcY4fy7tP-rU3rbgAAAho"] [Sat Aug 29 05:05:38.356992 2026] [security2:error] [pid 1017536:tid 1017691] [client 68.155.159.216:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9AiJcY4fy7tP-rU3rbwAAAi0"] [Sat Aug 29 05:05:38.371772 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.48.251.3:27170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/tax.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkfAAABg8"] [Sat Aug 29 05:05:38.377935 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.196.209.81:4481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/dxc.php"] [unique_id "apK9AiJcY4fy7tP-rU3rcQAAAoo"] [Sat Aug 29 05:05:38.379639 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.49.130:57643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/m.php"] [unique_id "apK9AiJcY4fy7tP-rU3rcgAAAmM"] [Sat Aug 29 05:05:38.395515 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.48.250.41:23524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/cytyr.php"] [unique_id "apK9AiJcY4fy7tP-rU3rcwAAAhs"] [Sat Aug 29 05:05:38.396086 2026] [security2:error] [pid 1018003:tid 1018105] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/@fs/.env"] [unique_id "apK9AjAh5Y1i2tUxg4HkfQAFvVQ"] [Sat Aug 29 05:05:38.403981 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.23.184.117:8066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-act.php"] [unique_id "apK9AiJcY4fy7tP-rU3rdAAAAo4"] [Sat Aug 29 05:05:38.415348 2026] [security2:error] [pid 1018003:tid 1018094] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hitechgs.com"] [uri "/wp-config.php.old"] [unique_id "apK9AjAh5Y1i2tUxg4HkfwAFxEk"] [Sat Aug 29 05:05:38.415808 2026] [security2:error] [pid 1018003:tid 1018112] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hitechgs.com"] [uri "/wp-config.php.bak"] [unique_id "apK9AjAh5Y1i2tUxg4HkgAAFxFs"] [Sat Aug 29 05:05:38.433984 2026] [security2:error] [pid 1017536:tid 1017778] [client 68.155.159.216:52857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9AiJcY4fy7tP-rU3reQAAAoQ"] [Sat Aug 29 05:05:38.475849 2026] [security2:error] [pid 1017536:tid 1017738] [client 158.23.184.117:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/core.php"] [unique_id "apK9AiJcY4fy7tP-rU3rgQAAAlw"] [Sat Aug 29 05:05:38.475881 2026] [security2:error] [pid 1017536:tid 1017744] [client 68.155.159.216:14229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-admin/css/index.php"] [unique_id "apK9AiJcY4fy7tP-rU3rgAAAAmI"] [Sat Aug 29 05:05:38.502616 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.48.251.3:27152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/linusadmin-phpinfo.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkhQAABec"] [Sat Aug 29 05:05:38.511031 2026] [security2:error] [pid 1018003:tid 1018114] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/@fs/.env"] [unique_id "apK9AjAh5Y1i2tUxg4HkhgAGIl0"] [Sat Aug 29 05:05:38.520962 2026] [security2:error] [pid 1018003:tid 1018186] [client 209.50.169.121:19235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.169.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkgwAABds"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:38.553218 2026] [security2:error] [pid 1017536:tid 1017687] [client 158.23.184.117:7270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/fff.php"] [unique_id "apK9AiJcY4fy7tP-rU3rhAAAAik"] [Sat Aug 29 05:05:38.585012 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.48.250.41:23454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/galer.php"] [unique_id "apK9AiJcY4fy7tP-rU3rhQAAAlA"] [Sat Aug 29 05:05:38.591153 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.23.147.79:25478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/.well-known/index.php"] [unique_id "apK9AiJcY4fy7tP-rU3rhgAAApM"] [Sat Aug 29 05:05:38.612526 2026] [security2:error] [pid 1018003:tid 1018116] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.90.148.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hitechgs.com"] [uri "/config.php.bak"] [unique_id "apK9AjAh5Y1i2tUxg4HkiAAF918"] [Sat Aug 29 05:05:38.621891 2026] [security2:error] [pid 1017536:tid 1017777] [client 158.23.184.117:27692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/data.php"] [unique_id "apK9AiJcY4fy7tP-rU3rhwAAAoM"] [Sat Aug 29 05:05:38.629935 2026] [security2:error] [pid 1018003:tid 1018117] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.90.148.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hitechgs.com"] [uri "/config/.env.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkiQAGIWA"] [Sat Aug 29 05:05:38.634155 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.251.3:27183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apK9AiJcY4fy7tP-rU3riAAAAjA"] [Sat Aug 29 05:05:38.644789 2026] [security2:error] [pid 1018003:tid 1018118] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.90.148.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hitechgs.com"] [uri "/.env.php.bak"] [unique_id "apK9AjAh5Y1i2tUxg4HkigAGAWE"] [Sat Aug 29 05:05:38.646425 2026] [security2:error] [pid 1018003:tid 1018121] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/core/.env"] [unique_id "apK9AjAh5Y1i2tUxg4HkiwAGAWQ"] [Sat Aug 29 05:05:38.665164 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.63.219.114:15770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/config.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkjAAABhE"] [Sat Aug 29 05:05:38.669121 2026] [security2:error] [pid 1017536:tid 1017702] [client 4.232.148.111:8445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/yanz.php"] [unique_id "apK9AiJcY4fy7tP-rU3riQAAAjg"] [Sat Aug 29 05:05:38.673851 2026] [security2:error] [pid 1017536:tid 1017723] [client 158.23.147.79:30704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9AiJcY4fy7tP-rU3rigAAAk0"] [Sat Aug 29 05:05:38.680021 2026] [security2:error] [pid 1018003:tid 1018227] [client 4.205.62.107:64241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/configuration.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkjQAABgQ"] [Sat Aug 29 05:05:38.680044 2026] [security2:error] [pid 1018003:tid 1018197] [client 158.158.54.35:26010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/txets.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkjgAABeY"] [Sat Aug 29 05:05:38.682478 2026] [security2:error] [pid 1017536:tid 1017790] [client 74.248.24.12:8972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-logs.php"] [unique_id "apK9AiJcY4fy7tP-rU3riwAAApA"] [Sat Aug 29 05:05:38.690897 2026] [security2:error] [pid 1018003:tid 1018029] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/laravel/.env"] [unique_id "apK9AjAh5Y1i2tUxg4HkjwAFwQg"] [Sat Aug 29 05:05:38.698510 2026] [security2:error] [pid 1017536:tid 1017737] [client 168.107.94.195:57672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9AiJcY4fy7tP-rU3rjQAAAls"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:38.702845 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.250.41:27399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/w1px.php"] [unique_id "apK9AiJcY4fy7tP-rU3rjgAAAmY"] [Sat Aug 29 05:05:38.709041 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.63.219.114:12404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/GOD.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkkAAABhk"] [Sat Aug 29 05:05:38.718807 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.196.209.81:15763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/bak.phps"] [unique_id "apK9AiJcY4fy7tP-rU3rjwAAAnk"] [Sat Aug 29 05:05:38.739179 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.184.117:7232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9AiJcY4fy7tP-rU3rkAAAAnc"] [Sat Aug 29 05:05:38.752582 2026] [security2:error] [pid 1018003:tid 1018199] [client 158.23.147.79:30665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/chosen.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkkQAABeg"] [Sat Aug 29 05:05:38.767152 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.184.117:52498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/db-status.php"] [unique_id "apK9AiJcY4fy7tP-rU3rkQAAAn8"] [Sat Aug 29 05:05:38.779625 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.48.251.3:28450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/agg.php"] [unique_id "apK9AiJcY4fy7tP-rU3rkwAAAnY"] [Sat Aug 29 05:05:38.784193 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.250.41:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/baixy.php"] [unique_id "apK9AiJcY4fy7tP-rU3rlAAAAis"] [Sat Aug 29 05:05:38.798603 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:12203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/x/index.php"] [unique_id "apK9AiJcY4fy7tP-rU3rlQAAAjo"] [Sat Aug 29 05:05:38.829084 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.251.3:33286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/koiy.php"] [unique_id "apK9AiJcY4fy7tP-rU3rlwAAAmo"] [Sat Aug 29 05:05:38.871908 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.250.41:27331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/to.php"] [unique_id "apK9AiJcY4fy7tP-rU3rmAAAAho"] [Sat Aug 29 05:05:38.873955 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.49.130:46570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/gecko-new.php"] [unique_id "apK9AiJcY4fy7tP-rU3rmQAAAic"] [Sat Aug 29 05:05:38.873985 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.147.79:48222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/NewFile.php/"] [unique_id "apK9AiJcY4fy7tP-rU3rmgAAAj0"] [Sat Aug 29 05:05:38.886623 2026] [security2:error] [pid 1018003:tid 1018211] [client 158.23.184.117:53513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/robots.php"] [unique_id "apK9AjAh5Y1i2tUxg4HklQAABfQ"] [Sat Aug 29 05:05:38.890657 2026] [security2:error] [pid 1018003:tid 1018068] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.90.148.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hitechgs.com"] [uri "/configuration.php.bak"] [unique_id "apK9AjAh5Y1i2tUxg4HklgAFzS8"] [Sat Aug 29 05:05:38.901294 2026] [security2:error] [pid 1017536:tid 1017785] [client 68.155.159.216:16217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9AiJcY4fy7tP-rU3rnAAAAos"] [Sat Aug 29 05:05:38.911804 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.48.251.3:28513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/requirements.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkmAAABgc"] [Sat Aug 29 05:05:38.915158 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.184.117:27660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/f35.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkmQAABjM"] [Sat Aug 29 05:05:38.924504 2026] [security2:error] [pid 1017536:tid 1017768] [client 20.196.209.81:4502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/wp-2019.php"] [unique_id "apK9AiJcY4fy7tP-rU3rnQAAAno"] [Sat Aug 29 05:05:38.934596 2026] [security2:error] [pid 1018003:tid 1018193] [client 20.104.49.130:63611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/wp.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkmgAABeI"] [Sat Aug 29 05:05:38.950339 2026] [security2:error] [pid 1018003:tid 1018115] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/storage/.env"] [unique_id "apK9AjAh5Y1i2tUxg4HkmwAFt14"] [Sat Aug 29 05:05:38.964053 2026] [security2:error] [pid 1018003:tid 1018154] [client 4.205.62.107:22287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/xin1.php"] [unique_id "apK9AjAh5Y1i2tUxg4HknQAABbs"] [Sat Aug 29 05:05:38.965310 2026] [security2:error] [pid 1018003:tid 1018122] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/.env.swp"] [unique_id "apK9AjAh5Y1i2tUxg4HknAAGGGU"] [Sat Aug 29 05:05:38.965349 2026] [security2:error] [pid 1018003:tid 1018153] [client 68.155.159.216:33656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/file88.php"] [unique_id "apK9AjAh5Y1i2tUxg4HkngAABbo"] [Sat Aug 29 05:05:38.974767 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.250.41:23435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ava.php"] [unique_id "apK9AiJcY4fy7tP-rU3rngAAAoE"] [Sat Aug 29 05:05:38.982829 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.104.49.130:48773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/df.php"] [unique_id "apK9AjAh5Y1i2tUxg4HknwAABgs"] [Sat Aug 29 05:05:38.991018 2026] [security2:error] [pid 1017536:tid 1017700] [client 4.205.62.107:21866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/app_local.php"] [unique_id "apK9AiJcY4fy7tP-rU3rnwAAAjY"] [Sat Aug 29 05:05:39.026918 2026] [security2:error] [pid 1017536:tid 1017779] [client 20.63.219.114:1869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/22.php"] [unique_id "apK9AyJcY4fy7tP-rU3roAAAAoU"] [Sat Aug 29 05:05:39.032193 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.184.117:7278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/.well-known/install.php"] [unique_id "apK9AyJcY4fy7tP-rU3roQAAAoQ"] [Sat Aug 29 05:05:39.034935 2026] [security2:error] [pid 1018003:tid 1018159] [client 4.205.62.107:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/phpinfo01.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkoAAABcA"] [Sat Aug 29 05:05:39.042007 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.48.251.3:27180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/var/www/wallet/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3rogAAAl4"] [Sat Aug 29 05:05:39.061810 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.184.117:52539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkogAABis"] [Sat Aug 29 05:05:39.076661 2026] [security2:error] [pid 1017536:tid 1017738] [client 4.205.62.107:61074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/umgebung.php"] [unique_id "apK9AyJcY4fy7tP-rU3rpAAAAlw"] [Sat Aug 29 05:05:39.076894 2026] [security2:error] [pid 1017536:tid 1017713] [client 168.107.94.195:58037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3rpQAAAkM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:39.078880 2026] [security2:error] [pid 1017536:tid 1017719] [client 4.205.62.107:2502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/333.php"] [unique_id "apK9AyJcY4fy7tP-rU3rpgAAAkk"] [Sat Aug 29 05:05:39.085320 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.219.114:15597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/ggfi.php"] [unique_id "apK9AyJcY4fy7tP-rU3rpwAAAkc"] [Sat Aug 29 05:05:39.086456 2026] [security2:error] [pid 1018003:tid 1018169] [client 40.83.93.50:14431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/post.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkowAABco"] [Sat Aug 29 05:05:39.110198 2026] [security2:error] [pid 1018003:tid 1018181] [client 4.205.62.107:53435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/asdf.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkpwAABdY"] [Sat Aug 29 05:05:39.112742 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.250.41:27479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/thui.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkqQAABfs"] [Sat Aug 29 05:05:39.126364 2026] [security2:error] [pid 1018003:tid 1018190] [client 216.26.243.244:40391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.243.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkpAAABd8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:39.126613 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.48.250.41:23383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/gdn.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkqwAABdo"] [Sat Aug 29 05:05:39.135979 2026] [security2:error] [pid 1018003:tid 1018233] [client 4.232.148.111:20639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/autoload_classmap.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkrAAABgk"] [Sat Aug 29 05:05:39.150534 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.196.209.81:4369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/install.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkrgAABjU"] [Sat Aug 29 05:05:39.187492 2026] [core:error] [pid 1018003:tid 1018244] [client 158.23.184.117:7295] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:39.187511 2026] [core:error] [pid 1018003:tid 1018244] [client 158.23.184.117:7295] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:39.190153 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.48.251.3:28532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/124.php"] [unique_id "apK9AyJcY4fy7tP-rU3rqQAAAk8"] [Sat Aug 29 05:05:39.206292 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.184.117:28409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/home.php"] [unique_id "apK9AyJcY4fy7tP-rU3rqwAAAh0"] [Sat Aug 29 05:05:39.224264 2026] [security2:error] [pid 1017536:tid 1017776] [client 74.248.24.12:31587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-admin/css/about.php"] [unique_id "apK9AyJcY4fy7tP-rU3rrAAAAoI"] [Sat Aug 29 05:05:39.242072 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.250.41:26933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/Jcrop.php"] [unique_id "apK9AyJcY4fy7tP-rU3rrQAAAmk"] [Sat Aug 29 05:05:39.242537 2026] [security2:error] [pid 1018003:tid 1018177] [client 45.148.10.62:50790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wagnerfarmscbd.com"] [uri "/.env"] [unique_id "apK9AzAh5Y1i2tUxg4HksQAABdI"] [Sat Aug 29 05:05:39.290148 2026] [security2:error] [pid 1018003:tid 1018223] [client 20.48.250.41:23434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/f2.php"] [unique_id "apK9AzAh5Y1i2tUxg4HksgAABgA"] [Sat Aug 29 05:05:39.290821 2026] [security2:error] [pid 1018003:tid 1018164] [client 68.155.159.216:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkswAABcU"] [Sat Aug 29 05:05:39.314272 2026] [security2:error] [pid 1017536:tid 1017683] [client 216.73.216.199:63580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origeneshechoamano.sortthru.com"] [uri "/webapp/wp-cron.php"] [unique_id "apK9AyJcY4fy7tP-rU3rswAAAiU"] [Sat Aug 29 05:05:39.323280 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.196.209.81:21072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/menu.php"] [unique_id "apK9AyJcY4fy7tP-rU3rtAAAAkY"] [Sat Aug 29 05:05:39.323523 2026] [security2:error] [pid 1017536:tid 1017687] [client 34.7.216.49:46216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/wp-config.php.bak"] [unique_id "apK9AyJcY4fy7tP-rU3rtQAAAik"] [Sat Aug 29 05:05:39.327917 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.48.251.3:13955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/php-info.php"] [unique_id "apK9AyJcY4fy7tP-rU3rtwAAAko"] [Sat Aug 29 05:05:39.328749 2026] [security2:error] [pid 1017536:tid 1017726] [client 34.7.216.49:46228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/wp-config.php.old"] [unique_id "apK9AyJcY4fy7tP-rU3ruAAAAlA"] [Sat Aug 29 05:05:39.335072 2026] [security2:error] [pid 1018003:tid 1018215] [client 68.155.159.216:51244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkugAABfg"] [Sat Aug 29 05:05:39.336549 2026] [security2:error] [pid 1017536:tid 1017693] [client 158.23.184.117:53529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-admin/about.php"] [unique_id "apK9AyJcY4fy7tP-rU3ruwAAAi8"] [Sat Aug 29 05:05:39.336595 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.48.251.3:57866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/test1.php"] [unique_id "apK9AyJcY4fy7tP-rU3rugAAAnY"] [Sat Aug 29 05:05:39.341270 2026] [security2:error] [pid 1017536:tid 1017793] [client 34.7.216.49:46206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.216.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/wp-config.php"] [unique_id "apK9AyJcY4fy7tP-rU3ruQAAApM"] [Sat Aug 29 05:05:39.343748 2026] [security2:error] [pid 1018003:tid 1018191] [client 34.7.216.49:46232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.216.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/config.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkuQAABeA"] [Sat Aug 29 05:05:39.347794 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.147.79:63843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkvAAABec"] [Sat Aug 29 05:05:39.351268 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.184.117:28372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3rvAAAAlo"] [Sat Aug 29 05:05:39.356310 2026] [security2:error] [pid 1017536:tid 1017668] [client 34.7.216.49:46234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.216.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/config.php.bak"] [unique_id "apK9AyJcY4fy7tP-rU3rvgAAAhY"] [Sat Aug 29 05:05:39.395337 2026] [security2:error] [pid 1018003:tid 1018175] [client 45.148.10.62:50790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wagnerfarmscbd.com"] [uri "/.env"] [unique_id "apK9AzAh5Y1i2tUxg4HkwAAABdA"] [Sat Aug 29 05:05:39.420666 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.250.41:26881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ws58.php"] [unique_id "apK9AyJcY4fy7tP-rU3rvwAAAmo"] [Sat Aug 29 05:05:39.421343 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.63.219.114:15611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/bak.phps"] [unique_id "apK9AyJcY4fy7tP-rU3rwAAAAlQ"] [Sat Aug 29 05:05:39.426591 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.250.41:23442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/grsiuk.php"] [unique_id "apK9AyJcY4fy7tP-rU3rwQAAAmw"] [Sat Aug 29 05:05:39.438915 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.158.54.35:16674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/themes/about.php"] [unique_id "apK9AyJcY4fy7tP-rU3rwwAAAnM"] [Sat Aug 29 05:05:39.441267 2026] [security2:error] [pid 1018003:tid 1018069] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/public/.env"] [unique_id "apK9AzAh5Y1i2tUxg4HkwQAFwjA"] [Sat Aug 29 05:05:39.457918 2026] [security2:error] [pid 1018003:tid 1018214] [client 168.107.94.195:58309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9AzAh5Y1i2tUxg4HkxAAABfc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:39.464595 2026] [security2:error] [pid 1017536:tid 1017749] [client 68.155.159.216:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9AyJcY4fy7tP-rU3rzQAAAmc"] [Sat Aug 29 05:05:39.468066 2026] [security2:error] [pid 1017536:tid 1017735] [client 20.48.251.3:57845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/bigdump.php"] [unique_id "apK9AyJcY4fy7tP-rU3r0gAAAlk"] [Sat Aug 29 05:05:39.468346 2026] [security2:error] [pid 1017536:tid 1017698] [client 34.143.179.161:39756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/api/v1/env"] [unique_id "apK9AyJcY4fy7tP-rU3r0wAAAjQ"] [Sat Aug 29 05:05:39.470295 2026] [security2:error] [pid 1018003:tid 1018123] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/web/.env"] [unique_id "apK9AzAh5Y1i2tUxg4HkyAAGLWY"] [Sat Aug 29 05:05:39.473873 2026] [security2:error] [pid 1018003:tid 1018120] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/wp/.env"] [unique_id "apK9AzAh5Y1i2tUxg4HkyQAGIWM"] [Sat Aug 29 05:05:39.481425 2026] [security2:error] [pid 1018003:tid 1018126] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hitechgs.com"] [uri "/wp-config.php~"] [unique_id "apK9AzAh5Y1i2tUxg4HkywAGAWk"] [Sat Aug 29 05:05:39.482458 2026] [security2:error] [pid 1017536:tid 1017692] [client 158.23.184.117:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-content/backup.php"] [unique_id "apK9AyJcY4fy7tP-rU3r2AAAAi4"] [Sat Aug 29 05:05:39.489709 2026] [security2:error] [pid 1018003:tid 1018127] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/wp-config.old"] [unique_id "apK9AzAh5Y1i2tUxg4HkzgAGBGo"] [Sat Aug 29 05:05:39.489701 2026] [security2:error] [pid 1018003:tid 1018124] [remote 34.148.90.28:50028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "hitechgs.com"] [uri "/wp-config.php.swp"] [unique_id "apK9AzAh5Y1i2tUxg4HkzwAGBGc"] [Sat Aug 29 05:05:39.498047 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.184.117:28367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/login.php"] [unique_id "apK9AyJcY4fy7tP-rU3r2wAAAi0"] [Sat Aug 29 05:05:39.507045 2026] [security2:error] [pid 1017536:tid 1017721] [client 45.148.10.62:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/wp-config.php"] [unique_id "apK9AyJcY4fy7tP-rU3r3QAAAks"] [Sat Aug 29 05:05:39.544247 2026] [security2:error] [pid 1018003:tid 1018249] [client 158.23.147.79:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9AzAh5Y1i2tUxg4Hk0gAABhk"] [Sat Aug 29 05:05:39.545785 2026] [security2:error] [pid 1017536:tid 1017731] [client 68.155.159.216:52795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3r3wAAAlU"] [Sat Aug 29 05:05:39.555145 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.196.209.81:9523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/colour.php"] [unique_id "apK9AyJcY4fy7tP-rU3r4AAAAoY"] [Sat Aug 29 05:05:39.570352 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.63.219.114:15761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/alfa-rex.php"] [unique_id "apK9AyJcY4fy7tP-rU3r4QAAAmA"] [Sat Aug 29 05:05:39.581804 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.250.41:23467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wp-scr1pts.php"] [unique_id "apK9AzAh5Y1i2tUxg4Hk1AAABh8"] [Sat Aug 29 05:05:39.586418 2026] [security2:error] [pid 1017536:tid 1017709] [client 87.250.224.229:63602] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "tntslotcarracing.com"] [uri "/robots.txt"] [unique_id "apK9AyJcY4fy7tP-rU3r4gAAAj8"] [Sat Aug 29 05:05:39.598340 2026] [security2:error] [pid 1017536:tid 1017740] [client 68.155.159.216:14331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-admin/images/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3r4wAAAl4"] [Sat Aug 29 05:05:39.605077 2026] [security2:error] [pid 1017536:tid 1017715] [client 40.83.93.50:14805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/flower.php"] [unique_id "apK9AyJcY4fy7tP-rU3r5AAAAkU"] [Sat Aug 29 05:05:39.620518 2026] [security2:error] [pid 1017536:tid 1017784] [client 4.232.148.111:15435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/bi.php"] [unique_id "apK9AyJcY4fy7tP-rU3r5QAAAoo"] [Sat Aug 29 05:05:39.630622 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.184.117:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/.well-known/aa.php"] [unique_id "apK9AyJcY4fy7tP-rU3r5gAAAoQ"] [Sat Aug 29 05:05:39.646576 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.184.117:52481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/logs233/index.php"] [unique_id "apK9AzAh5Y1i2tUxg4Hk1QAABhw"] [Sat Aug 29 05:05:39.670818 2026] [security2:error] [pid 1017536:tid 1017768] [client 209.50.172.92:18963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.172.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9AyJcY4fy7tP-rU3r5wAAAno"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:39.678122 2026] [security2:error] [pid 1018003:tid 1018211] [client 20.48.250.41:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/xs.php"] [unique_id "apK9AzAh5Y1i2tUxg4Hk1gAABfQ"] [Sat Aug 29 05:05:39.681840 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.104.49.130:30038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/dehnl.php"] [unique_id "apK9AyJcY4fy7tP-rU3r6AAAAog"] [Sat Aug 29 05:05:39.731126 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.196.209.81:10731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/alfa.php"] [unique_id "apK9AzAh5Y1i2tUxg4Hk2QAABgY"] [Sat Aug 29 05:05:39.771219 2026] [security2:error] [pid 1017536:tid 1017706] [client 74.248.24.12:33152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/system_log.php"] [unique_id "apK9AyJcY4fy7tP-rU3r8QAAAjw"] [Sat Aug 29 05:05:39.775732 2026] [security2:error] [pid 1017536:tid 1017757] [client 74.7.175.187:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcontacts.aantec.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/404.html"] [unique_id "apK9AyJcY4fy7tP-rU3r8AAAAm8"] [Sat Aug 29 05:05:39.777425 2026] [security2:error] [pid 1017536:tid 1017783] [client 74.7.175.187:53388] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcontacts.aantec.com"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "apK9AyJcY4fy7tP-rU3r6wACiUY"] [Sat Aug 29 05:05:39.781646 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:30610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/goods.php"] [unique_id "apK9AyJcY4fy7tP-rU3r8gAAAjE"] [Sat Aug 29 05:05:39.793024 2026] [security2:error] [pid 1018003:tid 1018259] [client 158.23.184.117:53505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9AzAh5Y1i2tUxg4Hk3AAABiM"] [Sat Aug 29 05:05:39.793618 2026] [security2:error] [pid 1017536:tid 1017693] [client 158.23.184.117:27688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/maintenance.php"] [unique_id "apK9AyJcY4fy7tP-rU3r8wAAAi8"] [Sat Aug 29 05:05:39.820929 2026] [security2:error] [pid 1018003:tid 1018195] [client 68.155.159.216:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/bk/index.php"] [unique_id "apK9AzAh5Y1i2tUxg4Hk3QAABeQ"] [Sat Aug 29 05:05:39.826006 2026] [security2:error] [pid 1017536:tid 1017754] [client 4.205.62.107:61776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/server_info.php"] [unique_id "apK9AyJcY4fy7tP-rU3r9AAAAmw"] [Sat Aug 29 05:05:39.837626 2026] [security2:error] [pid 1017536:tid 1017743] [client 168.107.94.195:58644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3r9QAAAmE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:39.860732 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.23.147.79:30602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3r9wAAAkI"] [Sat Aug 29 05:05:39.881835 2026] [security2:error] [pid 1017536:tid 1017764] [client 158.158.54.35:15920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3r-QAAAnY"] [Sat Aug 29 05:05:39.883803 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.63.219.114:12386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/install.php"] [unique_id "apK9AyJcY4fy7tP-rU3r-gAAAms"] [Sat Aug 29 05:05:39.888310 2026] [proxy_http:error] [pid 1018003:tid 1018254] (20014)Internal error (specific information not available): [client 34.21.253.104:11540] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.888329 2026] [proxy:error] [pid 1018003:tid 1018254] [client 34.21.253.104:11540] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ec2-user/.aws/config [Sat Aug 29 05:05:39.891308 2026] [security2:error] [pid 1017536:tid 1017684] [client 34.21.253.104:11416] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.replenishink.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apK9AyJcY4fy7tP-rU3r_QAAAiY"] [Sat Aug 29 05:05:39.892744 2026] [core:error] [pid 1017536:tid 1017751] [client 34.21.253.104:11430] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) [Sat Aug 29 05:05:39.893539 2026] [proxy_http:error] [pid 1017536:tid 1017787] (20014)Internal error (specific information not available): [client 34.21.253.104:11344] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.893554 2026] [proxy:error] [pid 1017536:tid 1017787] [client 34.21.253.104:11344] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.ssh/id_rsa [Sat Aug 29 05:05:39.893965 2026] [security2:error] [pid 1018003:tid 1018275] [client 34.21.253.104:11458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/app/credentials.json"] [unique_id "apK9AzAh5Y1i2tUxg4Hk5AAABjM"] [Sat Aug 29 05:05:39.895497 2026] [core:error] [pid 1017536:tid 1017705] [client 34.21.253.104:11446] AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) [Sat Aug 29 05:05:39.899336 2026] [security2:error] [pid 1017536:tid 1017774] [client 34.21.253.104:11374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.replenishink.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK9AyJcY4fy7tP-rU3sBgAAAoA"] [Sat Aug 29 05:05:39.899847 2026] [proxy_http:error] [pid 1017536:tid 1017751] (20014)Internal error (specific information not available): [client 34.21.253.104:11430] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.899858 2026] [proxy:error] [pid 1017536:tid 1017751] [client 34.21.253.104:11430] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/400.shtml [Sat Aug 29 05:05:39.900162 2026] [security2:error] [pid 1017536:tid 1017789] [client 34.21.253.104:11360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/etc/nginx/nginx.conf"] [unique_id "apK9AyJcY4fy7tP-rU3sCAAAAo8"] [Sat Aug 29 05:05:39.901881 2026] [security2:error] [pid 1017536:tid 1017716] [client 34.21.253.104:11600] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/home/ubuntu/.ovh.conf"] [unique_id "apK9AyJcY4fy7tP-rU3sCgAAAkY"] [Sat Aug 29 05:05:39.902054 2026] [security2:error] [pid 1017536:tid 1017781] [client 34.21.253.104:11438] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.replenishink.com"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apK9AyJcY4fy7tP-rU3sCwAAAoc"] [Sat Aug 29 05:05:39.905780 2026] [proxy_http:error] [pid 1018003:tid 1018231] (20014)Internal error (specific information not available): [client 34.21.253.104:11406] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.905815 2026] [proxy:error] [pid 1018003:tid 1018231] [client 34.21.253.104:11406] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/404.html [Sat Aug 29 05:05:39.908110 2026] [security2:error] [pid 1017536:tid 1017773] [client 34.21.253.104:11552] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/root/.config/gcloud/credentials.db"] [unique_id "apK9AyJcY4fy7tP-rU3sEAAAAn8"] [Sat Aug 29 05:05:39.930687 2026] [proxy_http:error] [pid 1018003:tid 1018212] (20014)Internal error (specific information not available): [client 34.21.253.104:11518] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.930704 2026] [proxy:error] [pid 1018003:tid 1018212] [client 34.21.253.104:11518] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.azure/credentials [Sat Aug 29 05:05:39.937380 2026] [security2:error] [pid 1017536:tid 1017747] [client 68.155.159.216:12265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9AyJcY4fy7tP-rU3sEQAAAmU"] [Sat Aug 29 05:05:39.939183 2026] [proxy_http:error] [pid 1017536:tid 1017776] (20014)Internal error (specific information not available): [client 34.21.253.104:11436] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.939203 2026] [proxy:error] [pid 1017536:tid 1017776] [client 34.21.253.104:11436] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/404.html [Sat Aug 29 05:05:39.943871 2026] [security2:error] [pid 1018003:tid 1018159] [client 158.23.184.117:27669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/min.php"] [unique_id "apK9AzAh5Y1i2tUxg4Hk6wAABcA"] [Sat Aug 29 05:05:39.944116 2026] [security2:error] [pid 1017536:tid 1017692] [client 158.23.184.117:7242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9AyJcY4fy7tP-rU3sEgAAAi4"] [Sat Aug 29 05:05:39.952122 2026] [proxy_http:error] [pid 1017536:tid 1017683] (20014)Internal error (specific information not available): [client 34.21.253.104:11572] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.952136 2026] [proxy:error] [pid 1017536:tid 1017683] [client 34.21.253.104:11572] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.config/hcloud/cli.toml [Sat Aug 29 05:05:39.957280 2026] [proxy_http:error] [pid 1017536:tid 1017765] (20014)Internal error (specific information not available): [client 34.21.253.104:11390] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.957296 2026] [proxy:error] [pid 1017536:tid 1017765] [client 34.21.253.104:11390] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/proc/self/cmdline [Sat Aug 29 05:05:39.958424 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.63.219.114:15599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/cookie.php"] [unique_id "apK9AyJcY4fy7tP-rU3sEwAAAmM"] [Sat Aug 29 05:05:39.962203 2026] [proxy_http:error] [pid 1017536:tid 1017687] (20014)Internal error (specific information not available): [client 34.21.253.104:11574] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.962216 2026] [proxy:error] [pid 1017536:tid 1017687] [client 34.21.253.104:11574] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.config/linode-cli [Sat Aug 29 05:05:39.967199 2026] [proxy_http:error] [pid 1017536:tid 1017726] (20014)Internal error (specific information not available): [client 34.21.253.104:11534] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.967209 2026] [proxy:error] [pid 1017536:tid 1017726] [client 34.21.253.104:11534] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.oci/config [Sat Aug 29 05:05:39.972130 2026] [proxy_http:error] [pid 1017536:tid 1017683] (20014)Internal error (specific information not available): [client 34.21.253.104:11572] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:39.972143 2026] [proxy:error] [pid 1017536:tid 1017683] [client 34.21.253.104:11572] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:05:39.976580 2026] [security2:error] [pid 1017536:tid 1017755] [client 158.23.147.79:60160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/bk/index.php"] [unique_id "apK9AyJcY4fy7tP-rU3sFAAAAm0"] [Sat Aug 29 05:05:39.980926 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.147.79:48308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/dropdown.php"] [unique_id "apK9AyJcY4fy7tP-rU3sFQAAAk4"] [Sat Aug 29 05:05:39.985554 2026] [security2:error] [pid 1017536:tid 1017707] [client 45.148.10.62:50800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/wp-config.php.old"] [unique_id "apK9AyJcY4fy7tP-rU3sFgAAAj0"] [Sat Aug 29 05:05:40.040242 2026] [security2:error] [pid 1017536:tid 1017709] [client 68.155.159.216:16304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9BCJcY4fy7tP-rU3sGAAAAj8"] [Sat Aug 29 05:05:40.061933 2026] [security2:error] [pid 1018003:tid 1018157] [client 45.148.10.62:50790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wagnerfarmscbd.com"] [uri "/api/.env"] [unique_id "apK9BDAh5Y1i2tUxg4Hk7QAABb4"] [Sat Aug 29 05:05:40.075322 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:33747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/NewFile.php/"] [unique_id "apK9BDAh5Y1i2tUxg4Hk7wAABgk"] [Sat Aug 29 05:05:40.090658 2026] [security2:error] [pid 1018003:tid 1018221] [client 158.23.184.117:28362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/module.php"] [unique_id "apK9BDAh5Y1i2tUxg4Hk8QAABf4"] [Sat Aug 29 05:05:40.097039 2026] [core:error] [pid 1017536:tid 1017672] [client 158.23.184.117:7254] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:40.097055 2026] [core:error] [pid 1017536:tid 1017672] [client 158.23.184.117:7254] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:40.098991 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.232.148.111:24899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/cc.php"] [unique_id "apK9BCJcY4fy7tP-rU3sHQAAAi0"] [Sat Aug 29 05:05:40.102638 2026] [security2:error] [pid 1017536:tid 1017696] [client 4.205.62.107:21595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/adminfus.php"] [unique_id "apK9BCJcY4fy7tP-rU3sHgAAAjI"] [Sat Aug 29 05:05:40.118824 2026] [security2:error] [pid 1018003:tid 1018183] [client 40.83.93.50:9773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/meta.php"] [unique_id "apK9BDAh5Y1i2tUxg4Hk8gAABdg"] [Sat Aug 29 05:05:40.131070 2026] [security2:error] [pid 1017536:tid 1017700] [client 20.196.209.81:4366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/OK.php"] [unique_id "apK9BCJcY4fy7tP-rU3sHwAAAjY"] [Sat Aug 29 05:05:40.131678 2026] [security2:error] [pid 1017536:tid 1017750] [client 4.205.62.107:21862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/xqq.php"] [unique_id "apK9BCJcY4fy7tP-rU3sIAAAAmg"] [Sat Aug 29 05:05:40.191097 2026] [security2:error] [pid 1017536:tid 1017772] [client 4.205.62.107:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/cxc.php"] [unique_id "apK9BCJcY4fy7tP-rU3sIgAAAn4"] [Sat Aug 29 05:05:40.211377 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.196.209.81:21061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK9BDAh5Y1i2tUxg4Hk-QAABjU"] [Sat Aug 29 05:05:40.218104 2026] [security2:error] [pid 1017536:tid 1017752] [client 4.205.62.107:2513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/a1vx.php"] [unique_id "apK9BCJcY4fy7tP-rU3sJQAAAmo"] [Sat Aug 29 05:05:40.219742 2026] [security2:error] [pid 1017536:tid 1017740] [client 209.50.163.36:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.163.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9BCJcY4fy7tP-rU3sIwAAAl4"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:40.220117 2026] [security2:error] [pid 1018003:tid 1018239] [client 168.107.94.195:58965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9BDAh5Y1i2tUxg4Hk-gAABg8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:40.237836 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.184.117:27683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/options.php"] [unique_id "apK9BDAh5Y1i2tUxg4Hk_AAABd0"] [Sat Aug 29 05:05:40.243747 2026] [security2:error] [pid 1017536:tid 1017783] [client 158.23.184.117:7236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/test.php"] [unique_id "apK9BCJcY4fy7tP-rU3sJwAAAok"] [Sat Aug 29 05:05:40.245793 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.63.219.114:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/colour.php"] [unique_id "apK9BCJcY4fy7tP-rU3sKAAAAnI"] [Sat Aug 29 05:05:40.255214 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.49.130:46558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/yawa.php"] [unique_id "apK9BDAh5Y1i2tUxg4Hk_gAABiw"] [Sat Aug 29 05:05:40.256803 2026] [security2:error] [pid 1017536:tid 1017754] [client 158.23.147.79:24412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin.php"] [unique_id "apK9BCJcY4fy7tP-rU3sKQAAAmw"] [Sat Aug 29 05:05:40.259209 2026] [security2:error] [pid 1018003:tid 1018268] [client 45.148.10.62:50790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.wagnerfarmscbd.com"] [uri "/.env.bak"] [unique_id "apK9BDAh5Y1i2tUxg4Hk_wAABiw"] [Sat Aug 29 05:05:40.269047 2026] [security2:error] [pid 1017536:tid 1017736] [client 4.205.62.107:53398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/zz.php"] [unique_id "apK9BCJcY4fy7tP-rU3sLQAAAlo"] [Sat Aug 29 05:05:40.273796 2026] [security2:error] [pid 1018003:tid 1018203] [client 74.248.24.12:8187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/24.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlAQAABew"] [Sat Aug 29 05:05:40.303276 2026] [security2:error] [pid 1018003:tid 1018186] [client 4.205.62.107:54439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/old_phpinfo.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlBQAABds"] [Sat Aug 29 05:05:40.319188 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.63.219.114:15775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/NewFile.php"] [unique_id "apK9BCJcY4fy7tP-rU3sLgAAAjE"] [Sat Aug 29 05:05:40.325526 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.158.54.35:16646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/index.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlBwAABg4"] [Sat Aug 29 05:05:40.329440 2026] [security2:error] [pid 1018003:tid 1018151] [client 66.248.203.2:49310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2014/08/30/"] [unique_id "apK9BDAh5Y1i2tUxg4HlCAAABbg"] [Sat Aug 29 05:05:40.335372 2026] [lsapi:warn] [pid 1017536:tid 1017674] [client 168.90.151.133:0] [host midayins.com] Backend log: PHP Warning: PHP Request Startup: Invalid date.timezone value 'America/New York', using 'America/Boise' instead in Unknown on line 0\n [Sat Aug 29 05:05:40.386612 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.184.117:28396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/panel.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlCQAABdA"] [Sat Aug 29 05:05:40.394068 2026] [security2:error] [pid 1017536:tid 1017774] [client 158.23.184.117:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/mani.php"] [unique_id "apK9BCJcY4fy7tP-rU3sMAAAAoA"] [Sat Aug 29 05:05:40.395277 2026] [security2:error] [pid 1017536:tid 1017698] [client 103.240.76.112:42648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9BCJcY4fy7tP-rU3sMQAAAjQ"] [Sat Aug 29 05:05:40.395383 2026] [security2:error] [pid 1017536:tid 1017698] [client 103.240.76.112:42648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9BCJcY4fy7tP-rU3sMQAAAjQ"] [Sat Aug 29 05:05:40.419753 2026] [security2:error] [pid 1018003:tid 1018166] [client 158.23.184.117:57614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.dj/index.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlCwAABcc"] [Sat Aug 29 05:05:40.444146 2026] [security2:error] [pid 1017536:tid 1017675] [client 68.155.159.216:51549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9BCJcY4fy7tP-rU3sMgAAAh0"] [Sat Aug 29 05:05:40.448106 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.147.79:59234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlDQAABb0"] [Sat Aug 29 05:05:40.501173 2026] [security2:error] [pid 1018003:tid 1018213] [client 45.148.10.62:50808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/config.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlDgAABfY"] [Sat Aug 29 05:05:40.515850 2026] [security2:error] [pid 1018003:tid 1018211] [client 20.48.251.3:14323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/infos.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlEQAABfQ"] [Sat Aug 29 05:05:40.532885 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.23.184.117:28366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlEgAABho"] [Sat Aug 29 05:05:40.534042 2026] [security2:error] [pid 1018003:tid 1018147] [remote 34.148.90.28:50028] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "hitechgs.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9BDAh5Y1i2tUxg4HlFAAFu34"] [Sat Aug 29 05:05:40.540027 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.184.117:7235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/Test.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlFQAABhw"] [Sat Aug 29 05:05:40.543061 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/dropdown.php"] [unique_id "apK9BCJcY4fy7tP-rU3sMwAAAks"] [Sat Aug 29 05:05:40.564253 2026] [security2:error] [pid 1018003:tid 1018222] [client 61.9.8.52:8153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlFgAABf8"] [Sat Aug 29 05:05:40.564345 2026] [security2:error] [pid 1018003:tid 1018222] [client 61.9.8.52:8153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlFgAABf8"] [Sat Aug 29 05:05:40.566759 2026] [security2:error] [pid 1018003:tid 1018264] [client 158.23.184.117:20263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.info.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlGAAABig"] [Sat Aug 29 05:05:40.570609 2026] [security2:error] [pid 1017536:tid 1017765] [client 68.155.159.216:61625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9BCJcY4fy7tP-rU3sNAAAAnc"] [Sat Aug 29 05:05:40.576683 2026] [security2:error] [pid 1018003:tid 1018257] [client 4.232.148.111:5901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/files/index.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlGgAABiE"] [Sat Aug 29 05:05:40.581625 2026] [security2:error] [pid 1018003:tid 1018220] [client 20.104.49.130:29954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/dex.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlHAAABf0"] [Sat Aug 29 05:05:40.598559 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.48.251.3:28484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wdf.php"] [unique_id "apK9BCJcY4fy7tP-rU3sNQAAAio"] [Sat Aug 29 05:05:40.600000 2026] [security2:error] [pid 1018003:tid 1018273] [client 40.83.93.50:8025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/randkeyword.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlHgAABjE"] [Sat Aug 29 05:05:40.600031 2026] [security2:error] [pid 1018003:tid 1018245] [client 168.107.94.195:59313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlHQAABhU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:40.602372 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.63.219.114:11484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/OK.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlHwAABes"] [Sat Aug 29 05:05:40.606618 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.196.209.81:9534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.firstcutfilm.com"] [uri "/aaa.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlIAAABgE"] [Sat Aug 29 05:05:40.623003 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.196.209.81:12699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/inputs.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlIgAABeg"] [Sat Aug 29 05:05:40.662129 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.147.79:49993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlJAAABbo"] [Sat Aug 29 05:05:40.669605 2026] [security2:error] [pid 1018003:tid 1018177] [client 103.171.189.88:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlJQAABdI"] [Sat Aug 29 05:05:40.669742 2026] [security2:error] [pid 1018003:tid 1018177] [client 103.171.189.88:52029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlJQAABdI"] [Sat Aug 29 05:05:40.672976 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.63.219.114:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/config.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlJwAABiM"] [Sat Aug 29 05:05:40.679712 2026] [security2:error] [pid 1018003:tid 1018159] [client 158.23.184.117:28359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/pki-validation/pl.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlKAAABcA"] [Sat Aug 29 05:05:40.687236 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.184.117:53548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/pomo.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlKQAABis"] [Sat Aug 29 05:05:40.704989 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.147.79:25488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlKgAABfs"] [Sat Aug 29 05:05:40.714639 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.184.117:20274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.trash7206/index.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlKwAABb4"] [Sat Aug 29 05:05:40.720542 2026] [security2:error] [pid 1018003:tid 1018236] [client 68.155.159.216:14307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/index.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlLAAABgw"] [Sat Aug 29 05:05:40.726973 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.251.3:28467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/bb.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlLQAABf4"] [Sat Aug 29 05:05:40.729826 2026] [security2:error] [pid 1017536:tid 1017716] [client 149.34.210.141:59289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9BCJcY4fy7tP-rU3sOAAAAkY"] [Sat Aug 29 05:05:40.729960 2026] [security2:error] [pid 1017536:tid 1017716] [client 149.34.210.141:59289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9BCJcY4fy7tP-rU3sOAAAAkY"] [Sat Aug 29 05:05:40.754213 2026] [security2:error] [pid 1018003:tid 1018253] [client 209.50.167.148:61597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.167.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlLgAABh0"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:40.773470 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.158.54.35:14048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/radio.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlMQAABek"] [Sat Aug 29 05:05:40.775100 2026] [security2:error] [pid 1018003:tid 1018162] [client 45.148.10.62:50790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wagnerfarmscbd.com"] [uri "/stripe/.env"] [unique_id "apK9BDAh5Y1i2tUxg4HlMgAABcM"] [Sat Aug 29 05:05:40.827139 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.184.117:27672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/pki-validation/x.php"] [unique_id "apK9BCJcY4fy7tP-rU3sOgAAAoQ"] [Sat Aug 29 05:05:40.858005 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.251.3:57835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/file59.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlMwAABeU"] [Sat Aug 29 05:05:40.861577 2026] [security2:error] [pid 1018003:tid 1018263] [client 158.23.184.117:20275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.trash7206/min.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlNAAABic"] [Sat Aug 29 05:05:40.867547 2026] [core:error] [pid 1017536:tid 1017689] [client 74.248.24.12:23829] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:40.867566 2026] [core:error] [pid 1017536:tid 1017689] [client 74.248.24.12:23829] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:40.887880 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:30663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9BCJcY4fy7tP-rU3sPQAAAkc"] [Sat Aug 29 05:05:40.917042 2026] [core:error] [pid 1017536:tid 1017672] [client 158.23.184.117:7250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:40.917065 2026] [core:error] [pid 1017536:tid 1017672] [client 158.23.184.117:7250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:40.955258 2026] [security2:error] [pid 1017536:tid 1017711] [client 68.155.159.216:16171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.showerdoorsdubuque.com"] [uri "/first.php"] [unique_id "apK9BCJcY4fy7tP-rU3sPwAAAkE"] [Sat Aug 29 05:05:40.958498 2026] [security2:error] [pid 1017536:tid 1017700] [client 4.205.62.107:64985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/hosty.php"] [unique_id "apK9BCJcY4fy7tP-rU3sQAAAAjY"] [Sat Aug 29 05:05:40.965007 2026] [security2:error] [pid 1017536:tid 1017706] [client 158.23.147.79:30692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/file.php"] [unique_id "apK9BCJcY4fy7tP-rU3sQQAAAjw"] [Sat Aug 29 05:05:40.970124 2026] [security2:error] [pid 1018003:tid 1018194] [client 45.148.10.62:50824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/config.php.bak"] [unique_id "apK9BDAh5Y1i2tUxg4HlNgAABeM"] [Sat Aug 29 05:05:40.979528 2026] [security2:error] [pid 1017536:tid 1017782] [client 158.23.184.117:28353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "apK9BCJcY4fy7tP-rU3sQgAAAog"] [Sat Aug 29 05:05:40.985774 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.48.251.3:27182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/cli_bootstrap.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlNwAABeY"] [Sat Aug 29 05:05:40.998931 2026] [security2:error] [pid 1018003:tid 1018265] [client 168.107.94.195:59617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9BDAh5Y1i2tUxg4HlOAAABik"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:41.008162 2026] [security2:error] [pid 1018003:tid 1018166] [client 158.23.184.117:20236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known//index.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlOQAABcc"] [Sat Aug 29 05:05:41.032108 2026] [security2:error] [pid 1017536:tid 1017793] [client 68.155.159.216:12286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9BSJcY4fy7tP-rU3sQwAAApM"] [Sat Aug 29 05:05:41.043821 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.48.251.3:14335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/xve22.php"] [unique_id "apK9BSJcY4fy7tP-rU3sRQAAAi8"] [Sat Aug 29 05:05:41.047310 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.196.209.81:21105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK9BSJcY4fy7tP-rU3sRgAAAi0"] [Sat Aug 29 05:05:41.048427 2026] [security2:error] [pid 1017536:tid 1017670] [client 4.232.148.111:8447] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.easyarranger.com"] [uri "/1.php7"] [unique_id "apK9BSJcY4fy7tP-rU3sRwAAAhg"] [Sat Aug 29 05:05:41.048506 2026] [security2:error] [pid 1017536:tid 1017670] [client 4.232.148.111:8447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/1.php7"] [unique_id "apK9BSJcY4fy7tP-rU3sRwAAAhg"] [Sat Aug 29 05:05:41.048530 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.63.219.114:15751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "travelprep-tv.wanderlustpictures.com"] [uri "/aaa.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlOgAABd4"] [Sat Aug 29 05:05:41.066940 2026] [security2:error] [pid 1018003:tid 1018021] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/web.config"] [unique_id "apK9BTAh5Y1i2tUxg4HlPgAGGQA"] [Sat Aug 29 05:05:41.081246 2026] [security2:error] [pid 1018003:tid 1018173] [client 158.23.147.79:62788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.condo4maui.com"] [uri "/first.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlQQAABc4"] [Sat Aug 29 05:05:41.086047 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.147.79:48215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/.well-known/index.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlQgAABgo"] [Sat Aug 29 05:05:41.090443 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.63.219.114:15759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/22.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlQwAABgQ"] [Sat Aug 29 05:05:41.104072 2026] [security2:error] [pid 1018003:tid 1018269] [client 40.83.93.50:14402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/goods.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlRQAABi0"] [Sat Aug 29 05:05:41.128071 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.184.117:28395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/security.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlRwAABcQ"] [Sat Aug 29 05:05:41.129575 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.251.3:28495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/dd.php"] [unique_id "apK9BSJcY4fy7tP-rU3sSgAAAos"] [Sat Aug 29 05:05:41.146059 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.184.117:7337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-admin/link-add.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlSAAABfY"] [Sat Aug 29 05:05:41.149729 2026] [security2:error] [pid 1017536:tid 1017730] [client 68.155.159.216:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/radio.php"] [unique_id "apK9BSJcY4fy7tP-rU3sSwAAAlQ"] [Sat Aug 29 05:05:41.155819 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.184.117:57617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/about.php"] [unique_id "apK9BSJcY4fy7tP-rU3sTAAAAlo"] [Sat Aug 29 05:05:41.189570 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.251.3:14002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/xin1.php"] [unique_id "apK9BSJcY4fy7tP-rU3sTQAAAmY"] [Sat Aug 29 05:05:41.221592 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.158.54.35:14071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/item.php"] [unique_id "apK9BSJcY4fy7tP-rU3sTgAAAnM"] [Sat Aug 29 05:05:41.241829 2026] [security2:error] [pid 1017536:tid 1017789] [client 68.155.159.216:33743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/dropdown.php"] [unique_id "apK9BSJcY4fy7tP-rU3sTwAAAo8"] [Sat Aug 29 05:05:41.242934 2026] [security2:error] [pid 1018003:tid 1018195] [client 4.205.62.107:21846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/env.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlSwAABeQ"] [Sat Aug 29 05:05:41.259686 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.48.251.3:28558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-tem.php"] [unique_id "apK9BSJcY4fy7tP-rU3sUAAAAiA"] [Sat Aug 29 05:05:41.272078 2026] [security2:error] [pid 1017536:tid 1017751] [client 158.23.184.117:28354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/system.php"] [unique_id "apK9BSJcY4fy7tP-rU3sUwAAAmk"] [Sat Aug 29 05:05:41.272661 2026] [security2:error] [pid 1017536:tid 1017705] [client 4.205.62.107:22285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/or.php"] [unique_id "apK9BSJcY4fy7tP-rU3sVAAAAjs"] [Sat Aug 29 05:05:41.273473 2026] [security2:error] [pid 1018003:tid 1018257] [client 35.198.240.194:62692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.env"] [unique_id "apK9BTAh5Y1i2tUxg4HlTgAABiE"] [Sat Aug 29 05:05:41.274266 2026] [security2:error] [pid 1017536:tid 1017747] [client 35.198.240.194:62704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/uploads../.env"] [unique_id "apK9BSJcY4fy7tP-rU3sUgAAAmU"] [Sat Aug 29 05:05:41.276442 2026] [security2:error] [pid 1017536:tid 1017675] [client 35.198.240.194:62716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/assets../.env"] [unique_id "apK9BSJcY4fy7tP-rU3sVQAAAh0"] [Sat Aug 29 05:05:41.276892 2026] [security2:error] [pid 1017536:tid 1017675] [client 35.198.240.194:62716] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.omni-staffing.com"] [uri "/assets../.env"] [unique_id "apK9BSJcY4fy7tP-rU3sVQAAAh0"] [Sat Aug 29 05:05:41.278133 2026] [security2:error] [pid 1017536:tid 1017673] [client 35.198.240.194:62762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/v2/.env"] [unique_id "apK9BSJcY4fy7tP-rU3sVwAAAhs"] [Sat Aug 29 05:05:41.278193 2026] [security2:error] [pid 1018003:tid 1018165] [client 35.198.240.194:62720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/img../.env"] [unique_id "apK9BTAh5Y1i2tUxg4HlUAAABcY"] [Sat Aug 29 05:05:41.278751 2026] [security2:error] [pid 1018003:tid 1018220] [client 35.198.240.194:62832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.env.old"] [unique_id "apK9BTAh5Y1i2tUxg4HlUQAABf0"] [Sat Aug 29 05:05:41.279303 2026] [security2:error] [pid 1017536:tid 1017728] [client 35.198.240.194:62808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.env.bak"] [unique_id "apK9BSJcY4fy7tP-rU3sXgAAAlI"] [Sat Aug 29 05:05:41.279575 2026] [security2:error] [pid 1017536:tid 1017733] [client 35.198.240.194:62736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/images../.env"] [unique_id "apK9BSJcY4fy7tP-rU3sWgAAAlc"] [Sat Aug 29 05:05:41.279826 2026] [security2:error] [pid 1017536:tid 1017687] [client 35.198.240.194:62924] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/config/.env"] [unique_id "apK9BSJcY4fy7tP-rU3sYAAAAik"] [Sat Aug 29 05:05:41.279974 2026] [security2:error] [pid 1017536:tid 1017692] [client 35.198.240.194:62742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.docker/.env"] [unique_id "apK9BSJcY4fy7tP-rU3sWAAAAi4"] [Sat Aug 29 05:05:41.280299 2026] [security2:error] [pid 1017536:tid 1017732] [client 35.198.240.194:62774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.env"] [unique_id "apK9BSJcY4fy7tP-rU3sWwAAAlY"] [Sat Aug 29 05:05:41.280514 2026] [security2:error] [pid 1017536:tid 1017776] [client 35.198.240.194:62746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/v1/.env"] [unique_id "apK9BSJcY4fy7tP-rU3sVgAAAoI"] [Sat Aug 29 05:05:41.282307 2026] [security2:error] [pid 1017536:tid 1017781] [client 35.198.240.194:62834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.env.backup"] [unique_id "apK9BSJcY4fy7tP-rU3sXAAAAoc"] [Sat Aug 29 05:05:41.282591 2026] [security2:error] [pid 1017536:tid 1017765] [client 35.198.240.194:62862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.env.swp"] [unique_id "apK9BSJcY4fy7tP-rU3sXQAAAnc"] [Sat Aug 29 05:05:41.282800 2026] [security2:error] [pid 1017536:tid 1017721] [client 35.198.240.194:62882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/api/.env"] [unique_id "apK9BSJcY4fy7tP-rU3sXwAAAks"] [Sat Aug 29 05:05:41.283258 2026] [security2:error] [pid 1018003:tid 1018240] [client 35.198.240.194:62932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.omni-staffing.com"] [uri "/backend/.env"] [unique_id "apK9BTAh5Y1i2tUxg4HlVgAABhA"] [Sat Aug 29 05:05:41.283341 2026] [security2:error] [pid 1018003:tid 1018275] [client 35.198.240.194:62952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/core/.env"] [unique_id "apK9BTAh5Y1i2tUxg4HlVAAABjM"] [Sat Aug 29 05:05:41.283348 2026] [security2:error] [pid 1017536:tid 1017683] [client 35.198.240.194:62900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/app/.env"] [unique_id "apK9BSJcY4fy7tP-rU3sYQAAAiU"] [Sat Aug 29 05:05:41.283975 2026] [security2:error] [pid 1017536:tid 1017667] [client 35.198.240.194:62942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/laravel/.env"] [unique_id "apK9BSJcY4fy7tP-rU3sZwAAAhU"] [Sat Aug 29 05:05:41.284282 2026] [security2:error] [pid 1018003:tid 1018235] [client 35.198.240.194:62966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/frontend/.env"] [unique_id "apK9BTAh5Y1i2tUxg4HlVQAABgs"] [Sat Aug 29 05:05:41.284328 2026] [security2:error] [pid 1017536:tid 1017688] [client 35.198.240.194:62946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/docker/.env"] [unique_id "apK9BSJcY4fy7tP-rU3saAAAAio"] [Sat Aug 29 05:05:41.285097 2026] [security2:error] [pid 1017536:tid 1017755] [client 35.198.240.194:62886] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9BSJcY4fy7tP-rU3sYgAAAm0"] [Sat Aug 29 05:05:41.285101 2026] [security2:error] [pid 1017536:tid 1017688] [client 35.198.240.194:62946] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.omni-staffing.com"] [uri "/docker/.env"] [unique_id "apK9BSJcY4fy7tP-rU3saAAAAio"] [Sat Aug 29 05:05:41.285668 2026] [security2:error] [pid 1017536:tid 1017726] [client 35.198.240.194:62996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/web/.env"] [unique_id "apK9BSJcY4fy7tP-rU3saQAAAlA"] [Sat Aug 29 05:05:41.285794 2026] [security2:error] [pid 1018003:tid 1018182] [client 35.198.240.194:62986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/server/.env"] [unique_id "apK9BTAh5Y1i2tUxg4HlVwAABdc"] [Sat Aug 29 05:05:41.287121 2026] [security2:error] [pid 1018003:tid 1018152] [client 35.198.240.194:62982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/src/.env"] [unique_id "apK9BTAh5Y1i2tUxg4HlWAAABbk"] [Sat Aug 29 05:05:41.292284 2026] [security2:error] [pid 1017536:tid 1017774] [client 158.23.184.117:7246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/Text.php"] [unique_id "apK9BSJcY4fy7tP-rU3sagAAAoA"] [Sat Aug 29 05:05:41.328786 2026] [security2:error] [pid 1018003:tid 1018245] [client 4.205.62.107:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/oiko6u.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlWQAABhU"] [Sat Aug 29 05:05:41.345786 2026] [security2:error] [pid 1017536:tid 1017764] [client 45.3.47.251:11285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9BSJcY4fy7tP-rU3sbAAAAnY"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:41.354400 2026] [security2:error] [pid 1018003:tid 1018246] [client 4.205.62.107:2685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/phpsysinfo.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlWgAABhY"] [Sat Aug 29 05:05:41.354412 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.184.117:20278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9BSJcY4fy7tP-rU3sbgAAAls"] [Sat Aug 29 05:05:41.355431 2026] [security2:error] [pid 1018003:tid 1018223] [client 20.48.251.3:13953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/sadd.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlWwAABgA"] [Sat Aug 29 05:05:41.367778 2026] [security2:error] [pid 1017536:tid 1017668] [client 158.23.147.79:24406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9BSJcY4fy7tP-rU3sbwAAAhY"] [Sat Aug 29 05:05:41.376675 2026] [security2:error] [pid 1018003:tid 1018150] [client 168.107.94.195:59897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlXAAABbc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:41.391379 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.48.251.3:28474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/txets.php"] [unique_id "apK9BSJcY4fy7tP-rU3scAAAAiE"] [Sat Aug 29 05:05:41.416462 2026] [security2:error] [pid 1018003:tid 1018222] [client 74.248.24.12:33213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlXQAABf8"] [Sat Aug 29 05:05:41.417077 2026] [security2:error] [pid 1017536:tid 1017709] [client 158.23.184.117:28380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/users.php"] [unique_id "apK9BSJcY4fy7tP-rU3scQAAAj8"] [Sat Aug 29 05:05:41.420954 2026] [security2:error] [pid 1018003:tid 1018174] [client 45.148.10.62:50790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wagnerfarmscbd.com"] [uri "/backend/.env"] [unique_id "apK9BTAh5Y1i2tUxg4HlYAAABc8"] [Sat Aug 29 05:05:41.440388 2026] [security2:error] [pid 1017536:tid 1017727] [client 158.23.184.117:53561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-trackback.php"] [unique_id "apK9BSJcY4fy7tP-rU3scgAAAlE"] [Sat Aug 29 05:05:41.455476 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.63.219.114:12355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/bak.phps"] [unique_id "apK9BTAh5Y1i2tUxg4HlZQAABjE"] [Sat Aug 29 05:05:41.456238 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.196.209.81:21096] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/1.php7"] [unique_id "apK9BSJcY4fy7tP-rU3sdAAAAow"] [Sat Aug 29 05:05:41.456309 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.196.209.81:21096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/1.php7"] [unique_id "apK9BSJcY4fy7tP-rU3sdAAAAow"] [Sat Aug 29 05:05:41.463174 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.104.49.130:57699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/tiny2.php"] [unique_id "apK9BSJcY4fy7tP-rU3sdQAAAlw"] [Sat Aug 29 05:05:41.463860 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.104.49.130:47834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/css.php"] [unique_id "apK9BSJcY4fy7tP-rU3sdgAAAoQ"] [Sat Aug 29 05:05:41.500763 2026] [security2:error] [pid 1017536:tid 1017784] [client 158.23.184.117:20232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "apK9BSJcY4fy7tP-rU3segAAAoo"] [Sat Aug 29 05:05:41.507828 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.251.3:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/application.config.php"] [unique_id "apK9BSJcY4fy7tP-rU3sewAAApI"] [Sat Aug 29 05:05:41.508303 2026] [security2:error] [pid 1017536:tid 1017768] [client 4.205.62.107:54461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop264olney.net"] [uri "/wp-act.php"] [unique_id "apK9BSJcY4fy7tP-rU3sfAAAAno"] [Sat Aug 29 05:05:41.521768 2026] [security2:error] [pid 1018003:tid 1018231] [client 4.232.148.111:24104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/disagraeosc.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlZwAABgc"] [Sat Aug 29 05:05:41.562061 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.184.117:27685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/wp-blog-header.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlaQAABis"] [Sat Aug 29 05:05:41.572342 2026] [security2:error] [pid 1018003:tid 1018190] [client 4.205.62.107:53393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wp-konfig.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlagAABd8"] [Sat Aug 29 05:05:41.577299 2026] [security2:error] [pid 1018003:tid 1018236] [client 45.148.10.62:50790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wagnerfarmscbd.com"] [uri "/test.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlawAABgw"] [Sat Aug 29 05:05:41.599854 2026] [security2:error] [pid 1018003:tid 1018177] [client 40.83.93.50:7799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/hehe.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlbAAABdI"] [Sat Aug 29 05:05:41.613835 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.184.117:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-admin/maint.php"] [unique_id "apK9BTAh5Y1i2tUxg4HlbQAABfs"] [Sat Aug 29 05:05:41.654711 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.158.54.35:14078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/t.php"] [unique_id "apK9BSJcY4fy7tP-rU3sgwAAAjI"] [Sat Aug 29 05:05:41.675946 2026] [security2:error] [pid 1017536:tid 1017783] [client 68.155.159.216:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9BSJcY4fy7tP-rU3shgAAAok"] [Sat Aug 29 05:05:41.702333 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.23.184.117:20269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9BSJcY4fy7tP-rU3shwAAAkI"] [Sat Aug 29 05:05:41.707767 2026] [security2:error] [pid 1017536:tid 1017752] [client 158.23.184.117:28402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/wp-links-opml.php"] [unique_id "apK9BSJcY4fy7tP-rU3siAAAAmo"] [Sat Aug 29 05:05:41.755735 2026] [security2:error] [pid 1017536:tid 1017695] [client 168.107.94.195:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9BSJcY4fy7tP-rU3siwAAAjE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:41.759797 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.184.117:53535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/num.php"] [unique_id "apK9BSJcY4fy7tP-rU3sjAAAAmc"] [Sat Aug 29 05:05:41.772867 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.147.79:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9BSJcY4fy7tP-rU3sjQAAAhw"] [Sat Aug 29 05:05:41.793616 2026] [security2:error] [pid 1017536:tid 1017743] [client 195.178.110.247:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lancastaluminum.com"] [uri "/index.php"] [unique_id "apK9BSJcY4fy7tP-rU3sjgAAAmE"] [Sat Aug 29 05:05:41.808552 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.63.219.114:12364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/install.php"] [unique_id "apK9BTAh5Y1i2tUxg4HldQAABd0"] [Sat Aug 29 05:05:41.843862 2026] [security2:error] [pid 1017536:tid 1017687] [client 68.155.159.216:14147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/mah.php"] [unique_id "apK9BSJcY4fy7tP-rU3skAAAAik"] [Sat Aug 29 05:05:41.847549 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.147.79:25590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/radio.php"] [unique_id "apK9BSJcY4fy7tP-rU3skQAAAhs"] [Sat Aug 29 05:05:41.850235 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.184.117:20237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "apK9BSJcY4fy7tP-rU3skgAAAn8"] [Sat Aug 29 05:05:41.850264 2026] [security2:error] [pid 1017536:tid 1017728] [client 20.104.49.130:52300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/002.php"] [unique_id "apK9BSJcY4fy7tP-rU3skwAAAlI"] [Sat Aug 29 05:05:41.852775 2026] [security2:error] [pid 1017536:tid 1017787] [client 158.23.184.117:28364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/wp-load.php"] [unique_id "apK9BSJcY4fy7tP-rU3slAAAAo0"] [Sat Aug 29 05:05:41.884825 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.196.209.81:4493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/ds.php"] [unique_id "apK9BSJcY4fy7tP-rU3slgAAAlo"] [Sat Aug 29 05:05:41.904801 2026] [security2:error] [pid 1017536:tid 1017733] [client 158.23.184.117:53547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/identity.php"] [unique_id "apK9BSJcY4fy7tP-rU3slwAAAlc"] [Sat Aug 29 05:05:41.955251 2026] [security2:error] [pid 1017536:tid 1017774] [client 74.7.228.40:40854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "strangeworx.com"] [uri "/robots.txt"] [unique_id "apK9BSJcY4fy7tP-rU3smAAAAoA"] [Sat Aug 29 05:05:41.957175 2026] [security2:error] [pid 1017536:tid 1017754] [client 195.178.110.247:54712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lancastaluminum.com"] [uri "/index.php"] [unique_id "apK9BSJcY4fy7tP-rU3smQAAAmw"] [Sat Aug 29 05:05:41.963185 2026] [core:error] [pid 1017536:tid 1017761] [client 74.248.24.12:33179] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:41.963200 2026] [core:error] [pid 1017536:tid 1017761] [client 74.248.24.12:33179] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:41.981815 2026] [security2:error] [pid 1017536:tid 1017742] [client 45.148.10.62:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/phpinfo.php"] [unique_id "apK9BSJcY4fy7tP-rU3sngAAAmA"] [Sat Aug 29 05:05:41.984805 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.232.148.111:18079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-logs.php"] [unique_id "apK9BSJcY4fy7tP-rU3snwAAAh0"] [Sat Aug 29 05:05:41.995910 2026] [security2:error] [pid 1017536:tid 1017688] [client 158.23.184.117:57649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/admin.php"] [unique_id "apK9BSJcY4fy7tP-rU3soAAAAio"] [Sat Aug 29 05:05:41.998015 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.184.117:28394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/wp-mail.php"] [unique_id "apK9BSJcY4fy7tP-rU3soQAAAk4"] [Sat Aug 29 05:05:42.000423 2026] [security2:error] [pid 1017536:tid 1017764] [client 158.23.147.79:30608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/file17.php"] [unique_id "apK9BSJcY4fy7tP-rU3sogAAAnY"] [Sat Aug 29 05:05:42.005819 2026] [security2:error] [pid 1018003:tid 1018198] [client 57.141.14.2:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK9BjAh5Y1i2tUxg4HleAAABec"] [Sat Aug 29 05:05:42.072964 2026] [security2:error] [pid 1018003:tid 1018025] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/app/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HlewAF5QQ"] [Sat Aug 29 05:05:42.073545 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.147.79:30593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/file5.php"] [unique_id "apK9BiJcY4fy7tP-rU3sqQAAApA"] [Sat Aug 29 05:05:42.074596 2026] [core:error] [pid 1018003:tid 1018186] [client 158.23.184.117:53555] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.074612 2026] [core:error] [pid 1018003:tid 1018186] [client 158.23.184.117:53555] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.077286 2026] [security2:error] [pid 1017536:tid 1017686] [client 40.83.93.50:7795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK9BiJcY4fy7tP-rU3sqgAAAig"] [Sat Aug 29 05:05:42.093899 2026] [security2:error] [pid 1017536:tid 1017775] [client 4.205.62.107:61863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/pass4.php"] [unique_id "apK9BiJcY4fy7tP-rU3srQAAAoE"] [Sat Aug 29 05:05:42.097386 2026] [security2:error] [pid 1017536:tid 1017755] [client 158.158.54.35:9411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/i.php"] [unique_id "apK9BiJcY4fy7tP-rU3srgAAAm0"] [Sat Aug 29 05:05:42.100228 2026] [security2:error] [pid 1018003:tid 1018038] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/src/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HlfgAGMhE"] [Sat Aug 29 05:05:42.100233 2026] [security2:error] [pid 1018003:tid 1018037] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/frontend/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HlfQAGMhA"] [Sat Aug 29 05:05:42.101011 2026] [security2:error] [pid 1018003:tid 1018074] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/server/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HlfwAGMjU"] [Sat Aug 29 05:05:42.102086 2026] [security2:error] [pid 1018003:tid 1018052] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/dev/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HlgQAGMh8"] [Sat Aug 29 05:05:42.103763 2026] [security2:error] [pid 1017536:tid 1017668] [client 74.7.228.40:56160] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "strangeworx.com"] [uri "/robots.txt"] [unique_id "apK9BiJcY4fy7tP-rU3sqwACFjM"], referer: http://strangeworx.com/robots.txt [Sat Aug 29 05:05:42.136255 2026] [security2:error] [pid 1018003:tid 1018214] [client 168.107.94.195:60673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlggAABfc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:42.142943 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.23.184.117:57621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/api.php"] [unique_id "apK9BiJcY4fy7tP-rU3srwAAAkQ"] [Sat Aug 29 05:05:42.144798 2026] [security2:error] [pid 1018003:tid 1018263] [client 158.23.184.117:28374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/wp-settings.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlgwAABic"] [Sat Aug 29 05:05:42.155127 2026] [security2:error] [pid 1017536:tid 1017711] [client 68.155.159.216:50300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/sad/about.php"] [unique_id "apK9BiJcY4fy7tP-rU3ssQAAAkE"] [Sat Aug 29 05:05:42.168991 2026] [security2:error] [pid 1018003:tid 1018183] [client 103.162.125.59:51412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlhAAABdg"] [Sat Aug 29 05:05:42.169117 2026] [security2:error] [pid 1018003:tid 1018183] [client 103.162.125.59:51412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlhAAABdg"] [Sat Aug 29 05:05:42.169892 2026] [security2:error] [pid 1017536:tid 1017706] [client 68.155.159.216:12202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-login.php"] [unique_id "apK9BiJcY4fy7tP-rU3ssgAAAjw"] [Sat Aug 29 05:05:42.186710 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.63.219.114:14404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/colour.php"] [unique_id "apK9BiJcY4fy7tP-rU3sswAAAiE"] [Sat Aug 29 05:05:42.201100 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.196.209.81:17049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK9BiJcY4fy7tP-rU3stAAAAjo"] [Sat Aug 29 05:05:42.289235 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.196.209.81:12681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/GOD.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlhgAABcw"] [Sat Aug 29 05:05:42.289565 2026] [security2:error] [pid 1017536:tid 1017719] [client 158.23.184.117:27676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/.well-known/wp-signup.php"] [unique_id "apK9BiJcY4fy7tP-rU3stwAAAkk"] [Sat Aug 29 05:05:42.290305 2026] [security2:error] [pid 1017536:tid 1017783] [client 158.23.184.117:57629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/chosen.php"] [unique_id "apK9BiJcY4fy7tP-rU3suAAAAok"] [Sat Aug 29 05:05:42.298706 2026] [security2:error] [pid 1017536:tid 1017689] [client 45.148.10.62:50838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.wagnerfarmscbd.com"] [uri "/.env.backup"] [unique_id "apK9BiJcY4fy7tP-rU3suQAAAis"] [Sat Aug 29 05:05:42.309425 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.184.117:8071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/Radio.php"] [unique_id "apK9BiJcY4fy7tP-rU3suwAAAmc"] [Sat Aug 29 05:05:42.392382 2026] [cgid:error] [pid 1017536:tid 1017573] [remote 216.41.232.163:31657] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/flowerfh/public_html/404.shtml, referer: https://www.flowerfh.com/obituaries.php [Sat Aug 29 05:05:42.395782 2026] [security2:error] [pid 1017536:tid 1017776] [client 4.205.62.107:22246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/ms-edit.php"] [unique_id "apK9BiJcY4fy7tP-rU3swgAAAoI"] [Sat Aug 29 05:05:42.405718 2026] [security2:error] [pid 1018003:tid 1018227] [client 68.155.159.216:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlhwAABgQ"] [Sat Aug 29 05:05:42.424215 2026] [security2:error] [pid 1017536:tid 1017733] [client 4.205.62.107:22271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/i.php"] [unique_id "apK9BiJcY4fy7tP-rU3swwAAAlc"] [Sat Aug 29 05:05:42.434791 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.184.117:28390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/002.php"] [unique_id "apK9BjAh5Y1i2tUxg4HliAAABgo"] [Sat Aug 29 05:05:42.449593 2026] [security2:error] [pid 1017536:tid 1017745] [client 45.148.10.62:50838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.wagnerfarmscbd.com"] [uri "/.env.old"] [unique_id "apK9BiJcY4fy7tP-rU3sxAAAAmM"] [Sat Aug 29 05:05:42.452854 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.184.117:20243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/config.php"] [unique_id "apK9BiJcY4fy7tP-rU3sxgAAAoc"] [Sat Aug 29 05:05:42.457175 2026] [core:error] [pid 1017536:tid 1017765] [client 158.23.184.117:7255] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.457190 2026] [core:error] [pid 1017536:tid 1017765] [client 158.23.184.117:7255] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.460937 2026] [autoindex:error] [pid 1017536:tid 1017587] [remote 45.148.10.62:50840] AH01276: Cannot serve directory /home3/vzofmemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:42.464753 2026] [security2:error] [pid 1017536:tid 1017694] [client 4.205.62.107:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/fraro.php"] [unique_id "apK9BiJcY4fy7tP-rU3s3gAAAjA"] [Sat Aug 29 05:05:42.467026 2026] [security2:error] [pid 1017536:tid 1017747] [client 4.232.148.111:34890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-admin/css/about.php"] [unique_id "apK9BiJcY4fy7tP-rU3s3wAAAmU"] [Sat Aug 29 05:05:42.489159 2026] [security2:error] [pid 1017536:tid 1017754] [client 158.23.147.79:24507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/lock.php"] [unique_id "apK9BiJcY4fy7tP-rU3s4AAAAmw"] [Sat Aug 29 05:05:42.501939 2026] [security2:error] [pid 1017536:tid 1017669] [client 111.235.68.106:56102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9BiJcY4fy7tP-rU3s4QAAAhc"] [Sat Aug 29 05:05:42.502034 2026] [security2:error] [pid 1017536:tid 1017669] [client 111.235.68.106:56102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9BiJcY4fy7tP-rU3s4QAAAhc"] [Sat Aug 29 05:05:42.509617 2026] [security2:error] [pid 1017536:tid 1017724] [client 4.205.62.107:2644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/koiy.php"] [unique_id "apK9BiJcY4fy7tP-rU3s4gAAAk4"] [Sat Aug 29 05:05:42.513998 2026] [security2:error] [pid 1017536:tid 1017548] [remote 52.167.144.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9BiJcY4fy7tP-rU3s4wACSgs"] [Sat Aug 29 05:05:42.515391 2026] [security2:error] [pid 1017536:tid 1017764] [client 168.107.94.195:61046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9BiJcY4fy7tP-rU3s5AAAAnY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:42.527955 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.48.251.3:28509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/time.php"] [unique_id "apK9BjAh5Y1i2tUxg4HliQAABio"] [Sat Aug 29 05:05:42.541386 2026] [security2:error] [pid 1017536:tid 1017670] [client 158.158.54.35:10838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/deepseek_d.php"] [unique_id "apK9BiJcY4fy7tP-rU3s5gAAAhg"] [Sat Aug 29 05:05:42.542018 2026] [core:error] [pid 1018003:tid 1018187] [client 74.248.24.12:34180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.542028 2026] [core:error] [pid 1018003:tid 1018187] [client 74.248.24.12:34180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.579868 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.184.117:28387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/0x.php"] [unique_id "apK9BiJcY4fy7tP-rU3s5wAAAls"] [Sat Aug 29 05:05:42.593597 2026] [security2:error] [pid 1017536:tid 1017774] [client 20.196.209.81:18734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/options-general.php"] [unique_id "apK9BiJcY4fy7tP-rU3s6AAAAoA"] [Sat Aug 29 05:05:42.600378 2026] [security2:error] [pid 1018003:tid 1018172] [client 158.23.184.117:20256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/core.php"] [unique_id "apK9BjAh5Y1i2tUxg4HliwAABc0"] [Sat Aug 29 05:05:42.602438 2026] [security2:error] [pid 1017536:tid 1017755] [client 158.23.184.117:7240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/Requests/Exception/file.php"] [unique_id "apK9BiJcY4fy7tP-rU3s6QAAAm0"] [Sat Aug 29 05:05:42.618339 2026] [security2:error] [pid 1017536:tid 1017721] [client 40.83.93.50:7794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/wp-contentt.php"] [unique_id "apK9BiJcY4fy7tP-rU3s7AAAAks"] [Sat Aug 29 05:05:42.640343 2026] [security2:error] [pid 1017536:tid 1017768] [client 68.155.159.216:51418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-login.php"] [unique_id "apK9BiJcY4fy7tP-rU3s7wAAAno"] [Sat Aug 29 05:05:42.659460 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.48.251.3:28506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/doc.php"] [unique_id "apK9BjAh5Y1i2tUxg4HljAAABhE"] [Sat Aug 29 05:05:42.661530 2026] [security2:error] [pid 1018003:tid 1018211] [client 20.63.219.114:15556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/OK.php"] [unique_id "apK9BjAh5Y1i2tUxg4HljQAABfQ"] [Sat Aug 29 05:05:42.710126 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.48.251.3:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/xp.php"] [unique_id "apK9BiJcY4fy7tP-rU3s8wAAAiI"] [Sat Aug 29 05:05:42.713303 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.196.209.81:12684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/ggfi.php"] [unique_id "apK9BjAh5Y1i2tUxg4HljwAABfY"] [Sat Aug 29 05:05:42.725603 2026] [security2:error] [pid 1017536:tid 1017782] [client 158.23.184.117:27656] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.kozo.com.mx"] [uri "/1.php"] [unique_id "apK9BiJcY4fy7tP-rU3s9QAAAog"] [Sat Aug 29 05:05:42.725689 2026] [security2:error] [pid 1017536:tid 1017782] [client 158.23.184.117:27656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/1.php"] [unique_id "apK9BiJcY4fy7tP-rU3s9QAAAog"] [Sat Aug 29 05:05:42.729291 2026] [security2:error] [pid 1018003:tid 1018195] [client 4.205.62.107:53365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/brc.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlkAAABeQ"] [Sat Aug 29 05:05:42.748921 2026] [core:error] [pid 1017536:tid 1017793] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.748934 2026] [core:error] [pid 1017536:tid 1017793] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.750533 2026] [core:error] [pid 1018003:tid 1018154] [client 158.23.184.117:7170] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.750548 2026] [core:error] [pid 1018003:tid 1018154] [client 158.23.184.117:7170] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:42.754230 2026] [security2:error] [pid 1017536:tid 1017779] [client 158.23.184.117:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/data.php"] [unique_id "apK9BiJcY4fy7tP-rU3s-AAAAoU"] [Sat Aug 29 05:05:42.754260 2026] [security2:error] [pid 1017536:tid 1017696] [client 45.148.10.62:50838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wagnerfarmscbd.com"] [uri "/.env.php.bak"] [unique_id "apK9BiJcY4fy7tP-rU3s9wAAAjI"] [Sat Aug 29 05:05:42.790930 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.48.251.3:28496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/classsmtps.php"] [unique_id "apK9BiJcY4fy7tP-rU3s-gAAAns"] [Sat Aug 29 05:05:42.792123 2026] [security2:error] [pid 1018003:tid 1018184] [client 68.155.159.216:40352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlkgAABdk"] [Sat Aug 29 05:05:42.834002 2026] [security2:error] [pid 1018003:tid 1018048] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/staging/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HllAAGMxs"] [Sat Aug 29 05:05:42.834026 2026] [security2:error] [pid 1018003:tid 1018044] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/docker/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HllgAGMxc"] [Sat Aug 29 05:05:42.834026 2026] [security2:error] [pid 1018003:tid 1018049] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/apps/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HlkwAGMxw"] [Sat Aug 29 05:05:42.834086 2026] [security2:error] [pid 1018003:tid 1018047] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/v2/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HllQAGMxo"] [Sat Aug 29 05:05:42.834792 2026] [security2:error] [pid 1018003:tid 1018049] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/v1/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HllwAGMxw"] [Sat Aug 29 05:05:42.835540 2026] [security2:error] [pid 1018003:tid 1018040] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/production/.env"] [unique_id "apK9BjAh5Y1i2tUxg4HlmAAGMxM"] [Sat Aug 29 05:05:42.868230 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:28371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/10.php"] [unique_id "apK9BiJcY4fy7tP-rU3s_AAAAjE"] [Sat Aug 29 05:05:42.894632 2026] [security2:error] [pid 1017536:tid 1017693] [client 158.23.184.117:7237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-admin/add.php"] [unique_id "apK9BiJcY4fy7tP-rU3s_gAAAi8"] [Sat Aug 29 05:05:42.895649 2026] [security2:error] [pid 1018003:tid 1018245] [client 168.107.94.195:61437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlmgAABhU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:42.903422 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.184.117:57609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/db-status.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlnAAABbk"] [Sat Aug 29 05:05:42.916616 2026] [security2:error] [pid 1017536:tid 1017604] [remote 45.148.10.62:50840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vzo.fme.mybluehost.me"] [uri "/wp-login.php"] [unique_id "apK9BiJcY4fy7tP-rU3tAQACUkM"] [Sat Aug 29 05:05:42.930498 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.48.251.3:28468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/cache-compat.php"] [unique_id "apK9BjAh5Y1i2tUxg4HlngAABc8"] [Sat Aug 29 05:05:42.935302 2026] [security2:error] [pid 1018003:tid 1018169] [client 114.119.148.56:48933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_info.php/cPath/8/products_id/1004/osCsid/hebmei56nknjf1vva0bovlcne6"] [unique_id "apK9BjAh5Y1i2tUxg4HloAAABco"], referer: http://www.classiclightingusa.com/catalog/index.php/cPath/8/osCsid/hebmei56nknjf1vva0bovlcne6 [Sat Aug 29 05:05:42.941697 2026] [security2:error] [pid 1017536:tid 1017730] [client 4.232.148.111:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/system_log.php"] [unique_id "apK9BiJcY4fy7tP-rU3tAgAAAlQ"] [Sat Aug 29 05:05:42.990469 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.196.209.81:17092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/options.php"] [unique_id "apK9BiJcY4fy7tP-rU3tAwAAAms"] [Sat Aug 29 05:05:43.009303 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.147.79:50149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/goat1.php"] [unique_id "apK9ByJcY4fy7tP-rU3tBAAAAlo"] [Sat Aug 29 05:05:43.013199 2026] [security2:error] [pid 1018003:tid 1018236] [client 158.23.184.117:27687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/100.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlogAABgw"] [Sat Aug 29 05:05:43.025188 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.63.219.114:1221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.coveryourauto.com"] [uri "/aaa.php"] [unique_id "apK9ByJcY4fy7tP-rU3tBQAAAkk"] [Sat Aug 29 05:05:43.039786 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.184.117:7310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/assets/about.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlowAABiY"] [Sat Aug 29 05:05:43.055315 2026] [security2:error] [pid 1018003:tid 1018050] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/env.bak"] [unique_id "apK9BzAh5Y1i2tUxg4HlpAAF_h0"] [Sat Aug 29 05:05:43.059692 2026] [security2:error] [pid 1018003:tid 1018205] [client 158.23.184.117:20042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/f35.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlpQAABe4"] [Sat Aug 29 05:05:43.061847 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.251.3:28461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/aws_keys.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlpwAABcs"] [Sat Aug 29 05:05:43.073963 2026] [security2:error] [pid 1018003:tid 1018150] [client 34.12.38.134:16536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/terraform.tfstate"] [unique_id "apK9BzAh5Y1i2tUxg4HlrAAABbc"] [Sat Aug 29 05:05:43.074600 2026] [core:error] [pid 1017536:tid 1017667] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.074615 2026] [core:error] [pid 1017536:tid 1017667] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.076583 2026] [security2:error] [pid 1018003:tid 1018051] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/site/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HlrQAGEh4"] [Sat Aug 29 05:05:43.078510 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.49.130:57472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/crgio.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlrgAABjU"] [Sat Aug 29 05:05:43.090239 2026] [core:error] [pid 1018003:tid 1018193] [client 34.12.38.134:16616] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.090254 2026] [core:error] [pid 1018003:tid 1018193] [client 34.12.38.134:16616] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.096530 2026] [security2:error] [pid 1018003:tid 1018267] [client 34.12.38.134:16646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HlsQAABis"] [Sat Aug 29 05:05:43.099925 2026] [core:error] [pid 1017536:tid 1017761] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.099938 2026] [core:error] [pid 1017536:tid 1017761] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.104730 2026] [security2:error] [pid 1017536:tid 1017742] [client 158.23.147.79:30683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/file88.php"] [unique_id "apK9ByJcY4fy7tP-rU3tDwAAAmA"] [Sat Aug 29 05:05:43.105366 2026] [security2:error] [pid 1018003:tid 1018261] [client 74.248.24.12:5254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9BzAh5Y1i2tUxg4HltAAABiU"] [Sat Aug 29 05:05:43.105694 2026] [core:error] [pid 1018003:tid 1018203] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.105702 2026] [core:error] [pid 1018003:tid 1018203] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.106870 2026] [core:error] [pid 1018003:tid 1018215] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.106881 2026] [core:error] [pid 1018003:tid 1018215] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.109061 2026] [security2:error] [pid 1018003:tid 1018043] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/old/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HltQAGJBY"] [Sat Aug 29 05:05:43.109072 2026] [security2:error] [pid 1018003:tid 1018199] [client 34.12.38.134:16562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HltgAABeg"] [Sat Aug 29 05:05:43.111025 2026] [security2:error] [pid 1018003:tid 1018054] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/.docker/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HltwAGIiE"] [Sat Aug 29 05:05:43.111064 2026] [security2:error] [pid 1018003:tid 1018222] [client 34.12.38.134:16556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HluAAABf8"] [Sat Aug 29 05:05:43.111811 2026] [security2:error] [pid 1018003:tid 1018053] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/env.old"] [unique_id "apK9BzAh5Y1i2tUxg4HluQAGIiA"] [Sat Aug 29 05:05:43.114276 2026] [security2:error] [pid 1018003:tid 1018231] [client 34.12.38.134:16610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/email/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HlugAABgc"] [Sat Aug 29 05:05:43.117189 2026] [core:error] [pid 1017536:tid 1017688] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.117202 2026] [core:error] [pid 1017536:tid 1017688] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.117738 2026] [security2:error] [pid 1018003:tid 1018055] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/portal/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HluwAF5SI"] [Sat Aug 29 05:05:43.123203 2026] [core:error] [pid 1018003:tid 1018161] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.123216 2026] [core:error] [pid 1018003:tid 1018161] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.123347 2026] [security2:error] [pid 1018003:tid 1018274] [client 158.158.54.35:9423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlvwAABjI"] [Sat Aug 29 05:05:43.132074 2026] [security2:error] [pid 1018003:tid 1018159] [client 34.12.38.134:16606] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/mail/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HlwAAABcA"] [Sat Aug 29 05:05:43.132430 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.196.209.81:10694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/alfa-rex.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlwQAABhQ"] [Sat Aug 29 05:05:43.135561 2026] [security2:error] [pid 1018003:tid 1018185] [client 34.12.38.134:16588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.skarchfrutale.com"] [uri "/___proxy_subdomain_cpcontacts/sendgrid/.env"] [unique_id "apK9BzAh5Y1i2tUxg4HlwgAABdo"] [Sat Aug 29 05:05:43.138647 2026] [core:error] [pid 1018003:tid 1018192] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.138657 2026] [core:error] [pid 1018003:tid 1018192] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.157339 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.184.117:28403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/2.php"] [unique_id "apK9ByJcY4fy7tP-rU3tEgAAAh0"] [Sat Aug 29 05:05:43.162271 2026] [core:error] [pid 1017536:tid 1017715] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.162289 2026] [core:error] [pid 1017536:tid 1017715] [client 34.12.38.134:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.166382 2026] [security2:error] [pid 1018003:tid 1018056] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/api/.env.bak"] [unique_id "apK9BzAh5Y1i2tUxg4HlxQAF8iM"] [Sat Aug 29 05:05:43.179593 2026] [security2:error] [pid 1018003:tid 1018278] [client 158.23.147.79:30611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/NewFile.php/"] [unique_id "apK9BzAh5Y1i2tUxg4HlxwAABjY"] [Sat Aug 29 05:05:43.185494 2026] [security2:error] [pid 1018003:tid 1018151] [client 158.23.184.117:7358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-content/themes/twentytwentythree.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlyAAABbg"] [Sat Aug 29 05:05:43.192432 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.48.251.3:27177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/umgebung.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlyQAABd4"] [Sat Aug 29 05:05:43.205472 2026] [security2:error] [pid 1017536:tid 1017710] [client 158.23.184.117:20277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK9ByJcY4fy7tP-rU3tFAAAAkA"] [Sat Aug 29 05:05:43.213673 2026] [security2:error] [pid 1017536:tid 1017776] [client 40.83.93.50:3197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/theme.php"] [unique_id "apK9ByJcY4fy7tP-rU3tFQAAAoI"] [Sat Aug 29 05:05:43.235518 2026] [security2:error] [pid 1018003:tid 1018173] [client 4.205.62.107:61774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/cu.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlywAABc4"] [Sat Aug 29 05:05:43.254292 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.184.117:7299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/update/da222.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlzgAABiA"] [Sat Aug 29 05:05:43.260150 2026] [security2:error] [pid 1017536:tid 1017775] [client 68.155.159.216:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/admin.php"] [unique_id "apK9ByJcY4fy7tP-rU3tFwAAAoE"] [Sat Aug 29 05:05:43.274056 2026] [security2:error] [pid 1018003:tid 1018172] [client 168.107.94.195:61770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9BzAh5Y1i2tUxg4HlzwAABc0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:43.279926 2026] [security2:error] [pid 1018003:tid 1018241] [client 68.155.159.216:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl0AAABhE"] [Sat Aug 29 05:05:43.288609 2026] [security2:error] [pid 1018003:tid 1018251] [client 45.148.10.62:50842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wagnerfarmscbd.com"] [uri "/.env.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl0QAABhs"] [Sat Aug 29 05:05:43.298924 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.184.117:28386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/222.php"] [unique_id "apK9ByJcY4fy7tP-rU3tGgAAAkM"] [Sat Aug 29 05:05:43.320810 2026] [security2:error] [pid 1018003:tid 1018062] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/.env.production.bak"] [unique_id "apK9BzAh5Y1i2tUxg4Hl0wAGKCk"] [Sat Aug 29 05:05:43.321226 2026] [security2:error] [pid 1017536:tid 1017738] [client 20.48.251.3:28436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/old_phpinfo.php"] [unique_id "apK9ByJcY4fy7tP-rU3tGwAAAlw"] [Sat Aug 29 05:05:43.350839 2026] [security2:error] [pid 1017536:tid 1017684] [client 158.23.184.117:20273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/home.php"] [unique_id "apK9ByJcY4fy7tP-rU3tHQAAAiY"] [Sat Aug 29 05:05:43.364234 2026] [security2:error] [pid 1018003:tid 1018220] [client 20.48.251.3:14314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/g3.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl1gAABf0"] [Sat Aug 29 05:05:43.369939 2026] [core:error] [pid 1017536:tid 1017698] [client 158.23.184.117:7336] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.369953 2026] [core:error] [pid 1017536:tid 1017698] [client 158.23.184.117:7336] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:43.384185 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.196.209.81:17046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/panel.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl2AAABgo"] [Sat Aug 29 05:05:43.403899 2026] [security2:error] [pid 1018003:tid 1018225] [client 4.232.148.111:8427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/24.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl3AAABgI"] [Sat Aug 29 05:05:43.411914 2026] [security2:error] [pid 1018003:tid 1018165] [client 158.23.184.117:53558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/xmr.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl3QAABcY"] [Sat Aug 29 05:05:43.442010 2026] [security2:error] [pid 1017536:tid 1017784] [client 158.23.184.117:51983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/24.php"] [unique_id "apK9ByJcY4fy7tP-rU3tIQAAAoo"] [Sat Aug 29 05:05:43.450566 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.48.251.3:57896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.fasthavoc.net"] [uri "/wp-act.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl3wAABgk"] [Sat Aug 29 05:05:43.461019 2026] [security2:error] [pid 1018003:tid 1018190] [client 158.23.147.79:25586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl4AAABd8"] [Sat Aug 29 05:05:43.482869 2026] [security2:error] [pid 1018003:tid 1018202] [client 68.155.159.216:14205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-blog-header.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl4gAABes"] [Sat Aug 29 05:05:43.497892 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.184.117:20227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/index.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl4wAABfU"] [Sat Aug 29 05:05:43.511809 2026] [security2:error] [pid 1017536:tid 1017782] [client 68.155.159.216:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9ByJcY4fy7tP-rU3tIgAAAog"] [Sat Aug 29 05:05:43.517608 2026] [security2:error] [pid 1017536:tid 1017700] [client 158.23.184.117:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-content/languages/themes/num.php"] [unique_id "apK9ByJcY4fy7tP-rU3tIwAAAjY"] [Sat Aug 29 05:05:43.529196 2026] [security2:error] [pid 1018003:tid 1018205] [client 20.104.49.130:51129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/xmini4.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl5AAABe4"] [Sat Aug 29 05:05:43.531591 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.196.209.81:12710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/cookie.php"] [unique_id "apK9ByJcY4fy7tP-rU3tJAAAAj4"] [Sat Aug 29 05:05:43.534424 2026] [security2:error] [pid 1017536:tid 1017793] [client 4.205.62.107:21885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/avim.php"] [unique_id "apK9ByJcY4fy7tP-rU3tJQAAApM"] [Sat Aug 29 05:05:43.558490 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.184.117:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl5QAABiY"] [Sat Aug 29 05:05:43.579164 2026] [security2:error] [pid 1017536:tid 1017685] [client 4.205.62.107:21601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/aww.php"] [unique_id "apK9ByJcY4fy7tP-rU3tJwAAAic"] [Sat Aug 29 05:05:43.587439 2026] [security2:error] [pid 1017536:tid 1017779] [client 158.23.184.117:28393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/3pjcpmfsd8b.php"] [unique_id "apK9ByJcY4fy7tP-rU3tKAAAAoU"] [Sat Aug 29 05:05:43.598524 2026] [security2:error] [pid 1017536:tid 1017752] [client 4.205.62.107:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/thui.php"] [unique_id "apK9ByJcY4fy7tP-rU3tKQAAAmo"] [Sat Aug 29 05:05:43.603495 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.251.3:14310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-konfig.php"] [unique_id "apK9ByJcY4fy7tP-rU3tKwAAAnk"] [Sat Aug 29 05:05:43.612747 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.23.147.79:24472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/index/function.php"] [unique_id "apK9ByJcY4fy7tP-rU3tLAAAAos"] [Sat Aug 29 05:05:43.630495 2026] [security2:error] [pid 1018003:tid 1018089] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/@fs/root/.env"] [unique_id "apK9BzAh5Y1i2tUxg4Hl5wAF1UQ"] [Sat Aug 29 05:05:43.633012 2026] [security2:error] [pid 1018003:tid 1018065] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/.env.prod.bak"] [unique_id "apK9BzAh5Y1i2tUxg4Hl6AAGKyw"] [Sat Aug 29 05:05:43.638012 2026] [security2:error] [pid 1018003:tid 1018022] [remote 34.148.90.28:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/@fs/.env"] [unique_id "apK9BzAh5Y1i2tUxg4Hl6QAGJQE"] [Sat Aug 29 05:05:43.643428 2026] [security2:error] [pid 1017536:tid 1017550] [remote 173.252.82.19:60270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villagebooksandbears.com"] [uri "/market/index.php"] [unique_id "apK9ByJcY4fy7tP-rU3tKgACMg0"] [Sat Aug 29 05:05:43.643589 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.184.117:20277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/login.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl6gAABhY"] [Sat Aug 29 05:05:43.649679 2026] [security2:error] [pid 1017536:tid 1017725] [client 4.205.62.107:2926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/test1.php"] [unique_id "apK9ByJcY4fy7tP-rU3tLQAAAk8"] [Sat Aug 29 05:05:43.653322 2026] [security2:error] [pid 1017536:tid 1017750] [client 168.107.94.195:62046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ByJcY4fy7tP-rU3tLgAAAmg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:43.679039 2026] [security2:error] [pid 1017536:tid 1017703] [client 158.23.184.117:53543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp.php"] [unique_id "apK9ByJcY4fy7tP-rU3tLwAAAjk"] [Sat Aug 29 05:05:43.700063 2026] [security2:error] [pid 1017536:tid 1017680] [client 74.248.24.12:23856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/num.php"] [unique_id "apK9ByJcY4fy7tP-rU3tMAAAAiI"] [Sat Aug 29 05:05:43.703716 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.158.54.35:6956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "apK9ByJcY4fy7tP-rU3tMQAAAjs"] [Sat Aug 29 05:05:43.703763 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.184.117:53534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/wp-act.php"] [unique_id "apK9ByJcY4fy7tP-rU3tMgAAAkc"] [Sat Aug 29 05:05:43.722739 2026] [security2:error] [pid 1018003:tid 1018243] [client 40.83.93.50:7787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/alumni_reg.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl7AAABhM"] [Sat Aug 29 05:05:43.734369 2026] [security2:error] [pid 1018003:tid 1018164] [client 158.23.184.117:28397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kozo.com.mx"] [uri "/403.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl7QAABcU"] [Sat Aug 29 05:05:43.781270 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.196.209.81:17102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/pk.php"] [unique_id "apK9ByJcY4fy7tP-rU3tNAAAAhw"] [Sat Aug 29 05:05:43.788462 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.184.117:20224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/logs233/index.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl7gAABec"] [Sat Aug 29 05:05:43.808616 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.48.251.3:14305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/25.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl7wAABgE"] [Sat Aug 29 05:05:43.822883 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.184.117:7291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/xmlrpc.php"] [unique_id "apK9ByJcY4fy7tP-rU3tNgAAAj0"] [Sat Aug 29 05:05:43.855681 2026] [security2:error] [pid 1018003:tid 1018181] [client 158.23.184.117:53512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/fff.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl8wAABdY"] [Sat Aug 29 05:05:43.919836 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.49.130:57719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/33.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl9wAABdg"] [Sat Aug 29 05:05:43.929574 2026] [security2:error] [pid 1018003:tid 1018244] [client 68.155.159.216:64876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/packed.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl-AAABhQ"] [Sat Aug 29 05:05:43.932001 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.196.209.81:21091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/NewFile.php"] [unique_id "apK9ByJcY4fy7tP-rU3tOAAAAms"] [Sat Aug 29 05:05:43.937728 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.23.184.117:57613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/maintenance.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl-QAABcI"] [Sat Aug 29 05:05:43.939585 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.48.251.3:33343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/nlnub.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl-gAABdo"] [Sat Aug 29 05:05:43.943976 2026] [security2:error] [pid 1018003:tid 1018186] [client 4.205.62.107:53392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/4563.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl-wAABds"] [Sat Aug 29 05:05:43.970756 2026] [security2:error] [pid 1018003:tid 1018159] [client 158.23.184.117:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/app.php"] [unique_id "apK9BzAh5Y1i2tUxg4Hl_AAABcA"] [Sat Aug 29 05:05:44.004487 2026] [security2:error] [pid 1018003:tid 1018197] [client 158.23.184.117:7284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9CDAh5Y1i2tUxg4Hl_QAABeY"] [Sat Aug 29 05:05:44.033638 2026] [security2:error] [pid 1017536:tid 1017688] [client 168.107.94.195:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9CCJcY4fy7tP-rU3tOgAAAio"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:44.044459 2026] [security2:error] [pid 1018003:tid 1018249] [client 4.232.148.111:27502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9CDAh5Y1i2tUxg4Hl_gAABhk"] [Sat Aug 29 05:05:44.057485 2026] [security2:error] [pid 1018003:tid 1018045] [remote 34.148.90.28:50036] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "hitechgs.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9CDAh5Y1i2tUxg4HmAgAGBBg"] [Sat Aug 29 05:05:44.080339 2026] [security2:error] [pid 1017536:tid 1017783] [client 158.23.184.117:20287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/min.php"] [unique_id "apK9CCJcY4fy7tP-rU3tOwAAAok"] [Sat Aug 29 05:05:44.115586 2026] [security2:error] [pid 1017536:tid 1017694] [client 158.23.184.117:7289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/aaa.php"] [unique_id "apK9CCJcY4fy7tP-rU3tPQAAAjA"] [Sat Aug 29 05:05:44.145244 2026] [security2:error] [pid 1017536:tid 1017720] [client 158.158.54.35:15933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/assets/images/doc.php"] [unique_id "apK9CCJcY4fy7tP-rU3tPwAAAko"] [Sat Aug 29 05:05:44.149868 2026] [security2:error] [pid 1017536:tid 1017723] [client 158.23.184.117:7353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/robots.php"] [unique_id "apK9CCJcY4fy7tP-rU3tQAAAAk0"] [Sat Aug 29 05:05:44.176449 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.196.209.81:18736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmBAAABc4"] [Sat Aug 29 05:05:44.176863 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.251.3:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/mga.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmBQAABh8"] [Sat Aug 29 05:05:44.200876 2026] [security2:error] [pid 1018003:tid 1018195] [client 158.23.147.79:48243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/themes/too.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmBwAABeQ"] [Sat Aug 29 05:05:44.205249 2026] [security2:error] [pid 1017536:tid 1017684] [client 158.23.147.79:30636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/dropdown.php"] [unique_id "apK9CCJcY4fy7tP-rU3tQgAAAiY"] [Sat Aug 29 05:05:44.223836 2026] [security2:error] [pid 1018003:tid 1018220] [client 158.23.147.79:50065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmCAAABf0"] [Sat Aug 29 05:05:44.226346 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.184.117:20282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/module.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmCQAABfY"] [Sat Aug 29 05:05:44.272173 2026] [core:error] [pid 1017536:tid 1017698] [client 158.23.184.117:53518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:44.272192 2026] [core:error] [pid 1017536:tid 1017698] [client 158.23.184.117:53518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:44.294257 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.104.49.130:57627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/az.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmCgAABhU"] [Sat Aug 29 05:05:44.300074 2026] [security2:error] [pid 1018003:tid 1018160] [client 158.23.184.117:53515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/.well-known/install.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmCwAABcE"] [Sat Aug 29 05:05:44.312185 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:30565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/index.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmEgAABb4"] [Sat Aug 29 05:05:44.326115 2026] [security2:error] [pid 1018003:tid 1018187] [client 40.83.93.50:3163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/colors.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmFAAABdw"] [Sat Aug 29 05:05:44.348871 2026] [security2:error] [pid 1018003:tid 1018174] [client 66.248.203.2:49312] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2020/02/15/"] [unique_id "apK9CDAh5Y1i2tUxg4HmFgAABc8"] [Sat Aug 29 05:05:44.358888 2026] [security2:error] [pid 1018003:tid 1018154] [client 20.196.209.81:12729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/config.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmFwAABbs"] [Sat Aug 29 05:05:44.367194 2026] [security2:error] [pid 1017536:tid 1017679] [client 68.155.159.216:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9CCJcY4fy7tP-rU3tRQAAAiE"] [Sat Aug 29 05:05:44.369094 2026] [security2:error] [pid 1018003:tid 1018271] [client 4.205.62.107:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/services.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmGAAABi8"] [Sat Aug 29 05:05:44.374822 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.184.117:20251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/options.php"] [unique_id "apK9CCJcY4fy7tP-rU3tRgAAAho"] [Sat Aug 29 05:05:44.387297 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:12138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/images/about.php"] [unique_id "apK9CCJcY4fy7tP-rU3tRwAAAjo"] [Sat Aug 29 05:05:44.401261 2026] [core:error] [pid 1018003:tid 1018217] [client 74.248.24.12:31575] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:44.401277 2026] [core:error] [pid 1018003:tid 1018217] [client 74.248.24.12:31575] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:44.413978 2026] [security2:error] [pid 1018003:tid 1018170] [client 168.107.94.195:62732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmGgAABcs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:44.418574 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.23.184.117:7308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/hehe.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmGwAABdI"] [Sat Aug 29 05:05:44.445776 2026] [core:error] [pid 1018003:tid 1018205] [client 158.23.184.117:8111] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:44.445793 2026] [core:error] [pid 1018003:tid 1018205] [client 158.23.184.117:8111] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:44.489110 2026] [security2:error] [pid 1017536:tid 1017610] [remote 34.148.90.28:50048] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "hitechgs.com"] [uri "/_image"] [unique_id "apK9CCJcY4fy7tP-rU3tSwACJ0k"] [Sat Aug 29 05:05:44.490269 2026] [security2:error] [pid 1017536:tid 1017600] [remote 34.148.90.28:50048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:href. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:href"] [severity "CRITICAL"] [hostname "hitechgs.com"] [uri "/_image"] [unique_id "apK9CCJcY4fy7tP-rU3tTAACJz8"] [Sat Aug 29 05:05:44.519158 2026] [security2:error] [pid 1018003:tid 1018091] [remote 216.73.216.199:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortthru.com"] [uri "/public_html/Luna-Conference-2013-old/wp-content/mu-plugins/prime-sentinel-tag.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmLAAGNUY"] [Sat Aug 29 05:05:44.553829 2026] [security2:error] [pid 1017536:tid 1017752] [client 158.23.184.117:20248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/panel.php"] [unique_id "apK9CCJcY4fy7tP-rU3tTgAAAmo"] [Sat Aug 29 05:05:44.569159 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.196.209.81:17028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK9CCJcY4fy7tP-rU3tTwAAAkQ"] [Sat Aug 29 05:05:44.573860 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.147.79:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/makeasmtp.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmLgAABiU"] [Sat Aug 29 05:05:44.591450 2026] [security2:error] [pid 1018003:tid 1018242] [client 158.158.54.35:9410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/bgymj.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmLwAABhI"] [Sat Aug 29 05:05:44.592324 2026] [security2:error] [pid 1018003:tid 1018180] [client 158.23.184.117:7256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/wp-admin/about.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmMAAABdU"] [Sat Aug 29 05:05:44.595296 2026] [security2:error] [pid 1017536:tid 1017712] [client 45.148.10.62:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wagnerfarmscbd.com"] [uri "/wp-config.php"] [unique_id "apK9CCJcY4fy7tP-rU3tUAAAAkI"] [Sat Aug 29 05:05:44.620177 2026] [security2:error] [pid 1017536:tid 1017769] [client 68.155.159.216:57359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/nf_tracking.php"] [unique_id "apK9CCJcY4fy7tP-rU3tUQAAAns"] [Sat Aug 29 05:05:44.631017 2026] [security2:error] [pid 1017536:tid 1017748] [client 68.155.159.216:14241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9CCJcY4fy7tP-rU3tUgAAAmY"] [Sat Aug 29 05:05:44.648346 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.184.117:7262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-includes/PHPMailer.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmNgAABew"] [Sat Aug 29 05:05:44.669440 2026] [security2:error] [pid 1018003:tid 1018198] [client 4.205.62.107:21623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/file21.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmOQAABec"] [Sat Aug 29 05:05:44.677673 2026] [security2:error] [pid 1017536:tid 1017706] [client 87.219.197.128:51366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9CCJcY4fy7tP-rU3tUwAAAjw"] [Sat Aug 29 05:05:44.677826 2026] [security2:error] [pid 1017536:tid 1017706] [client 87.219.197.128:51366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9CCJcY4fy7tP-rU3tUwAAAjw"] [Sat Aug 29 05:05:44.701464 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.184.117:20285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmOwAABew"] [Sat Aug 29 05:05:44.716204 2026] [security2:error] [pid 1017536:tid 1017674] [client 4.205.62.107:22233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/sgd.php"] [unique_id "apK9CCJcY4fy7tP-rU3tVQAAAhw"] [Sat Aug 29 05:05:44.731115 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.147.79:24561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/.well-known/content.php"] [unique_id "apK9CCJcY4fy7tP-rU3tVwAAAj0"] [Sat Aug 29 05:05:44.732562 2026] [security2:error] [pid 1017536:tid 1017719] [client 4.205.62.107:65415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/lala.php"] [unique_id "apK9CCJcY4fy7tP-rU3tWAAAAkk"] [Sat Aug 29 05:05:44.740056 2026] [security2:error] [pid 1018003:tid 1018244] [client 158.23.184.117:7267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/wp-content/backup.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmQAAABhQ"] [Sat Aug 29 05:05:44.741935 2026] [security2:error] [pid 1017536:tid 1017667] [client 68.155.159.216:51248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9CCJcY4fy7tP-rU3tWQAAAhU"] [Sat Aug 29 05:05:44.776726 2026] [security2:error] [pid 1018003:tid 1018234] [client 103.185.242.143:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmRwAABgo"] [Sat Aug 29 05:05:44.776843 2026] [security2:error] [pid 1018003:tid 1018234] [client 103.185.242.143:60158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmRwAABgo"] [Sat Aug 29 05:05:44.785509 2026] [security2:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/.env.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmSAAF4WQ"] [Sat Aug 29 05:05:44.786836 2026] [security2:error] [pid 1017536:tid 1017742] [client 4.205.62.107:3003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/lmfi2.php"] [unique_id "apK9CCJcY4fy7tP-rU3tWwAAAmA"] [Sat Aug 29 05:05:44.788174 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.196.209.81:12724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/22.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmSQAABek"] [Sat Aug 29 05:05:44.795020 2026] [security2:error] [pid 1017536:tid 1017726] [client 158.23.184.117:7258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "apK9CCJcY4fy7tP-rU3tXAAAAlA"] [Sat Aug 29 05:05:44.795443 2026] [security2:error] [pid 1017536:tid 1017733] [client 168.107.94.195:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9CCJcY4fy7tP-rU3tXQAAAlc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:44.803469 2026] [security2:error] [pid 1017536:tid 1017711] [client 34.7.216.49:46352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/api/graphql"] [unique_id "apK9CCJcY4fy7tP-rU3tXwAAAkE"] [Sat Aug 29 05:05:44.814737 2026] [security2:error] [pid 1017536:tid 1017789] [client 34.7.216.49:46424] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/.hermes/config.yaml"] [unique_id "apK9CCJcY4fy7tP-rU3tYgAAAo8"] [Sat Aug 29 05:05:44.819641 2026] [security2:error] [pid 1017536:tid 1017680] [client 34.7.216.49:46476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/awsConfig.js"] [unique_id "apK9CCJcY4fy7tP-rU3taQAAAiI"] [Sat Aug 29 05:05:44.850718 2026] [security2:error] [pid 1018003:tid 1018222] [client 4.232.148.111:32292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmXwAABf8"] [Sat Aug 29 05:05:44.850748 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.184.117:20226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/pki-validation/pl.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmXgAABbo"] [Sat Aug 29 05:05:44.885190 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.184.117:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/.well-known/aa.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmYAAABgc"] [Sat Aug 29 05:05:44.895886 2026] [security2:error] [pid 1017536:tid 1017788] [client 68.155.159.216:51847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/goat.php"] [unique_id "apK9CCJcY4fy7tP-rU3tbwAAAo4"] [Sat Aug 29 05:05:44.930410 2026] [core:error] [pid 1017536:tid 1017751] [client 74.248.24.12:30412] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:44.930438 2026] [core:error] [pid 1017536:tid 1017751] [client 74.248.24.12:30412] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:44.943714 2026] [security2:error] [pid 1018003:tid 1018223] [client 158.23.184.117:7268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/admin/alfa-rex.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmZwAABgA"] [Sat Aug 29 05:05:44.946120 2026] [security2:error] [pid 1017536:tid 1017745] [client 40.83.93.50:8062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/Js.php"] [unique_id "apK9CCJcY4fy7tP-rU3tcQAAAmM"] [Sat Aug 29 05:05:44.962665 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.196.209.81:17134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/security.php"] [unique_id "apK9CCJcY4fy7tP-rU3tcgAAAkY"] [Sat Aug 29 05:05:44.997489 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.184.117:57616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/pki-validation/x.php"] [unique_id "apK9CDAh5Y1i2tUxg4HmbAAABb0"] [Sat Aug 29 05:05:45.025257 2026] [security2:error] [pid 1017536:tid 1017731] [client 158.158.54.35:16694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9CSJcY4fy7tP-rU3tcwAAAlU"] [Sat Aug 29 05:05:45.032433 2026] [security2:error] [pid 1018003:tid 1018171] [client 158.23.184.117:53524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmcQAABcw"] [Sat Aug 29 05:05:45.045291 2026] [security2:error] [pid 1017536:tid 1017710] [client 68.155.159.216:61686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-content/packed.php"] [unique_id "apK9CSJcY4fy7tP-rU3tdAAAAkA"] [Sat Aug 29 05:05:45.075207 2026] [security2:error] [pid 1018003:tid 1018151] [client 45.148.10.62:38180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.wagnerfarmscbd.com"] [uri "/wp-config.php.old"] [unique_id "apK9CTAh5Y1i2tUxg4HmdQAABbg"] [Sat Aug 29 05:05:45.092840 2026] [security2:error] [pid 1018003:tid 1018269] [client 158.23.184.117:8105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/wp-content/export.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmdwAABi0"] [Sat Aug 29 05:05:45.110710 2026] [security2:error] [pid 1018003:tid 1018251] [client 4.205.62.107:53350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/lala.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmeQAABhs"] [Sat Aug 29 05:05:45.123532 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.48.251.3:13996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/xmy.php"] [unique_id "apK9CSJcY4fy7tP-rU3tdgAAAoY"] [Sat Aug 29 05:05:45.143647 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.23.184.117:57611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmfQAABho"] [Sat Aug 29 05:05:45.150177 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.49.130:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/new.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmfgAABeQ"] [Sat Aug 29 05:05:45.176697 2026] [security2:error] [pid 1017536:tid 1017672] [client 168.107.94.195:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9CSJcY4fy7tP-rU3teAAAAho"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:45.179028 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.184.117:7239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expressexecs.mikeycunningham.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9CSJcY4fy7tP-rU3teQAAAkM"] [Sat Aug 29 05:05:45.215761 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.196.209.81:4494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/bak.phps"] [unique_id "apK9CTAh5Y1i2tUxg4HmhgAABfc"] [Sat Aug 29 05:05:45.241212 2026] [security2:error] [pid 1017536:tid 1017772] [client 158.23.184.117:53559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cairnquartet.strangeworx.com"] [uri "/new.php"] [unique_id "apK9CSJcY4fy7tP-rU3tegAAAn4"] [Sat Aug 29 05:05:45.290665 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.184.117:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.supermachines.com"] [uri "/.well-known/security.php"] [unique_id "apK9CSJcY4fy7tP-rU3tfQAAAnw"] [Sat Aug 29 05:05:45.308675 2026] [security2:error] [pid 1018003:tid 1018233] [client 158.23.147.79:48239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/radio.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmkAAABgk"] [Sat Aug 29 05:05:45.311914 2026] [security2:error] [pid 1017536:tid 1017781] [client 68.155.159.216:24452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/file5.php"] [unique_id "apK9CSJcY4fy7tP-rU3tfwAAAoc"] [Sat Aug 29 05:05:45.313092 2026] [security2:error] [pid 1017536:tid 1017737] [client 4.232.148.111:18098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/num.php"] [unique_id "apK9CSJcY4fy7tP-rU3tgAAAAls"] [Sat Aug 29 05:05:45.315417 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.23.147.79:30596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9CSJcY4fy7tP-rU3tgQAAAmY"] [Sat Aug 29 05:05:45.326092 2026] [core:error] [pid 1018003:tid 1018245] [client 158.23.184.117:53538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:45.326119 2026] [core:error] [pid 1018003:tid 1018245] [client 158.23.184.117:53538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:45.360432 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.147.79:50128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmmAAABfA"] [Sat Aug 29 05:05:45.366027 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.196.209.81:17032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9CSJcY4fy7tP-rU3tiAAAApM"] [Sat Aug 29 05:05:45.409934 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.23.147.79:30605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/radio.php"] [unique_id "apK9CSJcY4fy7tP-rU3tiwAAAnM"] [Sat Aug 29 05:05:45.435897 2026] [security2:error] [pid 1017536:tid 1017764] [client 192.145.125.70:51600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK9CSJcY4fy7tP-rU3tjgAAAnY"] [Sat Aug 29 05:05:45.477807 2026] [security2:error] [pid 1017536:tid 1017694] [client 68.155.159.216:50257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9CSJcY4fy7tP-rU3tkwAAAjA"] [Sat Aug 29 05:05:45.482690 2026] [security2:error] [pid 1017536:tid 1017769] [client 40.83.93.50:7775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/access.php"] [unique_id "apK9CSJcY4fy7tP-rU3tlAAAAns"] [Sat Aug 29 05:05:45.489958 2026] [security2:error] [pid 1018003:tid 1018160] [client 74.248.24.12:27946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmpAAABcE"] [Sat Aug 29 05:05:45.503685 2026] [security2:error] [pid 1017536:tid 1017720] [client 68.155.159.216:12209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9CSJcY4fy7tP-rU3tlQAAAko"] [Sat Aug 29 05:05:45.510256 2026] [security2:error] [pid 1018003:tid 1018218] [client 4.205.62.107:64288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/filesystems.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmqAAABfs"] [Sat Aug 29 05:05:45.557783 2026] [security2:error] [pid 1018003:tid 1018170] [client 168.107.94.195:63994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmrAAABcs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:45.562751 2026] [security2:error] [pid 1018003:tid 1018206] [client 45.148.10.62:38188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wagnerfarmscbd.com"] [uri "/config.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmrQAABe8"] [Sat Aug 29 05:05:45.617712 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.196.209.81:21098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/install.php"] [unique_id "apK9CSJcY4fy7tP-rU3tlgAAAmg"] [Sat Aug 29 05:05:45.618799 2026] [security2:error] [pid 1017536:tid 1017703] [client 158.158.54.35:18407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-load.php"] [unique_id "apK9CSJcY4fy7tP-rU3tlwAAAjk"] [Sat Aug 29 05:05:45.667133 2026] [security2:error] [pid 1017536:tid 1017716] [client 68.155.159.216:18347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9CSJcY4fy7tP-rU3tmAAAAkY"] [Sat Aug 29 05:05:45.675697 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.147.79:25482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmugAABhY"] [Sat Aug 29 05:05:45.742939 2026] [security2:error] [pid 1017536:tid 1017710] [client 192.145.125.70:51616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.125.145.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "apK9CSJcY4fy7tP-rU3tmQAAAkA"] [Sat Aug 29 05:05:45.756673 2026] [security2:error] [pid 1017536:tid 1017679] [client 68.155.159.216:58323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wzy.php"] [unique_id "apK9CSJcY4fy7tP-rU3tmwAAAiE"] [Sat Aug 29 05:05:45.762405 2026] [security2:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/.wp-config.php.swp"] [unique_id "apK9CTAh5Y1i2tUxg4HmxQAF4SU"] [Sat Aug 29 05:05:45.762886 2026] [security2:error] [pid 1017536:tid 1017672] [client 68.155.159.216:14104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-admin/user/index.php"] [unique_id "apK9CSJcY4fy7tP-rU3tnAAAAho"] [Sat Aug 29 05:05:45.770760 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.196.209.81:17048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/system.php"] [unique_id "apK9CSJcY4fy7tP-rU3tngAAApI"] [Sat Aug 29 05:05:45.783525 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.48.251.3:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/ms-edit.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmyAAABek"] [Sat Aug 29 05:05:45.820615 2026] [security2:error] [pid 1018003:tid 1018254] [client 4.205.62.107:21592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wsws.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmzQAABh4"] [Sat Aug 29 05:05:45.842922 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.147.79:24568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/cong.php"] [unique_id "apK9CTAh5Y1i2tUxg4HmzwAABf8"] [Sat Aug 29 05:05:45.848224 2026] [security2:error] [pid 1018003:tid 1018164] [client 68.155.159.216:51465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9CTAh5Y1i2tUxg4Hm0QAABcU"] [Sat Aug 29 05:05:45.853736 2026] [security2:error] [pid 1017536:tid 1017772] [client 4.205.62.107:22338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/gecko-litespeed.php"] [unique_id "apK9CSJcY4fy7tP-rU3toQAAAn4"] [Sat Aug 29 05:05:45.868994 2026] [security2:error] [pid 1017536:tid 1017681] [client 4.205.62.107:65408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/public/bnn_.php.php"] [unique_id "apK9CSJcY4fy7tP-rU3togAAAiM"] [Sat Aug 29 05:05:45.919471 2026] [security2:error] [pid 1018003:tid 1018183] [client 34.21.253.104:54310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9CTAh5Y1i2tUxg4Hm2gAABdg"] [Sat Aug 29 05:05:45.934185 2026] [security2:error] [pid 1018003:tid 1018262] [client 34.21.253.104:54236] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/@fs/home/ubuntu/.anthropic/config.json"] [unique_id "apK9CTAh5Y1i2tUxg4Hm3gAABiY"] [Sat Aug 29 05:05:45.941631 2026] [security2:error] [pid 1018003:tid 1018197] [client 4.205.62.107:2524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/aws_sdk_settings.php"] [unique_id "apK9CTAh5Y1i2tUxg4Hm2wAABeY"] [Sat Aug 29 05:05:45.947447 2026] [security2:error] [pid 1017536:tid 1017667] [client 168.107.94.195:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9CSJcY4fy7tP-rU3tqgAAAhU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:45.953611 2026] [proxy_http:error] [pid 1018003:tid 1018265] (20014)Internal error (specific information not available): [client 34.21.253.104:54326] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:45.954472 2026] [proxy:error] [pid 1018003:tid 1018265] [client 34.21.253.104:54326] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@vite/env [Sat Aug 29 05:05:45.960585 2026] [security2:error] [pid 1017536:tid 1017608] [remote 104.219.248.116:33788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.248.219.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fellowsofmythgar.com"] [uri "/wp-login.php"] [unique_id "apK9CSJcY4fy7tP-rU3trAACf0c"] [Sat Aug 29 05:05:45.961579 2026] [security2:error] [pid 1018003:tid 1018090] [remote 104.219.248.116:33798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.248.219.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fellowsofmythgar.com"] [uri "/wp-login.php"] [unique_id "apK9CTAh5Y1i2tUxg4Hm4wAGIkU"] [Sat Aug 29 05:05:45.964013 2026] [proxy_http:error] [pid 1017536:tid 1017780] (20014)Internal error (specific information not available): [client 34.21.253.104:54276] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:45.964024 2026] [proxy:error] [pid 1017536:tid 1017780] [client 34.21.253.104:54276] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ubuntu/.openai/config.json [Sat Aug 29 05:05:45.966205 2026] [security2:error] [pid 1018003:tid 1018095] [remote 104.219.248.116:33792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.248.219.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fellowsofmythgar.com"] [uri "/wp-login.php"] [unique_id "apK9CTAh5Y1i2tUxg4Hm5QAGAEo"] [Sat Aug 29 05:05:45.966403 2026] [security2:error] [pid 1018003:tid 1018085] [remote 104.219.248.116:33800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.248.219.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fellowsofmythgar.com"] [uri "/wp-login.php"] [unique_id "apK9CTAh5Y1i2tUxg4Hm5AAFx0A"] [Sat Aug 29 05:05:45.969730 2026] [security2:error] [pid 1017536:tid 1017646] [remote 104.219.248.116:33802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.248.219.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fellowsofmythgar.com"] [uri "/wp-login.php"] [unique_id "apK9CSJcY4fy7tP-rU3trgACPW0"] [Sat Aug 29 05:05:45.975908 2026] [proxy_http:error] [pid 1018003:tid 1018265] (20014)Internal error (specific information not available): [client 34.21.253.104:54326] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:45.975923 2026] [proxy:error] [pid 1018003:tid 1018265] [client 34.21.253.104:54326] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:05:46.018537 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.196.209.81:11429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/colour.php"] [unique_id "apK9CjAh5Y1i2tUxg4Hm8gAABcM"] [Sat Aug 29 05:05:46.042242 2026] [security2:error] [pid 1017536:tid 1017626] [remote 104.219.248.116:33814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.248.219.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fellowsofmythgar.com"] [uri "/wp-login.php"] [unique_id "apK9CiJcY4fy7tP-rU3tsgACe1k"] [Sat Aug 29 05:05:46.042245 2026] [security2:error] [pid 1017536:tid 1017577] [remote 104.219.248.116:33828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.248.219.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fellowsofmythgar.com"] [uri "/wp-login.php"] [unique_id "apK9CiJcY4fy7tP-rU3tswACRSg"] [Sat Aug 29 05:05:46.042452 2026] [security2:error] [pid 1018003:tid 1018042] [remote 104.219.248.116:33844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.248.219.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fellowsofmythgar.com"] [uri "/wp-login.php"] [unique_id "apK9CjAh5Y1i2tUxg4Hm9AAGBBU"] [Sat Aug 29 05:05:46.057726 2026] [security2:error] [pid 1017536:tid 1017785] [client 45.148.10.62:38200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wagnerfarmscbd.com"] [uri "/config.php.bak"] [unique_id "apK9CiJcY4fy7tP-rU3ttQAAAos"] [Sat Aug 29 05:05:46.080336 2026] [security2:error] [pid 1018003:tid 1018181] [client 74.248.24.12:23808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "apK9CjAh5Y1i2tUxg4Hm-AAABdY"] [Sat Aug 29 05:05:46.107239 2026] [security2:error] [pid 1017536:tid 1017747] [client 40.83.93.50:7766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/classsmtps.php"] [unique_id "apK9CiJcY4fy7tP-rU3ttgAAAmU"] [Sat Aug 29 05:05:46.108302 2026] [security2:error] [pid 1017536:tid 1017703] [client 4.232.148.111:24958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apK9CiJcY4fy7tP-rU3ttwAAAjk"] [Sat Aug 29 05:05:46.134009 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.48.251.3:13992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/sys.php"] [unique_id "apK9CiJcY4fy7tP-rU3tuQAAAkY"] [Sat Aug 29 05:05:46.171784 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.196.209.81:18751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/test.php"] [unique_id "apK9CiJcY4fy7tP-rU3tuwAAAnI"] [Sat Aug 29 05:05:46.201437 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.158.54.35:15927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/a.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnAQAABdQ"] [Sat Aug 29 05:05:46.206339 2026] [security2:error] [pid 1017536:tid 1017719] [client 192.145.125.70:51622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9CiJcY4fy7tP-rU3tvAAAAkk"] [Sat Aug 29 05:05:46.215215 2026] [security2:error] [pid 1018003:tid 1018269] [client 129.121.86.192:43172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "roycehomesales.com"] [uri "/.env"] [unique_id "apK9CjAh5Y1i2tUxg4HnBAAABi0"] [Sat Aug 29 05:05:46.271008 2026] [security2:error] [pid 1018003:tid 1018264] [client 4.205.62.107:55953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnDQAABig"] [Sat Aug 29 05:05:46.274765 2026] [security2:error] [pid 1017536:tid 1017746] [client 4.205.62.107:8987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/sdsa.php"] [unique_id "apK9CiJcY4fy7tP-rU3txAAAAmQ"] [Sat Aug 29 05:05:46.275915 2026] [security2:error] [pid 1017536:tid 1017689] [client 34.143.179.161:39968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/wp-config.php.bak"] [unique_id "apK9CiJcY4fy7tP-rU3txQAAAis"] [Sat Aug 29 05:05:46.278551 2026] [security2:error] [pid 1017536:tid 1017750] [client 34.143.179.161:39984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/wp-config.php.old"] [unique_id "apK9CiJcY4fy7tP-rU3tyQAAAmg"] [Sat Aug 29 05:05:46.288458 2026] [security2:error] [pid 1017536:tid 1017704] [client 128.140.106.114:56692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.wticalumni.com"] [uri "/"] [unique_id "apK9CiJcY4fy7tP-rU3tygAAAjo"], referer: http://www.wticalumni.com [Sat Aug 29 05:05:46.289940 2026] [security2:error] [pid 1017536:tid 1017788] [client 34.143.179.161:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.179.143.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/wp-config.php"] [unique_id "apK9CiJcY4fy7tP-rU3tyAAAAo4"] [Sat Aug 29 05:05:46.290077 2026] [security2:error] [pid 1017536:tid 1017788] [client 34.143.179.161:39964] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/wp-config.php"] [unique_id "apK9CiJcY4fy7tP-rU3tyAAAAo4"] [Sat Aug 29 05:05:46.297815 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.251.3:33290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/phpsysinfo.php"] [unique_id "apK9CiJcY4fy7tP-rU3tzAAAApI"] [Sat Aug 29 05:05:46.301175 2026] [security2:error] [pid 1017536:tid 1017705] [client 34.143.179.161:40000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.179.143.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/config.php.bak"] [unique_id "apK9CiJcY4fy7tP-rU3tzQAAAjs"] [Sat Aug 29 05:05:46.303466 2026] [security2:error] [pid 1017536:tid 1017745] [client 34.143.179.161:39994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.179.143.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/config.php"] [unique_id "apK9CiJcY4fy7tP-rU3tywAAAmM"] [Sat Aug 29 05:05:46.321450 2026] [security2:error] [pid 1018003:tid 1018115] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnEAAGNl4"] [Sat Aug 29 05:05:46.327252 2026] [security2:error] [pid 1018003:tid 1018213] [client 168.107.94.195:64762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnEgAABfY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:46.368477 2026] [security2:error] [pid 1017536:tid 1017757] [client 34.143.179.161:40022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/config/secrets.yml"] [unique_id "apK9CiJcY4fy7tP-rU3tzwAAAm8"] [Sat Aug 29 05:05:46.405205 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.49.130:57661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/v2.php"] [unique_id "apK9CiJcY4fy7tP-rU3t0AAAAkI"] [Sat Aug 29 05:05:46.412827 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:24519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/file88.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnGwAABdc"] [Sat Aug 29 05:05:46.414023 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.147.79:48260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9CiJcY4fy7tP-rU3t0QAAAnw"] [Sat Aug 29 05:05:46.434080 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.196.209.81:4483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/OK.php"] [unique_id "apK9CiJcY4fy7tP-rU3t0gAAAmI"] [Sat Aug 29 05:05:46.453155 2026] [security2:error] [pid 1017536:tid 1017777] [client 158.23.147.79:30601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9CiJcY4fy7tP-rU3t0wAAAoM"] [Sat Aug 29 05:05:46.482567 2026] [security2:error] [pid 1017536:tid 1017669] [client 158.23.147.79:50157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9CiJcY4fy7tP-rU3t1AAAAhc"] [Sat Aug 29 05:05:46.524871 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.147.79:30700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/makeasmtp.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnJgAABbk"] [Sat Aug 29 05:05:46.524928 2026] [security2:error] [pid 1018003:tid 1018140] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/admin/phpinfo.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnJwAGNnc"] [Sat Aug 29 05:05:46.541863 2026] [security2:error] [pid 1018003:tid 1018245] [client 192.145.125.70:51624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9CjAh5Y1i2tUxg4HnKQAABhU"] [Sat Aug 29 05:05:46.557894 2026] [security2:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/admin_phpinfo.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnKwAF33g"] [Sat Aug 29 05:05:46.580828 2026] [security2:error] [pid 1018003:tid 1018252] [client 68.155.159.216:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/classwithtostring.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnLwAABhw"] [Sat Aug 29 05:05:46.593778 2026] [security2:error] [pid 1018003:tid 1018173] [client 4.232.148.111:18063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnMAAABc4"] [Sat Aug 29 05:05:46.595335 2026] [security2:error] [pid 1018003:tid 1018225] [client 40.83.93.50:8033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/contentloader1.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnMQAABgI"] [Sat Aug 29 05:05:46.631160 2026] [security2:error] [pid 1017536:tid 1017761] [client 74.248.24.12:5274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/gifclass.php"] [unique_id "apK9CiJcY4fy7tP-rU3t1gAAAnM"] [Sat Aug 29 05:05:46.645211 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.158.54.35:9460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/u.php"] [unique_id "apK9CiJcY4fy7tP-rU3t1wAAAoY"] [Sat Aug 29 05:05:46.674724 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.49.130:43026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.scubaetcfl.com"] [uri "/press.php"] [unique_id "apK9CiJcY4fy7tP-rU3t2AAAAnc"] [Sat Aug 29 05:05:46.707063 2026] [security2:error] [pid 1017536:tid 1017709] [client 168.107.94.195:65136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9CiJcY4fy7tP-rU3t2wAAAj8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:46.708830 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.196.209.81:17136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/user/f35.php"] [unique_id "apK9CiJcY4fy7tP-rU3t3AAAAko"] [Sat Aug 29 05:05:46.714106 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.251.3:14023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/fleen.php"] [unique_id "apK9CiJcY4fy7tP-rU3t3wAAAhw"] [Sat Aug 29 05:05:46.720716 2026] [security2:error] [pid 1018003:tid 1018170] [client 4.205.62.107:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/tax.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnRwAABcs"] [Sat Aug 29 05:05:46.728163 2026] [security2:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/api/info.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnSAAF33I"] [Sat Aug 29 05:05:46.755258 2026] [security2:error] [pid 1018003:tid 1018174] [client 128.140.106.114:17932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.wticalumni.com"] [uri "/index.htm"] [unique_id "apK9CjAh5Y1i2tUxg4HnSQAABc8"], referer: http://www.wticalumni.com [Sat Aug 29 05:05:46.756103 2026] [security2:error] [pid 1017536:tid 1017711] [client 68.155.159.216:12171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin.php"] [unique_id "apK9CiJcY4fy7tP-rU3t5gAAAkE"] [Sat Aug 29 05:05:46.769614 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.48.250.41:23476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/num.php"] [unique_id "apK9CiJcY4fy7tP-rU3t6AAAAi8"] [Sat Aug 29 05:05:46.780464 2026] [security2:error] [pid 1017536:tid 1017690] [client 158.23.147.79:25571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9CiJcY4fy7tP-rU3t6QAAAiw"] [Sat Aug 29 05:05:46.813593 2026] [security2:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/api/phpinfo.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnTwAF4g8"] [Sat Aug 29 05:05:46.842689 2026] [security2:error] [pid 1017536:tid 1017719] [client 192.145.125.70:51630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9CiJcY4fy7tP-rU3t7gAAAkk"] [Sat Aug 29 05:05:46.842875 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.196.209.81:11436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dickieberrycoaching.glowt-shirt.com"] [uri "/aaa.php"] [unique_id "apK9CiJcY4fy7tP-rU3t7wAAAos"] [Sat Aug 29 05:05:46.847423 2026] [security2:error] [pid 1018003:tid 1018242] [client 68.155.159.216:18237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnVQAABhI"] [Sat Aug 29 05:05:46.858086 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.48.250.41:26917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/zu.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnVwAABhg"] [Sat Aug 29 05:05:46.870248 2026] [security2:error] [pid 1018003:tid 1018203] [client 68.155.159.216:14140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/plugins.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnWgAABew"] [Sat Aug 29 05:05:46.874903 2026] [security2:error] [pid 1018003:tid 1018185] [client 68.155.159.216:58282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnWwAABdo"] [Sat Aug 29 05:05:46.919167 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.104.49.130:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/222.php"] [unique_id "apK9CiJcY4fy7tP-rU3t-wAAAlA"] [Sat Aug 29 05:05:46.926339 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.251.3:14008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/upload.form.php"] [unique_id "apK9CiJcY4fy7tP-rU3t_AAAAmE"] [Sat Aug 29 05:05:46.927155 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.250.41:23477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/a4.php"] [unique_id "apK9CiJcY4fy7tP-rU3t_QAAAj4"] [Sat Aug 29 05:05:46.961684 2026] [security2:error] [pid 1017536:tid 1017772] [client 4.205.62.107:22333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/ebahvhhh.php"] [unique_id "apK9CiJcY4fy7tP-rU3t_gAAAn4"] [Sat Aug 29 05:05:46.965994 2026] [security2:error] [pid 1017536:tid 1017782] [client 158.23.147.79:24436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9CiJcY4fy7tP-rU3t_wAAAog"] [Sat Aug 29 05:05:46.998085 2026] [security2:error] [pid 1017536:tid 1017722] [client 4.205.62.107:21917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/motu.php"] [unique_id "apK9CiJcY4fy7tP-rU3uAAAAAkw"] [Sat Aug 29 05:05:47.001688 2026] [security2:error] [pid 1018003:tid 1018240] [client 4.205.62.107:65418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/wsws.php"] [unique_id "apK9CjAh5Y1i2tUxg4HnagAABhA"] [Sat Aug 29 05:05:47.005487 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.48.250.41:27538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/lanka.php"] [unique_id "apK9CyJcY4fy7tP-rU3uAQAAAhU"] [Sat Aug 29 05:05:47.040228 2026] [security2:error] [pid 1017536:tid 1017707] [client 68.155.159.216:51845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9CyJcY4fy7tP-rU3uBAAAAj0"] [Sat Aug 29 05:05:47.057823 2026] [security2:error] [pid 1017536:tid 1017754] [client 4.232.148.111:24944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/gifclass.php"] [unique_id "apK9CyJcY4fy7tP-rU3uBgAAAmw"] [Sat Aug 29 05:05:47.078945 2026] [security2:error] [pid 1018003:tid 1018183] [client 4.205.62.107:2505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/mga.php"] [unique_id "apK9CzAh5Y1i2tUxg4HncQAABdg"] [Sat Aug 29 05:05:47.093963 2026] [security2:error] [pid 1017536:tid 1017670] [client 158.158.54.35:22941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/r.php"] [unique_id "apK9CyJcY4fy7tP-rU3uBwAAAhg"] [Sat Aug 29 05:05:47.103135 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.196.209.81:18717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/user/min.php"] [unique_id "apK9CyJcY4fy7tP-rU3uCAAAAiM"] [Sat Aug 29 05:05:47.106016 2026] [security2:error] [pid 1017536:tid 1017688] [client 168.107.94.195:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9CyJcY4fy7tP-rU3uCQAAAio"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:47.108073 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.250.41:23525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/tfm.php"] [unique_id "apK9CzAh5Y1i2tUxg4HncwAABcM"] [Sat Aug 29 05:05:47.141969 2026] [security2:error] [pid 1017536:tid 1017770] [client 40.83.93.50:3166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/al.php"] [unique_id "apK9CyJcY4fy7tP-rU3uCwAAAnw"] [Sat Aug 29 05:05:47.142862 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.48.250.41:27402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/gettest.php"] [unique_id "apK9CzAh5Y1i2tUxg4HndgAABfI"] [Sat Aug 29 05:05:47.147451 2026] [security2:error] [pid 1017536:tid 1017764] [client 68.155.159.216:64204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-l0gin.php"] [unique_id "apK9CyJcY4fy7tP-rU3uDAAAAnY"] [Sat Aug 29 05:05:47.149323 2026] [security2:error] [pid 1017536:tid 1017711] [client 192.145.125.70:51642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK9CyJcY4fy7tP-rU3uDQAAAkE"] [Sat Aug 29 05:05:47.179639 2026] [core:error] [pid 1018003:tid 1018164] [client 74.248.24.12:31601] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:47.179656 2026] [core:error] [pid 1018003:tid 1018164] [client 74.248.24.12:31601] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:47.192031 2026] [security2:error] [pid 1018003:tid 1018273] [client 45.148.10.62:38204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wagnerfarmscbd.com"] [uri "/phpinfo.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnfAAABjE"] [Sat Aug 29 05:05:47.202588 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.48.251.3:33338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aws_auth.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnfQAABdY"] [Sat Aug 29 05:05:47.219129 2026] [security2:error] [pid 1018003:tid 1018224] [client 34.7.40.70:37158] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9CzAh5Y1i2tUxg4HnfwAABgE"] [Sat Aug 29 05:05:47.220596 2026] [security2:error] [pid 1018003:tid 1018192] [client 34.7.40.70:37116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/.env"] [unique_id "apK9CzAh5Y1i2tUxg4HngAAABeE"] [Sat Aug 29 05:05:47.221669 2026] [security2:error] [pid 1018003:tid 1018198] [client 34.7.40.70:37180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apK9CzAh5Y1i2tUxg4HngQAABec"] [Sat Aug 29 05:05:47.221754 2026] [security2:error] [pid 1018003:tid 1018198] [client 34.7.40.70:37180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apK9CzAh5Y1i2tUxg4HngQAABec"] [Sat Aug 29 05:05:47.223902 2026] [security2:error] [pid 1017536:tid 1017692] [client 34.7.40.70:37148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/app/.env"] [unique_id "apK9CyJcY4fy7tP-rU3uDwAAAi4"] [Sat Aug 29 05:05:47.224583 2026] [cgid:error] [pid 1017536:tid 1017685] [client 34.7.40.70:37170] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.226888 2026] [cgid:error] [pid 1017536:tid 1017753] [client 34.7.40.70:37278] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.227476 2026] [security2:error] [pid 1018003:tid 1018258] [client 34.7.40.70:37200] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK9CzAh5Y1i2tUxg4HngwAABiI"] [Sat Aug 29 05:05:47.228304 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.49.130:57532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/reop3.php"] [unique_id "apK9CyJcY4fy7tP-rU3uFAAAAkY"] [Sat Aug 29 05:05:47.228842 2026] [security2:error] [pid 1018003:tid 1018262] [client 34.7.40.70:37132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/root/.env"] [unique_id "apK9CzAh5Y1i2tUxg4HnhgAABiY"] [Sat Aug 29 05:05:47.231212 2026] [cgid:error] [pid 1018003:tid 1018155] [client 34.7.40.70:37344] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.231221 2026] [security2:error] [pid 1018003:tid 1018166] [client 34.7.40.70:37182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env"] [unique_id "apK9CzAh5Y1i2tUxg4HnjQAABcc"] [Sat Aug 29 05:05:47.231248 2026] [cgid:error] [pid 1017536:tid 1017793] [client 34.7.40.70:37254] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.231292 2026] [cgid:error] [pid 1018003:tid 1018244] [client 34.7.40.70:37364] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.231321 2026] [security2:error] [pid 1018003:tid 1018166] [client 34.7.40.70:37182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env"] [unique_id "apK9CzAh5Y1i2tUxg4HnjQAABcc"] [Sat Aug 29 05:05:47.231681 2026] [security2:error] [pid 1018003:tid 1018186] [client 34.7.40.70:37130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/src/.env"] [unique_id "apK9CzAh5Y1i2tUxg4HnjAAABds"] [Sat Aug 29 05:05:47.231831 2026] [security2:error] [pid 1017536:tid 1017780] [client 34.7.40.70:37282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/root/.aws/credentials.backup"] [unique_id "apK9CyJcY4fy7tP-rU3uFQAAAoY"] [Sat Aug 29 05:05:47.231851 2026] [cgid:error] [pid 1017536:tid 1017790] [client 34.7.40.70:37292] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.232013 2026] [security2:error] [pid 1017536:tid 1017709] [client 34.7.40.70:37306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/root/.aws/credentials.bak"] [unique_id "apK9CyJcY4fy7tP-rU3uFgAAAj8"] [Sat Aug 29 05:05:47.232099 2026] [security2:error] [pid 1017536:tid 1017709] [client 34.7.40.70:37306] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/root/.aws/credentials.bak"] [unique_id "apK9CyJcY4fy7tP-rU3uFgAAAj8"] [Sat Aug 29 05:05:47.233414 2026] [cgid:error] [pid 1017536:tid 1017725] [client 34.7.40.70:37324] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.234026 2026] [cgid:error] [pid 1017536:tid 1017761] [client 34.7.40.70:37212] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.234042 2026] [cgid:error] [pid 1018003:tid 1018223] [client 34.7.40.70:37242] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.234092 2026] [cgid:error] [pid 1018003:tid 1018234] [client 34.7.40.70:37392] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.234095 2026] [cgid:error] [pid 1017536:tid 1017720] [client 34.7.40.70:37378] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.234419 2026] [security2:error] [pid 1017536:tid 1017720] [client 34.7.40.70:37378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9CyJcY4fy7tP-rU3uGAAAAko"] [Sat Aug 29 05:05:47.234438 2026] [cgid:error] [pid 1018003:tid 1018196] [client 34.7.40.70:37322] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.234527 2026] [cgid:error] [pid 1018003:tid 1018161] [client 34.7.40.70:37252] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.234538 2026] [security2:error] [pid 1018003:tid 1018196] [client 34.7.40.70:37322] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9CzAh5Y1i2tUxg4HnjgAABeU"] [Sat Aug 29 05:05:47.234716 2026] [cgid:error] [pid 1017536:tid 1017674] [client 34.7.40.70:37312] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.234783 2026] [security2:error] [pid 1017536:tid 1017674] [client 34.7.40.70:37312] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9CyJcY4fy7tP-rU3uGQAAAhw"] [Sat Aug 29 05:05:47.235522 2026] [core:error] [pid 1018003:tid 1018239] [client 34.7.40.70:37194] AH10244: invalid URI path (/@fs/../../.env?raw??) [Sat Aug 29 05:05:47.235729 2026] [security2:error] [pid 1018003:tid 1018197] [client 34.7.40.70:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apK9CzAh5Y1i2tUxg4HnkwAABeY"] [Sat Aug 29 05:05:47.235915 2026] [cgid:error] [pid 1018003:tid 1018194] [client 34.7.40.70:37340] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.236785 2026] [security2:error] [pid 1018003:tid 1018239] [client 34.7.40.70:37194] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/400.shtml"] [unique_id "apK9CzAh5Y1i2tUxg4HnlAAABg8"] [Sat Aug 29 05:05:47.237152 2026] [cgid:error] [pid 1018003:tid 1018265] [client 34.7.40.70:37320] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.237695 2026] [cgid:error] [pid 1018003:tid 1018274] [client 34.7.40.70:37228] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.238667 2026] [cgid:error] [pid 1018003:tid 1018156] [client 34.7.40.70:37348] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.238667 2026] [cgid:error] [pid 1018003:tid 1018226] [client 34.7.40.70:37206] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.239160 2026] [cgid:error] [pid 1018003:tid 1018175] [client 34.7.40.70:37386] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:47.255488 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.48.250.41:23396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/Geforce.php"] [unique_id "apK9CyJcY4fy7tP-rU3uGgAAAok"] [Sat Aug 29 05:05:47.272023 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.48.250.41:26937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/35.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnmAAABi0"] [Sat Aug 29 05:05:47.406128 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.250.41:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/click.php"] [unique_id "apK9CyJcY4fy7tP-rU3uGwAAAjo"] [Sat Aug 29 05:05:47.406747 2026] [security2:error] [pid 1017536:tid 1017726] [client 4.205.62.107:55952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9CyJcY4fy7tP-rU3uHAAAAlA"] [Sat Aug 29 05:05:47.425186 2026] [security2:error] [pid 1017536:tid 1017743] [client 4.205.62.107:53355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/bengi.php"] [unique_id "apK9CyJcY4fy7tP-rU3uHQAAAmE"] [Sat Aug 29 05:05:47.446251 2026] [security2:error] [pid 1017536:tid 1017708] [client 192.145.125.70:51658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9CyJcY4fy7tP-rU3uHgAAAj4"] [Sat Aug 29 05:05:47.485256 2026] [security2:error] [pid 1017536:tid 1017757] [client 168.107.94.195:49472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9CyJcY4fy7tP-rU3uIgAAAm8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:47.516094 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.196.209.81:17033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/users.php"] [unique_id "apK9CyJcY4fy7tP-rU3uIwAAAmQ"] [Sat Aug 29 05:05:47.518353 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.104.62:39068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/term.php"] [unique_id "apK9CyJcY4fy7tP-rU3uJAAAAjA"] [Sat Aug 29 05:05:47.519443 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:24566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/NewFile.php/"] [unique_id "apK9CzAh5Y1i2tUxg4HnsgAABdc"] [Sat Aug 29 05:05:47.535117 2026] [security2:error] [pid 1017536:tid 1017755] [client 35.198.240.194:31122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/public/.env"] [unique_id "apK9CyJcY4fy7tP-rU3uJQAAAm0"] [Sat Aug 29 05:05:47.537857 2026] [security2:error] [pid 1017536:tid 1017745] [client 158.158.54.35:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-blog.php"] [unique_id "apK9CyJcY4fy7tP-rU3uKQAAAmM"] [Sat Aug 29 05:05:47.538583 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.147.79:48300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/makeasmtp.php"] [unique_id "apK9CyJcY4fy7tP-rU3uKgAAAoc"] [Sat Aug 29 05:05:47.544066 2026] [security2:error] [pid 1018003:tid 1018216] [client 216.73.161.161:25999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.darwinsfox.com"] [uri "/wp-login.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnsQAABfk"] [Sat Aug 29 05:05:47.546857 2026] [security2:error] [pid 1017536:tid 1017781] [client 35.198.240.194:31162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.github/.env"] [unique_id "apK9CyJcY4fy7tP-rU3uLAAAAoc"] [Sat Aug 29 05:05:47.548167 2026] [security2:error] [pid 1017536:tid 1017722] [client 35.198.240.194:31250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9CyJcY4fy7tP-rU3uLwAAAkw"] [Sat Aug 29 05:05:47.571182 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.48.250.41:26941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/maraz.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnvwAABgk"] [Sat Aug 29 05:05:47.575350 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.147.79:30717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnwAAABhw"] [Sat Aug 29 05:05:47.603863 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.48.251.3:33292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/php-details.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnwQAABgI"] [Sat Aug 29 05:05:47.618788 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.48.250.41:23447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ms.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnwgAABeg"] [Sat Aug 29 05:05:47.633047 2026] [security2:error] [pid 1017536:tid 1017788] [client 40.83.93.50:3146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/global.php"] [unique_id "apK9CyJcY4fy7tP-rU3uMgAAAo4"] [Sat Aug 29 05:05:47.637503 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.147.79:30712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9CyJcY4fy7tP-rU3uMwAAAoI"] [Sat Aug 29 05:05:47.649107 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.23.147.79:50082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnxQAABfo"] [Sat Aug 29 05:05:47.685984 2026] [security2:error] [pid 1018003:tid 1018271] [client 4.232.148.111:32294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnygAABi8"] [Sat Aug 29 05:05:47.713406 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.104.104.62:39102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/ms-edit.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnzQAABjQ"] [Sat Aug 29 05:05:47.718352 2026] [security2:error] [pid 1017536:tid 1017714] [client 74.248.24.12:8999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9CyJcY4fy7tP-rU3uNAAAAkQ"] [Sat Aug 29 05:05:47.720634 2026] [security2:error] [pid 1018003:tid 1018150] [client 20.48.250.41:27573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/kbfr.php"] [unique_id "apK9CzAh5Y1i2tUxg4HnzwAABbc"] [Sat Aug 29 05:05:47.742417 2026] [security2:error] [pid 1018003:tid 1018205] [client 192.145.125.70:51672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9CzAh5Y1i2tUxg4Hn1wAABe4"] [Sat Aug 29 05:05:47.772048 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.48.250.41:23459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/zxekqlxb.php"] [unique_id "apK9CzAh5Y1i2tUxg4Hn2gAABc8"] [Sat Aug 29 05:05:47.802770 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.104.49.130:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/k.php"] [unique_id "apK9CyJcY4fy7tP-rU3uNwAAAns"] [Sat Aug 29 05:05:47.854267 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.48.250.41:26928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wp-act.php"] [unique_id "apK9CyJcY4fy7tP-rU3uOAAAAiI"] [Sat Aug 29 05:05:47.861866 2026] [security2:error] [pid 1018003:tid 1018215] [client 68.155.159.216:12239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9CzAh5Y1i2tUxg4Hn4wAABfg"] [Sat Aug 29 05:05:47.864337 2026] [security2:error] [pid 1018003:tid 1018267] [client 4.205.62.107:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/linusadmin-phpinfo.php"] [unique_id "apK9CzAh5Y1i2tUxg4Hn5AAABis"] [Sat Aug 29 05:05:47.864779 2026] [security2:error] [pid 1018003:tid 1018257] [client 168.107.94.195:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9CzAh5Y1i2tUxg4Hn5QAABiE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:47.888544 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.147.79:25585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9CzAh5Y1i2tUxg4Hn6AAABd0"] [Sat Aug 29 05:05:47.902634 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.48.250.41:23526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/init.php"] [unique_id "apK9CzAh5Y1i2tUxg4Hn6gAABhM"] [Sat Aug 29 05:05:47.908035 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.104.62:39078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/admin.php"] [unique_id "apK9CyJcY4fy7tP-rU3uOQAAAlc"] [Sat Aug 29 05:05:47.921781 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.196.209.81:18739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK9CzAh5Y1i2tUxg4Hn7AAABd8"] [Sat Aug 29 05:05:47.947532 2026] [security2:error] [pid 1018003:tid 1018171] [client 45.148.10.62:38224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wanderlustpictures.com"] [uri "/.env"] [unique_id "apK9CzAh5Y1i2tUxg4Hn8QAABcw"] [Sat Aug 29 05:05:47.984983 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:56907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9CyJcY4fy7tP-rU3uPgAAAms"] [Sat Aug 29 05:05:47.990946 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.158.54.35:16649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/xxx.php"] [unique_id "apK9CzAh5Y1i2tUxg4Hn9gAABhY"] [Sat Aug 29 05:05:48.032940 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.48.250.41:23482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/term.php"] [unique_id "apK9DCJcY4fy7tP-rU3uPwAAAoY"] [Sat Aug 29 05:05:48.036155 2026] [security2:error] [pid 1017536:tid 1017691] [client 192.145.125.70:51682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK9DCJcY4fy7tP-rU3uQAAAAi0"] [Sat Aug 29 05:05:48.041268 2026] [security2:error] [pid 1017536:tid 1017790] [client 57.141.14.105:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/46/"] [unique_id "apK9DCJcY4fy7tP-rU3uQQAAApA"] [Sat Aug 29 05:05:48.069203 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.48.250.41:27460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/24.php"] [unique_id "apK9DCJcY4fy7tP-rU3uQgAAAoo"] [Sat Aug 29 05:05:48.070504 2026] [security2:error] [pid 1018003:tid 1018186] [client 158.23.147.79:24571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/index.php"] [unique_id "apK9DDAh5Y1i2tUxg4Hn_wAABds"] [Sat Aug 29 05:05:48.083667 2026] [security2:error] [pid 1017536:tid 1017749] [client 74.7.244.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowrepairdubuque.com"] [uri "/index.php"] [unique_id "apK9CSJcY4fy7tP-rU3thQAAAmc"] [Sat Aug 29 05:05:48.085070 2026] [security2:error] [pid 1017536:tid 1017778] [client 74.7.244.46:59528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowrepairdubuque.com"] [uri "/robots.txt"] [unique_id "apK9CSJcY4fy7tP-rU3tggAChCA"] [Sat Aug 29 05:05:48.087744 2026] [security2:error] [pid 1018003:tid 1018224] [client 66.248.203.2:17846] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/"] [unique_id "apK9DDAh5Y1i2tUxg4HoAAAABgE"] [Sat Aug 29 05:05:48.102174 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.104.62:39086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/index.php"] [unique_id "apK9DCJcY4fy7tP-rU3uQwAAAj8"] [Sat Aug 29 05:05:48.102591 2026] [cgid:error] [pid 1018003:tid 1018197] [client 45.148.10.62:38224] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:48.127471 2026] [security2:error] [pid 1017536:tid 1017750] [client 4.205.62.107:22302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/bthil.php"] [unique_id "apK9DCJcY4fy7tP-rU3uRAAAAmg"] [Sat Aug 29 05:05:48.142588 2026] [security2:error] [pid 1017536:tid 1017726] [client 68.155.159.216:51462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9DCJcY4fy7tP-rU3uRQAAAlA"] [Sat Aug 29 05:05:48.142614 2026] [security2:error] [pid 1017536:tid 1017727] [client 4.205.62.107:22307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/rpk.php"] [unique_id "apK9DCJcY4fy7tP-rU3uRgAAAlE"] [Sat Aug 29 05:05:48.145542 2026] [security2:error] [pid 1017536:tid 1017743] [client 4.205.62.107:65428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/localconf.php"] [unique_id "apK9DCJcY4fy7tP-rU3uSAAAAmE"] [Sat Aug 29 05:05:48.146006 2026] [security2:error] [pid 1017536:tid 1017734] [client 40.83.93.50:3193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/update.php"] [unique_id "apK9DCJcY4fy7tP-rU3uRwAAAlg"] [Sat Aug 29 05:05:48.159967 2026] [security2:error] [pid 1017536:tid 1017710] [client 4.232.148.111:20634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/css/index.php"] [unique_id "apK9DCJcY4fy7tP-rU3uSQAAAkA"] [Sat Aug 29 05:05:48.160781 2026] [security2:error] [pid 1018003:tid 1018133] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoCAAF0HA"] [Sat Aug 29 05:05:48.179910 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.49.130:63606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/media.php"] [unique_id "apK9DCJcY4fy7tP-rU3uSgAAAhY"] [Sat Aug 29 05:05:48.189575 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.48.250.41:23468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/aaa.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoDAAABig"] [Sat Aug 29 05:05:48.192872 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.104.18.15:8071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/kerang.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoDQAABbg"] [Sat Aug 29 05:05:48.198829 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.48.251.3:33312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aww.php"] [unique_id "apK9DCJcY4fy7tP-rU3uTAAAAog"] [Sat Aug 29 05:05:48.215538 2026] [security2:error] [pid 1018003:tid 1018184] [client 4.205.62.107:2949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/konfig.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoDwAABdk"] [Sat Aug 29 05:05:48.224076 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.250.41:27457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/155.php"] [unique_id "apK9DCJcY4fy7tP-rU3uTwAAAmI"] [Sat Aug 29 05:05:48.246299 2026] [security2:error] [pid 1018003:tid 1018238] [client 168.107.94.195:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoEgAABg4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:48.262395 2026] [security2:error] [pid 1018003:tid 1018030] [remote 45.148.10.62:38220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wagnerfarmscbd.com"] [uri "/wp-login.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoFwAF5Ak"] [Sat Aug 29 05:05:48.281998 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.18.15:36690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/domvf.php"] [unique_id "apK9DCJcY4fy7tP-rU3uUwAAAls"] [Sat Aug 29 05:05:48.283474 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.104.18.15:7046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ws85.php"] [unique_id "apK9DCJcY4fy7tP-rU3uVQAAAmA"] [Sat Aug 29 05:05:48.284221 2026] [security2:error] [pid 1017536:tid 1017760] [client 45.148.10.62:38250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wanderlustpictures.com"] [uri "/.env"] [unique_id "apK9DCJcY4fy7tP-rU3uVAAAAnI"] [Sat Aug 29 05:05:48.291826 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.18.15:23436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/sallu.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoGQAABb4"] [Sat Aug 29 05:05:48.295953 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.104.62:39059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/about.php"] [unique_id "apK9DCJcY4fy7tP-rU3uVgAAAks"] [Sat Aug 29 05:05:48.299144 2026] [security2:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/aws.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoGgAF0HE"] [Sat Aug 29 05:05:48.303257 2026] [security2:error] [pid 1018003:tid 1018234] [client 74.248.24.12:8974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/css/index.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoGwAABgo"] [Sat Aug 29 05:05:48.315940 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.104.18.15:13189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/5656.php"] [unique_id "apK9DCJcY4fy7tP-rU3uVwAAAhU"] [Sat Aug 29 05:05:48.316773 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.196.209.81:17108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoHgAABi0"] [Sat Aug 29 05:05:48.317408 2026] [security2:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/config.inc.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoHwAF0AI"] [Sat Aug 29 05:05:48.335207 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.18.15:46948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/revo.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoIgAABbk"] [Sat Aug 29 05:05:48.339814 2026] [security2:error] [pid 1018003:tid 1018278] [client 192.145.125.70:51694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9DDAh5Y1i2tUxg4HoIwAABjY"] [Sat Aug 29 05:05:48.344954 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.250.41:23515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/xsox.php"] [unique_id "apK9DCJcY4fy7tP-rU3uWAAAAo4"] [Sat Aug 29 05:05:48.344970 2026] [security2:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/config.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoJAAF0HM"] [Sat Aug 29 05:05:48.350416 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.18.15:8114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/m.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoJQAABdw"] [Sat Aug 29 05:05:48.403688 2026] [security2:error] [pid 1018003:tid 1018038] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/env.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoKwAGHBE"] [Sat Aug 29 05:05:48.429179 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.48.250.41:27629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/file.php"] [unique_id "apK9DCJcY4fy7tP-rU3uWwAAAkU"] [Sat Aug 29 05:05:48.430297 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.104.18.15:36804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/biufile.php"] [unique_id "apK9DCJcY4fy7tP-rU3uXAAAAiY"] [Sat Aug 29 05:05:48.435605 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:23426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/codex.php"] [unique_id "apK9DCJcY4fy7tP-rU3uXwAAAh0"] [Sat Aug 29 05:05:48.455676 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.18.15:13304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/w3lls.php"] [unique_id "apK9DCJcY4fy7tP-rU3uYQAAAjQ"] [Sat Aug 29 05:05:48.482844 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.250.41:23360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/lkui.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoLwAABfs"] [Sat Aug 29 05:05:48.485772 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.18.15:8082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/fling.php"] [unique_id "apK9DCJcY4fy7tP-rU3uYgAAAn8"] [Sat Aug 29 05:05:48.489600 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.104.62:38927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/vx.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoMgAABfo"] [Sat Aug 29 05:05:48.498913 2026] [security2:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/module.config.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoNAAFyhk"] [Sat Aug 29 05:05:48.498936 2026] [security2:error] [pid 1018003:tid 1018047] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/nexmo.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoNQAFyho"] [Sat Aug 29 05:05:48.503141 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.104.18.15:7128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ffs.php"] [unique_id "apK9DCJcY4fy7tP-rU3uYwAAAi4"] [Sat Aug 29 05:05:48.506284 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.48.251.3:33323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/maxro.php"] [unique_id "apK9DCJcY4fy7tP-rU3uZAAAAms"] [Sat Aug 29 05:05:48.507884 2026] [cgid:error] [pid 1018003:tid 1018051] [remote 181.215.86.234:47268] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/flowerfh/public_html/404.shtml, referer: https://www.flowerfh.com/obituaries.php [Sat Aug 29 05:05:48.508141 2026] [security2:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/stripe.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoQgAFyhc"] [Sat Aug 29 05:05:48.529810 2026] [security2:error] [pid 1017536:tid 1017711] [client 197.219.150.206:57461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9DCJcY4fy7tP-rU3uZQAAAkE"] [Sat Aug 29 05:05:48.529917 2026] [security2:error] [pid 1017536:tid 1017711] [client 197.219.150.206:57461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9DCJcY4fy7tP-rU3uZQAAAkE"] [Sat Aug 29 05:05:48.544940 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.205.62.107:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/cloud.php"] [unique_id "apK9DCJcY4fy7tP-rU3uZgAAAi0"] [Sat Aug 29 05:05:48.563647 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.104.18.15:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/birrs.php"] [unique_id "apK9DCJcY4fy7tP-rU3uZwAAAk8"] [Sat Aug 29 05:05:48.567450 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.18.15:23480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/5656.php"] [unique_id "apK9DCJcY4fy7tP-rU3uaAAAAic"] [Sat Aug 29 05:05:48.570171 2026] [security2:error] [pid 1017536:tid 1017786] [client 4.205.62.107:53432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/groceries/index.php"] [unique_id "apK9DCJcY4fy7tP-rU3uaQAAAow"] [Sat Aug 29 05:05:48.591641 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.18.15:13211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/fpwch.php"] [unique_id "apK9DCJcY4fy7tP-rU3ubAAAAhw"] [Sat Aug 29 05:05:48.599589 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.104.18.15:36739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/blacks.php"] [unique_id "apK9DCJcY4fy7tP-rU3ubQAAAoo"] [Sat Aug 29 05:05:48.600796 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.250.41:27628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9DCJcY4fy7tP-rU3ubgAAAlo"] [Sat Aug 29 05:05:48.625341 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.18.15:8145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/btyuio.php"] [unique_id "apK9DCJcY4fy7tP-rU3ubwAAAis"] [Sat Aug 29 05:05:48.626749 2026] [security2:error] [pid 1018003:tid 1018212] [client 68.155.159.216:24460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/dropdown.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoSgAABfU"] [Sat Aug 29 05:05:48.627950 2026] [security2:error] [pid 1017536:tid 1017749] [client 168.107.94.195:50644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9DCJcY4fy7tP-rU3ucAAAAmc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:48.632840 2026] [security2:error] [pid 1018003:tid 1018174] [client 4.232.148.111:27506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-cron.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoSwAABc8"] [Sat Aug 29 05:05:48.635423 2026] [security2:error] [pid 1017536:tid 1017785] [client 192.145.125.70:51698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9DCJcY4fy7tP-rU3ucQAAAos"] [Sat Aug 29 05:05:48.637461 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.250.41:23506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9DCJcY4fy7tP-rU3ucgAAAmg"] [Sat Aug 29 05:05:48.637721 2026] [security2:error] [pid 1017536:tid 1017709] [client 158.23.147.79:48328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9DCJcY4fy7tP-rU3ucwAAAj8"] [Sat Aug 29 05:05:48.653509 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.104.18.15:7118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/nano.php"] [unique_id "apK9DCJcY4fy7tP-rU3udAAAAlA"] [Sat Aug 29 05:05:48.685394 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.104.104.62:38929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9DCJcY4fy7tP-rU3udgAAAlQ"] [Sat Aug 29 05:05:48.705623 2026] [core:error] [pid 1017536:tid 1017668] [client 20.197.61.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:48.705639 2026] [core:error] [pid 1017536:tid 1017668] [client 20.197.61.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:48.710503 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.196.209.81:17101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/wp-load.php"] [unique_id "apK9DCJcY4fy7tP-rU3ueAAAAnM"] [Sat Aug 29 05:05:48.713970 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.158.54.35:14028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/tool.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoWgAABis"] [Sat Aug 29 05:05:48.714849 2026] [security2:error] [pid 1017536:tid 1017745] [client 158.23.147.79:30708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9DCJcY4fy7tP-rU3ueQAAAmM"] [Sat Aug 29 05:05:48.722000 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.104.18.15:23515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/w3lls.php"] [unique_id "apK9DCJcY4fy7tP-rU3uegAAAkw"] [Sat Aug 29 05:05:48.743775 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.104.18.15:13218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/domvf.php"] [unique_id "apK9DCJcY4fy7tP-rU3ufAAAAmA"] [Sat Aug 29 05:05:48.747085 2026] [cgid:error] [pid 1017536:tid 1017760] [client 45.148.10.62:38250] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:48.759078 2026] [security2:error] [pid 1017536:tid 1017775] [client 68.155.159.216:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9DCJcY4fy7tP-rU3ufgAAAoE"] [Sat Aug 29 05:05:48.759965 2026] [security2:error] [pid 1017536:tid 1017754] [client 158.23.147.79:30671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/makeasmtp.php"] [unique_id "apK9DCJcY4fy7tP-rU3ufwAAAmw"] [Sat Aug 29 05:05:48.775449 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.18.15:46937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/sss.php"] [unique_id "apK9DCJcY4fy7tP-rU3ugQAAAnc"] [Sat Aug 29 05:05:48.785102 2026] [security2:error] [pid 1017536:tid 1017748] [client 68.155.159.216:50388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/install.php"] [unique_id "apK9DCJcY4fy7tP-rU3uggAAAmY"] [Sat Aug 29 05:05:48.790639 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.251.3:13979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/brc.php"] [unique_id "apK9DCJcY4fy7tP-rU3uhAAAAjA"] [Sat Aug 29 05:05:48.797131 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:7069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ano.php"] [unique_id "apK9DDAh5Y1i2tUxg4HobwAABi4"] [Sat Aug 29 05:05:48.805268 2026] [security2:error] [pid 1017536:tid 1017704] [client 40.83.93.50:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/blog.php"] [unique_id "apK9DCJcY4fy7tP-rU3uhwAAAjo"] [Sat Aug 29 05:05:48.811148 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.104.18.15:36628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/beck.php"] [unique_id "apK9DDAh5Y1i2tUxg4HocgAABhg"] [Sat Aug 29 05:05:48.815390 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.250.41:27608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/06.php"] [unique_id "apK9DCJcY4fy7tP-rU3uiAAAAkQ"] [Sat Aug 29 05:05:48.816088 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.250.41:23475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/motu.php"] [unique_id "apK9DCJcY4fy7tP-rU3uigAAAjs"] [Sat Aug 29 05:05:48.829483 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.18.15:8087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/dehnl.php"] [unique_id "apK9DDAh5Y1i2tUxg4HocwAABew"] [Sat Aug 29 05:05:48.859687 2026] [security2:error] [pid 1017536:tid 1017680] [client 173.239.211.120:33977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.darwinsfox.com"] [uri "/wp-login.php"] [unique_id "apK9DCJcY4fy7tP-rU3uiwAAAiI"], referer: https://duckduckgo.com/ [Sat Aug 29 05:05:48.862998 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.18.15:23378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/fpwch.php"] [unique_id "apK9DDAh5Y1i2tUxg4HodAAABek"] [Sat Aug 29 05:05:48.880526 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.104.62:10865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/private.php"] [unique_id "apK9DCJcY4fy7tP-rU3ujAAAAh0"] [Sat Aug 29 05:05:48.880672 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.18.15:13225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/biufile.php"] [unique_id "apK9DCJcY4fy7tP-rU3ujQAAAiA"] [Sat Aug 29 05:05:48.880740 2026] [security2:error] [pid 1018003:tid 1018233] [client 171.61.160.196:16819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoeAAABgk"] [Sat Aug 29 05:05:48.880808 2026] [security2:error] [pid 1018003:tid 1018233] [client 171.61.160.196:16819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoeAAABgk"] [Sat Aug 29 05:05:48.897188 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.104.62:39061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/goods.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoeQAABd0"] [Sat Aug 29 05:05:48.901159 2026] [security2:error] [pid 1017536:tid 1017732] [client 45.148.10.62:38250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wanderlustpictures.com"] [uri "/api/.env"] [unique_id "apK9DCJcY4fy7tP-rU3ujgAAAlY"] [Sat Aug 29 05:05:48.918406 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.104.62:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/sh3ll.php"] [unique_id "apK9DDAh5Y1i2tUxg4HogAAABeA"] [Sat Aug 29 05:05:48.923696 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.104.62:48580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/sf.php"] [unique_id "apK9DDAh5Y1i2tUxg4HogQAABhA"] [Sat Aug 29 05:05:48.932082 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.18.15:6993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/mgrr.php"] [unique_id "apK9DDAh5Y1i2tUxg4HogwAABdg"] [Sat Aug 29 05:05:48.938945 2026] [security2:error] [pid 1018003:tid 1018277] [client 192.145.125.70:51702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9DDAh5Y1i2tUxg4HohgAABjU"] [Sat Aug 29 05:05:48.975127 2026] [security2:error] [pid 1017536:tid 1017776] [client 74.248.24.12:41579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-cron.php"] [unique_id "apK9DCJcY4fy7tP-rU3ujwAAAoI"] [Sat Aug 29 05:05:48.981095 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.48.250.41:23459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/Ov-Simple1.php"] [unique_id "apK9DCJcY4fy7tP-rU3ukAAAAn8"] [Sat Aug 29 05:05:48.992261 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.18.15:8183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/zoo2.php"] [unique_id "apK9DDAh5Y1i2tUxg4HoigAABfw"] [Sat Aug 29 05:05:48.995081 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.104.104.62:41603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/6y7t.php"] [unique_id "apK9DCJcY4fy7tP-rU3ukQAAAi4"] [Sat Aug 29 05:05:48.995621 2026] [security2:error] [pid 1017536:tid 1017667] [client 60.243.207.176:60090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9DCJcY4fy7tP-rU3ukgAAAhU"] [Sat Aug 29 05:05:48.996038 2026] [security2:error] [pid 1017536:tid 1017667] [client 60.243.207.176:60090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9DCJcY4fy7tP-rU3ukgAAAhU"] [Sat Aug 29 05:05:48.996466 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.18.15:23466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/domvf.php"] [unique_id "apK9DCJcY4fy7tP-rU3ukwAAAms"] [Sat Aug 29 05:05:49.001201 2026] [security2:error] [pid 1017536:tid 1017793] [client 4.205.62.107:64941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apK9DSJcY4fy7tP-rU3ulAAAApM"] [Sat Aug 29 05:05:49.007460 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.18.15:46915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apK9DTAh5Y1i2tUxg4HoiwAABcg"] [Sat Aug 29 05:05:49.008431 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.23.147.79:25487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9DSJcY4fy7tP-rU3ulQAAAkE"] [Sat Aug 29 05:05:49.009039 2026] [security2:error] [pid 1017536:tid 1017691] [client 168.107.94.195:51083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9DSJcY4fy7tP-rU3ulgAAAi0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:49.013613 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.104.104.62:10457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/lfi.php"] [unique_id "apK9DTAh5Y1i2tUxg4HojAAABdY"] [Sat Aug 29 05:05:49.021936 2026] [security2:error] [pid 1017536:tid 1017725] [client 68.155.159.216:14308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9DSJcY4fy7tP-rU3umQAAAk8"] [Sat Aug 29 05:05:49.039308 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.18.15:36863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/t3.php"] [unique_id "apK9DSJcY4fy7tP-rU3umgAAAic"] [Sat Aug 29 05:05:49.044953 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.250.41:27510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/class.php"] [unique_id "apK9DSJcY4fy7tP-rU3umwAAAow"] [Sat Aug 29 05:05:49.045308 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.18.15:13280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/blacks.php"] [unique_id "apK9DSJcY4fy7tP-rU3unAAAAkk"] [Sat Aug 29 05:05:49.063237 2026] [security2:error] [pid 1017536:tid 1017783] [client 45.148.10.62:38250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.wanderlustpictures.com"] [uri "/.env.bak"] [unique_id "apK9DSJcY4fy7tP-rU3ungAAAok"] [Sat Aug 29 05:05:49.065462 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.251.3:13991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/vx.php"] [unique_id "apK9DSJcY4fy7tP-rU3unwAAAis"] [Sat Aug 29 05:05:49.081200 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.49.130:53682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/v2.php"] [unique_id "apK9DTAh5Y1i2tUxg4HokQAABeE"] [Sat Aug 29 05:05:49.092868 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.104.62:38940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/wp-access.php"] [unique_id "apK9DTAh5Y1i2tUxg4HokgAABiA"] [Sat Aug 29 05:05:49.098375 2026] [security2:error] [pid 1018003:tid 1018162] [client 4.232.148.111:32313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-block.php"] [unique_id "apK9DTAh5Y1i2tUxg4HolAAABcM"] [Sat Aug 29 05:05:49.115286 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.18.15:7127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/mac.php"] [unique_id "apK9DSJcY4fy7tP-rU3uoAAAAos"] [Sat Aug 29 05:05:49.132985 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.104.62:20853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/shell.php"] [unique_id "apK9DSJcY4fy7tP-rU3uoQAAAk0"] [Sat Aug 29 05:05:49.135518 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.196.209.81:18740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK9DTAh5Y1i2tUxg4HolgAABcw"] [Sat Aug 29 05:05:49.136775 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.18.15:23473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/biufile.php"] [unique_id "apK9DSJcY4fy7tP-rU3uogAAAmE"] [Sat Aug 29 05:05:49.140586 2026] [security2:error] [pid 1018003:tid 1018223] [client 20.104.104.62:48485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/super.php"] [unique_id "apK9DTAh5Y1i2tUxg4HolwAABgA"] [Sat Aug 29 05:05:49.150036 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.104.104.62:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/0xs.php"] [unique_id "apK9DTAh5Y1i2tUxg4HomAAABgE"] [Sat Aug 29 05:05:49.157941 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.158.54.35:14050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/k.php"] [unique_id "apK9DSJcY4fy7tP-rU3uowAAAoY"] [Sat Aug 29 05:05:49.158900 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.104.104.62:10448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/quoys.php"] [unique_id "apK9DTAh5Y1i2tUxg4HomwAABeY"] [Sat Aug 29 05:05:49.159976 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.48.250.41:23439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/wp-blogs.php"] [unique_id "apK9DTAh5Y1i2tUxg4HonAAABg8"] [Sat Aug 29 05:05:49.180389 2026] [security2:error] [pid 1017536:tid 1017668] [client 158.23.147.79:24477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/about/function.php"] [unique_id "apK9DSJcY4fy7tP-rU3upAAAAhY"] [Sat Aug 29 05:05:49.183305 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.104.18.15:13190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/beck.php"] [unique_id "apK9DSJcY4fy7tP-rU3upQAAAmQ"] [Sat Aug 29 05:05:49.192167 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.18.15:47035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/xmini4.php"] [unique_id "apK9DTAh5Y1i2tUxg4HoogAABgM"] [Sat Aug 29 05:05:49.195829 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.48.250.41:27511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/8.php"] [unique_id "apK9DSJcY4fy7tP-rU3upwAAAog"] [Sat Aug 29 05:05:49.214059 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.18.15:36852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp.php"] [unique_id "apK9DSJcY4fy7tP-rU3uqAAAAnM"] [Sat Aug 29 05:05:49.215264 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.49.130:34520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/f35.update.php"] [unique_id "apK9DSJcY4fy7tP-rU3uqQAAAmM"] [Sat Aug 29 05:05:49.217095 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.18.15:8181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/zoo1.php"] [unique_id "apK9DSJcY4fy7tP-rU3uqgAAAoc"] [Sat Aug 29 05:05:49.231803 2026] [cgid:error] [pid 1017536:tid 1017760] [client 45.148.10.62:38250] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:49.244403 2026] [security2:error] [pid 1017536:tid 1017788] [client 192.145.125.70:51704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9DSJcY4fy7tP-rU3urQAAAo4"] [Sat Aug 29 05:05:49.244489 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.104.18.15:7112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/simple.php"] [unique_id "apK9DSJcY4fy7tP-rU3urgAAAo8"] [Sat Aug 29 05:05:49.268180 2026] [security2:error] [pid 1018003:tid 1018195] [client 4.205.62.107:22308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/aws_auth.php"] [unique_id "apK9DTAh5Y1i2tUxg4HopwAABeQ"] [Sat Aug 29 05:05:49.273726 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.18.15:23366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/blacks.php"] [unique_id "apK9DTAh5Y1i2tUxg4HorQAABdc"] [Sat Aug 29 05:05:49.278771 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:65440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/bengi.php"] [unique_id "apK9DSJcY4fy7tP-rU3urwAAAnk"] [Sat Aug 29 05:05:49.284856 2026] [security2:error] [pid 1017536:tid 1017731] [client 40.83.93.50:7748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/bypass.php"] [unique_id "apK9DSJcY4fy7tP-rU3usQAAAlU"] [Sat Aug 29 05:05:49.287211 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.104.62:39079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/autoload_classmap/function.php"] [unique_id "apK9DTAh5Y1i2tUxg4HorgAABf4"] [Sat Aug 29 05:05:49.291633 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.104.62:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/waf.php"] [unique_id "apK9DTAh5Y1i2tUxg4HorwAABdA"] [Sat Aug 29 05:05:49.294257 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.104.62:10826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/vbbn.php"] [unique_id "apK9DTAh5Y1i2tUxg4HosAAABdQ"] [Sat Aug 29 05:05:49.295131 2026] [security2:error] [pid 1017536:tid 1017681] [client 4.205.62.107:21831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/ms.php"] [unique_id "apK9DSJcY4fy7tP-rU3uswAAAiM"] [Sat Aug 29 05:05:49.301157 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.104.49.130:29968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/wp-css.php"] [unique_id "apK9DSJcY4fy7tP-rU3utAAAAhg"] [Sat Aug 29 05:05:49.316828 2026] [security2:error] [pid 1018003:tid 1018251] [client 20.104.104.62:48689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/lufix1.php"] [unique_id "apK9DTAh5Y1i2tUxg4HotgAABhs"] [Sat Aug 29 05:05:49.325817 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.147.79:50084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9DTAh5Y1i2tUxg4HotwAABhw"] [Sat Aug 29 05:05:49.334783 2026] [security2:error] [pid 1018003:tid 1018214] [client 20.104.18.15:13258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/t3.php"] [unique_id "apK9DTAh5Y1i2tUxg4HouQAABfc"] [Sat Aug 29 05:05:49.340867 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.104.18.15:47067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/gulu.php"] [unique_id "apK9DSJcY4fy7tP-rU3utgAAAnw"] [Sat Aug 29 05:05:49.349903 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.250.41:27591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/0x0x.php"] [unique_id "apK9DTAh5Y1i2tUxg4HougAABcs"] [Sat Aug 29 05:05:49.353168 2026] [security2:error] [pid 1018003:tid 1018150] [client 4.205.62.107:2938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/nw.php"] [unique_id "apK9DTAh5Y1i2tUxg4HouwAABbc"] [Sat Aug 29 05:05:49.359229 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.250.41:23389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/mini.php"] [unique_id "apK9DSJcY4fy7tP-rU3utwAAAlc"] [Sat Aug 29 05:05:49.376802 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.104.18.15:8166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/radio.php"] [unique_id "apK9DTAh5Y1i2tUxg4HovwAABc4"] [Sat Aug 29 05:05:49.378675 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.18.15:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/abcd.php"] [unique_id "apK9DTAh5Y1i2tUxg4HowAAABiw"] [Sat Aug 29 05:05:49.382197 2026] [security2:error] [pid 1018003:tid 1018133] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/info.php"] [unique_id "apK9DTAh5Y1i2tUxg4HowgAF4nA"] [Sat Aug 29 05:05:49.390817 2026] [security2:error] [pid 1017536:tid 1017693] [client 168.107.94.195:51486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9DSJcY4fy7tP-rU3uuAAAAi8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:49.391901 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:7130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/xty.php"] [unique_id "apK9DSJcY4fy7tP-rU3uuQAAAh0"] [Sat Aug 29 05:05:49.422335 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.104.104.62:22670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/bnnof6.php"] [unique_id "apK9DSJcY4fy7tP-rU3uugAAAn4"] [Sat Aug 29 05:05:49.424532 2026] [security2:error] [pid 1018003:tid 1018157] [client 34.7.216.49:21954] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/Dockerfile"] [unique_id "apK9DTAh5Y1i2tUxg4HoxAAABb4"] [Sat Aug 29 05:05:49.425188 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.104.62:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/rfi.php"] [unique_id "apK9DSJcY4fy7tP-rU3uuwAAAjI"] [Sat Aug 29 05:05:49.425928 2026] [security2:error] [pid 1017536:tid 1017694] [client 34.7.216.49:21960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.216.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/i.php"] [unique_id "apK9DSJcY4fy7tP-rU3uvAAAAjA"] [Sat Aug 29 05:05:49.430870 2026] [security2:error] [pid 1018003:tid 1018278] [client 34.7.216.49:21966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.216.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/pi.php"] [unique_id "apK9DTAh5Y1i2tUxg4HoyQAABjY"] [Sat Aug 29 05:05:49.434234 2026] [cgid:error] [pid 1017536:tid 1017717] [client 45.148.10.62:38250] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:49.434558 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.18.15:23430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/beck.php"] [unique_id "apK9DSJcY4fy7tP-rU3uwAAAAn8"] [Sat Aug 29 05:05:49.436988 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.104.62:64767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/indonesia.php"] [unique_id "apK9DTAh5Y1i2tUxg4HoywAABe8"] [Sat Aug 29 05:05:49.462298 2026] [security2:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/infophp.php"] [unique_id "apK9DTAh5Y1i2tUxg4HozQAGGH0"] [Sat Aug 29 05:05:49.463090 2026] [security2:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/infos.php"] [unique_id "apK9DTAh5Y1i2tUxg4HozgAGGAA"] [Sat Aug 29 05:05:49.471408 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.104.18.15:46661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/replace.php"] [unique_id "apK9DSJcY4fy7tP-rU3uwwAAAhU"] [Sat Aug 29 05:05:49.480861 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.104.62:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/ms.php"] [unique_id "apK9DTAh5Y1i2tUxg4HozwAABc8"] [Sat Aug 29 05:05:49.491641 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.48.250.41:23402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/amp.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho0QAABew"] [Sat Aug 29 05:05:49.495008 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.18.15:13281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp.php"] [unique_id "apK9DSJcY4fy7tP-rU3uxQAAAic"] [Sat Aug 29 05:05:49.499162 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.250.41:27412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/166.php"] [unique_id "apK9DSJcY4fy7tP-rU3uxgAAAow"] [Sat Aug 29 05:05:49.508321 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.104.104.62:48489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/hack.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho1AAABdo"] [Sat Aug 29 05:05:49.535611 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.18.15:7082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/sallu.php"] [unique_id "apK9DSJcY4fy7tP-rU3uyAAAAko"] [Sat Aug 29 05:05:49.536018 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.18.15:8006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/one.php"] [unique_id "apK9DSJcY4fy7tP-rU3uyQAAAhw"] [Sat Aug 29 05:05:49.544252 2026] [security2:error] [pid 1018003:tid 1018241] [client 74.248.24.12:30589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-block.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho2QAABhE"] [Sat Aug 29 05:05:49.545565 2026] [security2:error] [pid 1018003:tid 1018200] [client 192.145.125.70:51712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9DTAh5Y1i2tUxg4Ho2gAABek"] [Sat Aug 29 05:05:49.547225 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.147.79:58104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho2wAABd0"] [Sat Aug 29 05:05:49.553178 2026] [security2:error] [pid 1018003:tid 1018254] [client 20.104.18.15:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/nofile.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho3AAABh4"] [Sat Aug 29 05:05:49.557278 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.104.104.62:46010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/ah24.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho3QAABd8"] [Sat Aug 29 05:05:49.559585 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.196.209.81:18707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "apK9DSJcY4fy7tP-rU3uygAAAjQ"] [Sat Aug 29 05:05:49.562312 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.104.62:10879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/tajj.php"] [unique_id "apK9DSJcY4fy7tP-rU3uywAAAok"] [Sat Aug 29 05:05:49.569044 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.104.18.15:23472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/t3.php"] [unique_id "apK9DSJcY4fy7tP-rU3uzAAAAoQ"] [Sat Aug 29 05:05:49.574060 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.232.148.111:18106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apK9DSJcY4fy7tP-rU3uzQAAAlY"] [Sat Aug 29 05:05:49.589050 2026] [security2:error] [pid 1017536:tid 1017750] [client 45.148.10.62:38250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wanderlustpictures.com"] [uri "/stripe/.env"] [unique_id "apK9DSJcY4fy7tP-rU3uzgAAAmg"] [Sat Aug 29 05:05:49.599761 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.49.130:63593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/zoo2.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho3gAABjU"] [Sat Aug 29 05:05:49.605189 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.158.54.35:22070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/root.php"] [unique_id "apK9DSJcY4fy7tP-rU3uzwAAAls"] [Sat Aug 29 05:05:49.615599 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.18.15:46969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/c4.php"] [unique_id "apK9DSJcY4fy7tP-rU3u0AAAAmE"] [Sat Aug 29 05:05:49.628194 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.104.18.15:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/abcd.php"] [unique_id "apK9DSJcY4fy7tP-rU3u0gAAAlQ"] [Sat Aug 29 05:05:49.636773 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.250.41:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/h2a2ck.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho5AAABcU"] [Sat Aug 29 05:05:49.662568 2026] [security2:error] [pid 1018003:tid 1018167] [client 68.155.159.216:52784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/simple.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho6gAABcg"] [Sat Aug 29 05:05:49.677217 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.104.18.15:7069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/codex.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho7AAABdY"] [Sat Aug 29 05:05:49.683667 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.104.18.15:8084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/503.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho7QAABgY"] [Sat Aug 29 05:05:49.688850 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.104.62:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/ztv.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho7gAABhY"] [Sat Aug 29 05:05:49.692680 2026] [security2:error] [pid 1018003:tid 1018192] [client 4.205.62.107:56000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/kerang.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho8AAABeE"] [Sat Aug 29 05:05:49.694992 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:36775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/run.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho8QAABec"] [Sat Aug 29 05:05:49.694992 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.49.130:43017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.scubaetcfl.com"] [uri "/edit.php"] [unique_id "apK9DSJcY4fy7tP-rU3u1AAAAhY"] [Sat Aug 29 05:05:49.697143 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.250.41:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/cc13.php"] [unique_id "apK9DSJcY4fy7tP-rU3u1QAAAmQ"] [Sat Aug 29 05:05:49.710105 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.104.62:10847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/grsiuk.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho8wAABbw"] [Sat Aug 29 05:05:49.714387 2026] [security2:error] [pid 1018003:tid 1018244] [client 4.205.62.107:53382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/server-info.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho9QAABhQ"] [Sat Aug 29 05:05:49.722855 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:48466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/155.php"] [unique_id "apK9DSJcY4fy7tP-rU3u2AAAAnM"] [Sat Aug 29 05:05:49.726560 2026] [security2:error] [pid 1018003:tid 1018171] [client 68.155.159.216:24537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/.well-known/index.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho9gAABcw"] [Sat Aug 29 05:05:49.728697 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.18.15:23538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp.php"] [unique_id "apK9DSJcY4fy7tP-rU3u2QAAAmM"] [Sat Aug 29 05:05:49.742042 2026] [cgid:error] [pid 1017536:tid 1017742] [client 45.148.10.62:38250] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:49.742619 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.104.104.62:38968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/adminfuns.php"] [unique_id "apK9DSJcY4fy7tP-rU3u3AAAAnI"] [Sat Aug 29 05:05:49.750940 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.147.79:48306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9DSJcY4fy7tP-rU3u3QAAAks"] [Sat Aug 29 05:05:49.754523 2026] [security2:error] [pid 1017536:tid 1017788] [client 68.155.159.216:51480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9DSJcY4fy7tP-rU3u3gAAAo4"] [Sat Aug 29 05:05:49.764686 2026] [security2:error] [pid 1017536:tid 1017723] [client 40.83.93.50:7759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/extractable-loader-head.php"] [unique_id "apK9DSJcY4fy7tP-rU3u3wAAAk0"] [Sat Aug 29 05:05:49.769792 2026] [security2:error] [pid 1017536:tid 1017765] [client 168.107.94.195:51857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9DSJcY4fy7tP-rU3u4AAAAnc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:49.771404 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.18.15:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/nofile.php"] [unique_id "apK9DSJcY4fy7tP-rU3u4QAAAmY"] [Sat Aug 29 05:05:49.778451 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.250.41:27587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/error_log.php"] [unique_id "apK9DSJcY4fy7tP-rU3u4gAAAjw"] [Sat Aug 29 05:05:49.818586 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.104.104.62:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/kure.php"] [unique_id "apK9DSJcY4fy7tP-rU3u4wAAAjo"] [Sat Aug 29 05:05:49.820006 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.23.147.79:30674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9DSJcY4fy7tP-rU3u5AAAAkQ"] [Sat Aug 29 05:05:49.832623 2026] [security2:error] [pid 1018003:tid 1018025] [remote 209.42.29.39:52516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.29.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.interfaith.thewaltongroupinc.com"] [uri "/wp-login.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho_gAF5gQ"] [Sat Aug 29 05:05:49.834600 2026] [security2:error] [pid 1018003:tid 1018034] [remote 209.42.29.39:52514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.29.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.interfaith.thewaltongroupinc.com"] [uri "/wp-login.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho_QAGAQ0"] [Sat Aug 29 05:05:49.844620 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.104.18.15:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/5656.php"] [unique_id "apK9DTAh5Y1i2tUxg4Ho_wAABig"] [Sat Aug 29 05:05:49.847171 2026] [security2:error] [pid 1017536:tid 1017672] [client 192.145.125.70:51728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9DSJcY4fy7tP-rU3u5QAAAho"] [Sat Aug 29 05:05:49.847231 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.104.18.15:8180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/504.php"] [unique_id "apK9DSJcY4fy7tP-rU3u5gAAAmU"] [Sat Aug 29 05:05:49.851264 2026] [security2:error] [pid 1017536:tid 1017768] [client 20.104.18.15:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/rxr.php"] [unique_id "apK9DSJcY4fy7tP-rU3u5wAAAno"] [Sat Aug 29 05:05:49.860067 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:23320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/aa.php"] [unique_id "apK9DSJcY4fy7tP-rU3u6AAAAnw"] [Sat Aug 29 05:05:49.866773 2026] [security2:error] [pid 1017536:tid 1017715] [client 158.23.147.79:30550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9DSJcY4fy7tP-rU3u6gAAAkU"] [Sat Aug 29 05:05:49.868073 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.104.62:44602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/ahy66.php"] [unique_id "apK9DSJcY4fy7tP-rU3u6wAAAkY"] [Sat Aug 29 05:05:49.874136 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.18.15:23427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/abcd.php"] [unique_id "apK9DTAh5Y1i2tUxg4HpAQAABdk"] [Sat Aug 29 05:05:49.879047 2026] [security2:error] [pid 1017536:tid 1017707] [client 68.155.159.216:18181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9DSJcY4fy7tP-rU3u7AAAAj0"] [Sat Aug 29 05:05:49.884975 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.104.62:20861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/1n73ction.php"] [unique_id "apK9DTAh5Y1i2tUxg4HpAwAABeQ"] [Sat Aug 29 05:05:49.901108 2026] [cgid:error] [pid 1017536:tid 1017675] [client 45.148.10.62:38250] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:49.920762 2026] [security2:error] [pid 1018003:tid 1018220] [client 20.104.18.15:36803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/new.php"] [unique_id "apK9DTAh5Y1i2tUxg4HpDQAABf0"] [Sat Aug 29 05:05:49.930047 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.18.15:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/run.php"] [unique_id "apK9DTAh5Y1i2tUxg4HpEQAABds"] [Sat Aug 29 05:05:49.930094 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.104.104.62:48656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/mcd.php"] [unique_id "apK9DTAh5Y1i2tUxg4HpEAAABeg"] [Sat Aug 29 05:05:49.930326 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.250.41:27586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/403.php"] [unique_id "apK9DTAh5Y1i2tUxg4HpEgAABgw"] [Sat Aug 29 05:05:49.932847 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:64252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK9DSJcY4fy7tP-rU3u8AAAAjI"] [Sat Aug 29 05:05:49.938681 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.104.62:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/wp-content/about.php"] [unique_id "apK9DSJcY4fy7tP-rU3u8QAAAiI"] [Sat Aug 29 05:05:49.953613 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.104.62:54529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/cafe.php"] [unique_id "apK9DTAh5Y1i2tUxg4HpFQAABdI"] [Sat Aug 29 05:05:49.983102 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.196.209.81:17055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK9DSJcY4fy7tP-rU3u8gAAAkw"] [Sat Aug 29 05:05:49.988837 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.104.18.15:8121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/admin.php"] [unique_id "apK9DSJcY4fy7tP-rU3u8wAAAjk"] [Sat Aug 29 05:05:49.991674 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.250.41:23367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/s1.php"] [unique_id "apK9DSJcY4fy7tP-rU3u9AAAAkI"] [Sat Aug 29 05:05:49.997920 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.104.104.62:10823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/gaje.php"] [unique_id "apK9DSJcY4fy7tP-rU3u9QAAAi4"] [Sat Aug 29 05:05:50.017852 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.23.147.79:32732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpGwAABiw"] [Sat Aug 29 05:05:50.021365 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.18.15:46971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.familiebon.com"] [uri "/reviall.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpHAAABiU"] [Sat Aug 29 05:05:50.025026 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.48.251.3:14004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/adminer-4.7.6-en.php"] [unique_id "apK9DiJcY4fy7tP-rU3u9gAAAhU"] [Sat Aug 29 05:05:50.027905 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.18.15:7090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/w3lls.php"] [unique_id "apK9DiJcY4fy7tP-rU3u9wAAApM"] [Sat Aug 29 05:05:50.047361 2026] [security2:error] [pid 1017536:tid 1017678] [client 4.232.148.111:8400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/m.php"] [unique_id "apK9DiJcY4fy7tP-rU3u-AAAAiA"] [Sat Aug 29 05:05:50.047752 2026] [security2:error] [pid 1018003:tid 1018050] [remote 47.128.24.73:49988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fivetownselc.org"] [uri "/robots.txt"] [unique_id "apK9DjAh5Y1i2tUxg4HpHwAFyh0"] [Sat Aug 29 05:05:50.048268 2026] [security2:error] [pid 1017536:tid 1017691] [client 68.155.159.216:51517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9DiJcY4fy7tP-rU3u-QAAAi0"] [Sat Aug 29 05:05:50.051094 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.158.54.35:22950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/p.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpIAAABfA"] [Sat Aug 29 05:05:50.056659 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.18.15:23471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/nofile.php"] [unique_id "apK9DiJcY4fy7tP-rU3u-wAAAic"] [Sat Aug 29 05:05:50.057171 2026] [cgid:error] [pid 1017536:tid 1017725] [client 45.148.10.62:38250] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:50.063407 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.48.250.41:27621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/cytyr.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpIQAABjY"] [Sat Aug 29 05:05:50.064705 2026] [security2:error] [pid 1017536:tid 1017674] [client 68.155.159.216:12163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/lock.php"] [unique_id "apK9DiJcY4fy7tP-rU3u_AAAAhw"] [Sat Aug 29 05:05:50.068091 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.18.15:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/new.php"] [unique_id "apK9DiJcY4fy7tP-rU3u_QAAAl4"] [Sat Aug 29 05:05:50.085014 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.104.62:22665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/eval.php"] [unique_id "apK9DiJcY4fy7tP-rU3u_gAAAjQ"] [Sat Aug 29 05:05:50.096094 2026] [security2:error] [pid 1018003:tid 1018252] [client 74.248.24.12:30414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpIwAABhw"] [Sat Aug 29 05:05:50.111039 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.18.15:36844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/inx.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpJAAABbk"] [Sat Aug 29 05:05:50.112481 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.147.79:25581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9DiJcY4fy7tP-rU3u_wAAAiU"] [Sat Aug 29 05:05:50.115431 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.104.62:48456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/waw.php"] [unique_id "apK9DiJcY4fy7tP-rU3vAAAAAlY"] [Sat Aug 29 05:05:50.126739 2026] [security2:error] [pid 1017536:tid 1017727] [client 68.155.159.216:14100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/goat1.php"] [unique_id "apK9DiJcY4fy7tP-rU3vAQAAAlE"] [Sat Aug 29 05:05:50.133151 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:39103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/66.php"] [unique_id "apK9DiJcY4fy7tP-rU3vAgAAAlo"] [Sat Aug 29 05:05:50.135591 2026] [security2:error] [pid 1017536:tid 1017726] [client 20.104.104.62:10819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/wp-admin/zwso.php"] [unique_id "apK9DiJcY4fy7tP-rU3vAwAAAlA"] [Sat Aug 29 05:05:50.140665 2026] [security2:error] [pid 1017536:tid 1017710] [client 4.205.62.107:64926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/agg.php"] [unique_id "apK9DiJcY4fy7tP-rU3vBQAAAkA"] [Sat Aug 29 05:05:50.142275 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.48.250.41:23385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/0byte.php"] [unique_id "apK9DiJcY4fy7tP-rU3vBgAAAlQ"] [Sat Aug 29 05:05:50.145210 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.104.62:64740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/374k.php"] [unique_id "apK9DiJcY4fy7tP-rU3vBwAAAms"] [Sat Aug 29 05:05:50.148040 2026] [security2:error] [pid 1017536:tid 1017713] [client 168.107.94.195:52210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9DiJcY4fy7tP-rU3vCAAAAkM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:50.153964 2026] [security2:error] [pid 1017536:tid 1017757] [client 192.145.125.70:51732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9DiJcY4fy7tP-rU3vCQAAAm8"] [Sat Aug 29 05:05:50.167198 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.104.18.15:7010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/fpwch.php"] [unique_id "apK9DiJcY4fy7tP-rU3vCgAAAog"] [Sat Aug 29 05:05:50.188766 2026] [security2:error] [pid 1018003:tid 1018089] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/php_info.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpKwAF4kQ"] [Sat Aug 29 05:05:50.211766 2026] [security2:error] [pid 1017536:tid 1017789] [client 45.148.10.62:38250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.wanderlustpictures.com"] [uri "/backend/.env"] [unique_id "apK9DiJcY4fy7tP-rU3vDQAAAo8"] [Sat Aug 29 05:05:50.213547 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.18.15:13244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/inx.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpLgAABc8"] [Sat Aug 29 05:05:50.215571 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.104.62:22656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/sao.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpLwAABdw"] [Sat Aug 29 05:05:50.228853 2026] [security2:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/phpinfo.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpMQAF7DE"] [Sat Aug 29 05:05:50.228865 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.18.15:23493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/run.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpMwAABf4"] [Sat Aug 29 05:05:50.253397 2026] [security2:error] [pid 1018003:tid 1018232] [client 20.104.18.15:8189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ws85.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpNQAABgg"] [Sat Aug 29 05:05:50.268753 2026] [security2:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/php.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpNwAGEUI"] [Sat Aug 29 05:05:50.268786 2026] [security2:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/php-info.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpOAAGETc"] [Sat Aug 29 05:05:50.269879 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.48.250.41:27626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/galer.php"] [unique_id "apK9DiJcY4fy7tP-rU3vDwAAAiE"] [Sat Aug 29 05:05:50.273470 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.104.62:10831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/Contrller.php"] [unique_id "apK9DiJcY4fy7tP-rU3vEAAAAig"] [Sat Aug 29 05:05:50.278365 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.250.41:23481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/xr.php"] [unique_id "apK9DiJcY4fy7tP-rU3vEQAAAlU"] [Sat Aug 29 05:05:50.281986 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.104.62:48699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/x23.php"] [unique_id "apK9DiJcY4fy7tP-rU3vEgAAAiM"] [Sat Aug 29 05:05:50.288384 2026] [security2:error] [pid 1017536:tid 1017785] [client 40.83.93.50:3159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/defaults.php"] [unique_id "apK9DiJcY4fy7tP-rU3vEwAAAos"] [Sat Aug 29 05:05:50.317799 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.18.15:7101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/domvf.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpPgAABdg"] [Sat Aug 29 05:05:50.318715 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.18.15:36689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/vpn.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpPwAABhA"] [Sat Aug 29 05:05:50.328998 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.104.62:38942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/elp.php"] [unique_id "apK9DiJcY4fy7tP-rU3vFAAAAnk"] [Sat Aug 29 05:05:50.345731 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.104.104.62:22670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/uuu.php"] [unique_id "apK9DiJcY4fy7tP-rU3vFQAAAiY"] [Sat Aug 29 05:05:50.366823 2026] [security2:error] [pid 1017536:tid 1017693] [client 45.148.10.62:38250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wanderlustpictures.com"] [uri "/test.php"] [unique_id "apK9DiJcY4fy7tP-rU3vFgAAAi8"] [Sat Aug 29 05:05:50.373939 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.49.130:47851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/ab.php"] [unique_id "apK9DiJcY4fy7tP-rU3vFwAAAh0"] [Sat Aug 29 05:05:50.379908 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.196.209.81:17098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-blog-header.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpRAAABfo"] [Sat Aug 29 05:05:50.385247 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.18.15:8190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ffs.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpRQAABhY"] [Sat Aug 29 05:05:50.394239 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.18.15:23524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/new.php"] [unique_id "apK9DiJcY4fy7tP-rU3vGAAAAmk"] [Sat Aug 29 05:05:50.394621 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:13141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/vpn.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpRgAABcA"] [Sat Aug 29 05:05:50.412136 2026] [security2:error] [pid 1018003:tid 1018198] [client 4.205.62.107:22222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/queue.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpSAAABec"] [Sat Aug 29 05:05:50.416689 2026] [security2:error] [pid 1018003:tid 1018258] [client 4.205.62.107:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/i.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpSQAABiI"] [Sat Aug 29 05:05:50.418005 2026] [security2:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/public/phpinfo.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpSwAF4So"] [Sat Aug 29 05:05:50.422185 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.49.130:63570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/read.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpTAAABiA"] [Sat Aug 29 05:05:50.429182 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.104.62:10465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/Zeiss.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpTQAABbw"] [Sat Aug 29 05:05:50.438714 2026] [security2:error] [pid 1017536:tid 1017694] [client 4.205.62.107:22369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/ccou.php"] [unique_id "apK9DiJcY4fy7tP-rU3vGQAAAjA"] [Sat Aug 29 05:05:50.440519 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.48.250.41:23491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/h02ugyh.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpUAAABcw"] [Sat Aug 29 05:05:50.450206 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.18.15:7126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/biufile.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpUQAABeU"] [Sat Aug 29 05:05:50.454321 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.104.49.130:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/wsd.php"] [unique_id "apK9DiJcY4fy7tP-rU3vGgAAAmw"] [Sat Aug 29 05:05:50.466795 2026] [security2:error] [pid 1017536:tid 1017722] [client 192.145.125.70:51746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xqk.etg.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK9DiJcY4fy7tP-rU3vGwAAAkw"] [Sat Aug 29 05:05:50.467844 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.18.15:36693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/shiny.php"] [unique_id "apK9DiJcY4fy7tP-rU3vHAAAAhs"] [Sat Aug 29 05:05:50.482844 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.104.62:22687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/private.php"] [unique_id "apK9DiJcY4fy7tP-rU3vHQAAApI"] [Sat Aug 29 05:05:50.487200 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.158.54.35:6963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/a1.php"] [unique_id "apK9DiJcY4fy7tP-rU3vHgAAAho"] [Sat Aug 29 05:05:50.494108 2026] [security2:error] [pid 1017536:tid 1017752] [client 4.205.62.107:2972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/myfile.php"] [unique_id "apK9DiJcY4fy7tP-rU3vHwAAAmo"] [Sat Aug 29 05:05:50.494451 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.48.250.41:27643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/baixy.php"] [unique_id "apK9DiJcY4fy7tP-rU3vIAAAAi4"] [Sat Aug 29 05:05:50.509688 2026] [security2:error] [pid 1018003:tid 1018167] [client 4.232.148.111:8421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpWQAABcg"] [Sat Aug 29 05:05:50.513155 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.104.104.62:48684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/ws66.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpWgAABig"] [Sat Aug 29 05:05:50.516941 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.104.18.15:8184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/nano.php"] [unique_id "apK9DiJcY4fy7tP-rU3vIgAAAhU"] [Sat Aug 29 05:05:50.524338 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.104.104.62:39052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/ioxi-o.php"] [unique_id "apK9DiJcY4fy7tP-rU3vJAAAAlM"] [Sat Aug 29 05:05:50.525176 2026] [security2:error] [pid 1018003:tid 1018245] [client 45.148.10.62:38264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.wanderlustpictures.com"] [uri "/.env.backup"] [unique_id "apK9DjAh5Y1i2tUxg4HpXwAABhU"] [Sat Aug 29 05:05:50.528780 2026] [security2:error] [pid 1018003:tid 1018202] [client 168.107.94.195:52514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpYgAABes"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:50.533396 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.104.62:64744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/cmd.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpZQAABeQ"] [Sat Aug 29 05:05:50.534679 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.104.18.15:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/inx.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpZgAABfk"] [Sat Aug 29 05:05:50.537442 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.18.15:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/shiny.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpZwAABdA"] [Sat Aug 29 05:05:50.564301 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.104.62:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/ww2.php"] [unique_id "apK9DiJcY4fy7tP-rU3vJwAAAkk"] [Sat Aug 29 05:05:50.591331 2026] [security2:error] [pid 1018003:tid 1018220] [client 20.48.250.41:23448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/xxw.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpbAAABf0"] [Sat Aug 29 05:05:50.604155 2026] [security2:error] [pid 1018003:tid 1018199] [client 158.23.147.79:50050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpbQAABeg"] [Sat Aug 29 05:05:50.615119 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.104.62:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/lfi.php"] [unique_id "apK9DiJcY4fy7tP-rU3vKQAAAok"] [Sat Aug 29 05:05:50.652074 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.104.18.15:8000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ano.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpcwAABcs"] [Sat Aug 29 05:05:50.654017 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.250.41:27492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ava.php"] [unique_id "apK9DiJcY4fy7tP-rU3vKwAAAlo"] [Sat Aug 29 05:05:50.659027 2026] [security2:error] [pid 1017536:tid 1017696] [client 74.248.24.12:29562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/m.php"] [unique_id "apK9DiJcY4fy7tP-rU3vLQAAAjI"] [Sat Aug 29 05:05:50.666865 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.18.15:7104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/blacks.php"] [unique_id "apK9DiJcY4fy7tP-rU3vLgAAAmE"] [Sat Aug 29 05:05:50.674171 2026] [security2:error] [pid 1018003:tid 1018275] [client 45.148.10.62:38264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.wanderlustpictures.com"] [uri "/.env.old"] [unique_id "apK9DjAh5Y1i2tUxg4HpdQAABjM"] [Sat Aug 29 05:05:50.682782 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.18.15:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/goods.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpdgAABdQ"] [Sat Aug 29 05:05:50.686610 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.18.15:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/goods.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpdwAABiw"] [Sat Aug 29 05:05:50.710886 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.104.62:10843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/anz.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpeQAABco"] [Sat Aug 29 05:05:50.731683 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.104.62:48753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/Cok.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpfAAABhI"] [Sat Aug 29 05:05:50.747367 2026] [access_compat:error] [pid 1018003:tid 1018029] [remote 52.167.144.65:0] AH01797: client denied by server configuration: /home1/giantsfa/public_html/robots.txt [Sat Aug 29 05:05:50.755934 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.104.62:55017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/quoys.php"] [unique_id "apK9DiJcY4fy7tP-rU3vMAAAAoY"] [Sat Aug 29 05:05:50.759924 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.18.15:23499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/vpn.php"] [unique_id "apK9DiJcY4fy7tP-rU3vMQAAAlg"] [Sat Aug 29 05:05:50.775700 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.196.209.81:17026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-blogs.php"] [unique_id "apK9DiJcY4fy7tP-rU3vMgAAAlE"] [Sat Aug 29 05:05:50.778270 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.250.41:23301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/bolt.php"] [unique_id "apK9DiJcY4fy7tP-rU3vMwAAAkM"] [Sat Aug 29 05:05:50.794285 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.104.104.62:38926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/wp-links-opml.php"] [unique_id "apK9DiJcY4fy7tP-rU3vNAAAAm8"] [Sat Aug 29 05:05:50.797433 2026] [security2:error] [pid 1017536:tid 1017668] [client 68.155.159.216:52823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-admin/about.php"] [unique_id "apK9DiJcY4fy7tP-rU3vNQAAAhY"] [Sat Aug 29 05:05:50.799321 2026] [security2:error] [pid 1017536:tid 1017732] [client 40.83.93.50:14442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/post.php"] [unique_id "apK9DiJcY4fy7tP-rU3vNgAAAlY"] [Sat Aug 29 05:05:50.801076 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.250.41:27581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/gdn.php"] [unique_id "apK9DiJcY4fy7tP-rU3vNwAAAmQ"] [Sat Aug 29 05:05:50.808183 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.104.18.15:7048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/beck.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpiQAABhM"] [Sat Aug 29 05:05:50.819651 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.18.15:13152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/alfa.php"] [unique_id "apK9DiJcY4fy7tP-rU3vOAAAAnM"] [Sat Aug 29 05:05:50.821063 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.104.18.15:8169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/mgrr.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpigAABiE"] [Sat Aug 29 05:05:50.822650 2026] [security2:error] [pid 1017536:tid 1017742] [client 68.155.159.216:24557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9DiJcY4fy7tP-rU3vOQAAAmA"] [Sat Aug 29 05:05:50.831801 2026] [security2:error] [pid 1017536:tid 1017723] [client 4.205.62.107:55943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/rem.php"] [unique_id "apK9DiJcY4fy7tP-rU3vOgAAAk0"] [Sat Aug 29 05:05:50.841617 2026] [cgid:error] [pid 1018003:tid 1018193] [client 45.148.10.62:38264] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:50.859386 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.104.62:10474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/bge.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpjQAABgo"] [Sat Aug 29 05:05:50.859902 2026] [security2:error] [pid 1018003:tid 1018248] [client 68.155.159.216:51539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/dropdown.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpjgAABhg"] [Sat Aug 29 05:05:50.860487 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.18.15:36840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/alfa.php"] [unique_id "apK9DiJcY4fy7tP-rU3vPQAAAos"] [Sat Aug 29 05:05:50.862914 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.251.3:14321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/phpi.php"] [unique_id "apK9DiJcY4fy7tP-rU3vPgAAAjo"] [Sat Aug 29 05:05:50.863691 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.104.104.62:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/jkt48_1.php"] [unique_id "apK9DiJcY4fy7tP-rU3vPwAAAkQ"] [Sat Aug 29 05:05:50.891813 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.104.62:22712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/vbbn.php"] [unique_id "apK9DjAh5Y1i2tUxg4HplQAABgk"] [Sat Aug 29 05:05:50.893279 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.104.18.15:23507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/shiny.php"] [unique_id "apK9DjAh5Y1i2tUxg4HplgAABfg"] [Sat Aug 29 05:05:50.908206 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.250.41:23497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/rtx.php"] [unique_id "apK9DiJcY4fy7tP-rU3vSAAAAoI"] [Sat Aug 29 05:05:50.911799 2026] [security2:error] [pid 1017536:tid 1017773] [client 168.107.94.195:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9DiJcY4fy7tP-rU3vSQAAAn8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:50.914747 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.68.135:16060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/sm.php"] [unique_id "apK9DiJcY4fy7tP-rU3vSgAAAjA"] [Sat Aug 29 05:05:50.915813 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.104.104.62:48497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/X7T6.php"] [unique_id "apK9DiJcY4fy7tP-rU3vSwAAAkc"] [Sat Aug 29 05:05:50.935176 2026] [security2:error] [pid 1017536:tid 1017722] [client 158.23.147.79:30664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9DiJcY4fy7tP-rU3vTAAAAkw"] [Sat Aug 29 05:05:50.937672 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.158.54.35:21810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpmQAABis"] [Sat Aug 29 05:05:50.938137 2026] [security2:error] [pid 1018003:tid 1018254] [client 4.205.62.107:53318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/xve22.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpmgAABh4"] [Sat Aug 29 05:05:50.943807 2026] [security2:error] [pid 1017536:tid 1017792] [client 68.155.159.216:50267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9DiJcY4fy7tP-rU3vTQAAApI"] [Sat Aug 29 05:05:50.947487 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.104.18.15:7137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/t3.php"] [unique_id "apK9DiJcY4fy7tP-rU3vTgAAAho"] [Sat Aug 29 05:05:50.954000 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.18.15:8161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/mac.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpnAAABeA"] [Sat Aug 29 05:05:50.980340 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.147.79:30609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9DiJcY4fy7tP-rU3vTwAAAnw"] [Sat Aug 29 05:05:50.984828 2026] [security2:error] [pid 1017536:tid 1017729] [client 68.155.159.216:18306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9DiJcY4fy7tP-rU3vUAAAAlM"] [Sat Aug 29 05:05:50.987114 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.104.104.62:44548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/wp-ana.php"] [unique_id "apK9DiJcY4fy7tP-rU3vUQAAAj0"] [Sat Aug 29 05:05:50.988504 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.104.62:39096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/feokc.php"] [unique_id "apK9DjAh5Y1i2tUxg4HpngAABi8"] [Sat Aug 29 05:05:50.989128 2026] [security2:error] [pid 1017536:tid 1017721] [client 4.232.148.111:33813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/222.php"] [unique_id "apK9DiJcY4fy7tP-rU3vUgAAAks"] [Sat Aug 29 05:05:50.989651 2026] [security2:error] [pid 1018003:tid 1018240] [client 45.148.10.62:38264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wanderlustpictures.com"] [uri "/.env.php.bak"] [unique_id "apK9DjAh5Y1i2tUxg4HpnwAABhA"] [Sat Aug 29 05:05:50.995665 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.18.15:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/33.php"] [unique_id "apK9DiJcY4fy7tP-rU3vUwAAApA"] [Sat Aug 29 05:05:51.012315 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.49.130:60770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/btyuio.php"] [unique_id "apK9DyJcY4fy7tP-rU3vVQAAAik"] [Sat Aug 29 05:05:51.021091 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.104.104.62:22707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/rfi.php"] [unique_id "apK9DyJcY4fy7tP-rU3vVgAAAmI"] [Sat Aug 29 05:05:51.023686 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.18.15:36703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/33.php"] [unique_id "apK9DyJcY4fy7tP-rU3vVwAAAkk"] [Sat Aug 29 05:05:51.026303 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.18.15:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/goods.php"] [unique_id "apK9DyJcY4fy7tP-rU3vWAAAAow"] [Sat Aug 29 05:05:51.036556 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.250.41:23473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/ckk.php"] [unique_id "apK9DyJcY4fy7tP-rU3vWQAAAjQ"] [Sat Aug 29 05:05:51.051643 2026] [security2:error] [pid 1017536:tid 1017778] [client 68.155.159.216:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/ans.php"] [unique_id "apK9DyJcY4fy7tP-rU3vXAAAAoQ"] [Sat Aug 29 05:05:51.056885 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.250.41:27606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/f2.php"] [unique_id "apK9DyJcY4fy7tP-rU3vXwAAAj8"] [Sat Aug 29 05:05:51.076723 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:7091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp.php"] [unique_id "apK9DyJcY4fy7tP-rU3vYQAAAkA"] [Sat Aug 29 05:05:51.101424 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:58275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpowAABd8"] [Sat Aug 29 05:05:51.128189 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:13219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/133.php"] [unique_id "apK9DzAh5Y1i2tUxg4HppgAABec"] [Sat Aug 29 05:05:51.131499 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.104.18.15:8160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/simple.php"] [unique_id "apK9DyJcY4fy7tP-rU3vYwAAAmQ"] [Sat Aug 29 05:05:51.135470 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.104.104.62:44563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/secret.php"] [unique_id "apK9DyJcY4fy7tP-rU3vZAAAAj4"] [Sat Aug 29 05:05:51.144706 2026] [security2:error] [pid 1018003:tid 1018258] [client 45.148.10.62:38224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wanderlustpictures.com"] [uri "/.env.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpqAAABiI"] [Sat Aug 29 05:05:51.147842 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:20648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/adminer.php"] [unique_id "apK9DyJcY4fy7tP-rU3vZQAAAnM"] [Sat Aug 29 05:05:51.155013 2026] [security2:error] [pid 1017536:tid 1017674] [client 103.171.189.88:52600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9DyJcY4fy7tP-rU3vZgAAAhw"] [Sat Aug 29 05:05:51.155123 2026] [security2:error] [pid 1017536:tid 1017674] [client 103.171.189.88:52600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9DyJcY4fy7tP-rU3vZgAAAhw"] [Sat Aug 29 05:05:51.155327 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.147.79:32756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpqQAABeE"] [Sat Aug 29 05:05:51.156188 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.104.104.62:22714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/tajj.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpqgAABcw"] [Sat Aug 29 05:05:51.174531 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.104.62:48452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/see.php"] [unique_id "apK9DyJcY4fy7tP-rU3vaQAAAoc"] [Sat Aug 29 05:05:51.176703 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.196.209.81:17065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-comments-post.php"] [unique_id "apK9DyJcY4fy7tP-rU3vagAAAjw"] [Sat Aug 29 05:05:51.180345 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.104.104.62:39074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/k.php"] [unique_id "apK9DyJcY4fy7tP-rU3vawAAAm8"] [Sat Aug 29 05:05:51.181963 2026] [security2:error] [pid 1017536:tid 1017760] [client 158.23.147.79:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-login.php"] [unique_id "apK9DyJcY4fy7tP-rU3vbAAAAnI"] [Sat Aug 29 05:05:51.183155 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.18.15:23373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/alfa.php"] [unique_id "apK9DyJcY4fy7tP-rU3vbQAAAoE"] [Sat Aug 29 05:05:51.183169 2026] [security2:error] [pid 1018003:tid 1018172] [client 68.155.159.216:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/index/function.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpsgAABc0"] [Sat Aug 29 05:05:51.185583 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.104.68.135:18478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/shell.php"] [unique_id "apK9DyJcY4fy7tP-rU3vbwAAAo4"] [Sat Aug 29 05:05:51.209734 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.250.41:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/grsiuk.php"] [unique_id "apK9DyJcY4fy7tP-rU3vcAAAAnc"] [Sat Aug 29 05:05:51.212605 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.18.15:7081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/abcd.php"] [unique_id "apK9DyJcY4fy7tP-rU3vcQAAAnc"] [Sat Aug 29 05:05:51.213849 2026] [security2:error] [pid 1017536:tid 1017695] [client 74.248.24.12:41009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "apK9DyJcY4fy7tP-rU3vcgAAAjE"] [Sat Aug 29 05:05:51.222259 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.23.147.79:25544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/asd.php"] [unique_id "apK9DyJcY4fy7tP-rU3vcwAAAos"] [Sat Aug 29 05:05:51.223518 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.48.250.41:23376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gocreativesolar.hawesinc.com"] [uri "/R57.php"] [unique_id "apK9DzAh5Y1i2tUxg4HptAAABeM"] [Sat Aug 29 05:05:51.253618 2026] [security2:error] [pid 1017536:tid 1017693] [client 61.9.8.240:1749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9DyJcY4fy7tP-rU3vdAAAAi8"] [Sat Aug 29 05:05:51.253748 2026] [security2:error] [pid 1017536:tid 1017693] [client 61.9.8.240:1749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9DyJcY4fy7tP-rU3vdAAAAi8"] [Sat Aug 29 05:05:51.262911 2026] [security2:error] [pid 1017536:tid 1017777] [client 68.155.159.216:14227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9DyJcY4fy7tP-rU3vdQAAAoM"] [Sat Aug 29 05:05:51.264032 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.18.15:8066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/xty.php"] [unique_id "apK9DyJcY4fy7tP-rU3vdgAAAmk"] [Sat Aug 29 05:05:51.271922 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.104.62:44604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/pro.php"] [unique_id "apK9DyJcY4fy7tP-rU3vdwAAAiI"] [Sat Aug 29 05:05:51.279489 2026] [security2:error] [pid 1017536:tid 1017768] [client 4.205.62.107:64195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/requirements.php"] [unique_id "apK9DyJcY4fy7tP-rU3veQAAAno"] [Sat Aug 29 05:05:51.291514 2026] [security2:error] [pid 1017536:tid 1017792] [client 168.107.94.195:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9DyJcY4fy7tP-rU3vfAAAApI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:51.298643 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.104.104.62:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/grsiuk.php"] [unique_id "apK9DyJcY4fy7tP-rU3vfwAAAmo"] [Sat Aug 29 05:05:51.298874 2026] [cgid:error] [pid 1017536:tid 1017724] [client 45.148.10.62:38238] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:51.302454 2026] [security2:error] [pid 1017536:tid 1017669] [client 149.34.210.141:15458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9DyJcY4fy7tP-rU3vgQAAAhc"] [Sat Aug 29 05:05:51.302543 2026] [security2:error] [pid 1017536:tid 1017669] [client 149.34.210.141:15458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9DyJcY4fy7tP-rU3vgQAAAhc"] [Sat Aug 29 05:05:51.308491 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.104.18.15:13302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/sym.php"] [unique_id "apK9DyJcY4fy7tP-rU3vgwAAAhU"] [Sat Aug 29 05:05:51.327525 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.23.147.79:24419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpuwAABh8"] [Sat Aug 29 05:05:51.333204 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.18.15:23522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/33.php"] [unique_id "apK9DyJcY4fy7tP-rU3vhAAAAic"] [Sat Aug 29 05:05:51.358171 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.104.18.15:7002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/nofile.php"] [unique_id "apK9DyJcY4fy7tP-rU3vhwAAAmI"] [Sat Aug 29 05:05:51.374317 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.104.62:48515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/horeg.php"] [unique_id "apK9DyJcY4fy7tP-rU3viQAAAow"] [Sat Aug 29 05:05:51.374517 2026] [security2:error] [pid 1017536:tid 1017789] [client 40.83.93.50:3178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/csv.php"] [unique_id "apK9DyJcY4fy7tP-rU3viAAAAo8"] [Sat Aug 29 05:05:51.374816 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.104.104.62:38932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/tx78.php"] [unique_id "apK9DyJcY4fy7tP-rU3vigAAAnY"] [Sat Aug 29 05:05:51.375762 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.158.54.35:6919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/alfa-rex.php7"] [unique_id "apK9DyJcY4fy7tP-rU3viwAAAkQ"] [Sat Aug 29 05:05:51.376730 2026] [security2:error] [pid 1017536:tid 1017690] [client 158.23.147.79:48284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/languages/about.php"] [unique_id "apK9DyJcY4fy7tP-rU3vjAAAAiw"] [Sat Aug 29 05:05:51.380531 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.68.135:16001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/simple.php"] [unique_id "apK9DyJcY4fy7tP-rU3vjQAAAiA"] [Sat Aug 29 05:05:51.401024 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.104.18.15:8129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/sallu.php"] [unique_id "apK9DyJcY4fy7tP-rU3vjwAAAlU"] [Sat Aug 29 05:05:51.409513 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.104.62:10445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/999.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpwQAABcg"] [Sat Aug 29 05:05:51.434094 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.104.104.62:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/ahy66.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpwwAABig"] [Sat Aug 29 05:05:51.450957 2026] [cgid:error] [pid 1017536:tid 1017713] [client 45.148.10.62:38238] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:51.455682 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.18.15:13224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/8.php"] [unique_id "apK9DyJcY4fy7tP-rU3vkQAAAhY"] [Sat Aug 29 05:05:51.458781 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.48.250.41:26918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wp-scr1pts.php"] [unique_id "apK9DyJcY4fy7tP-rU3vkgAAAok"] [Sat Aug 29 05:05:51.463517 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.104.62:40203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/rootx.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpxwAABiY"] [Sat Aug 29 05:05:51.464924 2026] [security2:error] [pid 1017536:tid 1017692] [client 4.232.148.111:34943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/mini.php"] [unique_id "apK9DyJcY4fy7tP-rU3vlAAAAi4"] [Sat Aug 29 05:05:51.479997 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.104.18.15:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/133.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpzAAABic"] [Sat Aug 29 05:05:51.503701 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.48.251.3:13965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpzQAABfw"] [Sat Aug 29 05:05:51.508747 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.18.15:23518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/133.php"] [unique_id "apK9DyJcY4fy7tP-rU3vlQAAAjw"] [Sat Aug 29 05:05:51.517070 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:7089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/run.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpzgAABes"] [Sat Aug 29 05:05:51.540792 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.104.104.62:44559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/sef.php"] [unique_id "apK9DyJcY4fy7tP-rU3vlgAAAhg"] [Sat Aug 29 05:05:51.543476 2026] [security2:error] [pid 1018003:tid 1018184] [client 4.205.62.107:22317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/plss3.php"] [unique_id "apK9DzAh5Y1i2tUxg4HpzwAABdk"] [Sat Aug 29 05:05:51.555844 2026] [security2:error] [pid 1018003:tid 1018164] [client 4.205.62.107:65521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/guk.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp0QAABcU"] [Sat Aug 29 05:05:51.564991 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.18.15:8091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/codex.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp0gAABdA"] [Sat Aug 29 05:05:51.567330 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.104.62:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/gaje.php"] [unique_id "apK9DyJcY4fy7tP-rU3vmQAAAiM"] [Sat Aug 29 05:05:51.568160 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.104.62:39075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9DyJcY4fy7tP-rU3vmgAAAoc"] [Sat Aug 29 05:05:51.575947 2026] [security2:error] [pid 1017536:tid 1017695] [client 4.205.62.107:22210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/66.php"] [unique_id "apK9DyJcY4fy7tP-rU3vmwAAAjE"] [Sat Aug 29 05:05:51.577182 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.104.68.135:16026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-admin.php"] [unique_id "apK9DyJcY4fy7tP-rU3vnAAAAm8"] [Sat Aug 29 05:05:51.579582 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.196.209.81:17081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-config.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp0wAABgQ"] [Sat Aug 29 05:05:51.584403 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.104.62:48587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/basic.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp1gAABik"] [Sat Aug 29 05:05:51.600958 2026] [cgid:error] [pid 1017536:tid 1017705] [client 45.148.10.62:38238] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:51.614614 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.18.15:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/goods.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp2gAABds"] [Sat Aug 29 05:05:51.629487 2026] [security2:error] [pid 1018003:tid 1018251] [client 20.48.250.41:27474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/num.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp3gAABhs"] [Sat Aug 29 05:05:51.631040 2026] [security2:error] [pid 1018003:tid 1018160] [client 4.205.62.107:3005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/thui.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp3wAABcE"] [Sat Aug 29 05:05:51.649890 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/sym.php"] [unique_id "apK9DyJcY4fy7tP-rU3vngAAAh0"] [Sat Aug 29 05:05:51.657958 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.18.15:23375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/sym.php"] [unique_id "apK9DyJcY4fy7tP-rU3vnwAAAi0"] [Sat Aug 29 05:05:51.663675 2026] [security2:error] [pid 1018003:tid 1018205] [client 20.104.18.15:6980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/new.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp4AAABe4"] [Sat Aug 29 05:05:51.668784 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.104.62:10491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/admin123.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp4QAABfs"] [Sat Aug 29 05:05:51.671964 2026] [security2:error] [pid 1018003:tid 1018151] [client 168.107.94.195:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp4gAABbg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:51.701022 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.104.62:54540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/wp-admin/zwso.php"] [unique_id "apK9DyJcY4fy7tP-rU3voAAAAmk"] [Sat Aug 29 05:05:51.721715 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.18.15:8093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/5656.php"] [unique_id "apK9DyJcY4fy7tP-rU3voQAAAn8"] [Sat Aug 29 05:05:51.725720 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.104.49.130:60943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/xa.php"] [unique_id "apK9DyJcY4fy7tP-rU3vogAAAkc"] [Sat Aug 29 05:05:51.731218 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.104.62:20837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/ls.php"] [unique_id "apK9DyJcY4fy7tP-rU3vowAAAmY"] [Sat Aug 29 05:05:51.757868 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.18.15:13153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ah.php"] [unique_id "apK9DyJcY4fy7tP-rU3vpQAAApI"] [Sat Aug 29 05:05:51.759447 2026] [cgid:error] [pid 1017536:tid 1017673] [client 45.148.10.62:38238] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:51.760939 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.104.104.62:48527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/monso.php"] [unique_id "apK9DyJcY4fy7tP-rU3vpgAAAk4"] [Sat Aug 29 05:05:51.762078 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.104.62:39088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/wp-content/sallu.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp6QAABfU"] [Sat Aug 29 05:05:51.774268 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.104.68.135:38419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "apK9DyJcY4fy7tP-rU3vpwAAAoI"] [Sat Aug 29 05:05:51.799610 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.104.62:10464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/7h.php"] [unique_id "apK9DyJcY4fy7tP-rU3vqAAAAik"] [Sat Aug 29 05:05:51.801329 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.18.15:7057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/inx.php"] [unique_id "apK9DyJcY4fy7tP-rU3vqQAAAow"] [Sat Aug 29 05:05:51.809707 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.250.41:27470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/a4.php"] [unique_id "apK9DyJcY4fy7tP-rU3vqgAAAkQ"] [Sat Aug 29 05:05:51.820431 2026] [security2:error] [pid 1018003:tid 1018177] [client 74.248.24.12:40944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/222.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp7QAABdI"] [Sat Aug 29 05:05:51.830444 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.18.15:23496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/8.php"] [unique_id "apK9DyJcY4fy7tP-rU3vqwAAAiA"] [Sat Aug 29 05:05:51.835659 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.18.15:36682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/8.php"] [unique_id "apK9DyJcY4fy7tP-rU3vrAAAAis"] [Sat Aug 29 05:05:51.838866 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:22711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/Contrller.php"] [unique_id "apK9DyJcY4fy7tP-rU3vrQAAAlo"] [Sat Aug 29 05:05:51.844332 2026] [security2:error] [pid 1017536:tid 1017777] [client 158.158.54.35:22027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK9DyJcY4fy7tP-rU3vrgAAAoM"] [Sat Aug 29 05:05:51.862679 2026] [security2:error] [pid 1018003:tid 1018154] [client 40.83.93.50:7762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/fox.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp7gAABbs"] [Sat Aug 29 05:05:51.909914 2026] [security2:error] [pid 1018003:tid 1018241] [client 20.104.18.15:7953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/w3lls.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp7wAABhE"] [Sat Aug 29 05:05:51.916601 2026] [cgid:error] [pid 1017536:tid 1017732] [client 45.148.10.62:38238] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:51.919681 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.18.15:13288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ws55.php"] [unique_id "apK9DyJcY4fy7tP-rU3vsQAAAlY"] [Sat Aug 29 05:05:51.932660 2026] [security2:error] [pid 1018003:tid 1018152] [client 4.232.148.111:8384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/aa.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp8AAABbk"] [Sat Aug 29 05:05:51.933766 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.104.62:44582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/wp-gzone.php"] [unique_id "apK9DyJcY4fy7tP-rU3vsgAAAiM"] [Sat Aug 29 05:05:51.934050 2026] [security2:error] [pid 1018003:tid 1018254] [client 20.197.61.180:13006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp8QAABh4"] [Sat Aug 29 05:05:51.938304 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.18.15:7134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/vpn.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp8wAABew"] [Sat Aug 29 05:05:51.946351 2026] [security2:error] [pid 1017536:tid 1017695] [client 68.155.159.216:24459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/radio.php"] [unique_id "apK9DyJcY4fy7tP-rU3vswAAAjE"] [Sat Aug 29 05:05:51.966906 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.104.62:39058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/0.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp9AAABd0"] [Sat Aug 29 05:05:51.967262 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:51409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/sad/about.php"] [unique_id "apK9DyJcY4fy7tP-rU3vtAAAAjo"] [Sat Aug 29 05:05:51.970750 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.104.104.62:22673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/Zeiss.php"] [unique_id "apK9DyJcY4fy7tP-rU3vtQAAAjk"] [Sat Aug 29 05:05:51.972230 2026] [security2:error] [pid 1017536:tid 1017754] [client 4.205.62.107:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/min.php"] [unique_id "apK9DyJcY4fy7tP-rU3vtgAAAmw"] [Sat Aug 29 05:05:51.974243 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.68.135:23814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-admin/includes/about.php"] [unique_id "apK9DyJcY4fy7tP-rU3vtwAAAoE"] [Sat Aug 29 05:05:51.978738 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.196.209.81:17415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-configs.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp-gAABdw"] [Sat Aug 29 05:05:51.979545 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.104.62:48648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/rce.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp-wAABi8"] [Sat Aug 29 05:05:51.986054 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.18.15:23525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/goods.php"] [unique_id "apK9DzAh5Y1i2tUxg4Hp_AAABhA"] [Sat Aug 29 05:05:52.005828 2026] [cgid:error] [pid 1017536:tid 1017734] [client 34.7.40.70:4418] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.020849 2026] [security2:error] [pid 1018003:tid 1018185] [client 34.7.40.70:4482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/var/www/html/.env"] [unique_id "apK9EDAh5Y1i2tUxg4Hp_wAABdo"] [Sat Aug 29 05:05:52.023759 2026] [cgid:error] [pid 1017536:tid 1017746] [client 34.7.40.70:4448] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.024646 2026] [cgid:error] [pid 1017536:tid 1017708] [client 34.7.40.70:4542] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.025635 2026] [security2:error] [pid 1017536:tid 1017721] [client 34.7.40.70:4470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/var/www/.env"] [unique_id "apK9ECJcY4fy7tP-rU3vvAAAAks"] [Sat Aug 29 05:05:52.033262 2026] [cgid:error] [pid 1017536:tid 1017692] [client 34.7.40.70:4508] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.034279 2026] [cgid:error] [pid 1017536:tid 1017772] [client 34.7.40.70:4502] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.035046 2026] [cgid:error] [pid 1018003:tid 1018232] [client 34.7.40.70:4496] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.035471 2026] [security2:error] [pid 1018003:tid 1018235] [client 34.7.40.70:4490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/usr/src/app/.env"] [unique_id "apK9EDAh5Y1i2tUxg4HqAQAABgs"] [Sat Aug 29 05:05:52.047567 2026] [cgid:error] [pid 1018003:tid 1018215] [client 34.7.40.70:4518] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.048800 2026] [cgid:error] [pid 1018003:tid 1018200] [client 34.7.40.70:4484] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.049147 2026] [security2:error] [pid 1018003:tid 1018200] [client 34.7.40.70:4484] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9EDAh5Y1i2tUxg4HqAwAABek"] [Sat Aug 29 05:05:52.049146 2026] [security2:error] [pid 1018003:tid 1018215] [client 34.7.40.70:4518] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9EDAh5Y1i2tUxg4HqAgAABfg"] [Sat Aug 29 05:05:52.049612 2026] [cgid:error] [pid 1018003:tid 1018274] [client 34.7.40.70:4454] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.049716 2026] [security2:error] [pid 1018003:tid 1018274] [client 34.7.40.70:4454] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9EDAh5Y1i2tUxg4HqBAAABjI"] [Sat Aug 29 05:05:52.050201 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.147.79:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9ECJcY4fy7tP-rU3vwQAAAn8"] [Sat Aug 29 05:05:52.051071 2026] [cgid:error] [pid 1017536:tid 1017674] [client 34.7.40.70:4420] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.051501 2026] [security2:error] [pid 1018003:tid 1018198] [client 168.107.94.195:53978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqBQAABec"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:52.052771 2026] [cgid:error] [pid 1017536:tid 1017743] [client 34.7.40.70:4528] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.057347 2026] [security2:error] [pid 1017536:tid 1017761] [client 34.7.40.70:4432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/home/ubuntu/.env"] [unique_id "apK9ECJcY4fy7tP-rU3vwgAAAnM"] [Sat Aug 29 05:05:52.059930 2026] [cgid:error] [pid 1017536:tid 1017712] [client 34.7.40.70:4556] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:52.063553 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.104.18.15:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/drykl.php"] [unique_id "apK9ECJcY4fy7tP-rU3vxAAAAkc"] [Sat Aug 29 05:05:52.066106 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.104.62:10480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/str.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqBgAABcA"] [Sat Aug 29 05:05:52.066286 2026] [security2:error] [pid 1017536:tid 1017748] [client 45.148.10.62:38238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wanderlustpictures.com"] [uri "/wp-config.php"] [unique_id "apK9ECJcY4fy7tP-rU3vxQAAAmY"] [Sat Aug 29 05:05:52.072952 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.104.18.15:8171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/fpwch.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqBwAABcM"] [Sat Aug 29 05:05:52.078630 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.48.250.41:27504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/tfm.php"] [unique_id "apK9ECJcY4fy7tP-rU3vxgAAAkw"] [Sat Aug 29 05:05:52.079105 2026] [security2:error] [pid 1017536:tid 1017768] [client 158.23.147.79:30614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/asd.php"] [unique_id "apK9ECJcY4fy7tP-rU3vxwAAAno"] [Sat Aug 29 05:05:52.085830 2026] [security2:error] [pid 1018003:tid 1018258] [client 4.205.62.107:8972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/privacy.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqCAAABiI"] [Sat Aug 29 05:05:52.114847 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.104.62:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/ww2.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqCwAABc0"] [Sat Aug 29 05:05:52.136657 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.104.62:48683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/exec.php"] [unique_id "apK9ECJcY4fy7tP-rU3vygAAApM"] [Sat Aug 29 05:05:52.139154 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.104.49.130:57518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/js.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqDQAABd4"] [Sat Aug 29 05:05:52.157110 2026] [security2:error] [pid 1017536:tid 1017770] [client 68.155.159.216:51501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin.php"] [unique_id "apK9ECJcY4fy7tP-rU3vywAAAnw"] [Sat Aug 29 05:05:52.162495 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.104.104.62:39077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/aa.php"] [unique_id "apK9ECJcY4fy7tP-rU3vzQAAAmo"] [Sat Aug 29 05:05:52.167636 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.68.135:18450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-admin/js/index.php"] [unique_id "apK9ECJcY4fy7tP-rU3vzgAAAhc"] [Sat Aug 29 05:05:52.197587 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.104.62:10857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/mega.php"] [unique_id "apK9ECJcY4fy7tP-rU3vzwAAAko"] [Sat Aug 29 05:05:52.213991 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.104.62:20859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/sym2019.php"] [unique_id "apK9ECJcY4fy7tP-rU3v0AAAAoM"] [Sat Aug 29 05:05:52.214375 2026] [security2:error] [pid 1017536:tid 1017730] [client 68.155.159.216:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9ECJcY4fy7tP-rU3v0QAAAlQ"] [Sat Aug 29 05:05:52.226061 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.104.62:52063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9ECJcY4fy7tP-rU3v0gAAAok"] [Sat Aug 29 05:05:52.258720 2026] [security2:error] [pid 1018003:tid 1018170] [client 74.7.228.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ministeriosemanuel.org"] [uri "/cgi-sys/404.html"] [unique_id "apK9EDAh5Y1i2tUxg4HqHAAABcs"] [Sat Aug 29 05:05:52.269056 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.250.41:27632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/Geforce.php"] [unique_id "apK9ECJcY4fy7tP-rU3v1QAAAjE"] [Sat Aug 29 05:05:52.274499 2026] [security2:error] [pid 1017536:tid 1017685] [client 74.7.228.11:48684] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ministeriosemanuel.org"] [uri "/robots.txt"] [unique_id "apK9ECJcY4fy7tP-rU3v0wACJ3I"] [Sat Aug 29 05:05:52.277502 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.104.62:22696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/anz.php"] [unique_id "apK9ECJcY4fy7tP-rU3v1wAAAos"] [Sat Aug 29 05:05:52.280636 2026] [security2:error] [pid 1017536:tid 1017760] [client 66.248.203.2:17862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2014/04/07/underpaid-really/"] [unique_id "apK9ECJcY4fy7tP-rU3v2AAAAnI"] [Sat Aug 29 05:05:52.286935 2026] [security2:error] [pid 1018003:tid 1018205] [client 158.23.147.79:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqHwAABe4"] [Sat Aug 29 05:05:52.293239 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.158.54.35:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/upload.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqIAAABgM"] [Sat Aug 29 05:05:52.322023 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.49.130:60981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/m.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqIwAABfs"] [Sat Aug 29 05:05:52.328527 2026] [security2:error] [pid 1017536:tid 1017688] [client 158.23.147.79:25575] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/1.php"] [unique_id "apK9ECJcY4fy7tP-rU3v2QAAAio"] [Sat Aug 29 05:05:52.328619 2026] [security2:error] [pid 1017536:tid 1017688] [client 158.23.147.79:25575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/1.php"] [unique_id "apK9ECJcY4fy7tP-rU3v2QAAAio"] [Sat Aug 29 05:05:52.347576 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.104.62:10435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/ww3.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqJgAABiw"] [Sat Aug 29 05:05:52.354375 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.49.130:30054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/well.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqJwAABiU"] [Sat Aug 29 05:05:52.357304 2026] [security2:error] [pid 1017536:tid 1017744] [client 40.83.93.50:7801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/disagraeosc.php"] [unique_id "apK9ECJcY4fy7tP-rU3v2gAAAmI"] [Sat Aug 29 05:05:52.364619 2026] [security2:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/test.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqKQAGM0c"] [Sat Aug 29 05:05:52.369810 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:14335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-admin/network/index.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqKgAABco"] [Sat Aug 29 05:05:52.371471 2026] [cgid:error] [pid 1017536:tid 1017704] [client 20.104.104.62:39055] AH01265: stderr from /home2/gollnet/public_html/cgi-bin/: attempt to invoke directory as script [Sat Aug 29 05:05:52.372052 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.196.209.81:17118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-conflg.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqKwAABgw"] [Sat Aug 29 05:05:52.378210 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.197.61.180:6060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/options-general.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqLQAABeM"] [Sat Aug 29 05:05:52.378906 2026] [proxy_http:error] [pid 1017536:tid 1017786] (20014)Internal error (specific information not available): [client 34.21.253.104:54408] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.379139 2026] [proxy:error] [pid 1017536:tid 1017786] [client 34.21.253.104:54408] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/v2/.env [Sat Aug 29 05:05:52.380791 2026] [security2:error] [pid 1017536:tid 1017714] [client 34.21.253.104:54414] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/v1/.env"] [unique_id "apK9ECJcY4fy7tP-rU3v4QAAAkQ"] [Sat Aug 29 05:05:52.381677 2026] [security2:error] [pid 1017536:tid 1017740] [client 34.21.253.104:54494] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/env.json"] [unique_id "apK9ECJcY4fy7tP-rU3v4gAAAl4"] [Sat Aug 29 05:05:52.382259 2026] [proxy_http:error] [pid 1018003:tid 1018263] (20014)Internal error (specific information not available): [client 34.21.253.104:54504] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.382267 2026] [proxy:error] [pid 1018003:tid 1018263] [client 34.21.253.104:54504] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/env.js [Sat Aug 29 05:05:52.382826 2026] [security2:error] [pid 1017536:tid 1017784] [client 34.21.253.104:54334] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/_nuxt/../.env"] [unique_id "apK9ECJcY4fy7tP-rU3v4wAAAoo"] [Sat Aug 29 05:05:52.383763 2026] [security2:error] [pid 1017536:tid 1017790] [client 34.21.253.104:54480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/app/.env"] [unique_id "apK9ECJcY4fy7tP-rU3v5gAAApA"] [Sat Aug 29 05:05:52.385691 2026] [proxy_http:error] [pid 1017536:tid 1017786] (20014)Internal error (specific information not available): [client 34.21.253.104:54408] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.385702 2026] [proxy:error] [pid 1017536:tid 1017786] [client 34.21.253.104:54408] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:05:52.387815 2026] [security2:error] [pid 1018003:tid 1018164] [client 34.21.253.104:54526] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/admin/.env"] [unique_id "apK9EDAh5Y1i2tUxg4HqNgAABcU"] [Sat Aug 29 05:05:52.387837 2026] [proxy_http:error] [pid 1018003:tid 1018263] (20014)Internal error (specific information not available): [client 34.21.253.104:54504] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.387847 2026] [proxy:error] [pid 1018003:tid 1018263] [client 34.21.253.104:54504] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:05:52.391493 2026] [proxy_http:error] [pid 1017536:tid 1017710] (20014)Internal error (specific information not available): [client 34.21.253.104:54564] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.391505 2026] [proxy:error] [pid 1017536:tid 1017710] [client 34.21.253.104:54564] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/core/.env [Sat Aug 29 05:05:52.392038 2026] [security2:error] [pid 1017536:tid 1017753] [client 74.248.24.12:30553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/mini.php"] [unique_id "apK9ECJcY4fy7tP-rU3v6wAAAms"] [Sat Aug 29 05:05:52.393762 2026] [proxy_http:error] [pid 1018003:tid 1018213] (20014)Internal error (specific information not available): [client 34.21.253.104:54432] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.393777 2026] [proxy:error] [pid 1018003:tid 1018213] [client 34.21.253.104:54432] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.production [Sat Aug 29 05:05:52.396293 2026] [proxy_http:error] [pid 1017536:tid 1017683] (20014)Internal error (specific information not available): [client 34.21.253.104:54598] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.396304 2026] [proxy:error] [pid 1017536:tid 1017683] [client 34.21.253.104:54598] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/web/.env [Sat Aug 29 05:05:52.398909 2026] [proxy_http:error] [pid 1018003:tid 1018202] (20014)Internal error (specific information not available): [client 34.21.253.104:54460] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.398919 2026] [proxy:error] [pid 1018003:tid 1018202] [client 34.21.253.104:54460] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.old [Sat Aug 29 05:05:52.401226 2026] [proxy_http:error] [pid 1017536:tid 1017736] (20014)Internal error (specific information not available): [client 34.21.253.104:54574] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.401237 2026] [proxy:error] [pid 1017536:tid 1017736] [client 34.21.253.104:54574] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/src/.env [Sat Aug 29 05:05:52.403762 2026] [proxy_http:error] [pid 1018003:tid 1018195] (20014)Internal error (specific information not available): [client 34.21.253.104:54506] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.403774 2026] [proxy:error] [pid 1018003:tid 1018195] [client 34.21.253.104:54506] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/backend/.env [Sat Aug 29 05:05:52.408647 2026] [proxy_http:error] [pid 1018003:tid 1018273] (20014)Internal error (specific information not available): [client 34.21.253.104:54544] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.408661 2026] [proxy:error] [pid 1018003:tid 1018273] [client 34.21.253.104:54544] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/laravel/.env [Sat Aug 29 05:05:52.415091 2026] [security2:error] [pid 1017536:tid 1017780] [client 4.232.148.111:27457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/c.php"] [unique_id "apK9ECJcY4fy7tP-rU3v7AAAAoY"] [Sat Aug 29 05:05:52.415091 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.104.62:22679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/bge.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqQAAABhI"] [Sat Aug 29 05:05:52.417994 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.250.41:27561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/click.php"] [unique_id "apK9ECJcY4fy7tP-rU3v7QAAAlc"] [Sat Aug 29 05:05:52.418067 2026] [proxy_http:error] [pid 1018003:tid 1018265] (20014)Internal error (specific information not available): [client 34.21.253.104:54594] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.418078 2026] [proxy:error] [pid 1018003:tid 1018265] [client 34.21.253.104:54594] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/frontend/.env [Sat Aug 29 05:05:52.418884 2026] [security2:error] [pid 1018003:tid 1018173] [client 4.205.62.107:64296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/var/www/wallet/index.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqQQAABc4"] [Sat Aug 29 05:05:52.419290 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.104.62:48649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/dbc.php"] [unique_id "apK9ECJcY4fy7tP-rU3v7gAAAkU"] [Sat Aug 29 05:05:52.422870 2026] [proxy_http:error] [pid 1018003:tid 1018216] (20014)Internal error (specific information not available): [client 34.21.253.104:54444] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.422883 2026] [proxy:error] [pid 1018003:tid 1018216] [client 34.21.253.104:54444] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.staging [Sat Aug 29 05:05:52.427344 2026] [proxy_http:error] [pid 1018003:tid 1018269] (20014)Internal error (specific information not available): [client 34.21.253.104:54582] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:52.427363 2026] [proxy:error] [pid 1018003:tid 1018269] [client 34.21.253.104:54582] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/server/.env [Sat Aug 29 05:05:52.429541 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.104.104.62:36980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9ECJcY4fy7tP-rU3v7wAAAmQ"] [Sat Aug 29 05:05:52.430906 2026] [security2:error] [pid 1017536:tid 1017708] [client 168.107.94.195:54407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ECJcY4fy7tP-rU3v8AAAAj4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:52.434843 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.68.135:12435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9ECJcY4fy7tP-rU3v8QAAAks"] [Sat Aug 29 05:05:52.435132 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.104.104.62:39055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/file.php"] [unique_id "apK9ECJcY4fy7tP-rU3v8gAAAi4"] [Sat Aug 29 05:05:52.449997 2026] [security2:error] [pid 1017536:tid 1017716] [client 158.23.147.79:24492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ECJcY4fy7tP-rU3v8wAAAkY"] [Sat Aug 29 05:05:52.452339 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.104.49.130:51098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/js.php"] [unique_id "apK9ECJcY4fy7tP-rU3v9AAAAn4"] [Sat Aug 29 05:05:52.478958 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.147.79:48311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/banners/about.php"] [unique_id "apK9ECJcY4fy7tP-rU3v-AAAAh0"] [Sat Aug 29 05:05:52.480352 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.104.62:10459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/sko.php"] [unique_id "apK9ECJcY4fy7tP-rU3v-QAAAi0"] [Sat Aug 29 05:05:52.492990 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.48.251.3:13976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/myfile.php"] [unique_id "apK9ECJcY4fy7tP-rU3v-wAAAn8"] [Sat Aug 29 05:05:52.543005 2026] [security2:error] [pid 1017536:tid 1017707] [client 68.155.159.216:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9ECJcY4fy7tP-rU3wAAAAAj0"] [Sat Aug 29 05:05:52.545442 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.104.104.62:41645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/wp-ana.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqSQAABhM"] [Sat Aug 29 05:05:52.548176 2026] [security2:error] [pid 1017536:tid 1017644] [remote 52.167.144.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9ECJcY4fy7tP-rU3wAQACW2s"] [Sat Aug 29 05:05:52.562888 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.48.250.41:27574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ms.php"] [unique_id "apK9ECJcY4fy7tP-rU3wAwAAAog"] [Sat Aug 29 05:05:52.601512 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.104.62:20710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/cc.php"] [unique_id "apK9ECJcY4fy7tP-rU3wBQAAAnc"] [Sat Aug 29 05:05:52.619182 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.104.62:48585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/wp-wlx.php"] [unique_id "apK9ECJcY4fy7tP-rU3wBgAAAic"] [Sat Aug 29 05:05:52.620935 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.104.62:10820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/zoz.php"] [unique_id "apK9ECJcY4fy7tP-rU3wBwAAAos"] [Sat Aug 29 05:05:52.628231 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.104.104.62:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/sc.php"] [unique_id "apK9ECJcY4fy7tP-rU3wCAAAAog"] [Sat Aug 29 05:05:52.630680 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.68.135:23842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-admin/network/admin.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqVAAABdI"] [Sat Aug 29 05:05:52.642840 2026] [security2:error] [pid 1017536:tid 1017686] [client 45.148.10.62:38302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.wanderlustpictures.com"] [uri "/wp-config.php.old"] [unique_id "apK9ECJcY4fy7tP-rU3wCQAAAig"] [Sat Aug 29 05:05:52.645985 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.49.130:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/gecko-new.php"] [unique_id "apK9ECJcY4fy7tP-rU3wCgAAAmg"] [Sat Aug 29 05:05:52.683539 2026] [security2:error] [pid 1018003:tid 1018277] [client 4.205.62.107:22267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/configuration.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqWAAABjU"] [Sat Aug 29 05:05:52.687435 2026] [security2:error] [pid 1018003:tid 1018249] [client 4.205.62.107:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/config_dev.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqWQAABhk"] [Sat Aug 29 05:05:52.690464 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:45990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/secret.php"] [unique_id "apK9ECJcY4fy7tP-rU3wCwAAAiU"] [Sat Aug 29 05:05:52.730311 2026] [security2:error] [pid 1017536:tid 1017721] [client 4.205.62.107:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-act.php"] [unique_id "apK9ECJcY4fy7tP-rU3wDgAAAks"] [Sat Aug 29 05:05:52.741431 2026] [security2:error] [pid 1017536:tid 1017716] [client 158.23.147.79:50158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/images/index.php"] [unique_id "apK9ECJcY4fy7tP-rU3wEAAAAkY"] [Sat Aug 29 05:05:52.754498 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.104.62:10630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/mmm.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqXgAABek"] [Sat Aug 29 05:05:52.758715 2026] [security2:error] [pid 1017536:tid 1017788] [client 103.162.125.59:51948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9ECJcY4fy7tP-rU3wEwAAAo4"] [Sat Aug 29 05:05:52.758835 2026] [security2:error] [pid 1017536:tid 1017788] [client 103.162.125.59:51948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9ECJcY4fy7tP-rU3wEwAAAo4"] [Sat Aug 29 05:05:52.763345 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.104.104.62:23407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/baee.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqXwAABjI"] [Sat Aug 29 05:05:52.765298 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.205.62.107:2974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/public/bnn_.php.php"] [unique_id "apK9ECJcY4fy7tP-rU3wFAAAAi0"] [Sat Aug 29 05:05:52.774747 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.196.209.81:18705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content.php"] [unique_id "apK9ECJcY4fy7tP-rU3wFQAAAoE"] [Sat Aug 29 05:05:52.787851 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.250.41:27427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/zxekqlxb.php"] [unique_id "apK9ECJcY4fy7tP-rU3wFgAAAhw"] [Sat Aug 29 05:05:52.797661 2026] [security2:error] [pid 1018003:tid 1018233] [client 34.143.179.161:62138] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/docker-compose.yml"] [unique_id "apK9EDAh5Y1i2tUxg4HqYAAABgk"] [Sat Aug 29 05:05:52.803727 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.104.62:48455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/attack.php"] [unique_id "apK9ECJcY4fy7tP-rU3wFwAAApI"] [Sat Aug 29 05:05:52.810479 2026] [security2:error] [pid 1017536:tid 1017680] [client 168.107.94.195:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ECJcY4fy7tP-rU3wGAAAAiI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:52.814042 2026] [security2:error] [pid 1017536:tid 1017747] [client 34.143.179.161:62204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/v1/graphql"] [unique_id "apK9ECJcY4fy7tP-rU3wGwAAAmU"] [Sat Aug 29 05:05:52.823557 2026] [security2:error] [pid 1018003:tid 1018267] [client 34.143.179.161:62226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/.openai/config.json"] [unique_id "apK9EDAh5Y1i2tUxg4HqZQAABis"] [Sat Aug 29 05:05:52.824076 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.104.104.62:22717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/pro.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqZwAABiI"] [Sat Aug 29 05:05:52.824111 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.104.104.62:39100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/tinyfilemanager.php"] [unique_id "apK9ECJcY4fy7tP-rU3wIQAAAmA"] [Sat Aug 29 05:05:52.824129 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.104.68.135:23825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-conflg/function.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqZgAABfg"] [Sat Aug 29 05:05:52.826491 2026] [security2:error] [pid 1017536:tid 1017703] [client 34.143.179.161:62306] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/.openclaw/.env"] [unique_id "apK9ECJcY4fy7tP-rU3wIgAAAjk"] [Sat Aug 29 05:05:52.832105 2026] [security2:error] [pid 1018003:tid 1018231] [client 34.143.179.161:62366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/.claude/settings.json"] [unique_id "apK9EDAh5Y1i2tUxg4HqbQAABgc"] [Sat Aug 29 05:05:52.865665 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.104.104.62:64715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/45.php"] [unique_id "apK9ECJcY4fy7tP-rU3wMAAAAns"] [Sat Aug 29 05:05:52.880606 2026] [security2:error] [pid 1017536:tid 1017729] [client 216.73.161.177:23789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.darwinsfox.com"] [uri "/wp-login.php"] [unique_id "apK9ECJcY4fy7tP-rU3wLwAAAlM"], referer: https://t.co/ [Sat Aug 29 05:05:52.886345 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.104.62:10829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/advanced.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqeQAABiA"] [Sat Aug 29 05:05:52.913558 2026] [security2:error] [pid 1017536:tid 1017692] [client 74.248.24.12:40939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/aa.php"] [unique_id "apK9ECJcY4fy7tP-rU3wMgAAAi4"] [Sat Aug 29 05:05:52.915260 2026] [security2:error] [pid 1017536:tid 1017696] [client 40.83.93.50:3147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/about.php525"] [unique_id "apK9ECJcY4fy7tP-rU3wMwAAAjI"] [Sat Aug 29 05:05:52.939293 2026] [security2:error] [pid 1018003:tid 1018198] [client 4.232.148.111:8387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/f.php"] [unique_id "apK9EDAh5Y1i2tUxg4HqfAAABec"] [Sat Aug 29 05:05:52.956750 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.104.62:23390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/d12.php"] [unique_id "apK9ECJcY4fy7tP-rU3wNAAAAhY"] [Sat Aug 29 05:05:52.957922 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.104.49.130:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/echkm.php"] [unique_id "apK9ECJcY4fy7tP-rU3wNQAAAlQ"] [Sat Aug 29 05:05:52.959872 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.104.104.62:55037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/999.php"] [unique_id "apK9ECJcY4fy7tP-rU3wNgAAAkM"] [Sat Aug 29 05:05:53.015548 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.104.104.62:48676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/file66.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqhAAABeY"] [Sat Aug 29 05:05:53.019311 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.104.68.135:12456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqhQAABgY"] [Sat Aug 29 05:05:53.025172 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.48.250.41:27469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/init.php"] [unique_id "apK9ESJcY4fy7tP-rU3wPAAAAok"] [Sat Aug 29 05:05:53.028045 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.104.62:10835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/blox.php"] [unique_id "apK9ESJcY4fy7tP-rU3wPQAAAik"] [Sat Aug 29 05:05:53.038681 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.104.104.62:39051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/upload.php"] [unique_id "apK9ESJcY4fy7tP-rU3wPwAAAlE"] [Sat Aug 29 05:05:53.042236 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.158.54.35:5004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/file.php"] [unique_id "apK9ESJcY4fy7tP-rU3wQAAAAms"] [Sat Aug 29 05:05:53.047470 2026] [security2:error] [pid 1017536:tid 1017712] [client 111.235.68.106:44942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9ESJcY4fy7tP-rU3wPgAAAkI"] [Sat Aug 29 05:05:53.047596 2026] [security2:error] [pid 1017536:tid 1017712] [client 111.235.68.106:44942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9ESJcY4fy7tP-rU3wPgAAAkI"] [Sat Aug 29 05:05:53.089644 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:51252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/admin.php"] [unique_id "apK9ESJcY4fy7tP-rU3wQQAAAks"] [Sat Aug 29 05:05:53.090150 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.104.62:54982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/sef.php"] [unique_id "apK9ESJcY4fy7tP-rU3wQgAAAkY"] [Sat Aug 29 05:05:53.091832 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.197.61.180:13055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/options.php"] [unique_id "apK9ESJcY4fy7tP-rU3wQwAAAj0"] [Sat Aug 29 05:05:53.111815 2026] [security2:error] [pid 1017536:tid 1017775] [client 4.205.62.107:56041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/saiga.php"] [unique_id "apK9ESJcY4fy7tP-rU3wRAAAAoE"] [Sat Aug 29 05:05:53.124741 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.104.62:20819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/1945.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqigAABgM"] [Sat Aug 29 05:05:53.149229 2026] [security2:error] [pid 1017536:tid 1017745] [client 45.148.10.62:38316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wanderlustpictures.com"] [uri "/config.php"] [unique_id "apK9ESJcY4fy7tP-rU3wRQAAAmM"] [Sat Aug 29 05:05:53.156908 2026] [security2:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/wp-config.php.bak"] [unique_id "apK9ETAh5Y1i2tUxg4HqiwAF5TA"] [Sat Aug 29 05:05:53.157430 2026] [security2:error] [pid 1018003:tid 1018111] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/wp-config.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqjAAF5Vo"] [Sat Aug 29 05:05:53.157851 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.250.41:27487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/term.php"] [unique_id "apK9ESJcY4fy7tP-rU3wRgAAAj4"] [Sat Aug 29 05:05:53.168960 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.104.62:44568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/kcs.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqkwAABgw"] [Sat Aug 29 05:05:53.189042 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.147.79:30719] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/1.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqlAAABeM"] [Sat Aug 29 05:05:53.189173 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.147.79:30719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/1.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqlAAABeM"] [Sat Aug 29 05:05:53.192005 2026] [security2:error] [pid 1017536:tid 1017703] [client 168.107.94.195:55271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ESJcY4fy7tP-rU3wRwAAAjk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:53.218528 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.104.104.62:48474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/zafir1.php"] [unique_id "apK9ESJcY4fy7tP-rU3wSAAAAmw"] [Sat Aug 29 05:05:53.224690 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.104.62:41629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/admin123.php"] [unique_id "apK9ESJcY4fy7tP-rU3wSQAAAjA"] [Sat Aug 29 05:05:53.226380 2026] [security2:error] [pid 1017536:tid 1017688] [client 4.205.62.107:53319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/zaza.php"] [unique_id "apK9ESJcY4fy7tP-rU3wSgAAAio"] [Sat Aug 29 05:05:53.232917 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.104.104.62:39094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goll.net"] [uri "/wp-act.php"] [unique_id "apK9ESJcY4fy7tP-rU3wTAAAAmU"] [Sat Aug 29 05:05:53.271430 2026] [security2:error] [pid 1017536:tid 1017705] [client 68.155.159.216:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9ESJcY4fy7tP-rU3wTgAAAjs"] [Sat Aug 29 05:05:53.284038 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.104.104.62:64718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wos.php"] [unique_id "apK9ESJcY4fy7tP-rU3wTwAAAk8"] [Sat Aug 29 05:05:53.286455 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.104.62:23388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/yyy.php"] [unique_id "apK9ESJcY4fy7tP-rU3wUAAAAnk"] [Sat Aug 29 05:05:53.289658 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.68.135:38412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-content/themes/fitnessbase/404.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqmAAABfA"] [Sat Aug 29 05:05:53.316510 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:12147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/.well-known/content.php"] [unique_id "apK9ESJcY4fy7tP-rU3wUQAAAjo"] [Sat Aug 29 05:05:53.331099 2026] [security2:error] [pid 1018003:tid 1018245] [client 68.155.159.216:58325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqmQAABhU"] [Sat Aug 29 05:05:53.343835 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.196.209.81:17071] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.hellospringford.com"] [uri "/wp-content/1.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqmgAABdk"] [Sat Aug 29 05:05:53.343941 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.196.209.81:17071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/1.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqmgAABdk"] [Sat Aug 29 05:05:53.385518 2026] [security2:error] [pid 1017536:tid 1017789] [client 158.23.147.79:58051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9ESJcY4fy7tP-rU3wUgAAAo8"] [Sat Aug 29 05:05:53.401039 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.49.130:30057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/forum.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqnQAABdc"] [Sat Aug 29 05:05:53.406055 2026] [security2:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/wp-config.php.old"] [unique_id "apK9ETAh5Y1i2tUxg4HqoQAF-Ws"] [Sat Aug 29 05:05:53.406055 2026] [security2:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:53320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/wp-config.php.new"] [unique_id "apK9ETAh5Y1i2tUxg4HqngAF-Wo"] [Sat Aug 29 05:05:53.423342 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.251.3:13987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/lm15.php"] [unique_id "apK9ESJcY4fy7tP-rU3wUwAAAnc"] [Sat Aug 29 05:05:53.424630 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.48.250.41:27465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/aaa.php"] [unique_id "apK9ESJcY4fy7tP-rU3wVAAAAic"] [Sat Aug 29 05:05:53.424735 2026] [security2:error] [pid 1017536:tid 1017711] [client 40.83.93.50:13838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/spip.php"] [unique_id "apK9ESJcY4fy7tP-rU3wVQAAAkE"] [Sat Aug 29 05:05:53.436625 2026] [security2:error] [pid 1017536:tid 1017669] [client 74.248.24.12:29537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/c.php"] [unique_id "apK9ESJcY4fy7tP-rU3wVgAAAhc"] [Sat Aug 29 05:05:53.440713 2026] [security2:error] [pid 1017536:tid 1017782] [client 158.23.147.79:25479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/ws.php"] [unique_id "apK9ESJcY4fy7tP-rU3wWAAAAog"] [Sat Aug 29 05:05:53.456391 2026] [security2:error] [pid 1017536:tid 1017737] [client 4.232.148.111:33799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/av.php"] [unique_id "apK9ESJcY4fy7tP-rU3wWgAAAls"] [Sat Aug 29 05:05:53.476703 2026] [security2:error] [pid 1018003:tid 1018239] [client 57.141.14.83:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK9ETAh5Y1i2tUxg4HqpQAABg8"] [Sat Aug 29 05:05:53.486419 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.68.135:5313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqpgAABgI"] [Sat Aug 29 05:05:53.493511 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.158.54.35:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/files.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqpwAABb4"] [Sat Aug 29 05:05:53.507645 2026] [security2:error] [pid 1017536:tid 1017783] [client 93.123.109.228:41102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9ESJcY4fy7tP-rU3wXAAAAok"] [Sat Aug 29 05:05:53.517528 2026] [security2:error] [pid 1017536:tid 1017690] [client 68.155.159.216:14296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9ESJcY4fy7tP-rU3wXgAAAiw"] [Sat Aug 29 05:05:53.533613 2026] [security2:error] [pid 1017536:tid 1017772] [client 35.198.240.194:31322] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/app-config.json"] [unique_id "apK9ESJcY4fy7tP-rU3wZwAAAn4"] [Sat Aug 29 05:05:53.536485 2026] [security2:error] [pid 1018003:tid 1018181] [client 35.198.240.194:31272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9ETAh5Y1i2tUxg4HqqQAABdY"] [Sat Aug 29 05:05:53.539494 2026] [security2:error] [pid 1018003:tid 1018155] [client 93.123.109.228:41122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9ETAh5Y1i2tUxg4HqtgAABbw"] [Sat Aug 29 05:05:53.540848 2026] [security2:error] [pid 1018003:tid 1018241] [client 35.198.240.194:31442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.omni-staffing.com"] [uri "/gcp-key.json"] [unique_id "apK9ETAh5Y1i2tUxg4HquQAABhE"] [Sat Aug 29 05:05:53.542688 2026] [security2:error] [pid 1017536:tid 1017727] [client 35.198.240.194:31326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9ESJcY4fy7tP-rU3wYwAAAlE"] [Sat Aug 29 05:05:53.543817 2026] [security2:error] [pid 1017536:tid 1017716] [client 35.198.240.194:31476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.ssh/id_rsa"] [unique_id "apK9ESJcY4fy7tP-rU3wbwAAAkY"] [Sat Aug 29 05:05:53.544046 2026] [security2:error] [pid 1017536:tid 1017712] [client 35.198.240.194:31324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9ESJcY4fy7tP-rU3wZgAAAkI"] [Sat Aug 29 05:05:53.545594 2026] [security2:error] [pid 1017536:tid 1017715] [client 35.198.240.194:31492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.ssh/id_dsa"] [unique_id "apK9ESJcY4fy7tP-rU3wbgAAAkU"] [Sat Aug 29 05:05:53.566522 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.205.62.107:64276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/124.php"] [unique_id "apK9ESJcY4fy7tP-rU3wcQAAAi0"] [Sat Aug 29 05:05:53.573432 2026] [security2:error] [pid 1018003:tid 1018191] [client 168.107.94.195:55689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqvQAABeA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:53.659636 2026] [security2:error] [pid 1017536:tid 1017667] [client 93.123.109.228:41102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9ESJcY4fy7tP-rU3weQAAAhU"] [Sat Aug 29 05:05:53.685277 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.68.135:18457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqxgAABhQ"] [Sat Aug 29 05:05:53.715023 2026] [security2:error] [pid 1017536:tid 1017767] [client 93.123.109.228:41180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9ESJcY4fy7tP-rU3wfwAAAnk"] [Sat Aug 29 05:05:53.728475 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.48.250.41:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/xsox.php"] [unique_id "apK9ESJcY4fy7tP-rU3wgQAAAkk"] [Sat Aug 29 05:05:53.732786 2026] [security2:error] [pid 1017536:tid 1017781] [client 45.148.10.62:38328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wanderlustpictures.com"] [uri "/config.php.bak"] [unique_id "apK9ESJcY4fy7tP-rU3wggAAAoc"] [Sat Aug 29 05:05:53.735167 2026] [security2:error] [pid 1017536:tid 1017749] [client 93.123.109.228:41206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9ESJcY4fy7tP-rU3wgwAAAmc"] [Sat Aug 29 05:05:53.767764 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.196.209.81:17151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/about.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqyQAABf8"] [Sat Aug 29 05:05:53.782346 2026] [security2:error] [pid 1017536:tid 1017726] [client 158.23.147.79:32709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9ESJcY4fy7tP-rU3whgAAAlA"] [Sat Aug 29 05:05:53.802864 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.197.61.180:17018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/panel.php"] [unique_id "apK9ESJcY4fy7tP-rU3whwAAAh0"] [Sat Aug 29 05:05:53.809091 2026] [security2:error] [pid 1017536:tid 1017790] [client 93.123.109.228:41212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9ESJcY4fy7tP-rU3wiAAAApA"] [Sat Aug 29 05:05:53.822823 2026] [security2:error] [pid 1018003:tid 1018189] [client 4.205.62.107:22239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/public/rip.php.php"] [unique_id "apK9ETAh5Y1i2tUxg4HqywAABd4"] [Sat Aug 29 05:05:53.844020 2026] [security2:error] [pid 1018003:tid 1018251] [client 4.205.62.107:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/aws-credentials.php"] [unique_id "apK9ETAh5Y1i2tUxg4Hq0AAABhs"] [Sat Aug 29 05:05:53.844471 2026] [security2:error] [pid 1018003:tid 1018261] [client 93.123.109.228:41122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9ETAh5Y1i2tUxg4HqzwAABiU"] [Sat Aug 29 05:05:53.855086 2026] [security2:error] [pid 1018003:tid 1018262] [client 93.123.109.228:41130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9ETAh5Y1i2tUxg4Hq0QAABiY"] [Sat Aug 29 05:05:53.861559 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.48.250.41:27494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/lkui.php"] [unique_id "apK9ETAh5Y1i2tUxg4Hq0wAABfI"] [Sat Aug 29 05:05:53.868633 2026] [security2:error] [pid 1017536:tid 1017770] [client 4.205.62.107:21850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/samll.php"] [unique_id "apK9ESJcY4fy7tP-rU3wjAAAAnw"] [Sat Aug 29 05:05:53.884586 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.68.135:38439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-content/uploads/de_fb_uploads/b.php"] [unique_id "apK9ESJcY4fy7tP-rU3wjwAAAjw"] [Sat Aug 29 05:05:53.904921 2026] [security2:error] [pid 1018003:tid 1018219] [client 4.205.62.107:2649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/php_info.php"] [unique_id "apK9ETAh5Y1i2tUxg4Hq1gAABfw"] [Sat Aug 29 05:05:53.919956 2026] [security2:error] [pid 1017536:tid 1017731] [client 40.83.93.50:8024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/backup.php"] [unique_id "apK9ESJcY4fy7tP-rU3wlAAAAlU"] [Sat Aug 29 05:05:53.924739 2026] [security2:error] [pid 1017536:tid 1017679] [client 158.158.54.35:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/o.php"] [unique_id "apK9ESJcY4fy7tP-rU3wlQAAAiE"] [Sat Aug 29 05:05:53.934711 2026] [security2:error] [pid 1017536:tid 1017777] [client 4.232.148.111:20632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/file.php"] [unique_id "apK9ESJcY4fy7tP-rU3wlgAAAoM"] [Sat Aug 29 05:05:53.935472 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.49.130:60739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/dehnl.php"] [unique_id "apK9ETAh5Y1i2tUxg4Hq1wAABdk"] [Sat Aug 29 05:05:53.947145 2026] [security2:error] [pid 1018003:tid 1018156] [client 68.155.159.216:9308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9ETAh5Y1i2tUxg4Hq2AAABb0"] [Sat Aug 29 05:05:53.954613 2026] [security2:error] [pid 1017536:tid 1017727] [client 168.107.94.195:56000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ESJcY4fy7tP-rU3wmAAAAlE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:53.975070 2026] [security2:error] [pid 1018003:tid 1018195] [client 93.123.109.228:41222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9ETAh5Y1i2tUxg4Hq2wAABeQ"] [Sat Aug 29 05:05:53.992625 2026] [security2:error] [pid 1017536:tid 1017733] [client 93.123.109.228:41102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/.env.php"] [unique_id "apK9ESJcY4fy7tP-rU3wnAAAAlc"] [Sat Aug 29 05:05:53.992953 2026] [security2:error] [pid 1017536:tid 1017723] [client 74.248.24.12:41010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/f.php"] [unique_id "apK9ESJcY4fy7tP-rU3wnQAAAk0"] [Sat Aug 29 05:05:54.016092 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.48.250.41:27631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9EjAh5Y1i2tUxg4Hq3wAABhw"] [Sat Aug 29 05:05:54.047008 2026] [security2:error] [pid 1018003:tid 1018257] [client 93.123.109.228:41284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9EjAh5Y1i2tUxg4Hq4gAABiE"] [Sat Aug 29 05:05:54.086260 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.68.135:12466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9EiJcY4fy7tP-rU3wowAAAkU"] [Sat Aug 29 05:05:54.106061 2026] [security2:error] [pid 1017536:tid 1017754] [client 68.155.159.216:18397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/simple.php"] [unique_id "apK9EiJcY4fy7tP-rU3wpgAAAmw"] [Sat Aug 29 05:05:54.138465 2026] [security2:error] [pid 1018003:tid 1018270] [client 68.155.159.216:50347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9EjAh5Y1i2tUxg4Hq6AAABi4"] [Sat Aug 29 05:05:54.144396 2026] [security2:error] [pid 1017536:tid 1017694] [client 93.123.109.228:41138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9EiJcY4fy7tP-rU3wpwAAAjA"] [Sat Aug 29 05:05:54.154239 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.48.250.41:27584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/motu.php"] [unique_id "apK9EiJcY4fy7tP-rU3wqQAAAmU"] [Sat Aug 29 05:05:54.166525 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.196.209.81:18697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/admin-header.php"] [unique_id "apK9EjAh5Y1i2tUxg4Hq6QAABhM"] [Sat Aug 29 05:05:54.180963 2026] [security2:error] [pid 1017536:tid 1017781] [client 68.155.159.216:64200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/worksec.php"] [unique_id "apK9EiJcY4fy7tP-rU3wrAAAAoc"] [Sat Aug 29 05:05:54.192287 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.49.130:34507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/term.php"] [unique_id "apK9EjAh5Y1i2tUxg4Hq7wAABgI"] [Sat Aug 29 05:05:54.211366 2026] [security2:error] [pid 1018003:tid 1018246] [client 93.123.109.228:41284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9EjAh5Y1i2tUxg4Hq8wAABhY"] [Sat Aug 29 05:05:54.212457 2026] [security2:error] [pid 1018003:tid 1018181] [client 93.123.109.228:41290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9EjAh5Y1i2tUxg4Hq9AAABdY"] [Sat Aug 29 05:05:54.237997 2026] [security2:error] [pid 1017536:tid 1017714] [client 93.123.109.228:41180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9EiJcY4fy7tP-rU3wswAAAkQ"] [Sat Aug 29 05:05:54.243763 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.147.79:49835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9EiJcY4fy7tP-rU3wtAAAAkM"] [Sat Aug 29 05:05:54.265642 2026] [security2:error] [pid 1018003:tid 1018190] [client 4.205.62.107:56040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ammika.php"] [unique_id "apK9EjAh5Y1i2tUxg4Hq9wAABd8"] [Sat Aug 29 05:05:54.267262 2026] [cgid:error] [pid 1017536:tid 1017703] [client 45.148.10.62:50908] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:54.285733 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.68.135:5330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9EjAh5Y1i2tUxg4Hq-QAABbw"] [Sat Aug 29 05:05:54.334722 2026] [security2:error] [pid 1018003:tid 1018183] [client 168.107.94.195:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9EjAh5Y1i2tUxg4Hq_gAABdg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:54.350993 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.250.41:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/Ov-Simple1.php"] [unique_id "apK9EiJcY4fy7tP-rU3wuQAAAlY"] [Sat Aug 29 05:05:54.372232 2026] [security2:error] [pid 1017536:tid 1017668] [client 158.158.54.35:4279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/file2.php"] [unique_id "apK9EiJcY4fy7tP-rU3wvAAAAhY"] [Sat Aug 29 05:05:54.394936 2026] [security2:error] [pid 1018003:tid 1018189] [client 159.203.140.4:61001] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "878"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.thesmartpm.com"] [uri "/wp-json/batch/v1"] [unique_id "apK9EjAh5Y1i2tUxg4HrBAAABd4"] [Sat Aug 29 05:05:54.398876 2026] [security2:error] [pid 1017536:tid 1017731] [client 4.205.62.107:53391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wp-config.backup.php"] [unique_id "apK9EiJcY4fy7tP-rU3wwAAAAlU"] [Sat Aug 29 05:05:54.418277 2026] [cgid:error] [pid 1017536:tid 1017753] [client 45.148.10.62:50908] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:54.427927 2026] [security2:error] [pid 1017536:tid 1017681] [client 68.155.159.216:12161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/cong.php"] [unique_id "apK9EiJcY4fy7tP-rU3wyQAAAiM"] [Sat Aug 29 05:05:54.428218 2026] [security2:error] [pid 1018003:tid 1018200] [client 40.83.93.50:7765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/haiterus.php"] [unique_id "apK9EjAh5Y1i2tUxg4HrCgAABek"] [Sat Aug 29 05:05:54.428312 2026] [security2:error] [pid 1018003:tid 1018274] [client 4.232.148.111:33861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9EjAh5Y1i2tUxg4HrDQAABjI"] [Sat Aug 29 05:05:54.435667 2026] [security2:error] [pid 1017536:tid 1017687] [client 68.155.159.216:57408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/packed.php"] [unique_id "apK9EiJcY4fy7tP-rU3wygAAAik"] [Sat Aug 29 05:05:54.438741 2026] [security2:error] [pid 1017536:tid 1017710] [client 68.155.159.216:51509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/lock.php"] [unique_id "apK9EiJcY4fy7tP-rU3wywAAAkA"] [Sat Aug 29 05:05:54.483614 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.68.135:16006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/PHPMailer/index.php"] [unique_id "apK9EiJcY4fy7tP-rU3wzQAAAmk"] [Sat Aug 29 05:05:54.491259 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.48.250.41:27620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/wp-blogs.php"] [unique_id "apK9EiJcY4fy7tP-rU3wzgAAAio"] [Sat Aug 29 05:05:54.494237 2026] [security2:error] [pid 1017536:tid 1017694] [client 158.23.147.79:58064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9EiJcY4fy7tP-rU3wzwAAAjA"] [Sat Aug 29 05:05:54.525945 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.197.61.180:5871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/pk.php"] [unique_id "apK9EiJcY4fy7tP-rU3w0QAAApA"] [Sat Aug 29 05:05:54.533085 2026] [security2:error] [pid 1018003:tid 1018205] [client 34.7.216.49:22366] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/.azure/accessTokens.json"] [unique_id "apK9EjAh5Y1i2tUxg4HrFQAABe4"] [Sat Aug 29 05:05:54.539284 2026] [security2:error] [pid 1018003:tid 1018151] [client 34.7.216.49:22346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/.azure/azureProfile.json"] [unique_id "apK9EjAh5Y1i2tUxg4HrHwAABbg"] [Sat Aug 29 05:05:54.557994 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.49.130:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/33.php"] [unique_id "apK9EiJcY4fy7tP-rU3w3AAAAjs"] [Sat Aug 29 05:05:54.563580 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.196.209.81:17042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/admin.php"] [unique_id "apK9EjAh5Y1i2tUxg4HrJwAABfw"] [Sat Aug 29 05:05:54.570916 2026] [cgid:error] [pid 1017536:tid 1017678] [client 45.148.10.62:50908] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:54.581492 2026] [security2:error] [pid 1018003:tid 1018236] [client 74.248.24.12:30409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/av.php"] [unique_id "apK9EjAh5Y1i2tUxg4HrKAAABgw"] [Sat Aug 29 05:05:54.638035 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.48.251.3:33282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/test.config.php"] [unique_id "apK9EiJcY4fy7tP-rU3w5AAAAoo"] [Sat Aug 29 05:05:54.655910 2026] [security2:error] [pid 1018003:tid 1018278] [client 158.23.147.79:48295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9EjAh5Y1i2tUxg4HrLgAABjY"] [Sat Aug 29 05:05:54.672598 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.48.250.41:27616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/mini.php"] [unique_id "apK9EjAh5Y1i2tUxg4HrMAAABdY"] [Sat Aug 29 05:05:54.709053 2026] [security2:error] [pid 1017536:tid 1017711] [client 4.205.62.107:64919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/test1.php"] [unique_id "apK9EiJcY4fy7tP-rU3w6gAAAkE"] [Sat Aug 29 05:05:54.715113 2026] [security2:error] [pid 1017536:tid 1017785] [client 168.107.94.195:56611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9EiJcY4fy7tP-rU3w6wAAAos"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:54.723268 2026] [security2:error] [pid 1017536:tid 1017732] [client 45.148.10.62:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wanderlustpictures.com"] [uri "/phpinfo.php"] [unique_id "apK9EiJcY4fy7tP-rU3w7QAAAlY"] [Sat Aug 29 05:05:54.733331 2026] [security2:error] [pid 1017536:tid 1017686] [client 68.155.159.216:14249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/.well-knownold/index.php"] [unique_id "apK9EiJcY4fy7tP-rU3w7gAAAig"] [Sat Aug 29 05:05:54.747394 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.151.200.44:64936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9EiJcY4fy7tP-rU3w7wAAAi8"] [Sat Aug 29 05:05:54.751882 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.68.135:38411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/SimplePie/autoload_classmap.php"] [unique_id "apK9EiJcY4fy7tP-rU3w8AAAAhY"] [Sat Aug 29 05:05:54.818915 2026] [security2:error] [pid 1017536:tid 1017692] [client 158.158.54.35:22972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK9EiJcY4fy7tP-rU3w-AAAAi4"] [Sat Aug 29 05:05:54.886265 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.23.147.79:32644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9EiJcY4fy7tP-rU3w_wAAAjQ"] [Sat Aug 29 05:05:54.887872 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.48.250.41:27489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/amp.php"] [unique_id "apK9EjAh5Y1i2tUxg4HrOwAABiA"] [Sat Aug 29 05:05:54.912594 2026] [security2:error] [pid 1017536:tid 1017770] [client 40.83.93.50:3196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/go.php"] [unique_id "apK9EiJcY4fy7tP-rU3xAAAAAnw"] [Sat Aug 29 05:05:54.914660 2026] [security2:error] [pid 1017536:tid 1017719] [client 4.232.148.111:19088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/gmo.php"] [unique_id "apK9EiJcY4fy7tP-rU3xAQAAAkk"] [Sat Aug 29 05:05:54.948268 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.68.135:38461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9EiJcY4fy7tP-rU3xBAAAAoE"] [Sat Aug 29 05:05:54.952602 2026] [security2:error] [pid 1017536:tid 1017715] [client 93.123.109.228:41180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/.wp-config.php.swp"] [unique_id "apK9EiJcY4fy7tP-rU3xBQAAAkU"] [Sat Aug 29 05:05:54.961413 2026] [security2:error] [pid 1018003:tid 1018174] [client 4.205.62.107:22349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/h.php"] [unique_id "apK9EjAh5Y1i2tUxg4HrPgAABc8"] [Sat Aug 29 05:05:54.963235 2026] [security2:error] [pid 1017536:tid 1017772] [client 93.123.109.228:41212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9EiJcY4fy7tP-rU3xBwAAAn4"] [Sat Aug 29 05:05:54.978787 2026] [security2:error] [pid 1018003:tid 1018217] [client 93.123.109.228:41130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9EjAh5Y1i2tUxg4HrQgAABfo"] [Sat Aug 29 05:05:54.989506 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.196.209.81:17063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK9EiJcY4fy7tP-rU3xCgAAAoY"] [Sat Aug 29 05:05:54.999043 2026] [security2:error] [pid 1017536:tid 1017747] [client 4.205.62.107:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/4563.php"] [unique_id "apK9EiJcY4fy7tP-rU3xDAAAAmU"] [Sat Aug 29 05:05:55.004569 2026] [security2:error] [pid 1017536:tid 1017769] [client 4.205.62.107:22331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/pass4.php"] [unique_id "apK9EyJcY4fy7tP-rU3xDwAAAns"] [Sat Aug 29 05:05:55.012260 2026] [security2:error] [pid 1017536:tid 1017622] [remote 74.7.227.154:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9EyJcY4fy7tP-rU3xEwACW1U"], referer: https://goodtogo.store/sitemap_index.xml [Sat Aug 29 05:05:55.013801 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.151.200.44:64918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9EyJcY4fy7tP-rU3xFAAAAmQ"] [Sat Aug 29 05:05:55.035493 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.49.130:46588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/sxxb.php"] [unique_id "apK9EyJcY4fy7tP-rU3xFQAAAiA"] [Sat Aug 29 05:05:55.041080 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.23.147.79:25474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9EyJcY4fy7tP-rU3xFgAAAmY"] [Sat Aug 29 05:05:55.042608 2026] [security2:error] [pid 1017536:tid 1017752] [client 4.205.62.107:2952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/broadcasting.php"] [unique_id "apK9EyJcY4fy7tP-rU3xFwAAAmo"] [Sat Aug 29 05:05:55.050169 2026] [security2:error] [pid 1017536:tid 1017743] [client 93.123.109.228:41154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9EyJcY4fy7tP-rU3xGAAAAmE"] [Sat Aug 29 05:05:55.053917 2026] [security2:error] [pid 1017536:tid 1017767] [client 93.123.109.228:41116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9EyJcY4fy7tP-rU3xGQAAAnk"] [Sat Aug 29 05:05:55.062320 2026] [security2:error] [pid 1018003:tid 1018200] [client 93.123.109.228:41290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9EzAh5Y1i2tUxg4HrRQAABek"] [Sat Aug 29 05:05:55.111390 2026] [security2:error] [pid 1017536:tid 1017670] [client 138.199.19.170:54402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.dgdevelco.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9EyJcY4fy7tP-rU3xGgAAAhg"] [Sat Aug 29 05:05:55.113792 2026] [security2:error] [pid 1018003:tid 1018274] [client 93.123.109.228:41244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9EzAh5Y1i2tUxg4HrRgAABjI"] [Sat Aug 29 05:05:55.114582 2026] [security2:error] [pid 1017536:tid 1017714] [client 93.123.109.228:41212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9EyJcY4fy7tP-rU3xGwAAAkQ"] [Sat Aug 29 05:05:55.120738 2026] [security2:error] [pid 1017536:tid 1017684] [client 168.107.94.195:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9EyJcY4fy7tP-rU3xHQAAAiY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:55.139129 2026] [security2:error] [pid 1017536:tid 1017754] [client 74.248.24.12:31601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/file.php"] [unique_id "apK9EyJcY4fy7tP-rU3xIAAAAmw"] [Sat Aug 29 05:05:55.142468 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.49.130:63598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/yawa.php"] [unique_id "apK9EyJcY4fy7tP-rU3xIQAAAig"] [Sat Aug 29 05:05:55.143330 2026] [security2:error] [pid 1018003:tid 1018180] [client 93.123.109.228:41284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9EzAh5Y1i2tUxg4HrSAAABdU"] [Sat Aug 29 05:05:55.147396 2026] [security2:error] [pid 1017536:tid 1017668] [client 158.23.147.79:30682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9EyJcY4fy7tP-rU3xIwAAAhY"] [Sat Aug 29 05:05:55.153150 2026] [security2:error] [pid 1017536:tid 1017721] [client 93.123.109.228:41194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9EyJcY4fy7tP-rU3xJQAAAks"] [Sat Aug 29 05:05:55.174386 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.250.41:27636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/cc13.php"] [unique_id "apK9EyJcY4fy7tP-rU3xJwAAAiM"] [Sat Aug 29 05:05:55.217670 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.68.135:38407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/blocks/buttons/index.php"] [unique_id "apK9EyJcY4fy7tP-rU3xLQAAAow"] [Sat Aug 29 05:05:55.219592 2026] [security2:error] [pid 1017536:tid 1017691] [client 68.155.159.216:18247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-admin/about.php"] [unique_id "apK9EyJcY4fy7tP-rU3xLgAAAi0"] [Sat Aug 29 05:05:55.224274 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.151.200.44:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/baee.php"] [unique_id "apK9EyJcY4fy7tP-rU3xLwAAAmM"] [Sat Aug 29 05:05:55.237250 2026] [security2:error] [pid 1017536:tid 1017704] [client 87.219.197.128:51953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9EyJcY4fy7tP-rU3xMAAAAjo"] [Sat Aug 29 05:05:55.237346 2026] [security2:error] [pid 1017536:tid 1017704] [client 87.219.197.128:51953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9EyJcY4fy7tP-rU3xMAAAAjo"] [Sat Aug 29 05:05:55.253348 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.197.61.180:6021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK9EyJcY4fy7tP-rU3xMQAAAoc"] [Sat Aug 29 05:05:55.271346 2026] [security2:error] [pid 1017536:tid 1017685] [client 158.158.54.35:10731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/xda.php"] [unique_id "apK9EyJcY4fy7tP-rU3xMgAAAic"] [Sat Aug 29 05:05:55.286853 2026] [security2:error] [pid 1018003:tid 1018273] [client 68.155.159.216:50241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-login.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrUQAABjE"] [Sat Aug 29 05:05:55.324545 2026] [security2:error] [pid 1018003:tid 1018195] [client 47.128.17.208:20702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.yemisys.com"] [uri "/robots.txt"] [unique_id "apK9EzAh5Y1i2tUxg4HrVQAABeQ"] [Sat Aug 29 05:05:55.326567 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.250.41:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/aa.php"] [unique_id "apK9EyJcY4fy7tP-rU3xOgAAAjE"] [Sat Aug 29 05:05:55.339077 2026] [security2:error] [pid 1017536:tid 1017678] [client 159.203.140.4:61082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "878"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.thesmartpm.sortthru.com"] [uri "/wp-json/batch/v1"] [unique_id "apK9EyJcY4fy7tP-rU3xOwAAAiA"] [Sat Aug 29 05:05:55.344120 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.49.130:30012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/3.php"] [unique_id "apK9EyJcY4fy7tP-rU3xPAAAAjw"] [Sat Aug 29 05:05:55.362204 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.151.200.44:64863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/d12.php"] [unique_id "apK9EyJcY4fy7tP-rU3xPwAAAnk"] [Sat Aug 29 05:05:55.382135 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.196.209.81:18718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK9EyJcY4fy7tP-rU3xQgAAAkU"] [Sat Aug 29 05:05:55.398844 2026] [security2:error] [pid 1017536:tid 1017722] [client 4.232.148.111:34886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/classwithtostring.php"] [unique_id "apK9EyJcY4fy7tP-rU3xRAAAAkw"] [Sat Aug 29 05:05:55.413323 2026] [security2:error] [pid 1017536:tid 1017752] [client 52.139.37.240:8595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/aged.php"] [unique_id "apK9EyJcY4fy7tP-rU3xRgAAAmo"] [Sat Aug 29 05:05:55.416298 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.104.68.135:38413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/css/autoload_classmap.php"] [unique_id "apK9EyJcY4fy7tP-rU3xRwAAAnI"] [Sat Aug 29 05:05:55.419191 2026] [security2:error] [pid 1017536:tid 1017703] [client 4.205.62.107:55938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/broadcasting.php"] [unique_id "apK9EyJcY4fy7tP-rU3xSAAAAjk"] [Sat Aug 29 05:05:55.429812 2026] [security2:error] [pid 1017536:tid 1017772] [client 40.83.93.50:8014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/gecko-new.php"] [unique_id "apK9EyJcY4fy7tP-rU3xSgAAAn4"] [Sat Aug 29 05:05:55.429818 2026] [security2:error] [pid 1017536:tid 1017788] [client 138.199.19.170:54410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.dgdevelco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9EyJcY4fy7tP-rU3xSQAAAo4"] [Sat Aug 29 05:05:55.447839 2026] [security2:error] [pid 1018003:tid 1018197] [client 93.123.109.228:41222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrXQAABeY"] [Sat Aug 29 05:05:55.469055 2026] [cgid:error] [pid 1017536:tid 1017617] [remote 45.148.10.62:50914] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:55.482944 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.250.41:27475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/s1.php"] [unique_id "apK9EyJcY4fy7tP-rU3xUQAAAlY"] [Sat Aug 29 05:05:55.501798 2026] [security2:error] [pid 1017536:tid 1017724] [client 168.107.94.195:57320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9EyJcY4fy7tP-rU3xVQAAAk4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:55.526004 2026] [security2:error] [pid 1017536:tid 1017667] [client 103.185.242.143:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9EyJcY4fy7tP-rU3xWAAAAhU"] [Sat Aug 29 05:05:55.526090 2026] [security2:error] [pid 1017536:tid 1017667] [client 103.185.242.143:60738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9EyJcY4fy7tP-rU3xWAAAAhU"] [Sat Aug 29 05:05:55.526417 2026] [security2:error] [pid 1017536:tid 1017663] [remote 74.7.227.154:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9EyJcY4fy7tP-rU3xVwACU34"], referer: https://goodtogo.store/sitemap_index.xml [Sat Aug 29 05:05:55.537999 2026] [security2:error] [pid 1018003:tid 1018170] [client 4.205.62.107:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/X57.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrYgAABcs"] [Sat Aug 29 05:05:55.542966 2026] [security2:error] [pid 1017536:tid 1017710] [client 68.155.159.216:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/packed.php"] [unique_id "apK9EyJcY4fy7tP-rU3xWgAAAkA"] [Sat Aug 29 05:05:55.549102 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.151.200.44:65489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/yyy.php"] [unique_id "apK9EyJcY4fy7tP-rU3xWwAAAi0"] [Sat Aug 29 05:05:55.598108 2026] [security2:error] [pid 1017536:tid 1017698] [client 68.155.159.216:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/index/function.php"] [unique_id "apK9EyJcY4fy7tP-rU3xXAAAAjQ"] [Sat Aug 29 05:05:55.608480 2026] [security2:error] [pid 1018003:tid 1018181] [client 52.139.37.240:8605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/essexec.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrZQAABdY"] [Sat Aug 29 05:05:55.608485 2026] [security2:error] [pid 1017536:tid 1017719] [client 158.23.147.79:24402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9EyJcY4fy7tP-rU3xXQAAAkk"] [Sat Aug 29 05:05:55.610534 2026] [security2:error] [pid 1017536:tid 1017773] [client 93.123.109.228:41164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9EyJcY4fy7tP-rU3xXgAAAn8"] [Sat Aug 29 05:05:55.620865 2026] [cgid:error] [pid 1017536:tid 1017539] [remote 45.148.10.62:50914] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/404.shtml [Sat Aug 29 05:05:55.621123 2026] [security2:error] [pid 1017536:tid 1017775] [client 68.155.159.216:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/js/index.php"] [unique_id "apK9EyJcY4fy7tP-rU3xYwAAAoE"] [Sat Aug 29 05:05:55.645421 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.147.79:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin.php"] [unique_id "apK9EzAh5Y1i2tUxg4HraQAABbw"] [Sat Aug 29 05:05:55.653373 2026] [security2:error] [pid 1017536:tid 1017781] [client 93.123.109.228:41138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/admin/phpinfo.php"] [unique_id "apK9EyJcY4fy7tP-rU3xZgAAAoc"] [Sat Aug 29 05:05:55.660006 2026] [security2:error] [pid 1018003:tid 1018230] [client 74.248.24.12:41020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrawAABgY"] [Sat Aug 29 05:05:55.682338 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.68.135:12446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/index.php"] [unique_id "apK9EyJcY4fy7tP-rU3xagAAAko"] [Sat Aug 29 05:05:55.688581 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.250.41:27430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/0byte.php"] [unique_id "apK9EyJcY4fy7tP-rU3xawAAAmc"] [Sat Aug 29 05:05:55.688609 2026] [security2:error] [pid 1017536:tid 1017793] [client 93.123.109.228:41212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/admin_phpinfo.php"] [unique_id "apK9EyJcY4fy7tP-rU3xbAAAApM"] [Sat Aug 29 05:05:55.702579 2026] [core:error] [pid 1017536:tid 1017790] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:55.702601 2026] [core:error] [pid 1017536:tid 1017790] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:55.719220 2026] [security2:error] [pid 1018003:tid 1018223] [client 158.158.54.35:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/theme.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrbgAABgA"] [Sat Aug 29 05:05:55.730043 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.104.49.130:57639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/red.php"] [unique_id "apK9EyJcY4fy7tP-rU3xbgAAAkM"] [Sat Aug 29 05:05:55.735231 2026] [security2:error] [pid 1018003:tid 1018254] [client 138.199.19.170:54414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.dgdevelco.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9EzAh5Y1i2tUxg4HrbwAABh4"] [Sat Aug 29 05:05:55.737718 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.49.130:39068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/memberfuns.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrcAAABc0"] [Sat Aug 29 05:05:55.744847 2026] [security2:error] [pid 1018003:tid 1018231] [client 93.123.109.228:41290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9EzAh5Y1i2tUxg4HrcQAABgc"] [Sat Aug 29 05:05:55.774649 2026] [security2:error] [pid 1017536:tid 1017576] [remote 45.148.10.62:50914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wanderlustpictures.com"] [uri "/wp-login.php"] [unique_id "apK9EyJcY4fy7tP-rU3xcAACHSc"] [Sat Aug 29 05:05:55.778507 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.104.49.130:47818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/df.php"] [unique_id "apK9EyJcY4fy7tP-rU3xcQAAAjk"] [Sat Aug 29 05:05:55.780289 2026] [security2:error] [pid 1017536:tid 1017757] [client 93.123.109.228:41116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9EyJcY4fy7tP-rU3xcgAAAm8"] [Sat Aug 29 05:05:55.785916 2026] [security2:error] [pid 1018003:tid 1018191] [client 93.123.109.228:41280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9EzAh5Y1i2tUxg4HrcwAABeA"] [Sat Aug 29 05:05:55.788911 2026] [security2:error] [pid 1018003:tid 1018239] [client 158.23.147.79:48305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/asd.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrdAAABg8"] [Sat Aug 29 05:05:55.792164 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.151.200.44:64933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9EyJcY4fy7tP-rU3xcwAAAo4"] [Sat Aug 29 05:05:55.799459 2026] [security2:error] [pid 1018003:tid 1018174] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9EzAh5Y1i2tUxg4HrdgAABc8"] [Sat Aug 29 05:05:55.803368 2026] [security2:error] [pid 1017536:tid 1017707] [client 52.139.37.240:8584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/fw.php"] [unique_id "apK9EyJcY4fy7tP-rU3xdQAAAj0"] [Sat Aug 29 05:05:55.808623 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.196.209.81:17080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrdwAABfg"] [Sat Aug 29 05:05:55.830368 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.151.200.44:65524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/bgymj.php"] [unique_id "apK9EyJcY4fy7tP-rU3xeAAAAiU"] [Sat Aug 29 05:05:55.863237 2026] [security2:error] [pid 1018003:tid 1018274] [client 4.205.62.107:61768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/bigdump.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrewAABjI"] [Sat Aug 29 05:05:55.865027 2026] [security2:error] [pid 1017536:tid 1017715] [client 4.232.148.111:8392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/404.php"] [unique_id "apK9EyJcY4fy7tP-rU3xewAAAkU"] [Sat Aug 29 05:05:55.867411 2026] [security2:error] [pid 1017536:tid 1017776] [client 68.155.159.216:14194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9EyJcY4fy7tP-rU3xfAAAAoI"] [Sat Aug 29 05:05:55.881048 2026] [security2:error] [pid 1017536:tid 1017729] [client 168.107.94.195:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9EyJcY4fy7tP-rU3xfQAAAlM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:55.884386 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.104.68.135:38456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9EzAh5Y1i2tUxg4HrfQAABfI"] [Sat Aug 29 05:05:55.940604 2026] [security2:error] [pid 1017536:tid 1017726] [client 40.83.93.50:7782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/wp-admin.php"] [unique_id "apK9EyJcY4fy7tP-rU3xgQAAAlA"] [Sat Aug 29 05:05:55.944088 2026] [security2:error] [pid 1017536:tid 1017710] [client 93.123.109.228:41262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/api/info.php"] [unique_id "apK9EyJcY4fy7tP-rU3xggAAAkA"] [Sat Aug 29 05:05:55.960431 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.197.61.180:17014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK9EyJcY4fy7tP-rU3xhAAAAkw"] [Sat Aug 29 05:05:55.982472 2026] [security2:error] [pid 1017536:tid 1017792] [client 93.123.109.228:41206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/api/phpinfo.php"] [unique_id "apK9EyJcY4fy7tP-rU3xiAAAApI"] [Sat Aug 29 05:05:55.999880 2026] [security2:error] [pid 1017536:tid 1017733] [client 52.139.37.240:8623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/zwso.php"] [unique_id "apK9EyJcY4fy7tP-rU3xigAAAlc"] [Sat Aug 29 05:05:56.009930 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.147.79:32657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/simple.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrhQAABfA"] [Sat Aug 29 05:05:56.026158 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.48.250.41:26904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/xr.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrhwAABhQ"] [Sat Aug 29 05:05:56.048496 2026] [security2:error] [pid 1017536:tid 1017775] [client 138.199.19.170:54424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.dgdevelco.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9FCJcY4fy7tP-rU3xjwAAAoE"] [Sat Aug 29 05:05:56.080802 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.68.135:5372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/pomo/wp-conflg.php"] [unique_id "apK9FCJcY4fy7tP-rU3xkAAAAjQ"] [Sat Aug 29 05:05:56.098942 2026] [security2:error] [pid 1018003:tid 1018269] [client 4.205.62.107:22345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/mamzi.php"] [unique_id "apK9FDAh5Y1i2tUxg4HriwAABi0"] [Sat Aug 29 05:05:56.129795 2026] [security2:error] [pid 1018003:tid 1018167] [client 93.123.109.228:41230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9FDAh5Y1i2tUxg4HrjgAABcg"] [Sat Aug 29 05:05:56.131708 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.48.251.3:33280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/loxi-o.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrjwAABeY"] [Sat Aug 29 05:05:56.141028 2026] [security2:error] [pid 1018003:tid 1018193] [client 4.205.62.107:65494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/cp2.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrkQAABeI"] [Sat Aug 29 05:05:56.144341 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.23.147.79:25568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrkgAABdI"] [Sat Aug 29 05:05:56.150422 2026] [security2:error] [pid 1018003:tid 1018159] [client 4.205.62.107:22489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/dd.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrlAAABcA"] [Sat Aug 29 05:05:56.156194 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.250.41:27542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/h02ugyh.php"] [unique_id "apK9FCJcY4fy7tP-rU3xlQAAAj8"] [Sat Aug 29 05:05:56.169181 2026] [security2:error] [pid 1017536:tid 1017719] [client 158.158.54.35:4246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/classwithtostring.php"] [unique_id "apK9FCJcY4fy7tP-rU3xlgAAAkk"] [Sat Aug 29 05:05:56.171639 2026] [security2:error] [pid 1017536:tid 1017747] [client 93.123.109.228:41278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9FCJcY4fy7tP-rU3xlwAAAmU"] [Sat Aug 29 05:05:56.179081 2026] [security2:error] [pid 1018003:tid 1018250] [client 4.205.62.107:2955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/v4.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrlwAABho"] [Sat Aug 29 05:05:56.192871 2026] [security2:error] [pid 1018003:tid 1018277] [client 52.139.37.240:8604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/admin/function.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrmAAABjU"] [Sat Aug 29 05:05:56.193030 2026] [security2:error] [pid 1017536:tid 1017790] [client 68.155.159.216:16305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9FCJcY4fy7tP-rU3xmQAAApA"] [Sat Aug 29 05:05:56.199978 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.151.200.44:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/fh26.php"] [unique_id "apK9FCJcY4fy7tP-rU3xmgAAAmI"] [Sat Aug 29 05:05:56.203187 2026] [security2:error] [pid 1017536:tid 1017767] [client 68.155.159.216:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9FCJcY4fy7tP-rU3xmwAAAnk"] [Sat Aug 29 05:05:56.212187 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.196.209.81:17132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/config.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrmQAABbg"] [Sat Aug 29 05:05:56.216972 2026] [security2:error] [pid 1017536:tid 1017723] [client 68.155.159.216:33729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/.well-known/index.php"] [unique_id "apK9FCJcY4fy7tP-rU3xnAAAAk0"] [Sat Aug 29 05:05:56.262370 2026] [security2:error] [pid 1018003:tid 1018267] [client 168.107.94.195:57940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrnQAABis"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:56.269122 2026] [security2:error] [pid 1017536:tid 1017715] [client 158.23.147.79:30632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9FCJcY4fy7tP-rU3xnwAAAkU"] [Sat Aug 29 05:05:56.292929 2026] [security2:error] [pid 1018003:tid 1018232] [client 20.48.250.41:26888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/xxw.php"] [unique_id "apK9FDAh5Y1i2tUxg4HroQAABgg"] [Sat Aug 29 05:05:56.299811 2026] [security2:error] [pid 1018003:tid 1018154] [client 158.23.147.79:30650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/ws.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrpAAABbs"] [Sat Aug 29 05:05:56.312269 2026] [security2:error] [pid 1017536:tid 1017732] [client 66.248.203.2:61870] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2015/12/15/fear-and-hate/"] [unique_id "apK9FCJcY4fy7tP-rU3xpQAAAlY"] [Sat Aug 29 05:05:56.319377 2026] [security2:error] [pid 1018003:tid 1018224] [client 68.155.159.216:40345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/x.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrpgAABgE"] [Sat Aug 29 05:05:56.334147 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.151.200.44:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/fgd.php"] [unique_id "apK9FCJcY4fy7tP-rU3xqQAAAk4"] [Sat Aug 29 05:05:56.347959 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.68.135:24170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-includes/rest-api/fields/index.php"] [unique_id "apK9FCJcY4fy7tP-rU3xrQAAAmE"] [Sat Aug 29 05:05:56.347999 2026] [security2:error] [pid 1017536:tid 1017748] [client 4.232.148.111:8424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/php.php"] [unique_id "apK9FCJcY4fy7tP-rU3xrAAAAmY"] [Sat Aug 29 05:05:56.349590 2026] [security2:error] [pid 1017536:tid 1017710] [client 68.155.159.216:18285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9FCJcY4fy7tP-rU3xrgAAAkA"] [Sat Aug 29 05:05:56.359132 2026] [security2:error] [pid 1018003:tid 1018236] [client 74.248.24.12:33441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/gmo.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrrgAABgw"] [Sat Aug 29 05:05:56.375910 2026] [core:error] [pid 1017536:tid 1017690] [client 34.7.40.70:4630] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) [Sat Aug 29 05:05:56.379620 2026] [core:error] [pid 1017536:tid 1017752] [client 34.7.40.70:4672] AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) [Sat Aug 29 05:05:56.380203 2026] [cgid:error] [pid 1017536:tid 1017713] [client 34.7.40.70:4574] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.380469 2026] [security2:error] [pid 1017536:tid 1017752] [client 34.7.40.70:4672] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/400.shtml"] [unique_id "apK9FCJcY4fy7tP-rU3xtgAAAmo"] [Sat Aug 29 05:05:56.380731 2026] [security2:error] [pid 1018003:tid 1018189] [client 34.7.40.70:4644] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9FDAh5Y1i2tUxg4HrsQAABd4"] [Sat Aug 29 05:05:56.380765 2026] [cgid:error] [pid 1018003:tid 1018170] [client 34.7.40.70:4722] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.380923 2026] [security2:error] [pid 1017536:tid 1017760] [client 34.7.40.70:4562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/root/.ssh/id_rsa"] [unique_id "apK9FCJcY4fy7tP-rU3xtQAAAnI"] [Sat Aug 29 05:05:56.381077 2026] [cgid:error] [pid 1018003:tid 1018163] [client 34.7.40.70:4738] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.381077 2026] [security2:error] [pid 1017536:tid 1017765] [client 34.7.40.70:4660] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apK9FCJcY4fy7tP-rU3xtwAAAnc"] [Sat Aug 29 05:05:56.381655 2026] [cgid:error] [pid 1017536:tid 1017764] [client 34.7.40.70:4628] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.381908 2026] [cgid:error] [pid 1017536:tid 1017675] [client 34.7.40.70:4800] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.383087 2026] [security2:error] [pid 1018003:tid 1018226] [client 34.7.40.70:4590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrtQAABgM"] [Sat Aug 29 05:05:56.383484 2026] [security2:error] [pid 1017536:tid 1017757] [client 34.7.40.70:4618] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apK9FCJcY4fy7tP-rU3xuwAAAm8"] [Sat Aug 29 05:05:56.383771 2026] [security2:error] [pid 1017536:tid 1017757] [client 34.7.40.70:4618] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/cgi-sys/403.html"] [unique_id "apK9FCJcY4fy7tP-rU3xuwAAAm8"] [Sat Aug 29 05:05:56.384645 2026] [cgid:error] [pid 1018003:tid 1018157] [client 34.7.40.70:4782] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.384722 2026] [cgid:error] [pid 1018003:tid 1018181] [client 34.7.40.70:4568] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.385005 2026] [cgid:error] [pid 1017536:tid 1017788] [client 34.7.40.70:4688] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.385745 2026] [security2:error] [pid 1018003:tid 1018223] [client 52.139.37.240:8577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/zoom1.php"] [unique_id "apK9FDAh5Y1i2tUxg4HruAAABgA"] [Sat Aug 29 05:05:56.386051 2026] [cgid:error] [pid 1017536:tid 1017740] [client 34.7.40.70:4772] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.386267 2026] [cgid:error] [pid 1018003:tid 1018235] [client 34.7.40.70:4748] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.386836 2026] [cgid:error] [pid 1017536:tid 1017777] [client 34.7.40.70:4686] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.387521 2026] [cgid:error] [pid 1018003:tid 1018190] [client 34.7.40.70:4746] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.387765 2026] [cgid:error] [pid 1017536:tid 1017703] [client 34.7.40.70:4742] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.387856 2026] [security2:error] [pid 1017536:tid 1017703] [client 34.7.40.70:4742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9FCJcY4fy7tP-rU3xuAAAAjk"] [Sat Aug 29 05:05:56.388234 2026] [cgid:error] [pid 1018003:tid 1018241] [client 34.7.40.70:4762] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.389245 2026] [cgid:error] [pid 1017536:tid 1017768] [client 34.7.40.70:4826] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.389566 2026] [cgid:error] [pid 1017536:tid 1017789] [client 34.7.40.70:4674] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.390001 2026] [cgid:error] [pid 1018003:tid 1018230] [client 34.7.40.70:4814] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.390752 2026] [security2:error] [pid 1017536:tid 1017717] [client 138.199.19.170:54440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.dgdevelco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9FCJcY4fy7tP-rU3xxAAAAkc"] [Sat Aug 29 05:05:56.390971 2026] [cgid:error] [pid 1018003:tid 1018264] [client 34.7.40.70:4696] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.391623 2026] [cgid:error] [pid 1017536:tid 1017707] [client 34.7.40.70:4676] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.392244 2026] [cgid:error] [pid 1018003:tid 1018258] [client 34.7.40.70:4576] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.392946 2026] [cgid:error] [pid 1018003:tid 1018188] [client 34.7.40.70:4818] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.393305 2026] [cgid:error] [pid 1017536:tid 1017711] [client 34.7.40.70:4596] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.393386 2026] [cgid:error] [pid 1018003:tid 1018185] [client 34.7.40.70:4708] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.393695 2026] [cgid:error] [pid 1017536:tid 1017784] [client 34.7.40.70:4788] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:05:56.395524 2026] [security2:error] [pid 1018003:tid 1018185] [client 68.155.159.216:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrvwAABdo"] [Sat Aug 29 05:05:56.396989 2026] [security2:error] [pid 1018003:tid 1018183] [client 93.123.109.228:41284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9FDAh5Y1i2tUxg4HrwAAABdg"] [Sat Aug 29 05:05:56.420970 2026] [security2:error] [pid 1018003:tid 1018261] [client 93.123.109.228:41244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9FDAh5Y1i2tUxg4HrwQAABiU"] [Sat Aug 29 05:05:56.424143 2026] [security2:error] [pid 1017536:tid 1017704] [client 216.244.66.243:45084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scottportfolio.com"] [uri "/userfiles/uroki-uvelichil-chlen-5655.xml"] [unique_id "apK9FCJcY4fy7tP-rU3xxwAAAjo"] [Sat Aug 29 05:05:56.424213 2026] [security2:error] [pid 1017536:tid 1017704] [client 216.244.66.243:45084] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scottportfolio.com"] [uri "/userfiles/uroki-uvelichil-chlen-5655.xml"] [unique_id "apK9FCJcY4fy7tP-rU3xxwAAAjo"] [Sat Aug 29 05:05:56.440619 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.48.250.41:27570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/bolt.php"] [unique_id "apK9FCJcY4fy7tP-rU3xygAAAoY"] [Sat Aug 29 05:05:56.465434 2026] [security2:error] [pid 1017536:tid 1017684] [client 40.83.93.50:3145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/wp-configs.php"] [unique_id "apK9FCJcY4fy7tP-rU3xywAAAiY"] [Sat Aug 29 05:05:56.479917 2026] [security2:error] [pid 1018003:tid 1018254] [client 51.68.107.149:16389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "swiapr.com"] [uri "/robots.txt"] [unique_id "apK9FDAh5Y1i2tUxg4HrxAAABh4"] [Sat Aug 29 05:05:56.480057 2026] [security2:error] [pid 1018003:tid 1018254] [client 51.68.107.149:16389] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "swiapr.com"] [uri "/robots.txt"] [unique_id "apK9FDAh5Y1i2tUxg4HrxAAABh4"] [Sat Aug 29 05:05:56.555565 2026] [security2:error] [pid 1017536:tid 1017749] [client 4.205.62.107:55955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/aws_config.php"] [unique_id "apK9FCJcY4fy7tP-rU3x0gAAAmc"] [Sat Aug 29 05:05:56.571594 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.48.250.41:27499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/rtx.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrywAABeM"] [Sat Aug 29 05:05:56.591496 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.49.130:53763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/tiny2.php"] [unique_id "apK9FCJcY4fy7tP-rU3x1AAAAk0"] [Sat Aug 29 05:05:56.593794 2026] [security2:error] [pid 1017536:tid 1017734] [client 52.139.37.240:8455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/about.php7"] [unique_id "apK9FCJcY4fy7tP-rU3x1QAAAlg"] [Sat Aug 29 05:05:56.609581 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.196.209.81:17418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/cong.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrzQAABdk"] [Sat Aug 29 05:05:56.612261 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.49.130:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/one.php"] [unique_id "apK9FDAh5Y1i2tUxg4HrzgAABec"] [Sat Aug 29 05:05:56.625351 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.158.54.35:12232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/news.php"] [unique_id "apK9FCJcY4fy7tP-rU3x2QAAAho"] [Sat Aug 29 05:05:56.665058 2026] [security2:error] [pid 1017536:tid 1017681] [client 168.107.94.195:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9FCJcY4fy7tP-rU3x3AAAAiM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:56.687738 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.197.61.180:5826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/security.php"] [unique_id "apK9FCJcY4fy7tP-rU3x3wAAAjQ"] [Sat Aug 29 05:05:56.694456 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.104.68.135:24157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-links-opml.php"] [unique_id "apK9FCJcY4fy7tP-rU3x4AAAAhU"] [Sat Aug 29 05:05:56.718839 2026] [security2:error] [pid 1018003:tid 1018259] [client 158.23.147.79:24485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/about.php"] [unique_id "apK9FDAh5Y1i2tUxg4Hr1AAABiM"] [Sat Aug 29 05:05:56.724702 2026] [security2:error] [pid 1018003:tid 1018242] [client 68.155.159.216:51263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/.well-known/content.php"] [unique_id "apK9FDAh5Y1i2tUxg4Hr1QAABhI"] [Sat Aug 29 05:05:56.729498 2026] [security2:error] [pid 1017536:tid 1017710] [client 68.155.159.216:12201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/index.php"] [unique_id "apK9FCJcY4fy7tP-rU3x5gAAAkA"] [Sat Aug 29 05:05:56.731378 2026] [security2:error] [pid 1018003:tid 1018167] [client 4.205.62.107:53373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/fucku.php"] [unique_id "apK9FDAh5Y1i2tUxg4Hr1wAABcg"] [Sat Aug 29 05:05:56.748964 2026] [security2:error] [pid 1018003:tid 1018275] [client 93.123.109.228:41130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9FDAh5Y1i2tUxg4Hr2QAABjM"] [Sat Aug 29 05:05:56.749034 2026] [security2:error] [pid 1018003:tid 1018227] [client 93.123.109.228:41256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9FDAh5Y1i2tUxg4Hr2gAABgQ"] [Sat Aug 29 05:05:56.749228 2026] [security2:error] [pid 1017536:tid 1017786] [client 93.123.109.228:41154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9FCJcY4fy7tP-rU3x5wAAAow"] [Sat Aug 29 05:05:56.753649 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9FCJcY4fy7tP-rU3x6AAAApI"] [Sat Aug 29 05:05:56.753854 2026] [security2:error] [pid 1017536:tid 1017785] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9EyJcY4fy7tP-rU3xOQACi0g"] [Sat Aug 29 05:05:56.758424 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.48.250.41:27416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/ckk.php"] [unique_id "apK9FCJcY4fy7tP-rU3x6QAAAkY"] [Sat Aug 29 05:05:56.788416 2026] [security2:error] [pid 1018003:tid 1018221] [client 93.123.109.228:41230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9FDAh5Y1i2tUxg4Hr3AAABf4"] [Sat Aug 29 05:05:56.792493 2026] [security2:error] [pid 1018003:tid 1018225] [client 93.123.109.228:41244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9FDAh5Y1i2tUxg4Hr3QAABgI"] [Sat Aug 29 05:05:56.800637 2026] [security2:error] [pid 1018003:tid 1018197] [client 52.139.37.240:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/cron.php"] [unique_id "apK9FDAh5Y1i2tUxg4Hr3gAABeY"] [Sat Aug 29 05:05:56.827624 2026] [security2:error] [pid 1018003:tid 1018244] [client 4.232.148.111:32318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/init.php"] [unique_id "apK9FDAh5Y1i2tUxg4Hr4AAABhQ"] [Sat Aug 29 05:05:56.890137 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.250.41:26893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.unitymarriageministry.org"] [uri "/R57.php"] [unique_id "apK9FCJcY4fy7tP-rU3x8QAAAkE"] [Sat Aug 29 05:05:56.890593 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.151.200.44:64899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/inject.php"] [unique_id "apK9FCJcY4fy7tP-rU3x8gAAAoo"] [Sat Aug 29 05:05:56.891697 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.68.135:16031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/wp-signup.php"] [unique_id "apK9FCJcY4fy7tP-rU3x8wAAAl4"] [Sat Aug 29 05:05:56.894470 2026] [security2:error] [pid 1017536:tid 1017688] [client 158.23.147.79:48344] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.lapoutine.co.uk"] [uri "/1.php"] [unique_id "apK9FCJcY4fy7tP-rU3x9AAAAio"] [Sat Aug 29 05:05:56.894567 2026] [security2:error] [pid 1017536:tid 1017688] [client 158.23.147.79:48344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/1.php"] [unique_id "apK9FCJcY4fy7tP-rU3x9AAAAio"] [Sat Aug 29 05:05:56.921033 2026] [security2:error] [pid 1018003:tid 1018218] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9FDAh5Y1i2tUxg4Hr6AAABfs"] [Sat Aug 29 05:05:56.925819 2026] [security2:error] [pid 1018003:tid 1018263] [client 138.199.19.170:54450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.dgdevelco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9FDAh5Y1i2tUxg4Hr6gAABic"] [Sat Aug 29 05:05:56.926563 2026] [security2:error] [pid 1017536:tid 1017704] [client 93.123.109.228:41096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9FCJcY4fy7tP-rU3x-AAAAjo"] [Sat Aug 29 05:05:56.933652 2026] [security2:error] [pid 1018003:tid 1018267] [client 93.123.109.228:41256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9FDAh5Y1i2tUxg4Hr6QAABis"] [Sat Aug 29 05:05:56.950703 2026] [security2:error] [pid 1017536:tid 1017765] [client 40.83.93.50:7802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/essexec.php"] [unique_id "apK9FCJcY4fy7tP-rU3x-QAAAnc"] [Sat Aug 29 05:05:56.960951 2026] [security2:error] [pid 1018003:tid 1018240] [client 74.248.24.12:40897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/classwithtostring.php"] [unique_id "apK9FDAh5Y1i2tUxg4Hr7QAABhA"] [Sat Aug 29 05:05:56.990069 2026] [security2:error] [pid 1017536:tid 1017679] [client 65.111.23.104:31249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9FCJcY4fy7tP-rU3x-gAAAiE"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:57.000298 2026] [security2:error] [pid 1018003:tid 1018232] [client 52.139.37.240:8460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/wp-2019.php"] [unique_id "apK9FDAh5Y1i2tUxg4Hr7gAABgg"] [Sat Aug 29 05:05:57.003094 2026] [security2:error] [pid 1017536:tid 1017736] [client 4.205.62.107:61829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/wdf.php"] [unique_id "apK9FSJcY4fy7tP-rU3x_AAAAlo"] [Sat Aug 29 05:05:57.025273 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.151.200.44:64860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/mga.php"] [unique_id "apK9FSJcY4fy7tP-rU3x_gAAAls"] [Sat Aug 29 05:05:57.028492 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.251.3:13982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/api.php"] [unique_id "apK9FTAh5Y1i2tUxg4Hr8QAABgM"] [Sat Aug 29 05:05:57.035564 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.196.209.81:17024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/content.php"] [unique_id "apK9FSJcY4fy7tP-rU3yAAAAAmM"] [Sat Aug 29 05:05:57.039759 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.48.250.41:60673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9FSJcY4fy7tP-rU3yAQAAAlg"] [Sat Aug 29 05:05:57.044448 2026] [security2:error] [pid 1017536:tid 1017674] [client 168.107.94.195:58659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9FSJcY4fy7tP-rU3yAgAAAhw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:57.054617 2026] [security2:error] [pid 1018003:tid 1018181] [client 93.123.109.228:41290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9FTAh5Y1i2tUxg4Hr8gAABdY"] [Sat Aug 29 05:05:57.078551 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.158.54.35:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/about/function.php"] [unique_id "apK9FSJcY4fy7tP-rU3yBgAAAks"] [Sat Aug 29 05:05:57.078608 2026] [security2:error] [pid 1017536:tid 1017672] [client 93.123.109.228:41096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9FSJcY4fy7tP-rU3yBQAAAho"] [Sat Aug 29 05:05:57.105759 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.68.135:51399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/xmlrpc.php"] [unique_id "apK9FSJcY4fy7tP-rU3yBwAAAko"] [Sat Aug 29 05:05:57.113389 2026] [security2:error] [pid 1018003:tid 1018215] [client 158.23.147.79:32727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/about.php"] [unique_id "apK9FTAh5Y1i2tUxg4Hr-QAABfg"] [Sat Aug 29 05:05:57.135752 2026] [security2:error] [pid 1018003:tid 1018164] [client 93.123.109.228:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config.php"] [unique_id "apK9FTAh5Y1i2tUxg4Hr-wAABcU"] [Sat Aug 29 05:05:57.156908 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.151.200.44:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/inwp.php"] [unique_id "apK9FSJcY4fy7tP-rU3yDQAAAlY"] [Sat Aug 29 05:05:57.200389 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.139.37.240:8589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/gecko-new.php"] [unique_id "apK9FTAh5Y1i2tUxg4Hr_wAABdg"] [Sat Aug 29 05:05:57.207641 2026] [security2:error] [pid 1018003:tid 1018173] [client 93.123.109.228:41290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9FTAh5Y1i2tUxg4HsAAAABc4"] [Sat Aug 29 05:05:57.219208 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.48.250.41:60790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsAQAABhU"] [Sat Aug 29 05:05:57.235910 2026] [security2:error] [pid 1018003:tid 1018192] [client 4.205.62.107:22323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/admin.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsAwAABeE"] [Sat Aug 29 05:05:57.246490 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.147.79:25511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/cong.php"] [unique_id "apK9FSJcY4fy7tP-rU3yEgAAAmE"] [Sat Aug 29 05:05:57.249004 2026] [security2:error] [pid 1017536:tid 1017792] [client 93.123.109.228:41154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/aws.php"] [unique_id "apK9FSJcY4fy7tP-rU3yEwAAApI"] [Sat Aug 29 05:05:57.265976 2026] [security2:error] [pid 1018003:tid 1018180] [client 93.123.109.228:41130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/config.inc.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsBgAABdU"] [Sat Aug 29 05:05:57.277717 2026] [security2:error] [pid 1017536:tid 1017716] [client 4.205.62.107:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/xda.php"] [unique_id "apK9FSJcY4fy7tP-rU3yFQAAAkY"] [Sat Aug 29 05:05:57.298753 2026] [security2:error] [pid 1017536:tid 1017764] [client 4.205.62.107:22252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/doc.php"] [unique_id "apK9FSJcY4fy7tP-rU3yGAAAAnY"] [Sat Aug 29 05:05:57.298753 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.151.200.44:64888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/ad1.php"] [unique_id "apK9FSJcY4fy7tP-rU3yFwAAAh0"] [Sat Aug 29 05:05:57.303776 2026] [security2:error] [pid 1017536:tid 1017681] [client 4.232.148.111:36582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "apK9FSJcY4fy7tP-rU3yGQAAAiM"] [Sat Aug 29 05:05:57.305010 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.68.135:24191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kevinpascoe.com"] [uri "/yas.php"] [unique_id "apK9FSJcY4fy7tP-rU3yGgAAAow"] [Sat Aug 29 05:05:57.310564 2026] [security2:error] [pid 1017536:tid 1017783] [client 68.155.159.216:51550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9FSJcY4fy7tP-rU3yGwAAAok"] [Sat Aug 29 05:05:57.317767 2026] [security2:error] [pid 1018003:tid 1018184] [client 4.205.62.107:2676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/debuggen.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsCQAABdk"] [Sat Aug 29 05:05:57.335186 2026] [security2:error] [pid 1017536:tid 1017711] [client 93.123.109.228:41278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/config.php"] [unique_id "apK9FSJcY4fy7tP-rU3yHAAAAkE"] [Sat Aug 29 05:05:57.335453 2026] [security2:error] [pid 1017536:tid 1017768] [client 68.155.159.216:33611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9FSJcY4fy7tP-rU3yHQAAAno"] [Sat Aug 29 05:05:57.346424 2026] [security2:error] [pid 1018003:tid 1018150] [client 68.155.159.216:16168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/login.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsDAAABbc"] [Sat Aug 29 05:05:57.370020 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.48.250.41:62495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ff1.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsDwAABeQ"] [Sat Aug 29 05:05:57.370744 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.251.3:13989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/temp.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsEAAABcI"] [Sat Aug 29 05:05:57.375907 2026] [security2:error] [pid 1018003:tid 1018259] [client 158.23.147.79:30619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsEQAABiM"] [Sat Aug 29 05:05:57.395869 2026] [security2:error] [pid 1017536:tid 1017704] [client 93.123.109.228:41094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/env.php"] [unique_id "apK9FSJcY4fy7tP-rU3yHwAAAjo"] [Sat Aug 29 05:05:57.397953 2026] [security2:error] [pid 1018003:tid 1018198] [client 52.139.37.240:8481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/add_actualites.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsEgAABec"] [Sat Aug 29 05:05:57.412580 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.251.3:61650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9FSJcY4fy7tP-rU3yIQAAAoc"] [Sat Aug 29 05:05:57.417331 2026] [security2:error] [pid 1018003:tid 1018219] [client 93.123.109.228:41284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/module.config.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsFAAABfw"] [Sat Aug 29 05:05:57.422677 2026] [security2:error] [pid 1017536:tid 1017684] [client 93.123.109.228:41164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/nexmo.php"] [unique_id "apK9FSJcY4fy7tP-rU3yIwAAAiY"] [Sat Aug 29 05:05:57.423747 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.197.61.180:16971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsFQAABbo"] [Sat Aug 29 05:05:57.427858 2026] [security2:error] [pid 1018003:tid 1018227] [client 185.104.184.230:38814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK9FTAh5Y1i2tUxg4HsFgAABgQ"] [Sat Aug 29 05:05:57.439863 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.196.209.81:18690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/core.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsFwAABdQ"] [Sat Aug 29 05:05:57.440818 2026] [security2:error] [pid 1017536:tid 1017669] [client 68.155.159.216:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-content/x.php"] [unique_id "apK9FSJcY4fy7tP-rU3yJQAAAhc"] [Sat Aug 29 05:05:57.446516 2026] [security2:error] [pid 1018003:tid 1018202] [client 40.83.93.50:8009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/hello.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsGQAABes"] [Sat Aug 29 05:05:57.446933 2026] [security2:error] [pid 1017536:tid 1017712] [client 168.107.94.195:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9FSJcY4fy7tP-rU3yJgAAAkI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:57.457547 2026] [security2:error] [pid 1017536:tid 1017679] [client 93.123.109.228:41194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/config/stripe.php"] [unique_id "apK9FSJcY4fy7tP-rU3yKAAAAiE"] [Sat Aug 29 05:05:57.504800 2026] [security2:error] [pid 1017536:tid 1017691] [client 68.155.159.216:50343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9FSJcY4fy7tP-rU3yLAAAAi0"] [Sat Aug 29 05:05:57.507294 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.151.200.44:64897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/1vbqo.php"] [unique_id "apK9FSJcY4fy7tP-rU3yLQAAAn8"] [Sat Aug 29 05:05:57.530585 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.250.41:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/t.php"] [unique_id "apK9FSJcY4fy7tP-rU3yLgAAAjw"] [Sat Aug 29 05:05:57.532859 2026] [security2:error] [pid 1017536:tid 1017717] [client 74.248.24.12:40935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/404.php"] [unique_id "apK9FSJcY4fy7tP-rU3yLwAAAkc"] [Sat Aug 29 05:05:57.540476 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.48.251.3:61673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsHgAABjY"] [Sat Aug 29 05:05:57.560196 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.49.130:47824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/xmini4.php"] [unique_id "apK9FSJcY4fy7tP-rU3yMAAAAls"] [Sat Aug 29 05:05:57.588372 2026] [security2:error] [pid 1018003:tid 1018244] [client 52.139.37.240:8450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/browse.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsIwAABhQ"] [Sat Aug 29 05:05:57.649179 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.151.200.44:64889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/h02ugyh.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsJgAABcw"] [Sat Aug 29 05:05:57.649742 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.49.130:51349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/wsd.php"] [unique_id "apK9FSJcY4fy7tP-rU3yOwAAAko"] [Sat Aug 29 05:05:57.653441 2026] [security2:error] [pid 1017536:tid 1017727] [client 65.111.23.85:26287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9FSJcY4fy7tP-rU3yOgAAAlE"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:05:57.669699 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.251.3:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/cloud.php"] [unique_id "apK9FSJcY4fy7tP-rU3yPwAAAjQ"] [Sat Aug 29 05:05:57.680375 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.48.250.41:60767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/erty.php"] [unique_id "apK9FSJcY4fy7tP-rU3yQAAAAms"] [Sat Aug 29 05:05:57.686146 2026] [security2:error] [pid 1017536:tid 1017725] [client 68.155.159.216:58361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-l0gin.php"] [unique_id "apK9FSJcY4fy7tP-rU3yQgAAAk8"] [Sat Aug 29 05:05:57.693280 2026] [security2:error] [pid 1017536:tid 1017724] [client 4.205.62.107:56003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/dialog.php"] [unique_id "apK9FSJcY4fy7tP-rU3yQwAAAk4"] [Sat Aug 29 05:05:57.703051 2026] [security2:error] [pid 1018003:tid 1018239] [client 93.123.109.228:41122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9FTAh5Y1i2tUxg4HsKAAABg8"] [Sat Aug 29 05:05:57.710989 2026] [security2:error] [pid 1018003:tid 1018203] [client 93.123.109.228:41290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9FTAh5Y1i2tUxg4HsKQAABew"] [Sat Aug 29 05:05:57.721564 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.158.54.35:19504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/admin.php"] [unique_id "apK9FSJcY4fy7tP-rU3yRAAAAmY"] [Sat Aug 29 05:05:57.733400 2026] [security2:error] [pid 1017536:tid 1017743] [client 93.123.109.228:41096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9FSJcY4fy7tP-rU3yRQAAAmE"] [Sat Aug 29 05:05:57.736937 2026] [security2:error] [pid 1017536:tid 1017785] [client 185.104.184.230:38822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "apK9FSJcY4fy7tP-rU3yRwAAAos"] [Sat Aug 29 05:05:57.741762 2026] [security2:error] [pid 1017536:tid 1017716] [client 93.123.109.228:41328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9FSJcY4fy7tP-rU3ySAAAAkY"] [Sat Aug 29 05:05:57.755531 2026] [security2:error] [pid 1018003:tid 1018232] [client 93.123.109.228:41330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9FTAh5Y1i2tUxg4HsLAAABgg"] [Sat Aug 29 05:05:57.758381 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.48.251.3:33326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/fm.php"] [unique_id "apK9FSJcY4fy7tP-rU3ySgAAAh0"] [Sat Aug 29 05:05:57.770979 2026] [security2:error] [pid 1017536:tid 1017764] [client 93.123.109.228:41298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9FSJcY4fy7tP-rU3ySwAAAnY"] [Sat Aug 29 05:05:57.773257 2026] [security2:error] [pid 1018003:tid 1018231] [client 52.139.37.240:8628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/contentloader1.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsLQAABgc"] [Sat Aug 29 05:05:57.782899 2026] [security2:error] [pid 1017536:tid 1017757] [client 93.123.109.228:41332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9FSJcY4fy7tP-rU3yTAAAAm8"] [Sat Aug 29 05:05:57.792197 2026] [security2:error] [pid 1017536:tid 1017786] [client 93.123.109.228:41314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9FSJcY4fy7tP-rU3yTgAAAow"] [Sat Aug 29 05:05:57.793162 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.151.200.44:64885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/shelp.php"] [unique_id "apK9FSJcY4fy7tP-rU3yTwAAAok"] [Sat Aug 29 05:05:57.800458 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.251.3:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/kerang.php"] [unique_id "apK9FSJcY4fy7tP-rU3yUAAAAo4"] [Sat Aug 29 05:05:57.812163 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.48.250.41:62525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/0x.php"] [unique_id "apK9FSJcY4fy7tP-rU3yUQAAAoM"] [Sat Aug 29 05:05:57.825417 2026] [security2:error] [pid 1017536:tid 1017784] [client 158.23.147.79:24514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9FSJcY4fy7tP-rU3yUwAAAoo"] [Sat Aug 29 05:05:57.828611 2026] [security2:error] [pid 1018003:tid 1018170] [client 168.107.94.195:59437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsLwAABcs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:57.833288 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.196.209.81:18725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/db-status.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsMAAABiA"] [Sat Aug 29 05:05:57.835547 2026] [security2:error] [pid 1017536:tid 1017688] [client 68.155.159.216:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/about/function.php"] [unique_id "apK9FSJcY4fy7tP-rU3yVAAAAio"] [Sat Aug 29 05:05:57.847206 2026] [security2:error] [pid 1017536:tid 1017707] [client 68.155.159.216:51249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/cong.php"] [unique_id "apK9FSJcY4fy7tP-rU3yVQAAAj0"] [Sat Aug 29 05:05:57.858015 2026] [security2:error] [pid 1017536:tid 1017775] [client 158.23.147.79:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/lock.php"] [unique_id "apK9FSJcY4fy7tP-rU3yVwAAAoE"] [Sat Aug 29 05:05:57.870477 2026] [security2:error] [pid 1017536:tid 1017669] [client 4.205.62.107:53378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/aws_config.php"] [unique_id "apK9FSJcY4fy7tP-rU3yWQAAAhc"] [Sat Aug 29 05:05:57.892080 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.49.130:48514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/x1da.php"] [unique_id "apK9FSJcY4fy7tP-rU3yXQAAAj8"] [Sat Aug 29 05:05:57.914055 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.49.130:63609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/dex.php"] [unique_id "apK9FSJcY4fy7tP-rU3yXgAAAi0"] [Sat Aug 29 05:05:57.917431 2026] [security2:error] [pid 1017536:tid 1017706] [client 40.83.93.50:23514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK9FSJcY4fy7tP-rU3yYAAAAjw"] [Sat Aug 29 05:05:57.931167 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.251.3:62109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/rem.php"] [unique_id "apK9FSJcY4fy7tP-rU3yYgAAAmc"] [Sat Aug 29 05:05:57.934510 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.151.200.44:64840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/13ede.php"] [unique_id "apK9FSJcY4fy7tP-rU3yZAAAAnk"] [Sat Aug 29 05:05:57.938567 2026] [security2:error] [pid 1018003:tid 1018191] [client 40.83.93.50:3142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/fi2.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsOQAABeA"] [Sat Aug 29 05:05:57.963232 2026] [security2:error] [pid 1018003:tid 1018190] [client 93.123.109.228:41230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9FTAh5Y1i2tUxg4HsOgAABd8"] [Sat Aug 29 05:05:57.964469 2026] [security2:error] [pid 1017536:tid 1017793] [client 52.139.37.240:9095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/upfile.php"] [unique_id "apK9FSJcY4fy7tP-rU3yaQAAApM"] [Sat Aug 29 05:05:57.980982 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.49.130:20651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/amax.php"] [unique_id "apK9FSJcY4fy7tP-rU3yagAAAk0"] [Sat Aug 29 05:05:57.981708 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.250.41:60677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/66.php"] [unique_id "apK9FTAh5Y1i2tUxg4HsPAAABgY"] [Sat Aug 29 05:05:57.983791 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9FSJcY4fy7tP-rU3yawAAAjI"] [Sat Aug 29 05:05:58.009269 2026] [security2:error] [pid 1018003:tid 1018241] [client 158.23.147.79:48313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/ws.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsPQAABhE"] [Sat Aug 29 05:05:58.020312 2026] [security2:error] [pid 1018003:tid 1018188] [client 93.123.109.228:41256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9FjAh5Y1i2tUxg4HsPwAABd0"] [Sat Aug 29 05:05:58.022856 2026] [security2:error] [pid 1017536:tid 1017720] [client 93.123.109.228:41322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9FiJcY4fy7tP-rU3ybgAAAko"] [Sat Aug 29 05:05:58.030956 2026] [security2:error] [pid 1018003:tid 1018185] [client 93.123.109.228:41280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsQAAABdo"] [Sat Aug 29 05:05:58.046575 2026] [security2:error] [pid 1017536:tid 1017693] [client 68.155.159.216:14231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9FiJcY4fy7tP-rU3ycgAAAi8"] [Sat Aug 29 05:05:58.052844 2026] [security2:error] [pid 1017536:tid 1017769] [client 74.248.24.12:33436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/php.php"] [unique_id "apK9FiJcY4fy7tP-rU3ydQAAAns"] [Sat Aug 29 05:05:58.059392 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.48.251.3:61651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/min.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsRAAABhU"] [Sat Aug 29 05:05:58.091963 2026] [security2:error] [pid 1018003:tid 1018254] [client 93.123.109.228:41348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsRgAABh4"] [Sat Aug 29 05:05:58.099810 2026] [security2:error] [pid 1017536:tid 1017724] [client 93.123.109.228:41328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9FiJcY4fy7tP-rU3yegAAAk4"] [Sat Aug 29 05:05:58.115545 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.251.3:14035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-blog.php"] [unique_id "apK9FiJcY4fy7tP-rU3yewAAAmY"] [Sat Aug 29 05:05:58.116527 2026] [security2:error] [pid 1017536:tid 1017792] [client 4.232.148.111:33863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-content/admin.php"] [unique_id "apK9FiJcY4fy7tP-rU3yfAAAApI"] [Sat Aug 29 05:05:58.142325 2026] [security2:error] [pid 1017536:tid 1017731] [client 4.205.62.107:64959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/bb.php"] [unique_id "apK9FiJcY4fy7tP-rU3ygAAAAlU"] [Sat Aug 29 05:05:58.154837 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.250.41:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/f35.php"] [unique_id "apK9FiJcY4fy7tP-rU3yggAAAkM"] [Sat Aug 29 05:05:58.164164 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.197.61.180:5845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/system.php"] [unique_id "apK9FiJcY4fy7tP-rU3ygwAAAn8"] [Sat Aug 29 05:05:58.171343 2026] [security2:error] [pid 1017536:tid 1017722] [client 52.139.37.240:8464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/form.php"] [unique_id "apK9FiJcY4fy7tP-rU3yhQAAAkw"] [Sat Aug 29 05:05:58.173363 2026] [security2:error] [pid 1017536:tid 1017752] [client 93.123.109.228:41322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/info.php"] [unique_id "apK9FiJcY4fy7tP-rU3yhgAAAmo"] [Sat Aug 29 05:05:58.183812 2026] [security2:error] [pid 1017536:tid 1017760] [client 93.123.109.228:41316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/infos.php"] [unique_id "apK9FiJcY4fy7tP-rU3yhwAAAnI"] [Sat Aug 29 05:05:58.187482 2026] [security2:error] [pid 1018003:tid 1018273] [client 93.123.109.228:41280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/infophp.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsSwAABjE"] [Sat Aug 29 05:05:58.188282 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.48.251.3:62129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/saiga.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsTAAABhw"] [Sat Aug 29 05:05:58.195184 2026] [security2:error] [pid 1018003:tid 1018194] [client 185.104.184.230:38832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9FjAh5Y1i2tUxg4HsTQAABeM"] [Sat Aug 29 05:05:58.208303 2026] [security2:error] [pid 1017536:tid 1017750] [client 168.107.94.195:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9FiJcY4fy7tP-rU3yiAAAAmg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:58.223048 2026] [security2:error] [pid 1018003:tid 1018150] [client 93.123.109.228:41122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsTwAABbc"] [Sat Aug 29 05:05:58.254574 2026] [security2:error] [pid 1018003:tid 1018195] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsUAAABeQ"] [Sat Aug 29 05:05:58.258111 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:32726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsUQAABdA"] [Sat Aug 29 05:05:58.258543 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.196.209.81:17079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsUgAABfY"] [Sat Aug 29 05:05:58.276174 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.151.200.44:64909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/k8.php"] [unique_id "apK9FiJcY4fy7tP-rU3yjAAAAmA"] [Sat Aug 29 05:05:58.283665 2026] [autoindex:error] [pid 1017536:tid 1017785] [client 45.148.10.166:49904] AH01276: Cannot serve directory /home3/uochiamy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:05:58.283919 2026] [security2:error] [pid 1018003:tid 1018156] [client 93.123.109.228:41230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsUwAABb0"] [Sat Aug 29 05:05:58.305039 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.250.41:60789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wen.php"] [unique_id "apK9FiJcY4fy7tP-rU3yjwAAAoE"] [Sat Aug 29 05:05:58.313763 2026] [security2:error] [pid 1018003:tid 1018257] [client 93.123.109.228:41348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsVQAABiE"] [Sat Aug 29 05:05:58.316548 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.48.251.3:62094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ammika.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsVgAABiM"] [Sat Aug 29 05:05:58.317243 2026] [security2:error] [pid 1017536:tid 1017704] [client 158.158.54.35:12268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/lock360.php"] [unique_id "apK9FiJcY4fy7tP-rU3ykAAAAjo"] [Sat Aug 29 05:05:58.325123 2026] [security2:error] [pid 1017536:tid 1017780] [client 93.123.109.228:41332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9FiJcY4fy7tP-rU3ykQAAAoY"] [Sat Aug 29 05:05:58.335749 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.251.3:14013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/erty.php"] [unique_id "apK9FiJcY4fy7tP-rU3ykgAAAmQ"] [Sat Aug 29 05:05:58.347659 2026] [security2:error] [pid 1018003:tid 1018275] [client 93.123.109.228:41256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsVwAABjM"] [Sat Aug 29 05:05:58.353017 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.147.79:25541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsWAAABbo"] [Sat Aug 29 05:05:58.373022 2026] [security2:error] [pid 1017536:tid 1017761] [client 52.139.37.240:8465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/wp-sigunq.php"] [unique_id "apK9FiJcY4fy7tP-rU3ylQAAAnM"] [Sat Aug 29 05:05:58.382742 2026] [security2:error] [pid 1017536:tid 1017717] [client 4.205.62.107:22248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/g3.php"] [unique_id "apK9FiJcY4fy7tP-rU3ylgAAAkc"] [Sat Aug 29 05:05:58.389079 2026] [security2:error] [pid 1017536:tid 1017788] [client 40.83.93.50:5893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/options-general.php"] [unique_id "apK9FiJcY4fy7tP-rU3ymAAAAo4"] [Sat Aug 29 05:05:58.389808 2026] [security2:error] [pid 1018003:tid 1018250] [client 93.123.109.228:41290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsXAAABho"] [Sat Aug 29 05:05:58.412556 2026] [security2:error] [pid 1017536:tid 1017703] [client 93.123.109.228:41096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9FiJcY4fy7tP-rU3ymgAAAjk"] [Sat Aug 29 05:05:58.419238 2026] [security2:error] [pid 1017536:tid 1017672] [client 68.155.159.216:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/classwithtostring.php"] [unique_id "apK9FiJcY4fy7tP-rU3ymwAAAho"] [Sat Aug 29 05:05:58.419927 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.151.200.44:64944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/alog.php"] [unique_id "apK9FiJcY4fy7tP-rU3ynAAAAlg"] [Sat Aug 29 05:05:58.422582 2026] [security2:error] [pid 1018003:tid 1018268] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsXQAABiw"] [Sat Aug 29 05:05:58.424560 2026] [security2:error] [pid 1017536:tid 1017670] [client 4.205.62.107:65410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/pinfo.php"] [unique_id "apK9FiJcY4fy7tP-rU3ynQAAAhg"] [Sat Aug 29 05:05:58.426544 2026] [security2:error] [pid 1017536:tid 1017688] [client 40.83.93.50:14429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/1p.php"] [unique_id "apK9FiJcY4fy7tP-rU3yngAAAio"] [Sat Aug 29 05:05:58.428726 2026] [security2:error] [pid 1018003:tid 1018225] [client 93.123.109.228:41354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsXgAABgI"] [Sat Aug 29 05:05:58.428862 2026] [security2:error] [pid 1017536:tid 1017730] [client 93.123.109.228:41328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9FiJcY4fy7tP-rU3ynwAAAlQ"] [Sat Aug 29 05:05:58.435232 2026] [security2:error] [pid 1017536:tid 1017754] [client 4.205.62.107:22472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/fun.php"] [unique_id "apK9FiJcY4fy7tP-rU3yoAAAAmw"] [Sat Aug 29 05:05:58.439150 2026] [security2:error] [pid 1017536:tid 1017715] [client 68.155.159.216:33750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/radio.php"] [unique_id "apK9FiJcY4fy7tP-rU3yoQAAAkU"] [Sat Aug 29 05:05:58.442333 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.48.251.3:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/broadcasting.php"] [unique_id "apK9FiJcY4fy7tP-rU3yogAAAiA"] [Sat Aug 29 05:05:58.453110 2026] [security2:error] [pid 1018003:tid 1018212] [client 93.123.109.228:41230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsXwAABfU"] [Sat Aug 29 05:05:58.455408 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:16147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/hehehehe.php"] [unique_id "apK9FiJcY4fy7tP-rU3ypgAAAms"] [Sat Aug 29 05:05:58.455440 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:2927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/wp-admin/sc.php"] [unique_id "apK9FiJcY4fy7tP-rU3ypQAAAnk"] [Sat Aug 29 05:05:58.455497 2026] [security2:error] [pid 1017536:tid 1017724] [client 93.123.109.228:41116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9FiJcY4fy7tP-rU3ypAAAAk4"] [Sat Aug 29 05:05:58.481602 2026] [security2:error] [pid 1017536:tid 1017792] [client 93.123.109.228:41332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9FiJcY4fy7tP-rU3yqgAAApI"] [Sat Aug 29 05:05:58.501810 2026] [security2:error] [pid 1018003:tid 1018276] [client 185.104.184.230:38848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9FjAh5Y1i2tUxg4HsZAAABjQ"] [Sat Aug 29 05:05:58.502018 2026] [security2:error] [pid 1017536:tid 1017722] [client 93.123.109.228:41314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9FiJcY4fy7tP-rU3yrwAAAkw"] [Sat Aug 29 05:05:58.503750 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.147.79:30603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9FiJcY4fy7tP-rU3ysAAAAiU"] [Sat Aug 29 05:05:58.513169 2026] [security2:error] [pid 1017536:tid 1017726] [client 34.21.253.104:1272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/.git/HEAD"] [unique_id "apK9FiJcY4fy7tP-rU3yuAAAAlA"] [Sat Aug 29 05:05:58.516001 2026] [proxy_http:error] [pid 1017536:tid 1017736] (20014)Internal error (specific information not available): [client 34.21.253.104:1406] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:58.516017 2026] [proxy:error] [pid 1017536:tid 1017736] [client 34.21.253.104:1406] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.gcloud/credentials [Sat Aug 29 05:05:58.519292 2026] [proxy_http:error] [pid 1018003:tid 1018205] (20014)Internal error (specific information not available): [client 34.21.253.104:1248] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:58.519312 2026] [proxy:error] [pid 1018003:tid 1018205] [client 34.21.253.104:1248] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/public/.env [Sat Aug 29 05:05:58.519697 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.48.250.41:62589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/inc.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsagAABhk"] [Sat Aug 29 05:05:58.522945 2026] [proxy_http:error] [pid 1017536:tid 1017705] (20014)Internal error (specific information not available): [client 34.21.253.104:1370] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:58.522964 2026] [proxy:error] [pid 1017536:tid 1017705] [client 34.21.253.104:1370] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/aws_credentials [Sat Aug 29 05:05:58.526634 2026] [proxy_http:error] [pid 1018003:tid 1018219] (20014)Internal error (specific information not available): [client 34.21.253.104:1356] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:58.526648 2026] [proxy:error] [pid 1018003:tid 1018219] [client 34.21.253.104:1356] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/aws.json [Sat Aug 29 05:05:58.528042 2026] [proxy_http:error] [pid 1017536:tid 1017749] (20014)Internal error (specific information not available): [client 34.21.253.104:1394] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:58.528051 2026] [proxy:error] [pid 1017536:tid 1017749] [client 34.21.253.104:1394] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.gcloud/credentials.json [Sat Aug 29 05:05:58.533877 2026] [proxy_http:error] [pid 1017536:tid 1017709] (20014)Internal error (specific information not available): [client 34.21.253.104:1344] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:05:58.533893 2026] [proxy:error] [pid 1017536:tid 1017709] [client 34.21.253.104:1344] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/aws.env [Sat Aug 29 05:05:58.561620 2026] [security2:error] [pid 1017536:tid 1017786] [client 68.155.159.216:61634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9FiJcY4fy7tP-rU3yuwAAAow"] [Sat Aug 29 05:05:58.561815 2026] [security2:error] [pid 1017536:tid 1017719] [client 74.248.24.12:41023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/init.php"] [unique_id "apK9FiJcY4fy7tP-rU3yvAAAAkk"] [Sat Aug 29 05:05:58.569554 2026] [security2:error] [pid 1017536:tid 1017752] [client 52.139.37.240:8578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mykaratetutor.com"] [uri "/07.php"] [unique_id "apK9FiJcY4fy7tP-rU3yvgAAAmo"] [Sat Aug 29 05:05:58.569593 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.48.251.3:62137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws_config.php"] [unique_id "apK9FiJcY4fy7tP-rU3yvwAAAoM"] [Sat Aug 29 05:05:58.590758 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.151.200.44:64902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/adin.php"] [unique_id "apK9FiJcY4fy7tP-rU3ywQAAAis"] [Sat Aug 29 05:05:58.591505 2026] [security2:error] [pid 1017536:tid 1017720] [client 4.232.148.111:34891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-configs.php"] [unique_id "apK9FiJcY4fy7tP-rU3ywwAAAko"] [Sat Aug 29 05:05:58.600879 2026] [security2:error] [pid 1018003:tid 1018154] [client 20.48.251.3:13988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-config.backup.php"] [unique_id "apK9FjAh5Y1i2tUxg4HscwAABbs"] [Sat Aug 29 05:05:58.611026 2026] [security2:error] [pid 1018003:tid 1018224] [client 68.155.159.216:50251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsdAAABgE"] [Sat Aug 29 05:05:58.627882 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.147.79:35818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9FiJcY4fy7tP-rU3yyQAAAj0"] [Sat Aug 29 05:05:58.641870 2026] [security2:error] [pid 1017536:tid 1017784] [client 168.107.94.195:60465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9FiJcY4fy7tP-rU3ywgAAAoo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:58.649633 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.48.250.41:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/6bcwiqwj.php"] [unique_id "apK9FiJcY4fy7tP-rU3yzQAAAnM"] [Sat Aug 29 05:05:58.656012 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.196.209.81:17076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/f35.php"] [unique_id "apK9FjAh5Y1i2tUxg4HseAAABfs"] [Sat Aug 29 05:05:58.698875 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.251.3:61196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/dialog.php"] [unique_id "apK9FiJcY4fy7tP-rU3y0wAAAhw"] [Sat Aug 29 05:05:58.715917 2026] [security2:error] [pid 1017536:tid 1017715] [client 173.239.198.74:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sungrove.org"] [uri "/.env"] [unique_id "apK9FiJcY4fy7tP-rU3y1QAAAkU"] [Sat Aug 29 05:05:58.717734 2026] [security2:error] [pid 1018003:tid 1018170] [client 93.123.109.228:41358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/php-info.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsfgAABcs"] [Sat Aug 29 05:05:58.728660 2026] [security2:error] [pid 1018003:tid 1018163] [client 93.123.109.228:41290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/php.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsfwAABcQ"] [Sat Aug 29 05:05:58.730635 2026] [security2:error] [pid 1017536:tid 1017698] [client 93.123.109.228:41096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/php_info.php"] [unique_id "apK9FiJcY4fy7tP-rU3y2AAAAjQ"] [Sat Aug 29 05:05:58.732264 2026] [security2:error] [pid 1017536:tid 1017753] [client 159.69.158.189:64508] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "drjrae.com"] [uri "/"] [unique_id "apK9FiJcY4fy7tP-rU3y2QAAAms"], referer: http://drjrae.com [Sat Aug 29 05:05:58.736311 2026] [security2:error] [pid 1017536:tid 1017776] [client 4.205.62.107:21886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9FiJcY4fy7tP-rU3y2gAAAoI"] [Sat Aug 29 05:05:58.751006 2026] [security2:error] [pid 1017536:tid 1017767] [client 57.141.14.102:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/44/"] [unique_id "apK9FiJcY4fy7tP-rU3y2wAAAnk"] [Sat Aug 29 05:05:58.754987 2026] [security2:error] [pid 1018003:tid 1018255] [client 93.123.109.228:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/phpinfo.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsgQAABh8"] [Sat Aug 29 05:05:58.756407 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.151.200.44:64879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/sf9.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsggAABgM"] [Sat Aug 29 05:05:58.759045 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.48.251.3:14027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/server-info.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsgwAABdY"] [Sat Aug 29 05:05:58.763384 2026] [security2:error] [pid 1017536:tid 1017730] [client 52.139.37.240:8454] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "mail.mykaratetutor.com"] [uri "/c99.php"] [unique_id "apK9FiJcY4fy7tP-rU3y3QAAAlQ"] [Sat Aug 29 05:05:58.774584 2026] [security2:error] [pid 1017536:tid 1017742] [client 158.158.54.35:10699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-conflg.php"] [unique_id "apK9FiJcY4fy7tP-rU3y3wAAAmA"] [Sat Aug 29 05:05:58.784047 2026] [security2:error] [pid 1017536:tid 1017669] [client 93.123.109.228:41116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9FiJcY4fy7tP-rU3y4AAAAhc"] [Sat Aug 29 05:05:58.802400 2026] [security2:error] [pid 1018003:tid 1018223] [client 185.104.184.230:44884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9FjAh5Y1i2tUxg4HshQAABgA"] [Sat Aug 29 05:05:58.807063 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.48.250.41:62524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/easy.php"] [unique_id "apK9FiJcY4fy7tP-rU3y4QAAAnI"] [Sat Aug 29 05:05:58.815008 2026] [security2:error] [pid 1017536:tid 1017679] [client 68.155.159.216:57467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9FiJcY4fy7tP-rU3y4wAAAiE"] [Sat Aug 29 05:05:58.831998 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.48.251.3:62140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/phpinfo01.php"] [unique_id "apK9FjAh5Y1i2tUxg4HshgAABhM"] [Sat Aug 29 05:05:58.832662 2026] [security2:error] [pid 1018003:tid 1018264] [client 4.205.62.107:55976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/phpinfo01.php"] [unique_id "apK9FjAh5Y1i2tUxg4HshwAABig"] [Sat Aug 29 05:05:58.835545 2026] [security2:error] [pid 1018003:tid 1018266] [client 93.123.109.228:41256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsiAAABio"] [Sat Aug 29 05:05:58.845843 2026] [security2:error] [pid 1017536:tid 1017736] [client 93.123.109.228:41328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9FiJcY4fy7tP-rU3y5gAAAlo"] [Sat Aug 29 05:05:58.845845 2026] [security2:error] [pid 1017536:tid 1017691] [client 93.123.109.228:41314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9FiJcY4fy7tP-rU3y5wAAAi0"] [Sat Aug 29 05:05:58.861693 2026] [security2:error] [pid 1018003:tid 1018258] [client 93.123.109.228:41122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsjAAABiI"] [Sat Aug 29 05:05:58.877620 2026] [security2:error] [pid 1017536:tid 1017693] [client 40.83.93.50:23506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/options.php"] [unique_id "apK9FiJcY4fy7tP-rU3y6gAAAi8"] [Sat Aug 29 05:05:58.878292 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.197.61.180:16963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/test.php"] [unique_id "apK9FiJcY4fy7tP-rU3y6wAAAoY"] [Sat Aug 29 05:05:58.896448 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.48.251.3:14056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/gk.php"] [unique_id "apK9FiJcY4fy7tP-rU3y7AAAAkk"] [Sat Aug 29 05:05:58.896461 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.151.200.44:64952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/lte7.php"] [unique_id "apK9FiJcY4fy7tP-rU3y7QAAAoM"] [Sat Aug 29 05:05:58.917199 2026] [security2:error] [pid 1018003:tid 1018173] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HsjgAABc4"] [Sat Aug 29 05:05:58.934700 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.147.79:24562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/themes.php"] [unique_id "apK9FjAh5Y1i2tUxg4HsjwAABeE"] [Sat Aug 29 05:05:58.939851 2026] [security2:error] [pid 1017536:tid 1017792] [client 40.83.93.50:3162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/Njima.php"] [unique_id "apK9FiJcY4fy7tP-rU3y7wAAApI"] [Sat Aug 29 05:05:58.943101 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.48.250.41:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/fresh3.php"] [unique_id "apK9FjAh5Y1i2tUxg4HskAAABdw"] [Sat Aug 29 05:05:58.944701 2026] [security2:error] [pid 1018003:tid 1018254] [client 68.155.159.216:12287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9FjAh5Y1i2tUxg4HskQAABh4"] [Sat Aug 29 05:05:58.952560 2026] [security2:error] [pid 1018003:tid 1018265] [client 93.123.109.228:41230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HskwAABik"] [Sat Aug 29 05:05:58.954187 2026] [security2:error] [pid 1018003:tid 1018233] [client 52.139.37.240:8461] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "mail.mykaratetutor.com"] [uri "/c99.php"] [unique_id "apK9FjAh5Y1i2tUxg4HslAAABgk"] [Sat Aug 29 05:05:58.960048 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.48.251.3:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/cxc.php"] [unique_id "apK9FiJcY4fy7tP-rU3y9AAAAok"] [Sat Aug 29 05:05:58.988708 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.23.147.79:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/index/function.php"] [unique_id "apK9FiJcY4fy7tP-rU3y9gAAAkQ"] [Sat Aug 29 05:05:58.989880 2026] [security2:error] [pid 1017536:tid 1017773] [client 93.123.109.228:41332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/public/phpinfo.php"] [unique_id "apK9FiJcY4fy7tP-rU3y9wAAAn8"] [Sat Aug 29 05:05:58.995116 2026] [security2:error] [pid 1017536:tid 1017784] [client 93.123.109.228:41328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9FiJcY4fy7tP-rU3y-QAAAoo"] [Sat Aug 29 05:05:58.998835 2026] [security2:error] [pid 1018003:tid 1018182] [client 93.123.109.228:41256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9FjAh5Y1i2tUxg4HslQAABdc"] [Sat Aug 29 05:05:59.045566 2026] [security2:error] [pid 1017536:tid 1017723] [client 168.107.94.195:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9FyJcY4fy7tP-rU3y_wAAAk0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:59.053276 2026] [security2:error] [pid 1017536:tid 1017768] [client 20.196.209.81:18689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/index.php"] [unique_id "apK9FyJcY4fy7tP-rU3zAAAAAno"] [Sat Aug 29 05:05:59.065896 2026] [security2:error] [pid 1018003:tid 1018277] [client 197.219.150.206:58018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsmwAABjU"] [Sat Aug 29 05:05:59.066027 2026] [security2:error] [pid 1018003:tid 1018277] [client 197.219.150.206:58018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsmwAABjU"] [Sat Aug 29 05:05:59.072255 2026] [security2:error] [pid 1017536:tid 1017782] [client 4.232.148.111:8425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/index.php"] [unique_id "apK9FyJcY4fy7tP-rU3zAQAAAog"] [Sat Aug 29 05:05:59.089609 2026] [security2:error] [pid 1017536:tid 1017690] [client 20.48.251.3:62096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/oiko6u.php"] [unique_id "apK9FyJcY4fy7tP-rU3zBAAAAiw"] [Sat Aug 29 05:05:59.099312 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.251.3:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/fff.php"] [unique_id "apK9FyJcY4fy7tP-rU3zCAAAAlY"] [Sat Aug 29 05:05:59.100865 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.151.200.44:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/tanjiro.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsnwAABiM"] [Sat Aug 29 05:05:59.104768 2026] [security2:error] [pid 1018003:tid 1018164] [client 74.248.24.12:30411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsoQAABcU"] [Sat Aug 29 05:05:59.106971 2026] [security2:error] [pid 1018003:tid 1018251] [client 158.23.147.79:48353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/css/index.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsogAABhs"] [Sat Aug 29 05:05:59.109164 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.250.41:62519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/bgymj.php"] [unique_id "apK9FyJcY4fy7tP-rU3zCwAAAkM"] [Sat Aug 29 05:05:59.110428 2026] [security2:error] [pid 1017536:tid 1017730] [client 185.104.184.230:44890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK9FyJcY4fy7tP-rU3zDAAAAlQ"] [Sat Aug 29 05:05:59.134528 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.49.130:60785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/133.php"] [unique_id "apK9FyJcY4fy7tP-rU3zDQAAAoY"] [Sat Aug 29 05:05:59.141071 2026] [security2:error] [pid 1018003:tid 1018220] [client 20.104.49.130:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/init.php"] [unique_id "apK9FzAh5Y1i2tUxg4HspAAABf0"] [Sat Aug 29 05:05:59.144719 2026] [security2:error] [pid 1018003:tid 1018250] [client 4.205.62.107:8965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/fraro.php"] [unique_id "apK9FzAh5Y1i2tUxg4HspQAABho"] [Sat Aug 29 05:05:59.161857 2026] [security2:error] [pid 1017536:tid 1017776] [client 52.139.37.240:8637] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "mail.mykaratetutor.com"] [uri "/c99.php"] [unique_id "apK9FyJcY4fy7tP-rU3zEQAAAoI"] [Sat Aug 29 05:05:59.168162 2026] [security2:error] [pid 1017536:tid 1017755] [client 34.7.216.49:49246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/secret.json"] [unique_id "apK9FyJcY4fy7tP-rU3zEwAAAm0"] [Sat Aug 29 05:05:59.192432 2026] [security2:error] [pid 1017536:tid 1017785] [client 159.69.158.189:61306] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "drjrae.com"] [uri "/"] [unique_id "apK9FyJcY4fy7tP-rU3zGQAAAos"], referer: http://drjrae.com [Sat Aug 29 05:05:59.198063 2026] [security2:error] [pid 1018003:tid 1018199] [client 34.7.216.49:49310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/service_account.json"] [unique_id "apK9FzAh5Y1i2tUxg4HsqAAABeg"] [Sat Aug 29 05:05:59.211338 2026] [security2:error] [pid 1018003:tid 1018270] [client 158.158.54.35:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/123.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsrAAABi4"] [Sat Aug 29 05:05:59.219823 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.48.251.3:62136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/fraro.php"] [unique_id "apK9FyJcY4fy7tP-rU3zIAAAAlM"] [Sat Aug 29 05:05:59.278955 2026] [core:error] [pid 1017536:tid 1017684] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.278974 2026] [core:error] [pid 1017536:tid 1017684] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.279470 2026] [core:error] [pid 1018003:tid 1018244] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.279485 2026] [core:error] [pid 1018003:tid 1018244] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.279538 2026] [core:error] [pid 1018003:tid 1018267] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.279541 2026] [core:error] [pid 1017536:tid 1017784] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.279548 2026] [core:error] [pid 1018003:tid 1018267] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.279555 2026] [core:error] [pid 1017536:tid 1017784] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.280067 2026] [core:error] [pid 1017536:tid 1017789] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.280074 2026] [core:error] [pid 1017536:tid 1017789] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.280217 2026] [core:error] [pid 1018003:tid 1018166] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.280232 2026] [core:error] [pid 1018003:tid 1018166] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.282214 2026] [core:error] [pid 1018003:tid 1018155] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.282229 2026] [core:error] [pid 1018003:tid 1018155] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.282410 2026] [core:error] [pid 1018003:tid 1018263] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.282428 2026] [core:error] [pid 1018003:tid 1018263] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.283033 2026] [core:error] [pid 1018003:tid 1018222] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.283041 2026] [core:error] [pid 1018003:tid 1018222] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.284340 2026] [core:error] [pid 1018003:tid 1018278] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.284366 2026] [core:error] [pid 1018003:tid 1018278] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.285471 2026] [core:error] [pid 1017536:tid 1017790] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.285488 2026] [core:error] [pid 1017536:tid 1017790] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.288789 2026] [core:error] [pid 1017536:tid 1017717] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.288802 2026] [core:error] [pid 1017536:tid 1017717] [client 34.97.179.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.294983 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.205.62.107:64976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/file59.php"] [unique_id "apK9FyJcY4fy7tP-rU3zOQAAAlY"] [Sat Aug 29 05:05:59.301331 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ws69.php"] [unique_id "apK9FyJcY4fy7tP-rU3zOgAAAmE"] [Sat Aug 29 05:05:59.349629 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.48.251.3:62113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/thui.php"] [unique_id "apK9FyJcY4fy7tP-rU3zPQAAAhc"] [Sat Aug 29 05:05:59.355095 2026] [security2:error] [pid 1018003:tid 1018181] [client 20.48.251.3:33322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/autogooey.php"] [unique_id "apK9FzAh5Y1i2tUxg4HswwAABdY"] [Sat Aug 29 05:05:59.355093 2026] [security2:error] [pid 1018003:tid 1018177] [client 40.83.93.50:5914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/panel.php"] [unique_id "apK9FzAh5Y1i2tUxg4HswgAABdI"] [Sat Aug 29 05:05:59.381927 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.147.79:50113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9FyJcY4fy7tP-rU3zPwAAAow"] [Sat Aug 29 05:05:59.382733 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.49.130:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/1xmomo.php"] [unique_id "apK9FyJcY4fy7tP-rU3zQAAAAiM"] [Sat Aug 29 05:05:59.395879 2026] [security2:error] [pid 1017536:tid 1017746] [client 158.23.147.79:32723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9FyJcY4fy7tP-rU3zQgAAAmQ"] [Sat Aug 29 05:05:59.411485 2026] [security2:error] [pid 1018003:tid 1018235] [client 93.123.109.228:41348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9FzAh5Y1i2tUxg4HsxwAABgs"] [Sat Aug 29 05:05:59.416211 2026] [security2:error] [pid 1017536:tid 1017772] [client 158.23.147.79:30672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/cong.php"] [unique_id "apK9FyJcY4fy7tP-rU3zRAAAAn4"] [Sat Aug 29 05:05:59.417850 2026] [security2:error] [pid 1017536:tid 1017727] [client 185.104.184.230:44898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9FyJcY4fy7tP-rU3zRQAAAlE"] [Sat Aug 29 05:05:59.426366 2026] [security2:error] [pid 1018003:tid 1018262] [client 168.107.94.195:61318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsyAAABiY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:59.435643 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.48.250.41:62558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ccs.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsygAABdg"] [Sat Aug 29 05:05:59.443762 2026] [security2:error] [pid 1018003:tid 1018196] [client 40.83.93.50:7780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/configs.php"] [unique_id "apK9FzAh5Y1i2tUxg4HsywAABeU"] [Sat Aug 29 05:05:59.445494 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.49.130:30045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/xwpg.php"] [unique_id "apK9FzAh5Y1i2tUxg4HszQAABeE"] [Sat Aug 29 05:05:59.452832 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.151.200.44:64937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/Rk41.php"] [unique_id "apK9FzAh5Y1i2tUxg4HszwAABdw"] [Sat Aug 29 05:05:59.455656 2026] [security2:error] [pid 1017536:tid 1017784] [client 158.23.147.79:25567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9FyJcY4fy7tP-rU3zRgAAAoo"] [Sat Aug 29 05:05:59.464994 2026] [security2:error] [pid 1017536:tid 1017707] [client 35.198.240.194:16816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/id_rsa"] [unique_id "apK9FyJcY4fy7tP-rU3zSwAAAj0"] [Sat Aug 29 05:05:59.467922 2026] [security2:error] [pid 1017536:tid 1017707] [client 35.198.240.194:16816] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.omni-staffing.com"] [uri "/id_rsa"] [unique_id "apK9FyJcY4fy7tP-rU3zSwAAAj0"] [Sat Aug 29 05:05:59.470104 2026] [security2:error] [pid 1017536:tid 1017679] [client 35.198.240.194:16860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/key.pem"] [unique_id "apK9FyJcY4fy7tP-rU3zTQAAAiE"] [Sat Aug 29 05:05:59.472283 2026] [security2:error] [pid 1018003:tid 1018233] [client 35.198.240.194:16912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.omni-staffing.com"] [uri "/wp-config.php.old"] [unique_id "apK9FzAh5Y1i2tUxg4Hs1AAABgk"] [Sat Aug 29 05:05:59.472733 2026] [security2:error] [pid 1017536:tid 1017672] [client 35.198.240.194:16846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/id_dsa"] [unique_id "apK9FyJcY4fy7tP-rU3zTwAAAho"] [Sat Aug 29 05:05:59.472926 2026] [security2:error] [pid 1018003:tid 1018209] [client 35.198.240.194:16906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.omni-staffing.com"] [uri "/wp-config.php.bak"] [unique_id "apK9FzAh5Y1i2tUxg4Hs1gAABfI"] [Sat Aug 29 05:05:59.475910 2026] [security2:error] [pid 1018003:tid 1018254] [client 35.198.240.194:16876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/privatekey.key"] [unique_id "apK9FzAh5Y1i2tUxg4Hs0AAABh4"] [Sat Aug 29 05:05:59.478919 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.251.3:61636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/lala.php"] [unique_id "apK9FyJcY4fy7tP-rU3zUwAAAls"] [Sat Aug 29 05:05:59.479183 2026] [security2:error] [pid 1018003:tid 1018182] [client 35.198.240.194:16914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.240.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.omni-staffing.com"] [uri "/config.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs2QAABdc"] [Sat Aug 29 05:05:59.480922 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.196.209.81:17457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/install.php"] [unique_id "apK9FyJcY4fy7tP-rU3zVAAAAms"] [Sat Aug 29 05:05:59.482467 2026] [security2:error] [pid 1018003:tid 1018274] [client 35.198.240.194:16902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.240.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.omni-staffing.com"] [uri "/wp-config.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs0QAABjI"] [Sat Aug 29 05:05:59.487230 2026] [security2:error] [pid 1018003:tid 1018169] [client 35.198.240.194:16920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.240.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.omni-staffing.com"] [uri "/config.php.bak"] [unique_id "apK9FzAh5Y1i2tUxg4Hs2gAABco"] [Sat Aug 29 05:05:59.518743 2026] [security2:error] [pid 1018003:tid 1018277] [client 68.155.159.216:51447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/install.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs3AAABjU"] [Sat Aug 29 05:05:59.528417 2026] [security2:error] [pid 1017536:tid 1017726] [client 4.205.62.107:22292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/cloud.php"] [unique_id "apK9FyJcY4fy7tP-rU3zVQAAAlA"] [Sat Aug 29 05:05:59.530738 2026] [security2:error] [pid 1018003:tid 1018207] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9FzAh5Y1i2tUxg4Hs4AAABfA"] [Sat Aug 29 05:05:59.548870 2026] [security2:error] [pid 1017536:tid 1017678] [client 68.155.159.216:33661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9FyJcY4fy7tP-rU3zYQAAAiA"] [Sat Aug 29 05:05:59.550899 2026] [security2:error] [pid 1017536:tid 1017690] [client 93.123.109.228:41364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9FyJcY4fy7tP-rU3zYgAAAiw"] [Sat Aug 29 05:05:59.554839 2026] [security2:error] [pid 1018003:tid 1018220] [client 93.123.109.228:41122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9FzAh5Y1i2tUxg4Hs5AAABf0"] [Sat Aug 29 05:05:59.554964 2026] [security2:error] [pid 1017536:tid 1017776] [client 4.232.148.111:33863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-admin/a.php"] [unique_id "apK9FyJcY4fy7tP-rU3zYwAAAoI"] [Sat Aug 29 05:05:59.570526 2026] [security2:error] [pid 1017536:tid 1017705] [client 4.205.62.107:65506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/X57.php"] [unique_id "apK9FyJcY4fy7tP-rU3zZgAAAjs"] [Sat Aug 29 05:05:59.573860 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.250.41:59385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/mar.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs5QAABf4"] [Sat Aug 29 05:05:59.574524 2026] [security2:error] [pid 1018003:tid 1018159] [client 4.205.62.107:22209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/bb.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs5gAABcA"] [Sat Aug 29 05:05:59.578125 2026] [security2:error] [pid 1017536:tid 1017713] [client 68.155.159.216:16206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9FyJcY4fy7tP-rU3zZwAAAkM"] [Sat Aug 29 05:05:59.593948 2026] [security2:error] [pid 1017536:tid 1017742] [client 4.205.62.107:2887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/application.config.php"] [unique_id "apK9FyJcY4fy7tP-rU3zaQAAAmA"] [Sat Aug 29 05:05:59.598081 2026] [security2:error] [pid 1017536:tid 1017544] [remote 34.138.144.127:57736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/wp-config.old"] [unique_id "apK9FyJcY4fy7tP-rU3zagACVAc"] [Sat Aug 29 05:05:59.605702 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.48.251.3:62102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/public/bnn_.php.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs6QAABhY"] [Sat Aug 29 05:05:59.622549 2026] [security2:error] [pid 1018003:tid 1018264] [client 60.243.207.176:60663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs7QAABig"] [Sat Aug 29 05:05:59.622652 2026] [security2:error] [pid 1018003:tid 1018264] [client 60.243.207.176:60663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs7QAABig"] [Sat Aug 29 05:05:59.635898 2026] [core:error] [pid 1017536:tid 1017781] [client 74.248.24.12:15220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.635916 2026] [core:error] [pid 1017536:tid 1017781] [client 74.248.24.12:15220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:05:59.635996 2026] [security2:error] [pid 1017536:tid 1017764] [client 158.23.147.79:30690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9FyJcY4fy7tP-rU3zbgAAAnY"] [Sat Aug 29 05:05:59.648566 2026] [security2:error] [pid 1018003:tid 1018150] [client 159.69.158.189:61316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drjrae.com"] [uri "/index.html"] [unique_id "apK9FzAh5Y1i2tUxg4Hs7wAABbc"], referer: http://drjrae.com [Sat Aug 29 05:05:59.653734 2026] [security2:error] [pid 1017536:tid 1017650] [remote 34.138.144.127:57736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "old.theenprogroup.com"] [uri "/wp-config.php.swp"] [unique_id "apK9FyJcY4fy7tP-rU3zcgACbXE"] [Sat Aug 29 05:05:59.654467 2026] [security2:error] [pid 1017536:tid 1017662] [remote 34.138.144.127:57736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "old.theenprogroup.com"] [uri "/wp-config.php~"] [unique_id "apK9FyJcY4fy7tP-rU3zcwACbX0"] [Sat Aug 29 05:05:59.667114 2026] [security2:error] [pid 1017536:tid 1017670] [client 68.155.159.216:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/log-mama/function.php"] [unique_id "apK9FyJcY4fy7tP-rU3zeAAAAhg"] [Sat Aug 29 05:05:59.667590 2026] [security2:error] [pid 1018003:tid 1018215] [client 158.158.54.35:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/yanz.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs8AAABfg"] [Sat Aug 29 05:05:59.680156 2026] [security2:error] [pid 1018003:tid 1018244] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9FzAh5Y1i2tUxg4Hs8QAABhQ"] [Sat Aug 29 05:05:59.684089 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.151.200.44:65476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9FyJcY4fy7tP-rU3zfAAAAnM"] [Sat Aug 29 05:05:59.694743 2026] [security2:error] [pid 1017536:tid 1017777] [client 93.123.109.228:41504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9FyJcY4fy7tP-rU3zfQAAAoM"] [Sat Aug 29 05:05:59.705511 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.250.41:62469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ccu.php"] [unique_id "apK9FyJcY4fy7tP-rU3zgAAAAiU"] [Sat Aug 29 05:05:59.712561 2026] [security2:error] [pid 1017536:tid 1017686] [client 68.155.159.216:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin.php"] [unique_id "apK9FyJcY4fy7tP-rU3zgQAAAig"] [Sat Aug 29 05:05:59.713955 2026] [security2:error] [pid 1018003:tid 1018263] [client 185.104.184.230:44904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9FzAh5Y1i2tUxg4Hs9AAABic"] [Sat Aug 29 05:05:59.731159 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.48.251.3:62143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wsws.php"] [unique_id "apK9FyJcY4fy7tP-rU3zhAAAAks"] [Sat Aug 29 05:05:59.732047 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.147.79:35790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9FyJcY4fy7tP-rU3zhQAAAn8"] [Sat Aug 29 05:05:59.789565 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.52.41.200:1746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/.trash7206/index.php"] [unique_id "apK9FyJcY4fy7tP-rU3zhwAAAk0"] [Sat Aug 29 05:05:59.806968 2026] [security2:error] [pid 1017536:tid 1017706] [client 168.107.94.195:61667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9FyJcY4fy7tP-rU3ziQAAAjw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:05:59.821231 2026] [security2:error] [pid 1018003:tid 1018205] [client 93.123.109.228:41374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9FzAh5Y1i2tUxg4Hs-AAABe4"] [Sat Aug 29 05:05:59.822897 2026] [security2:error] [pid 1017536:tid 1017698] [client 40.83.93.50:5942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/pk.php"] [unique_id "apK9FyJcY4fy7tP-rU3ziwAAAjQ"] [Sat Aug 29 05:05:59.822951 2026] [security2:error] [pid 1017536:tid 1017708] [client 93.123.109.228:41328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9FyJcY4fy7tP-rU3zigAAAj4"] [Sat Aug 29 05:05:59.826818 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.151.200.44:64930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/7logs.php"] [unique_id "apK9FyJcY4fy7tP-rU3zjAAAAls"] [Sat Aug 29 05:05:59.843763 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.197.61.180:5858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/user/f35.php"] [unique_id "apK9FzAh5Y1i2tUxg4Hs-gAABg8"] [Sat Aug 29 05:05:59.850882 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:60745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ak.php"] [unique_id "apK9FyJcY4fy7tP-rU3zjgAAAmM"] [Sat Aug 29 05:05:59.855379 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.251.3:13971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-class.php"] [unique_id "apK9FyJcY4fy7tP-rU3zjwAAAoE"] [Sat Aug 29 05:05:59.859138 2026] [security2:error] [pid 1017536:tid 1017792] [client 34.143.179.161:45076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.179.143.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/pi.php"] [unique_id "apK9FyJcY4fy7tP-rU3zkQAAApI"] [Sat Aug 29 05:05:59.861113 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.48.251.3:61658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/localconf.php"] [unique_id "apK9FyJcY4fy7tP-rU3zkgAAAkU"] [Sat Aug 29 05:05:59.870757 2026] [security2:error] [pid 1017536:tid 1017729] [client 34.143.179.161:45060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.179.143.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/i.php"] [unique_id "apK9FyJcY4fy7tP-rU3zlgAAAlM"] [Sat Aug 29 05:05:59.877881 2026] [security2:error] [pid 1017536:tid 1017734] [client 93.123.109.228:41298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9FyJcY4fy7tP-rU3zmQAAAlg"] [Sat Aug 29 05:05:59.890251 2026] [security2:error] [pid 1017536:tid 1017760] [client 4.205.62.107:21864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9FyJcY4fy7tP-rU3zoQAAAnI"] [Sat Aug 29 05:05:59.900689 2026] [security2:error] [pid 1018003:tid 1018153] [client 34.143.179.161:45164] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/.bash_history"] [unique_id "apK9FzAh5Y1i2tUxg4HtAgAABbo"] [Sat Aug 29 05:05:59.926131 2026] [security2:error] [pid 1017536:tid 1017685] [client 40.83.93.50:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/disagraeed.php"] [unique_id "apK9FyJcY4fy7tP-rU3zpQAAAic"] [Sat Aug 29 05:05:59.970959 2026] [security2:error] [pid 1017536:tid 1017750] [client 4.205.62.107:55982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/cxc.php"] [unique_id "apK9FyJcY4fy7tP-rU3zqQAAAmg"] [Sat Aug 29 05:05:59.982876 2026] [security2:error] [pid 1017536:tid 1017724] [client 68.155.159.216:51485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9FyJcY4fy7tP-rU3zqwAAAk4"] [Sat Aug 29 05:05:59.991560 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.48.251.3:61659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/bengi.php"] [unique_id "apK9FzAh5Y1i2tUxg4HtCwAABeA"] [Sat Aug 29 05:05:59.999795 2026] [security2:error] [pid 1018003:tid 1018216] [client 84.75.155.103:41866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.155.75.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinpanband.com"] [uri "/wordpress/index.php"] [unique_id "apK9FzAh5Y1i2tUxg4HtDQAABfk"] [Sat Aug 29 05:06:00.008045 2026] [security2:error] [pid 1017536:tid 1017780] [client 68.155.159.216:56944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK9GCJcY4fy7tP-rU3zrAAAAoY"] [Sat Aug 29 05:06:00.015948 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.196.209.81:18694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9GCJcY4fy7tP-rU3zrQAAAmY"] [Sat Aug 29 05:06:00.016978 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.250.41:60746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/lib.php"] [unique_id "apK9GCJcY4fy7tP-rU3zrgAAAoc"] [Sat Aug 29 05:06:00.020688 2026] [security2:error] [pid 1017536:tid 1017691] [client 185.104.184.230:44920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9GCJcY4fy7tP-rU3zrwAAAi0"] [Sat Aug 29 05:06:00.041210 2026] [security2:error] [pid 1017536:tid 1017670] [client 158.23.147.79:24520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-mail.php"] [unique_id "apK9GCJcY4fy7tP-rU3zsAAAAhg"] [Sat Aug 29 05:06:00.043212 2026] [security2:error] [pid 1017536:tid 1017744] [client 93.123.109.228:41380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9GCJcY4fy7tP-rU3zsQAAAmI"] [Sat Aug 29 05:06:00.045641 2026] [security2:error] [pid 1018003:tid 1018167] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtDgAABcg"] [Sat Aug 29 05:06:00.055271 2026] [security2:error] [pid 1017536:tid 1017683] [client 93.123.109.228:41116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9GCJcY4fy7tP-rU3ztAAAAiU"] [Sat Aug 29 05:06:00.121889 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.48.251.3:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/i.php"] [unique_id "apK9GCJcY4fy7tP-rU3zuwAAAhc"] [Sat Aug 29 05:06:00.124300 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.158.54.35:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/autoload_classmap.php"] [unique_id "apK9GCJcY4fy7tP-rU3zvAAAAjI"] [Sat Aug 29 05:06:00.158334 2026] [security2:error] [pid 1017536:tid 1017708] [client 68.155.159.216:18292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/chosen.php"] [unique_id "apK9GCJcY4fy7tP-rU3zwQAAAj4"] [Sat Aug 29 05:06:00.165512 2026] [security2:error] [pid 1018003:tid 1018192] [client 68.155.159.216:14305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/images/index.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtFgAABeE"] [Sat Aug 29 05:06:00.169234 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.49.130:30022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/kerang.php"] [unique_id "apK9GCJcY4fy7tP-rU3zwgAAAjQ"] [Sat Aug 29 05:06:00.174776 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:41374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtFwAABdw"] [Sat Aug 29 05:06:00.179625 2026] [security2:error] [pid 1018003:tid 1018233] [client 93.123.109.228:41478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtGQAABgk"] [Sat Aug 29 05:06:00.191048 2026] [core:error] [pid 1017536:tid 1017789] [client 74.248.24.12:41008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:00.191294 2026] [core:error] [pid 1017536:tid 1017789] [client 74.248.24.12:41008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:00.195744 2026] [security2:error] [pid 1017536:tid 1017760] [client 168.107.94.195:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9GCJcY4fy7tP-rU3zxwAAAnI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:00.206768 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.48.250.41:60681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wp-style.php"] [unique_id "apK9GCJcY4fy7tP-rU3zyAAAAiA"] [Sat Aug 29 05:06:00.213974 2026] [security2:error] [pid 1018003:tid 1018165] [client 158.23.147.79:48299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtGwAABcY"] [Sat Aug 29 05:06:00.219120 2026] [security2:error] [pid 1017536:tid 1017775] [client 66.248.203.2:61872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2023/07/13/"] [unique_id "apK9GCJcY4fy7tP-rU3zywAAAoE"] [Sat Aug 29 05:06:00.220632 2026] [security2:error] [pid 1017536:tid 1017772] [client 4.232.148.111:34909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9GCJcY4fy7tP-rU3zzQAAAn4"] [Sat Aug 29 05:06:00.221741 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.151.200.44:64843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/sf.php"] [unique_id "apK9GCJcY4fy7tP-rU3zzgAAAmU"] [Sat Aug 29 05:06:00.252639 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.48.251.3:61687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/guk.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtHQAABc0"] [Sat Aug 29 05:06:00.282964 2026] [security2:error] [pid 1018003:tid 1018195] [client 4.205.62.107:53325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/lm15.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtIAAABeQ"] [Sat Aug 29 05:06:00.287894 2026] [security2:error] [pid 1017536:tid 1017707] [client 40.83.93.50:24065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK9GCJcY4fy7tP-rU3z0gAAAj0"] [Sat Aug 29 05:06:00.293094 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.52.41.200:1221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wk/index.php"] [unique_id "apK9GCJcY4fy7tP-rU3z0wAAAmw"] [Sat Aug 29 05:06:00.297781 2026] [security2:error] [pid 1018003:tid 1018277] [client 114.119.136.113:29789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_info.php/cPath/41/products_id/1020/osCsid/b0156b149dcbdab5f810a839c8938f61"] [unique_id "apK9GDAh5Y1i2tUxg4HtIQAABjU"], referer: http://www.classiclightingusa.com/catalog/index.php/cPath/41/osCsid/b0156b149dcbdab5f810a839c8938f61 [Sat Aug 29 05:06:00.308348 2026] [security2:error] [pid 1017536:tid 1017716] [client 93.123.109.228:41298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9GCJcY4fy7tP-rU3z1QAAAkY"] [Sat Aug 29 05:06:00.314782 2026] [security2:error] [pid 1017536:tid 1017730] [client 185.104.184.230:44932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9GCJcY4fy7tP-rU3z1gAAAlQ"] [Sat Aug 29 05:06:00.316659 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.48.250.41:65094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtIgAABiM"] [Sat Aug 29 05:06:00.320132 2026] [security2:error] [pid 1017536:tid 1017750] [client 93.123.109.228:41314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/test.php"] [unique_id "apK9GCJcY4fy7tP-rU3z1wAAAmg"] [Sat Aug 29 05:06:00.324345 2026] [security2:error] [pid 1018003:tid 1018220] [client 93.123.109.228:41230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtJAAABf0"] [Sat Aug 29 05:06:00.331565 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.251.3:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/database.php"] [unique_id "apK9GCJcY4fy7tP-rU3z2QAAAk4"] [Sat Aug 29 05:06:00.344415 2026] [security2:error] [pid 1017536:tid 1017783] [client 103.240.76.112:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9GCJcY4fy7tP-rU3z2gAAAok"] [Sat Aug 29 05:06:00.344574 2026] [security2:error] [pid 1017536:tid 1017783] [client 103.240.76.112:42816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9GCJcY4fy7tP-rU3z2gAAAok"] [Sat Aug 29 05:06:00.351591 2026] [security2:error] [pid 1018003:tid 1018275] [client 93.123.109.228:41330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtKQAABjM"] [Sat Aug 29 05:06:00.378080 2026] [security2:error] [pid 1018003:tid 1018256] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtKgAABiA"] [Sat Aug 29 05:06:00.384105 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.251.3:62091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/config_dev.php"] [unique_id "apK9GCJcY4fy7tP-rU3z3QAAAnc"] [Sat Aug 29 05:06:00.406687 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.48.250.41:62538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/browse.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtKwAABgQ"] [Sat Aug 29 05:06:00.413371 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.196.209.81:25020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK9GCJcY4fy7tP-rU3z3wAAAoI"] [Sat Aug 29 05:06:00.417095 2026] [security2:error] [pid 1017536:tid 1017681] [client 93.123.109.228:41116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9GCJcY4fy7tP-rU3z4wAAAiM"] [Sat Aug 29 05:06:00.430465 2026] [security2:error] [pid 1018003:tid 1018175] [client 93.123.109.228:41122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtLAAABdA"] [Sat Aug 29 05:06:00.430934 2026] [security2:error] [pid 1018003:tid 1018264] [client 4.205.62.107:64307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/cli_bootstrap.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtLQAABig"] [Sat Aug 29 05:06:00.457886 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.250.41:65095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9GCJcY4fy7tP-rU3z5gAAAmQ"] [Sat Aug 29 05:06:00.484600 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.151.200.44:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/baee.php"] [unique_id "apK9GCJcY4fy7tP-rU3z6wAAAig"] [Sat Aug 29 05:06:00.487322 2026] [security2:error] [pid 1017536:tid 1017712] [client 40.83.93.50:8021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/add_actualites.php"] [unique_id "apK9GCJcY4fy7tP-rU3z7AAAAkI"] [Sat Aug 29 05:06:00.492297 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.147.79:50054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9GCJcY4fy7tP-rU3z7QAAAks"] [Sat Aug 29 05:06:00.514594 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.48.251.3:61634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws_credentials.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtLwAABi4"] [Sat Aug 29 05:06:00.542277 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.147.79:30648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9GCJcY4fy7tP-rU3z8gAAAho"] [Sat Aug 29 05:06:00.554069 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.197.61.180:13029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/user/min.php"] [unique_id "apK9GCJcY4fy7tP-rU3z8wAAAhY"] [Sat Aug 29 05:06:00.565702 2026] [core:error] [pid 1018003:tid 1018224] [client 45.148.10.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:00.565721 2026] [core:error] [pid 1018003:tid 1018224] [client 45.148.10.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:00.568213 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.147.79:25518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9GCJcY4fy7tP-rU3z9gAAAow"] [Sat Aug 29 05:06:00.576409 2026] [security2:error] [pid 1017536:tid 1017720] [client 158.158.54.35:5033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/bi.php"] [unique_id "apK9GCJcY4fy7tP-rU3z-QAAAko"] [Sat Aug 29 05:06:00.577625 2026] [security2:error] [pid 1017536:tid 1017715] [client 168.107.94.195:62407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9GCJcY4fy7tP-rU3z-gAAAkU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:00.591719 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.48.250.41:62547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/zoo.php"] [unique_id "apK9GCJcY4fy7tP-rU3z-wAAAh0"] [Sat Aug 29 05:06:00.615227 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.48.250.41:65117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ff1.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtOgAABec"] [Sat Aug 29 05:06:00.626052 2026] [security2:error] [pid 1017536:tid 1017678] [client 185.104.184.230:44948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9GCJcY4fy7tP-rU3z_QAAAiA"] [Sat Aug 29 05:06:00.644181 2026] [security2:error] [pid 1018003:tid 1018218] [client 68.155.159.216:51413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtPAAABfs"] [Sat Aug 29 05:06:00.655673 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.48.251.3:61222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws-credentials.php"] [unique_id "apK9GCJcY4fy7tP-rU3z_gAAAk8"] [Sat Aug 29 05:06:00.665025 2026] [security2:error] [pid 1017536:tid 1017674] [client 4.205.62.107:22237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/f35.php"] [unique_id "apK9GCJcY4fy7tP-rU3z_wAAAhw"] [Sat Aug 29 05:06:00.668050 2026] [security2:error] [pid 1017536:tid 1017793] [client 93.123.109.228:41364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9GCJcY4fy7tP-rU30AAAAApM"] [Sat Aug 29 05:06:00.683629 2026] [security2:error] [pid 1017536:tid 1017692] [client 68.155.159.216:16236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/admin.php"] [unique_id "apK9GCJcY4fy7tP-rU30AwAAAi4"] [Sat Aug 29 05:06:00.687330 2026] [security2:error] [pid 1017536:tid 1017696] [client 4.232.148.111:8401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.148.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.easyarranger.com"] [uri "/wp-admin.php"] [unique_id "apK9GCJcY4fy7tP-rU30BQAAAjI"] [Sat Aug 29 05:06:00.687506 2026] [security2:error] [pid 1017536:tid 1017705] [client 93.123.109.228:41360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9GCJcY4fy7tP-rU30BAAAAjs"] [Sat Aug 29 05:06:00.701367 2026] [security2:error] [pid 1018003:tid 1018217] [client 93.123.109.228:41478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtPwAABfo"] [Sat Aug 29 05:06:00.705721 2026] [security2:error] [pid 1017536:tid 1017707] [client 4.205.62.107:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/register.php"] [unique_id "apK9GCJcY4fy7tP-rU30BwAAAj0"] [Sat Aug 29 05:06:00.711044 2026] [security2:error] [pid 1017536:tid 1017754] [client 4.205.62.107:21877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/06.php"] [unique_id "apK9GCJcY4fy7tP-rU30CgAAAmw"] [Sat Aug 29 05:06:00.730276 2026] [security2:error] [pid 1018003:tid 1018155] [client 4.205.62.107:2520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/v2.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtQwAABbw"] [Sat Aug 29 05:06:00.730786 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.250.41:62586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/elp.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtRAAABcs"] [Sat Aug 29 05:06:00.734041 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:30618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtRQAABgc"] [Sat Aug 29 05:06:00.752624 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.52.41.200:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/admin.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtRwAABf8"] [Sat Aug 29 05:06:00.755937 2026] [security2:error] [pid 1018003:tid 1018232] [client 20.151.200.44:64853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/super.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtSgAABgg"] [Sat Aug 29 05:06:00.756762 2026] [security2:error] [pid 1018003:tid 1018271] [client 40.83.93.50:12424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtSwAABi8"] [Sat Aug 29 05:06:00.764658 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.250.41:65050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/t.php"] [unique_id "apK9GCJcY4fy7tP-rU30EQAAAoc"] [Sat Aug 29 05:06:00.772211 2026] [security2:error] [pid 1017536:tid 1017757] [client 68.155.159.216:40264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/bk/index.php"] [unique_id "apK9GCJcY4fy7tP-rU30EgAAAm8"] [Sat Aug 29 05:06:00.785863 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.251.3:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/4563.php"] [unique_id "apK9GCJcY4fy7tP-rU30FAAAAis"] [Sat Aug 29 05:06:00.808818 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.196.209.81:17106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/languages/index.php"] [unique_id "apK9GCJcY4fy7tP-rU30FgAAAik"] [Sat Aug 29 05:06:00.810469 2026] [security2:error] [pid 1018003:tid 1018219] [client 68.155.159.216:50209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtUgAABfw"] [Sat Aug 29 05:06:00.816184 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.104.49.130:46585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/berlin.php"] [unique_id "apK9GCJcY4fy7tP-rU30FwAAAkQ"] [Sat Aug 29 05:06:00.856669 2026] [security2:error] [pid 1018003:tid 1018200] [client 93.123.109.228:41478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9GDAh5Y1i2tUxg4HtVAAABek"] [Sat Aug 29 05:06:00.868037 2026] [security2:error] [pid 1017536:tid 1017706] [client 93.123.109.228:41380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/wp-config.php"] [unique_id "apK9GCJcY4fy7tP-rU30IQAAAjw"] [Sat Aug 29 05:06:00.875329 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:41230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/wp-config.php.bak"] [unique_id "apK9GDAh5Y1i2tUxg4HtVQAABdw"] [Sat Aug 29 05:06:00.883106 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.250.41:62528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/666.php"] [unique_id "apK9GCJcY4fy7tP-rU30IgAAAj4"] [Sat Aug 29 05:06:00.886064 2026] [security2:error] [pid 1017536:tid 1017732] [client 93.123.109.228:41298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/wp-config.php.new"] [unique_id "apK9GCJcY4fy7tP-rU30IwAAAlY"] [Sat Aug 29 05:06:00.888409 2026] [security2:error] [pid 1017536:tid 1017782] [client 158.23.147.79:35785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9GCJcY4fy7tP-rU30JAAAAog"] [Sat Aug 29 05:06:00.892454 2026] [security2:error] [pid 1018003:tid 1018233] [client 93.123.109.228:41108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/wp-config.php.old"] [unique_id "apK9GDAh5Y1i2tUxg4HtVgAABgk"] [Sat Aug 29 05:06:00.896730 2026] [security2:error] [pid 1017536:tid 1017775] [client 74.248.24.12:41002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-content/admin.php"] [unique_id "apK9GCJcY4fy7tP-rU30JQAAAoE"] [Sat Aug 29 05:06:00.914373 2026] [security2:error] [pid 1018003:tid 1018245] [client 93.123.109.228:41348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.ericamontgomeryphotography.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9GDAh5Y1i2tUxg4HtVwAABhU"] [Sat Aug 29 05:06:00.916112 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.48.251.3:61672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/cp2.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtWAAABfI"] [Sat Aug 29 05:06:00.940027 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.48.251.3:33300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aws_sdk_settings.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtWgAABdU"] [Sat Aug 29 05:06:00.941644 2026] [security2:error] [pid 1017536:tid 1017730] [client 185.104.184.230:44962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9GCJcY4fy7tP-rU30KwAAAlQ"] [Sat Aug 29 05:06:00.958220 2026] [security2:error] [pid 1018003:tid 1018169] [client 168.107.94.195:62776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtWwAABco"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:00.972172 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.250.41:65052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/erty.php"] [unique_id "apK9GDAh5Y1i2tUxg4HtXAAABcI"] [Sat Aug 29 05:06:00.975682 2026] [security2:error] [pid 1018003:tid 1018188] [client 40.83.93.50:7793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/alfanew.php7"] [unique_id "apK9GDAh5Y1i2tUxg4HtXQAABd0"] [Sat Aug 29 05:06:01.011942 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.158.54.35:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/cc.php"] [unique_id "apK9GSJcY4fy7tP-rU30LgAAAho"] [Sat Aug 29 05:06:01.028776 2026] [security2:error] [pid 1018003:tid 1018164] [client 4.205.62.107:21879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/cloud.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtYAAABcU"] [Sat Aug 29 05:06:01.032042 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.48.250.41:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/knmt.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtYQAABcA"] [Sat Aug 29 05:06:01.043655 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.48.251.3:62118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/xda.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtYgAABe8"] [Sat Aug 29 05:06:01.095744 2026] [security2:error] [pid 1017536:tid 1017692] [client 68.155.159.216:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/index.php"] [unique_id "apK9GSJcY4fy7tP-rU30MQAAAi4"] [Sat Aug 29 05:06:01.111235 2026] [security2:error] [pid 1018003:tid 1018227] [client 4.205.62.107:55973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/oiko6u.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtZgAABgQ"] [Sat Aug 29 05:06:01.111452 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.151.200.44:64241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/lufix1.php"] [unique_id "apK9GSJcY4fy7tP-rU30MgAAAjI"] [Sat Aug 29 05:06:01.115086 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.250.41:64321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/0x.php"] [unique_id "apK9GSJcY4fy7tP-rU30MwAAAjs"] [Sat Aug 29 05:06:01.117003 2026] [security2:error] [pid 1017536:tid 1017773] [client 68.155.159.216:57352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/ans.php"] [unique_id "apK9GSJcY4fy7tP-rU30NAAAAn8"] [Sat Aug 29 05:06:01.119379 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/.well-known/content.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtZwAABdA"] [Sat Aug 29 05:06:01.162105 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.147.79:24501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/cgi-bin/index.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtaQAABdQ"] [Sat Aug 29 05:06:01.173648 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.48.251.3:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/pinfo.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtawAABhk"] [Sat Aug 29 05:06:01.203673 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.52.41.200:1762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/php8.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtbQAABf4"] [Sat Aug 29 05:06:01.203673 2026] [security2:error] [pid 1017536:tid 1017727] [client 20.48.250.41:62466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/sbhu.php"] [unique_id "apK9GSJcY4fy7tP-rU30OwAAAlE"] [Sat Aug 29 05:06:01.216709 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.251.3:13824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-admin/sc.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtbgAABis"] [Sat Aug 29 05:06:01.230244 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.196.209.81:24998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/languages/min.php"] [unique_id "apK9GSJcY4fy7tP-rU30PgAAApI"] [Sat Aug 29 05:06:01.231113 2026] [security2:error] [pid 1017536:tid 1017674] [client 40.83.93.50:5891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/security.php"] [unique_id "apK9GSJcY4fy7tP-rU30PwAAAhw"] [Sat Aug 29 05:06:01.262377 2026] [security2:error] [pid 1017536:tid 1017748] [client 185.104.184.230:44974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9GSJcY4fy7tP-rU30QAAAAmY"] [Sat Aug 29 05:06:01.265826 2026] [security2:error] [pid 1018003:tid 1018242] [client 68.155.159.216:18311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/goods.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtbwAABhI"] [Sat Aug 29 05:06:01.272464 2026] [security2:error] [pid 1017536:tid 1017781] [client 68.155.159.216:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9GSJcY4fy7tP-rU30QQAAAoc"] [Sat Aug 29 05:06:01.275535 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.197.61.180:16989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/users.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtcAAABho"] [Sat Aug 29 05:06:01.283606 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.250.41:64323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/66.php"] [unique_id "apK9GSJcY4fy7tP-rU30QgAAAm8"] [Sat Aug 29 05:06:01.304040 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.251.3:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/X57.php"] [unique_id "apK9GSJcY4fy7tP-rU30QwAAAmQ"] [Sat Aug 29 05:06:01.322021 2026] [security2:error] [pid 1018003:tid 1018248] [client 158.23.147.79:48221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/cong.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtcwAABhg"] [Sat Aug 29 05:06:01.336688 2026] [security2:error] [pid 1018003:tid 1018156] [client 168.107.94.195:63177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtdQAABb0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:01.346776 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.250.41:62583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/a332.php"] [unique_id "apK9GSJcY4fy7tP-rU30RgAAAkQ"] [Sat Aug 29 05:06:01.372326 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.151.200.44:64905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/hack.php"] [unique_id "apK9GSJcY4fy7tP-rU30TAAAAk0"] [Sat Aug 29 05:06:01.417625 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.48.250.41:64327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/f35.php"] [unique_id "apK9GSJcY4fy7tP-rU30TgAAAog"] [Sat Aug 29 05:06:01.433448 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.251.3:62124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/register.php"] [unique_id "apK9GSJcY4fy7tP-rU30UAAAAmg"] [Sat Aug 29 05:06:01.435057 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.251.3:33305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/debug.php"] [unique_id "apK9GSJcY4fy7tP-rU30UQAAAow"] [Sat Aug 29 05:06:01.456599 2026] [security2:error] [pid 1017536:tid 1017667] [client 158.158.54.35:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/files/index.php"] [unique_id "apK9GSJcY4fy7tP-rU30UgAAAhU"] [Sat Aug 29 05:06:01.479171 2026] [security2:error] [pid 1018003:tid 1018166] [client 74.248.24.12:30404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-configs.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtdwAABcc"] [Sat Aug 29 05:06:01.483778 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.48.250.41:60769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ws66.php"] [unique_id "apK9GSJcY4fy7tP-rU30VAAAAko"] [Sat Aug 29 05:06:01.511019 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.151.200.44:64832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/155.php"] [unique_id "apK9GSJcY4fy7tP-rU30VQAAAho"] [Sat Aug 29 05:06:01.520392 2026] [security2:error] [pid 1017536:tid 1017717] [client 40.83.93.50:7790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/xmlrpc.php0"] [unique_id "apK9GSJcY4fy7tP-rU30UwAAAkc"] [Sat Aug 29 05:06:01.528145 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.104.49.130:30030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/makeasmtp.php"] [unique_id "apK9GSJcY4fy7tP-rU30WAAAAoQ"] [Sat Aug 29 05:06:01.543228 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.250.41:65084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wen.php"] [unique_id "apK9GSJcY4fy7tP-rU30WgAAAnk"] [Sat Aug 29 05:06:01.562806 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.48.251.3:61667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/xqq.php"] [unique_id "apK9GTAh5Y1i2tUxg4HteAAABgc"] [Sat Aug 29 05:06:01.566291 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.48.251.3:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/66.php"] [unique_id "apK9GTAh5Y1i2tUxg4HteQAABc8"] [Sat Aug 29 05:06:01.570248 2026] [security2:error] [pid 1018003:tid 1018232] [client 4.205.62.107:64304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/dd.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtegAABgg"] [Sat Aug 29 05:06:01.571158 2026] [security2:error] [pid 1017536:tid 1017773] [client 185.104.184.230:44988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9GSJcY4fy7tP-rU30XwAAAn8"] [Sat Aug 29 05:06:01.594063 2026] [security2:error] [pid 1017536:tid 1017740] [client 4.205.62.107:53407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/nzv.php"] [unique_id "apK9GSJcY4fy7tP-rU30YgAAAl4"] [Sat Aug 29 05:06:01.605541 2026] [security2:error] [pid 1017536:tid 1017585] [remote 34.138.144.127:57736] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "old.theenprogroup.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9GSJcY4fy7tP-rU30YwACkjA"] [Sat Aug 29 05:06:01.613767 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.250.41:60778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ws68.php"] [unique_id "apK9GSJcY4fy7tP-rU30ZAAAAhw"] [Sat Aug 29 05:06:01.631539 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.196.209.81:17115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/languages/pk.php"] [unique_id "apK9GSJcY4fy7tP-rU30ZgAAAmI"] [Sat Aug 29 05:06:01.642362 2026] [security2:error] [pid 1017536:tid 1017793] [client 103.171.189.88:53210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9GSJcY4fy7tP-rU30ZwAAApM"] [Sat Aug 29 05:06:01.642472 2026] [security2:error] [pid 1017536:tid 1017793] [client 103.171.189.88:53210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9GSJcY4fy7tP-rU30ZwAAApM"] [Sat Aug 29 05:06:01.645733 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.147.79:30684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/radio.php"] [unique_id "apK9GSJcY4fy7tP-rU30aQAAAoc"] [Sat Aug 29 05:06:01.671884 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.147.79:25484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/radio.php"] [unique_id "apK9GSJcY4fy7tP-rU30bAAAAi0"] [Sat Aug 29 05:06:01.676330 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.250.41:65047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/inc.php"] [unique_id "apK9GSJcY4fy7tP-rU30bQAAAm8"] [Sat Aug 29 05:06:01.681153 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.151.200.44:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/mcd.php"] [unique_id "apK9GSJcY4fy7tP-rU30bgAAAns"] [Sat Aug 29 05:06:01.693789 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.251.3:62092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/a1vx.php"] [unique_id "apK9GSJcY4fy7tP-rU30bwAAAoI"] [Sat Aug 29 05:06:01.712346 2026] [cgid:error] [pid 1018003:tid 1018222] [client 34.7.40.70:14714] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.712830 2026] [cgid:error] [pid 1018003:tid 1018162] [client 34.7.40.70:14674] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.715513 2026] [cgid:error] [pid 1017536:tid 1017705] [client 34.7.40.70:14724] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.716365 2026] [security2:error] [pid 1017536:tid 1017790] [client 40.83.93.50:5906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9GSJcY4fy7tP-rU30eAAAApA"] [Sat Aug 29 05:06:01.716439 2026] [security2:error] [pid 1017536:tid 1017716] [client 34.7.40.70:14722] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/root/.openai/config.json"] [unique_id "apK9GSJcY4fy7tP-rU30eQAAAkY"] [Sat Aug 29 05:06:01.716642 2026] [security2:error] [pid 1018003:tid 1018243] [client 168.107.94.195:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtfgAABhM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:01.716807 2026] [cgid:error] [pid 1017536:tid 1017707] [client 34.7.40.70:14752] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.719724 2026] [security2:error] [pid 1017536:tid 1017695] [client 34.7.40.70:14774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK9GSJcY4fy7tP-rU30fQAAAjE"] [Sat Aug 29 05:06:01.719860 2026] [security2:error] [pid 1017536:tid 1017695] [client 34.7.40.70:14774] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK9GSJcY4fy7tP-rU30fQAAAjE"] [Sat Aug 29 05:06:01.720091 2026] [cgid:error] [pid 1017536:tid 1017683] [client 34.7.40.70:14806] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.720246 2026] [cgid:error] [pid 1017536:tid 1017678] [client 34.7.40.70:14690] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.720438 2026] [cgid:error] [pid 1017536:tid 1017703] [client 34.7.40.70:14738] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.720489 2026] [cgid:error] [pid 1018003:tid 1018262] [client 34.7.40.70:14698] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.720529 2026] [cgid:error] [pid 1017536:tid 1017713] [client 34.7.40.70:14680] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.721221 2026] [cgid:error] [pid 1017536:tid 1017731] [client 34.7.40.70:14700] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.725237 2026] [security2:error] [pid 1017536:tid 1017670] [client 34.7.40.70:14792] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9GSJcY4fy7tP-rU30ggAAAhg"] [Sat Aug 29 05:06:01.725781 2026] [cgid:error] [pid 1017536:tid 1017726] [client 34.7.40.70:14818] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.726095 2026] [security2:error] [pid 1017536:tid 1017749] [client 34.7.40.70:14764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/@fs/var/task/.env"] [unique_id "apK9GSJcY4fy7tP-rU30gQAAAmc"] [Sat Aug 29 05:06:01.728246 2026] [cgid:error] [pid 1017536:tid 1017669] [client 34.7.40.70:14786] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:01.729385 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.251.3:33319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/admin.php"] [unique_id "apK9GSJcY4fy7tP-rU30hAAAAmc"] [Sat Aug 29 05:06:01.748331 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.48.250.41:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/users.php"] [unique_id "apK9GSJcY4fy7tP-rU30hQAAAoM"] [Sat Aug 29 05:06:01.762729 2026] [security2:error] [pid 1017536:tid 1017708] [client 35.159.194.1:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.jobindjibouti.com"] [uri "/"] [unique_id "apK9GSJcY4fy7tP-rU30hgAAAj4"] [Sat Aug 29 05:06:01.770043 2026] [security2:error] [pid 1018003:tid 1018276] [client 171.61.160.196:14935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtgAAABjQ"] [Sat Aug 29 05:06:01.770196 2026] [security2:error] [pid 1018003:tid 1018276] [client 171.61.160.196:14935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtgAAABjQ"] [Sat Aug 29 05:06:01.803393 2026] [security2:error] [pid 1018003:tid 1018258] [client 4.205.62.107:22326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/params.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtgQAABiI"] [Sat Aug 29 05:06:01.810606 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.250.41:65054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/6bcwiqwj.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtggAABbo"] [Sat Aug 29 05:06:01.822577 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.48.251.3:61665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/public/vx.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtgwAABcQ"] [Sat Aug 29 05:06:01.828120 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.52.41.200:1223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/install.php"] [unique_id "apK9GSJcY4fy7tP-rU30iAAAAh0"] [Sat Aug 29 05:06:01.841996 2026] [security2:error] [pid 1017536:tid 1017784] [client 149.34.210.141:22729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9GSJcY4fy7tP-rU30igAAAoo"] [Sat Aug 29 05:06:01.842077 2026] [security2:error] [pid 1017536:tid 1017784] [client 149.34.210.141:22729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9GSJcY4fy7tP-rU30igAAAoo"] [Sat Aug 29 05:06:01.850679 2026] [security2:error] [pid 1018003:tid 1018183] [client 4.205.62.107:22477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/otuz1.php"] [unique_id "apK9GTAh5Y1i2tUxg4HthQAABdg"] [Sat Aug 29 05:06:01.855731 2026] [security2:error] [pid 1017536:tid 1017685] [client 158.23.147.79:30707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9GSJcY4fy7tP-rU30jQAAAic"] [Sat Aug 29 05:06:01.856010 2026] [security2:error] [pid 1017536:tid 1017608] [remote 66.29.146.59:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.146.29.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raffajapan-org.juntoohki.com"] [uri "/wp-login.php"] [unique_id "apK9GSJcY4fy7tP-rU30iQACckc"] [Sat Aug 29 05:06:01.857373 2026] [security2:error] [pid 1017536:tid 1017672] [client 4.205.62.107:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/xqq.php"] [unique_id "apK9GSJcY4fy7tP-rU30jgAAAho"] [Sat Aug 29 05:06:01.863481 2026] [security2:error] [pid 1017536:tid 1017755] [client 185.104.184.230:45004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9GSJcY4fy7tP-rU30jwAAAm0"] [Sat Aug 29 05:06:01.865433 2026] [security2:error] [pid 1017536:tid 1017646] [remote 66.29.146.59:54566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.146.29.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raffajapan-org.juntoohki.com"] [uri "/wp-login.php"] [unique_id "apK9GSJcY4fy7tP-rU30jAACQW0"] [Sat Aug 29 05:06:01.868156 2026] [security2:error] [pid 1017536:tid 1017717] [client 4.205.62.107:2881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/cli_bootstrap.php"] [unique_id "apK9GSJcY4fy7tP-rU30kAAAAkc"] [Sat Aug 29 05:06:01.870101 2026] [security2:error] [pid 1017536:tid 1017772] [client 61.9.8.151:57271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9GSJcY4fy7tP-rU30iwAAAn4"] [Sat Aug 29 05:06:01.870176 2026] [security2:error] [pid 1017536:tid 1017772] [client 61.9.8.151:57271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9GSJcY4fy7tP-rU30iwAAAn4"] [Sat Aug 29 05:06:01.877520 2026] [security2:error] [pid 1017536:tid 1017692] [client 68.155.159.216:61647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gavirestaurant.com"] [uri "/first.php"] [unique_id "apK9GSJcY4fy7tP-rU30kQAAAi4"] [Sat Aug 29 05:06:01.879398 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.250.41:62479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/bzjdlofz.php"] [unique_id "apK9GTAh5Y1i2tUxg4HthgAABgw"] [Sat Aug 29 05:06:01.884029 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.49.130:29958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/wpxml.php"] [unique_id "apK9GSJcY4fy7tP-rU30kgAAAlc"] [Sat Aug 29 05:06:01.903857 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.158.54.35:12240] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.santarosairis.org"] [uri "/1.php7"] [unique_id "apK9GTAh5Y1i2tUxg4HthwAABio"] [Sat Aug 29 05:06:01.903969 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.158.54.35:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/1.php7"] [unique_id "apK9GTAh5Y1i2tUxg4HthwAABio"] [Sat Aug 29 05:06:01.914014 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.151.200.44:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/waw.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtiAAABgY"] [Sat Aug 29 05:06:01.919551 2026] [security2:error] [pid 1017536:tid 1017740] [client 68.155.159.216:50217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/lock.php"] [unique_id "apK9GSJcY4fy7tP-rU30kwAAAl4"] [Sat Aug 29 05:06:01.952903 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.251.3:62135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/log.php"] [unique_id "apK9GSJcY4fy7tP-rU30lAAAAmY"] [Sat Aug 29 05:06:01.971976 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.197.61.180:17017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK9GSJcY4fy7tP-rU30lQAAAk0"] [Sat Aug 29 05:06:02.000726 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.48.250.41:65131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/easy.php"] [unique_id "apK9GTAh5Y1i2tUxg4HtiwAABd0"] [Sat Aug 29 05:06:02.004881 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.250.41:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/selesai.php"] [unique_id "apK9GiJcY4fy7tP-rU30lwAAAmo"] [Sat Aug 29 05:06:02.013867 2026] [security2:error] [pid 1017536:tid 1017720] [client 40.83.93.50:8058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/content.php"] [unique_id "apK9GiJcY4fy7tP-rU30mAAAAko"] [Sat Aug 29 05:06:02.017487 2026] [security2:error] [pid 1017536:tid 1017730] [client 74.248.24.12:25457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/index.php"] [unique_id "apK9GiJcY4fy7tP-rU30mQAAAlQ"] [Sat Aug 29 05:06:02.022559 2026] [security2:error] [pid 1017536:tid 1017693] [client 158.23.147.79:35777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9GiJcY4fy7tP-rU30mgAAAi8"] [Sat Aug 29 05:06:02.023869 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.48.251.3:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/chosen.php"] [unique_id "apK9GiJcY4fy7tP-rU30mwAAAns"] [Sat Aug 29 05:06:02.024866 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.196.209.81:7754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hellospringford.com"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtjAAABhU"] [Sat Aug 29 05:06:02.056803 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.49.130:58077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/about.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtjQAABjU"] [Sat Aug 29 05:06:02.068152 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.151.200.44:64906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/x23.php"] [unique_id "apK9GiJcY4fy7tP-rU30nwAAAiE"] [Sat Aug 29 05:06:02.082035 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.48.251.3:61655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ebahvhhh.php"] [unique_id "apK9GiJcY4fy7tP-rU30ogAAAkY"] [Sat Aug 29 05:06:02.095795 2026] [security2:error] [pid 1017536:tid 1017683] [client 168.107.94.195:63837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9GiJcY4fy7tP-rU30owAAAiU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:02.109845 2026] [security2:error] [pid 1017536:tid 1017678] [client 35.159.194.1:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.jobindjibouti.com"] [uri "/jobs/"] [unique_id "apK9GiJcY4fy7tP-rU30pAAAAiA"] [Sat Aug 29 05:06:02.141939 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.48.250.41:59329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/shlo.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtjgAABfA"] [Sat Aug 29 05:06:02.165852 2026] [security2:error] [pid 1018003:tid 1018220] [client 4.205.62.107:22367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/kerang.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtkAAABf0"] [Sat Aug 29 05:06:02.166479 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.250.41:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/fresh3.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtkQAABcU"] [Sat Aug 29 05:06:02.170489 2026] [security2:error] [pid 1017536:tid 1017708] [client 185.104.184.230:45018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9GiJcY4fy7tP-rU30rgAAAj4"] [Sat Aug 29 05:06:02.197290 2026] [security2:error] [pid 1017536:tid 1017681] [client 40.83.93.50:5913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/system.php"] [unique_id "apK9GiJcY4fy7tP-rU30sgAAAiM"] [Sat Aug 29 05:06:02.207579 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.48.251.3:62095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/asa.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtkgAABjM"] [Sat Aug 29 05:06:02.222117 2026] [security2:error] [pid 1017536:tid 1017764] [client 158.23.147.79:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/cong.php"] [unique_id "apK9GiJcY4fy7tP-rU30swAAAnY"] [Sat Aug 29 05:06:02.226483 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.251.3:33293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/admin-ajax.php"] [unique_id "apK9GiJcY4fy7tP-rU30tQAAAkI"] [Sat Aug 29 05:06:02.227349 2026] [security2:error] [pid 1017536:tid 1017675] [client 68.155.159.216:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/worksec.php"] [unique_id "apK9GiJcY4fy7tP-rU30tgAAAh0"] [Sat Aug 29 05:06:02.259608 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.151.200.44:64310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/ws66.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtkwAABeg"] [Sat Aug 29 05:06:02.263576 2026] [security2:error] [pid 1017536:tid 1017724] [client 4.205.62.107:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/fraro.php"] [unique_id "apK9GiJcY4fy7tP-rU30twAAAk4"] [Sat Aug 29 05:06:02.265931 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.23.147.79:24484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9GiJcY4fy7tP-rU30uAAAAos"] [Sat Aug 29 05:06:02.280001 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.52.41.200:1760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/ioxi-o.php"] [unique_id "apK9GiJcY4fy7tP-rU30uQAAAhc"] [Sat Aug 29 05:06:02.297888 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.48.250.41:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/bgymj.php"] [unique_id "apK9GiJcY4fy7tP-rU30ugAAAkc"] [Sat Aug 29 05:06:02.327628 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.48.250.41:60779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/asax.php"] [unique_id "apK9GiJcY4fy7tP-rU30vgAAAmU"] [Sat Aug 29 05:06:02.330188 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.48.251.3:61637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/radio.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtlAAABhw"] [Sat Aug 29 05:06:02.330886 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:49167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9GiJcY4fy7tP-rU30wAAAAjI"] [Sat Aug 29 05:06:02.346336 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.158.54.35:5008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/disagraeosc.php"] [unique_id "apK9GiJcY4fy7tP-rU30wgAAAjQ"] [Sat Aug 29 05:06:02.349801 2026] [security2:error] [pid 1017536:tid 1017754] [client 68.155.159.216:51877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/about/function.php"] [unique_id "apK9GiJcY4fy7tP-rU30wwAAAmw"] [Sat Aug 29 05:06:02.360510 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.151.200.44:64890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/d12.php"] [unique_id "apK9GiJcY4fy7tP-rU30xAAAApI"] [Sat Aug 29 05:06:02.375671 2026] [security2:error] [pid 1017536:tid 1017748] [client 68.155.159.216:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9GiJcY4fy7tP-rU30yAAAAmY"] [Sat Aug 29 05:06:02.383469 2026] [security2:error] [pid 1017536:tid 1017723] [client 68.155.159.216:18303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9GiJcY4fy7tP-rU30yQAAAk0"] [Sat Aug 29 05:06:02.393824 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.151.200.44:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/Cok.php"] [unique_id "apK9GiJcY4fy7tP-rU30zAAAAko"] [Sat Aug 29 05:06:02.427574 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.147.79:48223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9GiJcY4fy7tP-rU30zQAAAj0"] [Sat Aug 29 05:06:02.456838 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.48.251.3:62134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/xa.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtlwAABdQ"] [Sat Aug 29 05:06:02.457368 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.250.41:62566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/fetch.php"] [unique_id "apK9GiJcY4fy7tP-rU30zgAAAiU"] [Sat Aug 29 05:06:02.464700 2026] [security2:error] [pid 1018003:tid 1018270] [client 185.104.184.230:45034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.nhu.jca.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK9GjAh5Y1i2tUxg4HtmAAABi4"] [Sat Aug 29 05:06:02.465725 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.48.250.41:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ws69.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtmQAABiM"] [Sat Aug 29 05:06:02.475704 2026] [security2:error] [pid 1017536:tid 1017731] [client 168.107.94.195:64183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9GiJcY4fy7tP-rU30zwAAAlU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:02.500909 2026] [security2:error] [pid 1017536:tid 1017773] [client 40.83.93.50:7754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/wxo.php"] [unique_id "apK9GiJcY4fy7tP-rU300wAAAn8"] [Sat Aug 29 05:06:02.505214 2026] [security2:error] [pid 1018003:tid 1018249] [client 158.23.147.79:32761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/chosen.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtmgAABhk"] [Sat Aug 29 05:06:02.529514 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.251.3:14009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/ms.php"] [unique_id "apK9GiJcY4fy7tP-rU301AAAAlY"] [Sat Aug 29 05:06:02.548236 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.151.200.44:64847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/X7T6.php"] [unique_id "apK9GiJcY4fy7tP-rU301QAAAj4"] [Sat Aug 29 05:06:02.564028 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.49.130:46536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/ty.php"] [unique_id "apK9GiJcY4fy7tP-rU301wAAAls"] [Sat Aug 29 05:06:02.576398 2026] [security2:error] [pid 1017536:tid 1017727] [client 74.248.24.12:8982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-admin/a.php"] [unique_id "apK9GiJcY4fy7tP-rU302AAAAlE"] [Sat Aug 29 05:06:02.586582 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.48.251.3:61660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ws61.php"] [unique_id "apK9GiJcY4fy7tP-rU302QAAAkk"] [Sat Aug 29 05:06:02.598797 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.250.41:62526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/vx.php"] [unique_id "apK9GiJcY4fy7tP-rU302gAAAo4"] [Sat Aug 29 05:06:02.636629 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.48.250.41:65133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ccs.php"] [unique_id "apK9GiJcY4fy7tP-rU302wAAAh0"] [Sat Aug 29 05:06:02.671924 2026] [security2:error] [pid 1017536:tid 1017761] [client 40.83.93.50:12458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/test.php"] [unique_id "apK9GiJcY4fy7tP-rU303AAAAnM"] [Sat Aug 29 05:06:02.680203 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.197.61.180:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK9GiJcY4fy7tP-rU303QAAAkQ"] [Sat Aug 29 05:06:02.683659 2026] [security2:error] [pid 1017536:tid 1017755] [client 158.23.147.79:49801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9GiJcY4fy7tP-rU303gAAAm0"] [Sat Aug 29 05:06:02.710351 2026] [security2:error] [pid 1018003:tid 1018250] [client 4.205.62.107:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/wp-tem.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtnQAABho"] [Sat Aug 29 05:06:02.721902 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.251.3:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/xza.php"] [unique_id "apK9GiJcY4fy7tP-rU304QAAAnk"] [Sat Aug 29 05:06:02.722094 2026] [security2:error] [pid 1017536:tid 1017692] [client 20.48.251.3:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/fucku.php"] [unique_id "apK9GiJcY4fy7tP-rU304gAAAi4"] [Sat Aug 29 05:06:02.752710 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.250.41:59343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/global.php"] [unique_id "apK9GiJcY4fy7tP-rU305AAAAj8"] [Sat Aug 29 05:06:02.753820 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.147.79:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/login.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtnwAABfY"] [Sat Aug 29 05:06:02.754018 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.52.41.200:1769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/xmlrpc.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtngAABhQ"] [Sat Aug 29 05:06:02.763506 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.151.200.44:64201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/see.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtoAAABhA"] [Sat Aug 29 05:06:02.774332 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:51426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9GiJcY4fy7tP-rU305QAAAjI"] [Sat Aug 29 05:06:02.776507 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.23.147.79:25491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9GiJcY4fy7tP-rU305gAAAjQ"] [Sat Aug 29 05:06:02.815594 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.158.54.35:10700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-logs.php"] [unique_id "apK9GiJcY4fy7tP-rU306AAAAos"] [Sat Aug 29 05:06:02.823460 2026] [security2:error] [pid 1017536:tid 1017753] [client 4.205.62.107:53423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/pouhg.php"] [unique_id "apK9GiJcY4fy7tP-rU306QAAAms"] [Sat Aug 29 05:06:02.827102 2026] [security2:error] [pid 1017536:tid 1017642] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/web.config"] [unique_id "apK9GiJcY4fy7tP-rU307AACZmk"] [Sat Aug 29 05:06:02.828677 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.48.250.41:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/mar.php"] [unique_id "apK9GiJcY4fy7tP-rU307gAAApM"] [Sat Aug 29 05:06:02.855276 2026] [security2:error] [pid 1017536:tid 1017757] [client 168.107.94.195:64551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9GiJcY4fy7tP-rU308wAAAm8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:02.861203 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.48.251.3:61677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ms-edit.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtoQAABjI"] [Sat Aug 29 05:06:02.897676 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.48.250.41:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/fs.php"] [unique_id "apK9GiJcY4fy7tP-rU309QAAAlQ"] [Sat Aug 29 05:06:02.936986 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.251.3:13978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/error_log.php"] [unique_id "apK9GiJcY4fy7tP-rU309wAAAoI"] [Sat Aug 29 05:06:02.939778 2026] [security2:error] [pid 1017536:tid 1017776] [client 4.205.62.107:22515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/debug.php"] [unique_id "apK9GiJcY4fy7tP-rU30-AAAAoI"] [Sat Aug 29 05:06:02.952716 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.151.200.44:64938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/horeg.php"] [unique_id "apK9GiJcY4fy7tP-rU30-gAAAmA"] [Sat Aug 29 05:06:02.971695 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.48.250.41:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ccu.php"] [unique_id "apK9GjAh5Y1i2tUxg4HtpAAABcc"] [Sat Aug 29 05:06:02.975213 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.147.79:30697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/hehehehe.php"] [unique_id "apK9GiJcY4fy7tP-rU30_QAAAj0"] [Sat Aug 29 05:06:02.986695 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.251.3:61653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/lmfi2.php"] [unique_id "apK9GiJcY4fy7tP-rU30_gAAAis"] [Sat Aug 29 05:06:02.988509 2026] [security2:error] [pid 1017536:tid 1017684] [client 4.205.62.107:22255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/filesystems.php"] [unique_id "apK9GiJcY4fy7tP-rU30_wAAAiY"] [Sat Aug 29 05:06:02.992255 2026] [security2:error] [pid 1017536:tid 1017713] [client 4.205.62.107:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/a1vx.php"] [unique_id "apK9GiJcY4fy7tP-rU31AAAAAkM"] [Sat Aug 29 05:06:02.997610 2026] [security2:error] [pid 1017536:tid 1017720] [client 40.83.93.50:8003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/as.php"] [unique_id "apK9GiJcY4fy7tP-rU31BQAAAko"] [Sat Aug 29 05:06:03.004777 2026] [security2:error] [pid 1018003:tid 1018152] [client 68.155.159.216:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtpQAABbk"] [Sat Aug 29 05:06:03.005809 2026] [security2:error] [pid 1017536:tid 1017731] [client 4.205.62.107:2305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/wander.php"] [unique_id "apK9GyJcY4fy7tP-rU31BgAAAlU"] [Sat Aug 29 05:06:03.022720 2026] [security2:error] [pid 1018003:tid 1018203] [client 68.155.159.216:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/index/function.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtpgAABew"] [Sat Aug 29 05:06:03.042265 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.250.41:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ioxi.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtpwAABcs"] [Sat Aug 29 05:06:03.107493 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.151.200.44:65500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/yyy.php"] [unique_id "apK9GyJcY4fy7tP-rU31DQAAAjk"] [Sat Aug 29 05:06:03.112753 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.151.200.44:65485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/basic.php"] [unique_id "apK9GyJcY4fy7tP-rU31DgAAAjA"] [Sat Aug 29 05:06:03.112980 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.151.200.44:47301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9GyJcY4fy7tP-rU31DwAAAkk"] [Sat Aug 29 05:06:03.114139 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.48.250.41:65116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ak.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtqgAABd4"] [Sat Aug 29 05:06:03.116465 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.251.3:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wpver.php"] [unique_id "apK9GyJcY4fy7tP-rU31EAAAAiM"] [Sat Aug 29 05:06:03.125251 2026] [core:error] [pid 1018003:tid 1018264] [client 74.248.24.12:30544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:03.125266 2026] [core:error] [pid 1018003:tid 1018264] [client 74.248.24.12:30544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:03.172183 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.104.49.130:51130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/kerang.php"] [unique_id "apK9GyJcY4fy7tP-rU31EgAAAmc"] [Sat Aug 29 05:06:03.176112 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.23.147.79:35727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/simple.php"] [unique_id "apK9GyJcY4fy7tP-rU31FwAAAkI"] [Sat Aug 29 05:06:03.204778 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.49.130:53882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/az.php"] [unique_id "apK9GyJcY4fy7tP-rU31GwAAAkE"] [Sat Aug 29 05:06:03.208169 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.52.41.200:1731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/filemanager.php"] [unique_id "apK9GyJcY4fy7tP-rU31HAAAAkw"] [Sat Aug 29 05:06:03.209930 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.250.41:60753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/bootstrap.php"] [unique_id "apK9GyJcY4fy7tP-rU31HQAAAoE"] [Sat Aug 29 05:06:03.235378 2026] [security2:error] [pid 1017536:tid 1017733] [client 168.107.94.195:64887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9GyJcY4fy7tP-rU31HwAAAlc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:03.246181 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.48.251.3:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ah25.php"] [unique_id "apK9GyJcY4fy7tP-rU31IgAAAmU"] [Sat Aug 29 05:06:03.281756 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.158.54.35:22916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/css/about.php"] [unique_id "apK9GyJcY4fy7tP-rU31IwAAAo4"] [Sat Aug 29 05:06:03.287394 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.48.250.41:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/lib.php"] [unique_id "apK9GyJcY4fy7tP-rU31JAAAAl4"] [Sat Aug 29 05:06:03.303770 2026] [security2:error] [pid 1017536:tid 1017687] [client 4.205.62.107:22230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/rem.php"] [unique_id "apK9GyJcY4fy7tP-rU31JQAAAik"] [Sat Aug 29 05:06:03.306779 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.151.200.44:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9GyJcY4fy7tP-rU31JgAAAos"] [Sat Aug 29 05:06:03.321992 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.151.200.44:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/monso.php"] [unique_id "apK9GyJcY4fy7tP-rU31JwAAAic"] [Sat Aug 29 05:06:03.335119 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/x.php"] [unique_id "apK9GyJcY4fy7tP-rU31KAAAAms"] [Sat Aug 29 05:06:03.346297 2026] [security2:error] [pid 1017536:tid 1017744] [client 158.23.147.79:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9GyJcY4fy7tP-rU31LAAAAmI"] [Sat Aug 29 05:06:03.369059 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.250.41:59372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/export.php"] [unique_id "apK9GyJcY4fy7tP-rU31LgAAAmk"] [Sat Aug 29 05:06:03.370159 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.48.251.3:13994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/doc.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtsQAABiY"] [Sat Aug 29 05:06:03.371832 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.251.3:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/groceries/index.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtsgAABd8"] [Sat Aug 29 05:06:03.373612 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.147.79:24411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/content.php"] [unique_id "apK9GyJcY4fy7tP-rU31LwAAAmE"] [Sat Aug 29 05:06:03.389836 2026] [security2:error] [pid 1018003:tid 1018276] [client 40.83.93.50:12470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/user/f35.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtswAABjQ"] [Sat Aug 29 05:06:03.396901 2026] [security2:error] [pid 1017536:tid 1017679] [client 4.205.62.107:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/thui.php"] [unique_id "apK9GyJcY4fy7tP-rU31MwAAAiE"] [Sat Aug 29 05:06:03.405317 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.197.61.180:13016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/wp-load.php"] [unique_id "apK9GzAh5Y1i2tUxg4HttAAABgI"] [Sat Aug 29 05:06:03.428009 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.48.250.41:65061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wp-style.php"] [unique_id "apK9GzAh5Y1i2tUxg4HttQAABiI"] [Sat Aug 29 05:06:03.435634 2026] [security2:error] [pid 1018003:tid 1018163] [client 68.155.159.216:49190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9GzAh5Y1i2tUxg4HttgAABcQ"] [Sat Aug 29 05:06:03.458694 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.151.200.44:64941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/bgymj.php"] [unique_id "apK9GyJcY4fy7tP-rU31NgAAAlU"] [Sat Aug 29 05:06:03.459457 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.151.200.44:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/rce.php"] [unique_id "apK9GyJcY4fy7tP-rU31NwAAAnI"] [Sat Aug 29 05:06:03.487834 2026] [security2:error] [pid 1017536:tid 1017789] [client 68.155.159.216:18307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9GyJcY4fy7tP-rU31OAAAAo8"] [Sat Aug 29 05:06:03.488666 2026] [security2:error] [pid 1017536:tid 1017668] [client 68.155.159.216:14177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9GyJcY4fy7tP-rU31OQAAAhY"] [Sat Aug 29 05:06:03.498679 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.251.3:61648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/konfig.php"] [unique_id "apK9GyJcY4fy7tP-rU31OgAAAoc"] [Sat Aug 29 05:06:03.503005 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.48.250.41:62582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/gk.php"] [unique_id "apK9GzAh5Y1i2tUxg4HttwAABiU"] [Sat Aug 29 05:06:03.516178 2026] [security2:error] [pid 1017536:tid 1017724] [client 40.83.93.50:3165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/room.php"] [unique_id "apK9GyJcY4fy7tP-rU31OwAAAk4"] [Sat Aug 29 05:06:03.516319 2026] [security2:error] [pid 1017536:tid 1017683] [client 103.162.125.59:52495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9GyJcY4fy7tP-rU31PAAAAiU"] [Sat Aug 29 05:06:03.516400 2026] [security2:error] [pid 1017536:tid 1017683] [client 103.162.125.59:52495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9GyJcY4fy7tP-rU31PAAAAiU"] [Sat Aug 29 05:06:03.530204 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.151.200.44:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/baee.php"] [unique_id "apK9GyJcY4fy7tP-rU31PQAAAkA"] [Sat Aug 29 05:06:03.551085 2026] [security2:error] [pid 1017536:tid 1017670] [client 111.235.68.106:11202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9GyJcY4fy7tP-rU31QAAAAhg"] [Sat Aug 29 05:06:03.551173 2026] [security2:error] [pid 1017536:tid 1017670] [client 111.235.68.106:11202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9GyJcY4fy7tP-rU31QAAAAhg"] [Sat Aug 29 05:06:03.552560 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.147.79:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9GyJcY4fy7tP-rU31QQAAAhs"] [Sat Aug 29 05:06:03.590520 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.48.250.41:65066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/browse.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtuAAABgk"] [Sat Aug 29 05:06:03.601206 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.151.200.44:64928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/exec.php"] [unique_id "apK9GyJcY4fy7tP-rU31SwAAAlg"] [Sat Aug 29 05:06:03.611907 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.147.79:32719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/goods.php"] [unique_id "apK9GyJcY4fy7tP-rU31TgAAAmc"] [Sat Aug 29 05:06:03.614189 2026] [security2:error] [pid 1017536:tid 1017675] [client 168.107.94.195:65368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9GyJcY4fy7tP-rU31TwAAAh0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:03.628804 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.151.200.44:64942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/fh26.php"] [unique_id "apK9GyJcY4fy7tP-rU31UwAAAjo"] [Sat Aug 29 05:06:03.629189 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.48.251.3:61644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/paths.php"] [unique_id "apK9GyJcY4fy7tP-rU31VAAAAk8"] [Sat Aug 29 05:06:03.633230 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.250.41:62577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/logs1.php"] [unique_id "apK9GyJcY4fy7tP-rU31VQAAAkE"] [Sat Aug 29 05:06:03.661499 2026] [security2:error] [pid 1017536:tid 1017772] [client 20.52.41.200:1742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9GyJcY4fy7tP-rU31VwAAAn4"] [Sat Aug 29 05:06:03.686018 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.251.3:14047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/css.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtvAAABes"] [Sat Aug 29 05:06:03.699196 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.151.200.44:46545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/d12.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtvQAABcI"] [Sat Aug 29 05:06:03.713290 2026] [security2:error] [pid 1017536:tid 1017784] [client 158.158.54.35:19508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/system_log.php"] [unique_id "apK9GyJcY4fy7tP-rU31WQAAAoo"] [Sat Aug 29 05:06:03.713290 2026] [security2:error] [pid 1018003:tid 1018200] [client 74.248.24.12:29533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtvgAABek"] [Sat Aug 29 05:06:03.754209 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.48.250.41:65032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/zoo.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtwQAABdk"] [Sat Aug 29 05:06:03.760782 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.251.3:62098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/olfclass.php"] [unique_id "apK9GyJcY4fy7tP-rU31WwAAAig"] [Sat Aug 29 05:06:03.791685 2026] [security2:error] [pid 1017536:tid 1017730] [client 20.151.200.44:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/dbc.php"] [unique_id "apK9GyJcY4fy7tP-rU31YAAAAlQ"] [Sat Aug 29 05:06:03.797580 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:62581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/inege.php"] [unique_id "apK9GyJcY4fy7tP-rU31YgAAAmE"] [Sat Aug 29 05:06:03.800457 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:16143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/xmlrpc.php"] [unique_id "apK9GyJcY4fy7tP-rU31YwAAAks"] [Sat Aug 29 05:06:03.831720 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.151.200.44:47351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/yyy.php"] [unique_id "apK9GyJcY4fy7tP-rU31ZAAAAkc"] [Sat Aug 29 05:06:03.836785 2026] [security2:error] [pid 1017536:tid 1017689] [client 158.23.147.79:50057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/nf_tracking.php"] [unique_id "apK9GyJcY4fy7tP-rU31ZQAAAis"] [Sat Aug 29 05:06:03.844545 2026] [security2:error] [pid 1018003:tid 1018164] [client 4.205.62.107:61855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/txets.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtwwAABcU"] [Sat Aug 29 05:06:03.859833 2026] [security2:error] [pid 1018003:tid 1018206] [client 158.23.147.79:30670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtxQAABe8"] [Sat Aug 29 05:06:03.870329 2026] [security2:error] [pid 1017536:tid 1017785] [client 40.83.93.50:22228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/user/min.php"] [unique_id "apK9GyJcY4fy7tP-rU31ZgAAAos"] [Sat Aug 29 05:06:03.871788 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.104.49.130:30056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/dk.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtxgAABeM"] [Sat Aug 29 05:06:03.882767 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.23.147.79:25553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/login.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtxwAABiw"] [Sat Aug 29 05:06:03.884945 2026] [security2:error] [pid 1018003:tid 1018235] [client 68.155.159.216:51251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtyAAABgs"] [Sat Aug 29 05:06:03.889397 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.48.251.3:61692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/gnmlc.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtyQAABbg"] [Sat Aug 29 05:06:03.899381 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.48.250.41:65070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/elp.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtygAABhw"] [Sat Aug 29 05:06:03.929217 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.48.250.41:62500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wp-link10.php"] [unique_id "apK9GzAh5Y1i2tUxg4HtywAABiE"] [Sat Aug 29 05:06:03.994133 2026] [security2:error] [pid 1017536:tid 1017789] [client 168.107.94.195:49343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9GyJcY4fy7tP-rU31ZwAAAo8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:04.011579 2026] [security2:error] [pid 1018003:tid 1018220] [client 40.83.93.50:3150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/class-wp-cmd.php"] [unique_id "apK9HDAh5Y1i2tUxg4HtzAAABf0"] [Sat Aug 29 05:06:04.012898 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.151.200.44:46646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/bgymj.php"] [unique_id "apK9HCJcY4fy7tP-rU31aAAAAow"] [Sat Aug 29 05:06:04.017688 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.251.3:62120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/koiy.php"] [unique_id "apK9HCJcY4fy7tP-rU31bAAAAnc"] [Sat Aug 29 05:06:04.069275 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.250.41:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/666.php"] [unique_id "apK9HCJcY4fy7tP-rU31bQAAAj4"] [Sat Aug 29 05:06:04.078493 2026] [security2:error] [pid 1017536:tid 1017748] [client 4.205.62.107:21848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/dialog.php"] [unique_id "apK9HCJcY4fy7tP-rU31bgAAAmY"] [Sat Aug 29 05:06:04.078602 2026] [security2:error] [pid 1017536:tid 1017670] [client 158.23.147.79:30530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/admin.php"] [unique_id "apK9HCJcY4fy7tP-rU31bwAAAhg"] [Sat Aug 29 05:06:04.082040 2026] [security2:error] [pid 1017536:tid 1017680] [client 4.205.62.107:53431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/environment.php"] [unique_id "apK9HCJcY4fy7tP-rU31cAAAAiI"] [Sat Aug 29 05:06:04.095274 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.151.200.44:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/wp-wlx.php"] [unique_id "apK9HCJcY4fy7tP-rU31cQAAAnw"] [Sat Aug 29 05:06:04.105810 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.52.41.200:1764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/css/admin.php"] [unique_id "apK9HCJcY4fy7tP-rU31dAAAAjw"] [Sat Aug 29 05:06:04.111246 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.197.61.180:5851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK9HDAh5Y1i2tUxg4HtzwAABc4"] [Sat Aug 29 05:06:04.118793 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.151.200.44:64931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/fgd.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht0AAABic"] [Sat Aug 29 05:06:04.126216 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.205.62.107:22243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/server_info.php"] [unique_id "apK9HCJcY4fy7tP-rU31dQAAAh0"] [Sat Aug 29 05:06:04.126633 2026] [security2:error] [pid 1017536:tid 1017715] [client 68.155.159.216:50279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/.well-known/content.php"] [unique_id "apK9HCJcY4fy7tP-rU31dgAAAkU"] [Sat Aug 29 05:06:04.136608 2026] [security2:error] [pid 1017536:tid 1017704] [client 4.205.62.107:26682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/public/vx.php"] [unique_id "apK9HCJcY4fy7tP-rU31eAAAAjo"] [Sat Aug 29 05:06:04.142520 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.251.3:61646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/w.php"] [unique_id "apK9HCJcY4fy7tP-rU31eQAAAkE"] [Sat Aug 29 05:06:04.142724 2026] [security2:error] [pid 1017536:tid 1017681] [client 66.248.203.2:61874] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2007/11/11/what-i-learned-from-being-downsized/"] [unique_id "apK9HCJcY4fy7tP-rU31egAAAiM"] [Sat Aug 29 05:06:04.144414 2026] [security2:error] [pid 1017536:tid 1017775] [client 68.155.159.216:52859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/chosen.php"] [unique_id "apK9HCJcY4fy7tP-rU31ewAAAoE"] [Sat Aug 29 05:06:04.145933 2026] [security2:error] [pid 1017536:tid 1017755] [client 20.151.200.44:47311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/fh26.php"] [unique_id "apK9HCJcY4fy7tP-rU31fAAAAm0"] [Sat Aug 29 05:06:04.155106 2026] [security2:error] [pid 1017536:tid 1017668] [client 158.158.54.35:16007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/24.php"] [unique_id "apK9HCJcY4fy7tP-rU31fQAAAhY"] [Sat Aug 29 05:06:04.156319 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.48.250.41:59277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ww.php"] [unique_id "apK9HCJcY4fy7tP-rU31fgAAAjI"] [Sat Aug 29 05:06:04.160922 2026] [security2:error] [pid 1017536:tid 1017698] [client 4.205.62.107:2309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mcdcomputers.net"] [uri "/ah25.php"] [unique_id "apK9HCJcY4fy7tP-rU31fwAAAjQ"] [Sat Aug 29 05:06:04.223811 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.250.41:65124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/knmt.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht0wAABcE"] [Sat Aug 29 05:06:04.268441 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.251.3:61639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/btx25.php"] [unique_id "apK9HCJcY4fy7tP-rU31iwAAAig"] [Sat Aug 29 05:06:04.280343 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.48.251.3:14332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/php_info.php"] [unique_id "apK9HCJcY4fy7tP-rU31jAAAAkw"] [Sat Aug 29 05:06:04.329985 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.147.79:35800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/about.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht2AAABfs"] [Sat Aug 29 05:06:04.330789 2026] [security2:error] [pid 1017536:tid 1017777] [client 74.248.24.12:31563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "falloutgroup.johnharveymusic.com"] [uri "/wp-admin.php"] [unique_id "apK9HCJcY4fy7tP-rU31jQAAAoM"] [Sat Aug 29 05:06:04.332769 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.250.41:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/w1px.php"] [unique_id "apK9HCJcY4fy7tP-rU31jgAAAoI"] [Sat Aug 29 05:06:04.333908 2026] [security2:error] [pid 1017536:tid 1017782] [client 20.151.200.44:47360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/fgd.php"] [unique_id "apK9HCJcY4fy7tP-rU31jwAAAog"] [Sat Aug 29 05:06:04.336679 2026] [security2:error] [pid 1017536:tid 1017740] [client 40.83.93.50:5949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/users.php"] [unique_id "apK9HCJcY4fy7tP-rU31kAAAAl4"] [Sat Aug 29 05:06:04.355010 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.250.41:65105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/sbhu.php"] [unique_id "apK9HCJcY4fy7tP-rU31kQAAAjs"] [Sat Aug 29 05:06:04.372814 2026] [security2:error] [pid 1017536:tid 1017679] [client 168.107.94.195:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9HCJcY4fy7tP-rU31kgAAAiE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:04.393899 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.251.3:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/app_dev.php"] [unique_id "apK9HCJcY4fy7tP-rU31lAAAAis"] [Sat Aug 29 05:06:04.428714 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.151.200.44:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/attack.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht2gAABbk"] [Sat Aug 29 05:06:04.441965 2026] [security2:error] [pid 1017536:tid 1017760] [client 4.205.62.107:22212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/min.php"] [unique_id "apK9HCJcY4fy7tP-rU31lgAAAnI"] [Sat Aug 29 05:06:04.448722 2026] [security2:error] [pid 1017536:tid 1017729] [client 68.155.159.216:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/x.php"] [unique_id "apK9HCJcY4fy7tP-rU31lwAAAlM"] [Sat Aug 29 05:06:04.481551 2026] [security2:error] [pid 1017536:tid 1017789] [client 158.23.147.79:24457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK9HCJcY4fy7tP-rU31mgAAAo8"] [Sat Aug 29 05:06:04.489598 2026] [security2:error] [pid 1017536:tid 1017743] [client 40.83.93.50:8032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/disagreed.php"] [unique_id "apK9HCJcY4fy7tP-rU31mwAAAmE"] [Sat Aug 29 05:06:04.507379 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.147.79:63012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/index.php"] [unique_id "apK9HCJcY4fy7tP-rU31nAAAAnc"] [Sat Aug 29 05:06:04.517826 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.48.250.41:64264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/a332.php"] [unique_id "apK9HCJcY4fy7tP-rU31nQAAAio"] [Sat Aug 29 05:06:04.521257 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.251.3:62107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/php-info.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht2wAABcs"] [Sat Aug 29 05:06:04.531137 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.48.250.41:60795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/to.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht3AAABhY"] [Sat Aug 29 05:06:04.534794 2026] [security2:error] [pid 1017536:tid 1017708] [client 4.205.62.107:56035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/lala.php"] [unique_id "apK9HCJcY4fy7tP-rU31ngAAAj4"] [Sat Aug 29 05:06:04.535890 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.151.200.44:47407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/inject.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht3QAABgc"] [Sat Aug 29 05:06:04.553524 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.104.49.130:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/css.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht3gAABd4"] [Sat Aug 29 05:06:04.560498 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.52.41.200:1738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/adminfuns.php"] [unique_id "apK9HCJcY4fy7tP-rU31oAAAAiY"] [Sat Aug 29 05:06:04.589112 2026] [security2:error] [pid 1017536:tid 1017772] [client 68.155.159.216:14291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9HCJcY4fy7tP-rU31owAAAn4"] [Sat Aug 29 05:06:04.601394 2026] [security2:error] [pid 1017536:tid 1017784] [client 68.155.159.216:49154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9HCJcY4fy7tP-rU31pQAAAoo"] [Sat Aug 29 05:06:04.605897 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.151.200.44:64312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/inject.php"] [unique_id "apK9HCJcY4fy7tP-rU31pgAAAls"] [Sat Aug 29 05:06:04.642970 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.250.41:65138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ws66.php"] [unique_id "apK9HCJcY4fy7tP-rU31pwAAApI"] [Sat Aug 29 05:06:04.649766 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.251.3:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/infos.php"] [unique_id "apK9HCJcY4fy7tP-rU31qQAAAmQ"] [Sat Aug 29 05:06:04.665926 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.48.250.41:62468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/thui.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht4QAABc0"] [Sat Aug 29 05:06:04.666968 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.23.147.79:48236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht4gAABdk"] [Sat Aug 29 05:06:04.698174 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.151.200.44:65505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/file66.php"] [unique_id "apK9HCJcY4fy7tP-rU31rQAAAi0"] [Sat Aug 29 05:06:04.709991 2026] [security2:error] [pid 1017536:tid 1017667] [client 34.7.216.49:49406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/app/config.json"] [unique_id "apK9HCJcY4fy7tP-rU31sQAAAhU"] [Sat Aug 29 05:06:04.711101 2026] [security2:error] [pid 1017536:tid 1017783] [client 34.7.216.49:49422] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/backend/config.json"] [unique_id "apK9HCJcY4fy7tP-rU31sgAAAok"] [Sat Aug 29 05:06:04.713160 2026] [security2:error] [pid 1018003:tid 1018217] [client 34.7.216.49:49510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/config/application.yml"] [unique_id "apK9HDAh5Y1i2tUxg4Ht6AAABfo"] [Sat Aug 29 05:06:04.714618 2026] [security2:error] [pid 1017536:tid 1017764] [client 34.7.216.49:49550] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/secrets/aws.json"] [unique_id "apK9HCJcY4fy7tP-rU31tgAAAnY"] [Sat Aug 29 05:06:04.720351 2026] [security2:error] [pid 1018003:tid 1018225] [client 34.7.216.49:49612] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/secrets.yaml"] [unique_id "apK9HDAh5Y1i2tUxg4Ht8AAABgI"] [Sat Aug 29 05:06:04.722501 2026] [security2:error] [pid 1017536:tid 1017711] [client 34.7.216.49:49648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/app/settings.py"] [unique_id "apK9HCJcY4fy7tP-rU31vwAAAkE"] [Sat Aug 29 05:06:04.726491 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.147.79:32749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht9QAABeM"] [Sat Aug 29 05:06:04.729306 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.151.200.44:46549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/mga.php"] [unique_id "apK9HCJcY4fy7tP-rU31wQAAAo8"] [Sat Aug 29 05:06:04.747394 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.158.54.35:5022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht9wAABiw"] [Sat Aug 29 05:06:04.753863 2026] [security2:error] [pid 1018003:tid 1018235] [client 168.107.94.195:49988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht-AAABgs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:04.759665 2026] [security2:error] [pid 1017536:tid 1017693] [client 57.141.14.77:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/"] [unique_id "apK9HCJcY4fy7tP-rU31xAAAAi8"] [Sat Aug 29 05:06:04.771014 2026] [security2:error] [pid 1017536:tid 1017586] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/src/.env"] [unique_id "apK9HCJcY4fy7tP-rU31xgACTTE"] [Sat Aug 29 05:06:04.780052 2026] [proxy_http:error] [pid 1017536:tid 1017754] (20014)Internal error (specific information not available): [client 34.21.253.104:29574] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.780067 2026] [proxy:error] [pid 1017536:tid 1017754] [client 34.21.253.104:29574] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config.js [Sat Aug 29 05:06:04.781228 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.48.251.3:61666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/env.php"] [unique_id "apK9HCJcY4fy7tP-rU31zAAAAio"] [Sat Aug 29 05:06:04.782267 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.48.250.41:65108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ws68.php"] [unique_id "apK9HDAh5Y1i2tUxg4Ht_gAABg4"] [Sat Aug 29 05:06:04.783290 2026] [proxy_http:error] [pid 1018003:tid 1018187] (20014)Internal error (specific information not available): [client 34.21.253.104:29560] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.783304 2026] [proxy:error] [pid 1018003:tid 1018187] [client 34.21.253.104:29560] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/secrets.json [Sat Aug 29 05:06:04.787585 2026] [proxy_http:error] [pid 1017536:tid 1017685] (20014)Internal error (specific information not available): [client 34.21.253.104:29564] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.787595 2026] [proxy:error] [pid 1017536:tid 1017685] [client 34.21.253.104:29564] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config.json [Sat Aug 29 05:06:04.787677 2026] [security2:error] [pid 1018003:tid 1018165] [client 34.21.253.104:29766] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/.ssh/id_ecdsa"] [unique_id "apK9HDAh5Y1i2tUxg4HuAQAABcY"] [Sat Aug 29 05:06:04.790614 2026] [security2:error] [pid 1018003:tid 1018182] [client 34.21.253.104:29702] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/__/firebase/init.json"] [unique_id "apK9HDAh5Y1i2tUxg4HuBQAABdc"] [Sat Aug 29 05:06:04.791703 2026] [security2:error] [pid 1017536:tid 1017745] [client 34.21.253.104:29728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/gcp-key.json"] [unique_id "apK9HCJcY4fy7tP-rU312AAAAmM"] [Sat Aug 29 05:06:04.794915 2026] [proxy_http:error] [pid 1017536:tid 1017761] (20014)Internal error (specific information not available): [client 34.21.253.104:29626] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.794930 2026] [proxy:error] [pid 1017536:tid 1017761] [client 34.21.253.104:29626] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/env [Sat Aug 29 05:06:04.799176 2026] [proxy_http:error] [pid 1018003:tid 1018187] (20014)Internal error (specific information not available): [client 34.21.253.104:29560] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.799186 2026] [proxy:error] [pid 1018003:tid 1018187] [client 34.21.253.104:29560] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:06:04.801366 2026] [proxy_http:error] [pid 1017536:tid 1017753] (20014)Internal error (specific information not available): [client 34.21.253.104:29604] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.801378 2026] [proxy:error] [pid 1017536:tid 1017753] [client 34.21.253.104:29604] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/runtime-config.js [Sat Aug 29 05:06:04.806670 2026] [proxy_http:error] [pid 1018003:tid 1018265] (20014)Internal error (specific information not available): [client 34.21.253.104:29638] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.806681 2026] [proxy:error] [pid 1018003:tid 1018265] [client 34.21.253.104:29638] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/v1/config [Sat Aug 29 05:06:04.808317 2026] [proxy_http:error] [pid 1017536:tid 1017781] (20014)Internal error (specific information not available): [client 34.21.253.104:29678] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.808325 2026] [proxy:error] [pid 1017536:tid 1017781] [client 34.21.253.104:29678] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/firebase-adminsdk.json [Sat Aug 29 05:06:04.809205 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.250.41:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/Jcrop.php"] [unique_id "apK9HDAh5Y1i2tUxg4HuCgAABfU"] [Sat Aug 29 05:06:04.812625 2026] [proxy_http:error] [pid 1018003:tid 1018230] (20014)Internal error (specific information not available): [client 34.21.253.104:29788] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.812636 2026] [proxy:error] [pid 1018003:tid 1018230] [client 34.21.253.104:29788] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.ssh/config [Sat Aug 29 05:06:04.814779 2026] [proxy_http:error] [pid 1017536:tid 1017724] (20014)Internal error (specific information not available): [client 34.21.253.104:29688] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.814789 2026] [proxy:error] [pid 1017536:tid 1017724] [client 34.21.253.104:29688] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/firebase-config.json [Sat Aug 29 05:06:04.818682 2026] [proxy_http:error] [pid 1018003:tid 1018192] (20014)Internal error (specific information not available): [client 34.21.253.104:29752] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.818696 2026] [proxy:error] [pid 1018003:tid 1018192] [client 34.21.253.104:29752] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.ssh/id_rsa [Sat Aug 29 05:06:04.820544 2026] [proxy_http:error] [pid 1017536:tid 1017752] (20014)Internal error (specific information not available): [client 34.21.253.104:29724] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.820560 2026] [proxy:error] [pid 1017536:tid 1017752] [client 34.21.253.104:29724] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/google-credentials.json [Sat Aug 29 05:06:04.825059 2026] [proxy_http:error] [pid 1018003:tid 1018161] (20014)Internal error (specific information not available): [client 34.21.253.104:29746] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:04.825071 2026] [proxy:error] [pid 1018003:tid 1018161] [client 34.21.253.104:29746] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/keys/service-account.json [Sat Aug 29 05:06:04.830683 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.197.61.180:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "apK9HDAh5Y1i2tUxg4HuDQAABf8"] [Sat Aug 29 05:06:04.830850 2026] [security2:error] [pid 1017536:tid 1017740] [client 40.83.93.50:12464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK9HCJcY4fy7tP-rU312QAAAl4"] [Sat Aug 29 05:06:04.884850 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.151.200.44:46565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/inwp.php"] [unique_id "apK9HCJcY4fy7tP-rU312gAAAls"] [Sat Aug 29 05:06:04.905707 2026] [security2:error] [pid 1017536:tid 1017722] [client 68.155.159.216:16289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/atomlib.php"] [unique_id "apK9HCJcY4fy7tP-rU313QAAAkw"] [Sat Aug 29 05:06:04.911319 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.251.3:61641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/xve22.php"] [unique_id "apK9HCJcY4fy7tP-rU313gAAAmk"] [Sat Aug 29 05:06:04.929257 2026] [security2:error] [pid 1017536:tid 1017650] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/frontend/.env"] [unique_id "apK9HCJcY4fy7tP-rU313wACZHE"] [Sat Aug 29 05:06:04.942674 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.48.250.41:62514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ws58.php"] [unique_id "apK9HCJcY4fy7tP-rU314AAAAoM"] [Sat Aug 29 05:06:04.947242 2026] [security2:error] [pid 1017536:tid 1017662] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/app/.env"] [unique_id "apK9HCJcY4fy7tP-rU314QACgn0"] [Sat Aug 29 05:06:04.950992 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.48.250.41:65104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/users.php"] [unique_id "apK9HCJcY4fy7tP-rU314gAAAiE"] [Sat Aug 29 05:06:04.952935 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.49.130:34508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/abcd.php"] [unique_id "apK9HCJcY4fy7tP-rU314wAAAlo"] [Sat Aug 29 05:06:04.968053 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.147.79:30625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/xmlrpc.php"] [unique_id "apK9HDAh5Y1i2tUxg4HuDwAABfY"] [Sat Aug 29 05:06:04.974381 2026] [security2:error] [pid 1017536:tid 1017783] [client 4.205.62.107:64258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/time.php"] [unique_id "apK9HCJcY4fy7tP-rU315gAAAok"] [Sat Aug 29 05:06:04.989697 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.147.79:25552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/hehehehe.php"] [unique_id "apK9HCJcY4fy7tP-rU316AAAAhs"] [Sat Aug 29 05:06:05.015158 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.52.41.200:1782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/goods.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuEAAABgQ"] [Sat Aug 29 05:06:05.040242 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.251.3:61669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/06.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuEwAABis"] [Sat Aug 29 05:06:05.044766 2026] [security2:error] [pid 1017536:tid 1017683] [client 68.155.159.216:51250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-login.php"] [unique_id "apK9HSJcY4fy7tP-rU317QAAAiU"] [Sat Aug 29 05:06:05.076452 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/xs.php"] [unique_id "apK9HSJcY4fy7tP-rU317wAAAj0"] [Sat Aug 29 05:06:05.089848 2026] [security2:error] [pid 1017536:tid 1017721] [client 40.83.93.50:3138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/class_api.php"] [unique_id "apK9HSJcY4fy7tP-rU318QAAAks"] [Sat Aug 29 05:06:05.092080 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.250.41:64334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/bzjdlofz.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuFAAABfs"] [Sat Aug 29 05:06:05.094701 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.151.200.44:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/ad1.php"] [unique_id "apK9HSJcY4fy7tP-rU318gAAAjQ"] [Sat Aug 29 05:06:05.133707 2026] [security2:error] [pid 1018003:tid 1018246] [client 168.107.94.195:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuFQAABhY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:05.145508 2026] [security2:error] [pid 1017536:tid 1017581] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/server/.env"] [unique_id "apK9HSJcY4fy7tP-rU318wACRiw"] [Sat Aug 29 05:06:05.152162 2026] [security2:error] [pid 1017536:tid 1017616] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/production/.env"] [unique_id "apK9HSJcY4fy7tP-rU319AACRU8"] [Sat Aug 29 05:06:05.161000 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.196.209.81:5541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuGAAABiY"] [Sat Aug 29 05:06:05.169124 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.48.251.3:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/xin1.php"] [unique_id "apK9HSJcY4fy7tP-rU319QAAAhc"] [Sat Aug 29 05:06:05.204958 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.250.41:60741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/zu.php"] [unique_id "apK9HSJcY4fy7tP-rU31-gAAAmw"] [Sat Aug 29 05:06:05.217029 2026] [security2:error] [pid 1017536:tid 1017695] [client 4.205.62.107:22363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/doc.php"] [unique_id "apK9HSJcY4fy7tP-rU31-wAAAjE"] [Sat Aug 29 05:06:05.226519 2026] [security2:error] [pid 1018003:tid 1018203] [client 4.205.62.107:53419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/koiy.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuGwAABew"] [Sat Aug 29 05:06:05.234622 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:50222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/cong.php"] [unique_id "apK9HSJcY4fy7tP-rU31_QAAAms"] [Sat Aug 29 05:06:05.249013 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.23.147.79:30693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/atomlib.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuHQAABek"] [Sat Aug 29 05:06:05.259199 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.151.200.44:46534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/1vbqo.php"] [unique_id "apK9HSJcY4fy7tP-rU32AAAAAk4"] [Sat Aug 29 05:06:05.262605 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.48.250.41:64337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/selesai.php"] [unique_id "apK9HSJcY4fy7tP-rU32AgAAAk8"] [Sat Aug 29 05:06:05.264732 2026] [security2:error] [pid 1017536:tid 1017752] [client 4.205.62.107:21576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/87.php"] [unique_id "apK9HSJcY4fy7tP-rU32AwAAAmo"] [Sat Aug 29 05:06:05.293111 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.220.204.93:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9HSJcY4fy7tP-rU32BgAAAhY"] [Sat Aug 29 05:06:05.297628 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.48.251.3:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/sadd.php"] [unique_id "apK9HSJcY4fy7tP-rU32BwAAAoo"] [Sat Aug 29 05:06:05.302181 2026] [security2:error] [pid 1017536:tid 1017775] [client 4.205.62.107:65443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/log.php"] [unique_id "apK9HSJcY4fy7tP-rU32CAAAAoE"] [Sat Aug 29 05:06:05.306781 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.151.200.44:64887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/mga.php"] [unique_id "apK9HSJcY4fy7tP-rU32CgAAAo4"] [Sat Aug 29 05:06:05.309303 2026] [security2:error] [pid 1018003:tid 1018254] [client 20.151.200.44:64842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/zafir1.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuIQAABh4"] [Sat Aug 29 05:06:05.312620 2026] [security2:error] [pid 1017536:tid 1017660] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/docker/.env"] [unique_id "apK9HSJcY4fy7tP-rU32CwACSXs"] [Sat Aug 29 05:06:05.313891 2026] [security2:error] [pid 1017536:tid 1017573] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/dev/.env"] [unique_id "apK9HSJcY4fy7tP-rU32DAACSSQ"] [Sat Aug 29 05:06:05.315091 2026] [security2:error] [pid 1017536:tid 1017564] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/apps/.env"] [unique_id "apK9HSJcY4fy7tP-rU32DgACSRs"] [Sat Aug 29 05:06:05.315512 2026] [security2:error] [pid 1017536:tid 1017602] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/staging/.env"] [unique_id "apK9HSJcY4fy7tP-rU32DQACSUE"] [Sat Aug 29 05:06:05.317483 2026] [security2:error] [pid 1017536:tid 1017744] [client 40.83.93.50:12420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK9HSJcY4fy7tP-rU32DwAAAmI"] [Sat Aug 29 05:06:05.367414 2026] [security2:error] [pid 1017536:tid 1017751] [client 195.178.110.247:46420] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http:///x"] [hostname "go.gracelife.org"] [uri "/index.php"] [unique_id "apK9HSJcY4fy7tP-rU32EAAAAmk"] [Sat Aug 29 05:06:05.375508 2026] [security2:error] [pid 1017536:tid 1017655] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/v1/.env"] [unique_id "apK9HSJcY4fy7tP-rU32EgACO3Y"] [Sat Aug 29 05:06:05.382430 2026] [security2:error] [pid 1017536:tid 1017589] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/v2/.env"] [unique_id "apK9HSJcY4fy7tP-rU32EwACgjQ"] [Sat Aug 29 05:06:05.404469 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.151.200.44:45464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/h02ugyh.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuJwAABjM"] [Sat Aug 29 05:06:05.423575 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.48.251.3:61214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/application.config.php"] [unique_id "apK9HSJcY4fy7tP-rU32FQAAAi0"] [Sat Aug 29 05:06:05.424183 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.48.250.41:65036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/shlo.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuKAAABeA"] [Sat Aug 29 05:06:05.443761 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.250.41:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/lanka.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuKQAABgM"] [Sat Aug 29 05:06:05.450114 2026] [security2:error] [pid 1018003:tid 1018264] [client 158.23.147.79:35720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuKgAABig"] [Sat Aug 29 05:06:05.455859 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.52.41.200:1770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/css.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuKwAABeQ"] [Sat Aug 29 05:06:05.458218 2026] [security2:error] [pid 1017536:tid 1017667] [client 68.155.159.216:51805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9HSJcY4fy7tP-rU32FgAAAhU"] [Sat Aug 29 05:06:05.475038 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.220.204.93:64379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuLgAABdU"] [Sat Aug 29 05:06:05.514925 2026] [security2:error] [pid 1018003:tid 1018151] [client 158.158.54.35:19505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/images/index.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuLwAABbg"] [Sat Aug 29 05:06:05.515448 2026] [security2:error] [pid 1017536:tid 1017711] [client 168.107.94.195:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9HSJcY4fy7tP-rU32FwAAAkE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:05.528683 2026] [security2:error] [pid 1018003:tid 1018255] [client 195.178.110.247:52064] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http:///x"] [hostname "go.gracelife.org"] [uri "/index.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuMAAABh8"] [Sat Aug 29 05:06:05.528731 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.197.61.180:17008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK9HSJcY4fy7tP-rU32GAAAAjo"] [Sat Aug 29 05:06:05.548367 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:61657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/xp.php"] [unique_id "apK9HSJcY4fy7tP-rU32GgAAAjw"] [Sat Aug 29 05:06:05.556588 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.196.209.81:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/options-general.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuMQAABeM"] [Sat Aug 29 05:06:05.562659 2026] [security2:error] [pid 1017536:tid 1017736] [client 40.83.93.50:8055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/aksinet.php"] [unique_id "apK9HSJcY4fy7tP-rU32GwAAAlo"] [Sat Aug 29 05:06:05.563097 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.250.41:65087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/asax.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuMgAABdc"] [Sat Aug 29 05:06:05.565622 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.151.200.44:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/console.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuMwAABgw"] [Sat Aug 29 05:06:05.572366 2026] [security2:error] [pid 1018003:tid 1018169] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuLQAFyiw"] [Sat Aug 29 05:06:05.581787 2026] [security2:error] [pid 1017536:tid 1017726] [client 4.205.62.107:22491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/saiga.php"] [unique_id "apK9HSJcY4fy7tP-rU32IAAAAlA"] [Sat Aug 29 05:06:05.583201 2026] [security2:error] [pid 1017536:tid 1017755] [client 35.198.240.194:10424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.hermes/.env"] [unique_id "apK9HSJcY4fy7tP-rU32IQAAAm0"] [Sat Aug 29 05:06:05.583637 2026] [security2:error] [pid 1017536:tid 1017717] [client 35.198.240.194:10490] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "apK9HSJcY4fy7tP-rU32JQAAAkc"] [Sat Aug 29 05:06:05.584603 2026] [security2:error] [pid 1018003:tid 1018219] [client 35.198.240.194:10438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.openclaw/.env"] [unique_id "apK9HTAh5Y1i2tUxg4HuOQAABfw"] [Sat Aug 29 05:06:05.587252 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:24460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuPAAABdA"] [Sat Aug 29 05:06:05.616555 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.48.250.41:60799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/gettest.php"] [unique_id "apK9HSJcY4fy7tP-rU32KwAAAik"] [Sat Aug 29 05:06:05.651813 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.151.200.44:47397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/shelp.php"] [unique_id "apK9HSJcY4fy7tP-rU32LgAAAmY"] [Sat Aug 29 05:06:05.660824 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.220.204.93:64260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ff1.php"] [unique_id "apK9HSJcY4fy7tP-rU32LwAAAmw"] [Sat Aug 29 05:06:05.662839 2026] [security2:error] [pid 1018003:tid 1018249] [client 158.23.147.79:63011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/about/function.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuQAAABhk"] [Sat Aug 29 05:06:05.669340 2026] [security2:error] [pid 1017536:tid 1017732] [client 35.198.240.194:10570] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9HSJcY4fy7tP-rU32MgAAAlY"] [Sat Aug 29 05:06:05.669863 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.251.3:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/g3.php"] [unique_id "apK9HSJcY4fy7tP-rU32NAAAAoc"] [Sat Aug 29 05:06:05.670390 2026] [security2:error] [pid 1018003:tid 1018224] [client 35.198.240.194:10544] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9HTAh5Y1i2tUxg4HuQgAABgE"] [Sat Aug 29 05:06:05.672754 2026] [security2:error] [pid 1017536:tid 1017734] [client 68.155.159.216:18305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/file.php"] [unique_id "apK9HSJcY4fy7tP-rU32NQAAAlg"] [Sat Aug 29 05:06:05.676230 2026] [security2:error] [pid 1017536:tid 1017724] [client 4.205.62.107:55954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/public/bnn_.php.php"] [unique_id "apK9HSJcY4fy7tP-rU32NgAAAk4"] [Sat Aug 29 05:06:05.690798 2026] [security2:error] [pid 1017536:tid 1017601] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/site/.env"] [unique_id "apK9HSJcY4fy7tP-rU32NwACTUA"] [Sat Aug 29 05:06:05.690966 2026] [security2:error] [pid 1017536:tid 1017653] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/old/.env"] [unique_id "apK9HSJcY4fy7tP-rU32OAACTXQ"] [Sat Aug 29 05:06:05.692072 2026] [security2:error] [pid 1017536:tid 1017567] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/env.old"] [unique_id "apK9HSJcY4fy7tP-rU32OQACTR4"] [Sat Aug 29 05:06:05.706434 2026] [security2:error] [pid 1017536:tid 1017557] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/.docker/.env"] [unique_id "apK9HSJcY4fy7tP-rU32OgACfhQ"] [Sat Aug 29 05:06:05.707997 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.48.250.41:65121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/fetch.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuQwAABgQ"] [Sat Aug 29 05:06:05.711205 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.251.3:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/h.php"] [unique_id "apK9HSJcY4fy7tP-rU32PAAAAo4"] [Sat Aug 29 05:06:05.752057 2026] [security2:error] [pid 1017536:tid 1017683] [client 87.219.197.128:52542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9HSJcY4fy7tP-rU32QAAAAiU"] [Sat Aug 29 05:06:05.752154 2026] [security2:error] [pid 1017536:tid 1017683] [client 87.219.197.128:52542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9HSJcY4fy7tP-rU32QAAAAiU"] [Sat Aug 29 05:06:05.754318 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.250.41:60714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/35.php"] [unique_id "apK9HSJcY4fy7tP-rU32QQAAAjs"] [Sat Aug 29 05:06:05.771656 2026] [security2:error] [pid 1017536:tid 1017691] [client 68.155.159.216:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/goods.php"] [unique_id "apK9HSJcY4fy7tP-rU32QgAAAi0"] [Sat Aug 29 05:06:05.778643 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.23.147.79:48147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/radio.php"] [unique_id "apK9HSJcY4fy7tP-rU32QwAAAoY"] [Sat Aug 29 05:06:05.787136 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.151.200.44:64911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/blnux.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuRAAABhg"] [Sat Aug 29 05:06:05.795271 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.48.251.3:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-konfig.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuRQAABiU"] [Sat Aug 29 05:06:05.799858 2026] [security2:error] [pid 1017536:tid 1017708] [client 40.83.93.50:22223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/wp-load.php"] [unique_id "apK9HSJcY4fy7tP-rU32RAAAAj4"] [Sat Aug 29 05:06:05.841110 2026] [security2:error] [pid 1018003:tid 1018251] [client 158.23.147.79:32746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuRwAABhs"] [Sat Aug 29 05:06:05.861545 2026] [security2:error] [pid 1018003:tid 1018209] [client 20.151.200.44:46570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/13ede.php"] [unique_id "apK9HTAh5Y1i2tUxg4HuSAAABfI"] [Sat Aug 29 05:06:05.871133 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:65112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/vx.php"] [unique_id "apK9HSJcY4fy7tP-rU32RQAAAj0"] [Sat Aug 29 05:06:05.883844 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.220.204.93:63851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/t.php"] [unique_id "apK9HSJcY4fy7tP-rU32RwAAAik"] [Sat Aug 29 05:06:05.888971 2026] [security2:error] [pid 1017536:tid 1017768] [client 20.48.250.41:62471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/maraz.php"] [unique_id "apK9HSJcY4fy7tP-rU32SAAAAno"] [Sat Aug 29 05:06:05.898221 2026] [security2:error] [pid 1017536:tid 1017743] [client 168.107.94.195:51144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9HSJcY4fy7tP-rU32SQAAAmE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:05.919883 2026] [cgid:error] [pid 1018003:tid 1018218] [client 20.52.41.200:1739] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:05.925137 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.251.3:61218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/25.php"] [unique_id "apK9HSJcY4fy7tP-rU32SgAAAj8"] [Sat Aug 29 05:06:05.951151 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.196.209.81:23626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/options.php"] [unique_id "apK9HSJcY4fy7tP-rU32SwAAAjo"] [Sat Aug 29 05:06:05.957616 2026] [security2:error] [pid 1017536:tid 1017680] [client 158.158.54.35:8666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/num.php"] [unique_id "apK9HSJcY4fy7tP-rU32TAAAAiI"] [Sat Aug 29 05:06:05.992370 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.151.200.44:64833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/pentest.php"] [unique_id "apK9HSJcY4fy7tP-rU32TwAAAiM"] [Sat Aug 29 05:06:06.002643 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.151.200.44:47416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/k8.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuTQAABdc"] [Sat Aug 29 05:06:06.003559 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.48.250.41:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/global.php"] [unique_id "apK9HiJcY4fy7tP-rU32UAAAAhY"] [Sat Aug 29 05:06:06.007945 2026] [security2:error] [pid 1017536:tid 1017784] [client 68.155.159.216:16379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/lv.php"] [unique_id "apK9HiJcY4fy7tP-rU32UgAAAoo"] [Sat Aug 29 05:06:06.019283 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.49.130:52521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/classwithtostring.php"] [unique_id "apK9HiJcY4fy7tP-rU32VAAAApA"] [Sat Aug 29 05:06:06.020526 2026] [security2:error] [pid 1017536:tid 1017582] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/api/.env.bak"] [unique_id "apK9HiJcY4fy7tP-rU32UwACKi0"] [Sat Aug 29 05:06:06.021343 2026] [security2:error] [pid 1017536:tid 1017596] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/.env.production.bak"] [unique_id "apK9HiJcY4fy7tP-rU32VQACKjs"] [Sat Aug 29 05:06:06.023368 2026] [security2:error] [pid 1017536:tid 1017612] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/.env.prod.bak"] [unique_id "apK9HiJcY4fy7tP-rU32VwACKks"] [Sat Aug 29 05:06:06.032634 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.48.250.41:62570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/kbfr.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuTwAABi0"] [Sat Aug 29 05:06:06.039333 2026] [security2:error] [pid 1017536:tid 1017755] [client 34.143.179.161:45338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/config.env"] [unique_id "apK9HiJcY4fy7tP-rU32WgAAAm0"] [Sat Aug 29 05:06:06.053776 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.48.251.3:61661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/nlnub.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuWAAABhM"] [Sat Aug 29 05:06:06.054847 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:50144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wzy.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuWgAABdA"] [Sat Aug 29 05:06:06.061653 2026] [security2:error] [pid 1018003:tid 1018195] [client 34.143.179.161:45322] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/config/anthropic.json"] [unique_id "apK9HjAh5Y1i2tUxg4HuYQAABeQ"] [Sat Aug 29 05:06:06.072857 2026] [security2:error] [pid 1018003:tid 1018167] [client 40.83.93.50:8011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/alfa-rex1.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuZAAABcg"] [Sat Aug 29 05:06:06.073515 2026] [cgid:error] [pid 1018003:tid 1018276] [client 20.52.41.200:1739] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:06.086810 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.147.79:30557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/lv.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuZgAABf8"] [Sat Aug 29 05:06:06.108391 2026] [security2:error] [pid 1018003:tid 1018230] [client 4.205.62.107:64963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/doc.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuagAABgY"] [Sat Aug 29 05:06:06.144202 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.151.200.44:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/6y7t.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuawAABiM"] [Sat Aug 29 05:06:06.144229 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.151.200.44:64922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/inwp.php"] [unique_id "apK9HjAh5Y1i2tUxg4HubAAABcA"] [Sat Aug 29 05:06:06.153664 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.250.41:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/fs.php"] [unique_id "apK9HiJcY4fy7tP-rU32bQAAAlU"] [Sat Aug 29 05:06:06.156942 2026] [security2:error] [pid 1018003:tid 1018165] [client 103.185.242.143:61299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9HjAh5Y1i2tUxg4HubQAABcY"] [Sat Aug 29 05:06:06.157049 2026] [security2:error] [pid 1018003:tid 1018165] [client 103.185.242.143:61299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9HjAh5Y1i2tUxg4HubQAABcY"] [Sat Aug 29 05:06:06.179213 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.250.41:60675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wp-act.php"] [unique_id "apK9HiJcY4fy7tP-rU32bwAAAkE"] [Sat Aug 29 05:06:06.180920 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.151.200.44:47330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/alog.php"] [unique_id "apK9HjAh5Y1i2tUxg4HubgAABbo"] [Sat Aug 29 05:06:06.181728 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.251.3:61654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/mga.php"] [unique_id "apK9HiJcY4fy7tP-rU32cgAAAj4"] [Sat Aug 29 05:06:06.189643 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.220.204.93:64959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/erty.php"] [unique_id "apK9HiJcY4fy7tP-rU32cwAAAo8"] [Sat Aug 29 05:06:06.223744 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.52.41.200:1739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/w.php"] [unique_id "apK9HjAh5Y1i2tUxg4HubwAABc4"] [Sat Aug 29 05:06:06.240631 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.49.130:30018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/txets.php"] [unique_id "apK9HiJcY4fy7tP-rU32dwAAAhc"] [Sat Aug 29 05:06:06.247656 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.197.61.180:17395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-blog-header.php"] [unique_id "apK9HiJcY4fy7tP-rU32eQAAAo4"] [Sat Aug 29 05:06:06.271594 2026] [security2:error] [pid 1017536:tid 1017770] [client 40.83.93.50:12428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK9HiJcY4fy7tP-rU32egAAAnw"] [Sat Aug 29 05:06:06.278525 2026] [security2:error] [pid 1017536:tid 1017685] [client 168.107.94.195:51447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9HiJcY4fy7tP-rU32ewAAAic"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:06.290002 2026] [security2:error] [pid 1018003:tid 1018150] [client 20.151.200.44:64209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/0xs.php"] [unique_id "apK9HjAh5Y1i2tUxg4HucAAABbc"] [Sat Aug 29 05:06:06.309795 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.251.3:62141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ccou.php"] [unique_id "apK9HjAh5Y1i2tUxg4HucQAABjU"] [Sat Aug 29 05:06:06.319514 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.250.41:65040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ioxi.php"] [unique_id "apK9HiJcY4fy7tP-rU32fAAAAoc"] [Sat Aug 29 05:06:06.335853 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.48.250.41:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/24.php"] [unique_id "apK9HjAh5Y1i2tUxg4HucgAABfA"] [Sat Aug 29 05:06:06.341932 2026] [security2:error] [pid 1017536:tid 1017670] [client 68.155.159.216:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9HiJcY4fy7tP-rU32fwAAAhg"] [Sat Aug 29 05:06:06.347477 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.151.200.44:46537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/adin.php"] [unique_id "apK9HjAh5Y1i2tUxg4HucwAABb0"] [Sat Aug 29 05:06:06.354734 2026] [security2:error] [pid 1017536:tid 1017734] [client 4.205.62.107:22365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/atex1.php"] [unique_id "apK9HiJcY4fy7tP-rU32gAAAAlg"] [Sat Aug 29 05:06:06.356057 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.196.209.81:5565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/panel.php"] [unique_id "apK9HiJcY4fy7tP-rU32gQAAAjI"] [Sat Aug 29 05:06:06.387657 2026] [security2:error] [pid 1018003:tid 1018170] [client 4.205.62.107:53312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/gk.php"] [unique_id "apK9HjAh5Y1i2tUxg4HudgAABcs"] [Sat Aug 29 05:06:06.418521 2026] [security2:error] [pid 1017536:tid 1017755] [client 4.205.62.107:21938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/kedi.php"] [unique_id "apK9HiJcY4fy7tP-rU32iAAAAm0"] [Sat Aug 29 05:06:06.438722 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.48.251.3:61225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/rum.or.php"] [unique_id "apK9HiJcY4fy7tP-rU32igAAAl8"] [Sat Aug 29 05:06:06.441948 2026] [security2:error] [pid 1017536:tid 1017717] [client 4.205.62.107:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ebahvhhh.php"] [unique_id "apK9HiJcY4fy7tP-rU32iwAAAkc"] [Sat Aug 29 05:06:06.468749 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.48.250.41:64288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/bootstrap.php"] [unique_id "apK9HjAh5Y1i2tUxg4HueQAABgo"] [Sat Aug 29 05:06:06.478567 2026] [security2:error] [pid 1018003:tid 1018186] [client 17.166.234.215:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/2016/08/08/chou-blanc-braise-en-cocotte/"] [unique_id "apK9HjAh5Y1i2tUxg4HuewAABds"] [Sat Aug 29 05:06:06.505262 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.151.200.44:47421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/sf9.php"] [unique_id "apK9HjAh5Y1i2tUxg4HufQAABi0"] [Sat Aug 29 05:06:06.511159 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.250.41:62480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/155.php"] [unique_id "apK9HjAh5Y1i2tUxg4HufgAABco"] [Sat Aug 29 05:06:06.521747 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.151.200.44:64876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/waf.php"] [unique_id "apK9HjAh5Y1i2tUxg4HufwAABfU"] [Sat Aug 29 05:06:06.557289 2026] [security2:error] [pid 1017536:tid 1017606] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/portal/.env"] [unique_id "apK9HiJcY4fy7tP-rU32kgACPUU"] [Sat Aug 29 05:06:06.558022 2026] [security2:error] [pid 1017536:tid 1017603] [remote 34.138.144.127:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/env.bak"] [unique_id "apK9HiJcY4fy7tP-rU32kQACPUI"] [Sat Aug 29 05:06:06.558740 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:51858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/index.php"] [unique_id "apK9HjAh5Y1i2tUxg4HugQAABbw"] [Sat Aug 29 05:06:06.560044 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.49.130:29964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/kj.php"] [unique_id "apK9HjAh5Y1i2tUxg4HugwAABf8"] [Sat Aug 29 05:06:06.567310 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.48.251.3:62128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/xmy.php"] [unique_id "apK9HjAh5Y1i2tUxg4HujAAABi4"] [Sat Aug 29 05:06:06.568320 2026] [security2:error] [pid 1017536:tid 1017595] [remote 34.138.144.127:57742] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "old.theenprogroup.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9HiJcY4fy7tP-rU32oAACazo"] [Sat Aug 29 05:06:06.575117 2026] [security2:error] [pid 1018003:tid 1018157] [client 40.83.93.50:8059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/headerg.php"] [unique_id "apK9HjAh5Y1i2tUxg4HujQAABb4"] [Sat Aug 29 05:06:06.576964 2026] [security2:error] [pid 1017536:tid 1017767] [client 34.7.40.70:14848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/img../.env"] [unique_id "apK9HiJcY4fy7tP-rU32oQAAAnk"] [Sat Aug 29 05:06:06.577412 2026] [security2:error] [pid 1017536:tid 1017765] [client 34.7.40.70:14862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/assets../.env"] [unique_id "apK9HiJcY4fy7tP-rU32ogAAAnc"] [Sat Aug 29 05:06:06.579764 2026] [security2:error] [pid 1017536:tid 1017722] [client 34.7.40.70:14868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/images../.env"] [unique_id "apK9HiJcY4fy7tP-rU32owAAAkw"] [Sat Aug 29 05:06:06.579815 2026] [security2:error] [pid 1018003:tid 1018231] [client 34.7.40.70:14882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/v2/.env"] [unique_id "apK9HjAh5Y1i2tUxg4HujgAABgc"] [Sat Aug 29 05:06:06.579886 2026] [security2:error] [pid 1018003:tid 1018174] [client 34.7.40.70:14846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/uploads../.env"] [unique_id "apK9HjAh5Y1i2tUxg4HujwAABc8"] [Sat Aug 29 05:06:06.580736 2026] [security2:error] [pid 1018003:tid 1018261] [client 34.7.40.70:14832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env"] [unique_id "apK9HjAh5Y1i2tUxg4HukAAABiU"] [Sat Aug 29 05:06:06.581159 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.220.204.93:64945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/0x.php"] [unique_id "apK9HiJcY4fy7tP-rU32pAAAAic"] [Sat Aug 29 05:06:06.581188 2026] [security2:error] [pid 1017536:tid 1017777] [client 34.7.40.70:14870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.docker/.env"] [unique_id "apK9HiJcY4fy7tP-rU32pQAAAoM"] [Sat Aug 29 05:06:06.581779 2026] [security2:error] [pid 1017536:tid 1017746] [client 34.7.40.70:14872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/v1/.env"] [unique_id "apK9HiJcY4fy7tP-rU32pgAAAmQ"] [Sat Aug 29 05:06:06.582723 2026] [security2:error] [pid 1017536:tid 1017672] [client 34.7.40.70:14888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env"] [unique_id "apK9HiJcY4fy7tP-rU32qAAAAho"] [Sat Aug 29 05:06:06.582897 2026] [cgid:error] [pid 1018003:tid 1018203] [client 34.7.40.70:14914] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:06.583466 2026] [cgid:error] [pid 1017536:tid 1017712] [client 34.7.40.70:14904] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:06.584592 2026] [security2:error] [pid 1017536:tid 1017751] [client 34.7.40.70:14944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env.old"] [unique_id "apK9HiJcY4fy7tP-rU32qQAAAmk"] [Sat Aug 29 05:06:06.586091 2026] [cgid:error] [pid 1018003:tid 1018189] [client 34.7.40.70:14918] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:06.587698 2026] [security2:error] [pid 1017536:tid 1017683] [client 34.7.40.70:14942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env.bak"] [unique_id "apK9HiJcY4fy7tP-rU32qwAAAiU"] [Sat Aug 29 05:06:06.588015 2026] [cgid:error] [pid 1017536:tid 1017782] [client 34.7.40.70:14934] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:06.590180 2026] [cgid:error] [pid 1017536:tid 1017776] [client 34.7.40.70:14982] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:06.590688 2026] [security2:error] [pid 1018003:tid 1018251] [client 34.7.40.70:15032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/config/.env"] [unique_id "apK9HjAh5Y1i2tUxg4HukwAABhs"] [Sat Aug 29 05:06:06.591127 2026] [security2:error] [pid 1017536:tid 1017705] [client 34.7.40.70:14952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env.backup"] [unique_id "apK9HiJcY4fy7tP-rU32rQAAAjs"] [Sat Aug 29 05:06:06.591908 2026] [security2:error] [pid 1017536:tid 1017745] [client 34.7.40.70:15004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/api/.env"] [unique_id "apK9HiJcY4fy7tP-rU32sQAAAmM"] [Sat Aug 29 05:06:06.592190 2026] [security2:error] [pid 1017536:tid 1017769] [client 34.7.40.70:15000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/app/.env"] [unique_id "apK9HiJcY4fy7tP-rU32sAAAAns"] [Sat Aug 29 05:06:06.592239 2026] [security2:error] [pid 1017536:tid 1017698] [client 34.7.40.70:15062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/src/.env"] [unique_id "apK9HiJcY4fy7tP-rU32rgAAAjQ"] [Sat Aug 29 05:06:06.592770 2026] [security2:error] [pid 1017536:tid 1017733] [client 34.7.40.70:15038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/laravel/.env"] [unique_id "apK9HiJcY4fy7tP-rU32sgAAAlc"] [Sat Aug 29 05:06:06.593034 2026] [security2:error] [pid 1018003:tid 1018200] [client 34.7.40.70:14980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env.swp"] [unique_id "apK9HjAh5Y1i2tUxg4HulAAABek"] [Sat Aug 29 05:06:06.593597 2026] [cgid:error] [pid 1017536:tid 1017726] [client 34.7.40.70:14968] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:06.593870 2026] [security2:error] [pid 1018003:tid 1018209] [client 34.7.40.70:15068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/frontend/.env"] [unique_id "apK9HjAh5Y1i2tUxg4HulQAABfI"] [Sat Aug 29 05:06:06.594499 2026] [security2:error] [pid 1017536:tid 1017691] [client 34.7.40.70:15042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/docker/.env"] [unique_id "apK9HiJcY4fy7tP-rU32swAAAi0"] [Sat Aug 29 05:06:06.595794 2026] [security2:error] [pid 1018003:tid 1018185] [client 34.7.40.70:15052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/core/.env"] [unique_id "apK9HjAh5Y1i2tUxg4HulgAABdo"] [Sat Aug 29 05:06:06.595866 2026] [security2:error] [pid 1017536:tid 1017725] [client 34.7.40.70:15020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/backend/.env"] [unique_id "apK9HiJcY4fy7tP-rU32tQAAAk8"] [Sat Aug 29 05:06:06.597660 2026] [cgid:error] [pid 1017536:tid 1017678] [client 34.7.40.70:14994] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:06.598797 2026] [security2:error] [pid 1017536:tid 1017678] [client 34.7.40.70:14994] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9HiJcY4fy7tP-rU32tAAAAiA"] [Sat Aug 29 05:06:06.599013 2026] [security2:error] [pid 1018003:tid 1018255] [client 34.7.40.70:15082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/web/.env"] [unique_id "apK9HjAh5Y1i2tUxg4HumQAABh8"] [Sat Aug 29 05:06:06.599039 2026] [security2:error] [pid 1018003:tid 1018218] [client 34.7.40.70:15066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/server/.env"] [unique_id "apK9HjAh5Y1i2tUxg4HulwAABfs"] [Sat Aug 29 05:06:06.601037 2026] [cgid:error] [pid 1018003:tid 1018183] [client 34.7.40.70:15030] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:06.629601 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.48.250.41:65049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/export.php"] [unique_id "apK9HiJcY4fy7tP-rU32tgAAAhg"] [Sat Aug 29 05:06:06.653826 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.151.200.44:47318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/lte7.php"] [unique_id "apK9HiJcY4fy7tP-rU32uAAAAjI"] [Sat Aug 29 05:06:06.662224 2026] [security2:error] [pid 1017536:tid 1017750] [client 168.107.94.195:51917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9HiJcY4fy7tP-rU32uQAAAmg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:06.670138 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.250.41:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/file.php"] [unique_id "apK9HiJcY4fy7tP-rU32uwAAAkQ"] [Sat Aug 29 05:06:06.679933 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.52.41.200:1230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/ahax.php"] [unique_id "apK9HjAh5Y1i2tUxg4HumwAABhM"] [Sat Aug 29 05:06:06.687014 2026] [security2:error] [pid 1017536:tid 1017784] [client 158.23.147.79:24332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/index.php"] [unique_id "apK9HiJcY4fy7tP-rU32vQAAAoo"] [Sat Aug 29 05:06:06.694955 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.251.3:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ms-edit.php"] [unique_id "apK9HiJcY4fy7tP-rU32vgAAAmA"] [Sat Aug 29 05:06:06.701350 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.151.200.44:65494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/ad1.php"] [unique_id "apK9HiJcY4fy7tP-rU32vwAAAlM"] [Sat Aug 29 05:06:06.704389 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.158.54.35:16019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/upgrade/index.php"] [unique_id "apK9HiJcY4fy7tP-rU32wAAAAmc"] [Sat Aug 29 05:06:06.717717 2026] [security2:error] [pid 1017536:tid 1017679] [client 4.205.62.107:22494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/ammika.php"] [unique_id "apK9HiJcY4fy7tP-rU32wgAAAiE"] [Sat Aug 29 05:06:06.750809 2026] [security2:error] [pid 1018003:tid 1018250] [client 68.155.159.216:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9HjAh5Y1i2tUxg4HunQAABho"] [Sat Aug 29 05:06:06.754252 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.196.209.81:20392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/pk.php"] [unique_id "apK9HjAh5Y1i2tUxg4HungAABiM"] [Sat Aug 29 05:06:06.755103 2026] [security2:error] [pid 1018003:tid 1018173] [client 68.155.159.216:14318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/nf_tracking.php"] [unique_id "apK9HjAh5Y1i2tUxg4HunwAABc4"] [Sat Aug 29 05:06:06.762584 2026] [security2:error] [pid 1017536:tid 1017704] [client 40.83.93.50:22261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/wp-settings.php"] [unique_id "apK9HiJcY4fy7tP-rU32xAAAAjo"] [Sat Aug 29 05:06:06.768122 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.48.250.41:65063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/gk.php"] [unique_id "apK9HiJcY4fy7tP-rU32xQAAAo8"] [Sat Aug 29 05:06:06.771686 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.220.204.93:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/66.php"] [unique_id "apK9HiJcY4fy7tP-rU32xgAAAnI"] [Sat Aug 29 05:06:06.794407 2026] [security2:error] [pid 1017536:tid 1017768] [client 20.151.200.44:64856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/bnnof6.php"] [unique_id "apK9HiJcY4fy7tP-rU32yAAAAno"] [Sat Aug 29 05:06:06.813955 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.151.200.44:46614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/tanjiro.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuowAABb0"] [Sat Aug 29 05:06:06.817053 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.250.41:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9HiJcY4fy7tP-rU32ywAAAnc"] [Sat Aug 29 05:06:06.823393 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.48.251.3:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/sys.php"] [unique_id "apK9HjAh5Y1i2tUxg4HupAAABhk"] [Sat Aug 29 05:06:06.829485 2026] [security2:error] [pid 1017536:tid 1017746] [client 4.205.62.107:55980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wsws.php"] [unique_id "apK9HiJcY4fy7tP-rU32zAAAAmQ"] [Sat Aug 29 05:06:06.839169 2026] [security2:error] [pid 1017536:tid 1017745] [client 158.23.147.79:63839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9HiJcY4fy7tP-rU32zgAAAmM"] [Sat Aug 29 05:06:06.860244 2026] [security2:error] [pid 1017536:tid 1017691] [client 68.155.159.216:18207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/file17.php"] [unique_id "apK9HiJcY4fy7tP-rU320AAAAi0"] [Sat Aug 29 05:06:06.878778 2026] [security2:error] [pid 1017536:tid 1017761] [client 68.155.159.216:52762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9HiJcY4fy7tP-rU320QAAAnM"] [Sat Aug 29 05:06:06.880498 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.147.79:48229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuqAAABhY"] [Sat Aug 29 05:06:06.891446 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.147.79:30599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9HiJcY4fy7tP-rU320gAAApA"] [Sat Aug 29 05:06:06.900783 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.250.41:65107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/logs1.php"] [unique_id "apK9HiJcY4fy7tP-rU321AAAAlY"] [Sat Aug 29 05:06:06.945151 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.147.79:32642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/file.php"] [unique_id "apK9HiJcY4fy7tP-rU321gAAAmc"] [Sat Aug 29 05:06:06.947849 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.151.200.44:64846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/1vbqo.php"] [unique_id "apK9HiJcY4fy7tP-rU321wAAAjk"] [Sat Aug 29 05:06:06.952819 2026] [security2:error] [pid 1017536:tid 1017737] [client 68.155.159.216:24550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9HiJcY4fy7tP-rU322QAAAls"] [Sat Aug 29 05:06:06.954420 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.48.251.3:62125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/phpsysinfo.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuqQAABdw"] [Sat Aug 29 05:06:06.960256 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.197.61.180:5848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-blogs.php"] [unique_id "apK9HjAh5Y1i2tUxg4HuqgAABgE"] [Sat Aug 29 05:06:06.962557 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.250.41:60729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/06.php"] [unique_id "apK9HiJcY4fy7tP-rU322gAAAj4"] [Sat Aug 29 05:06:06.973509 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.151.200.44:47329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/Rk41.php"] [unique_id "apK9HiJcY4fy7tP-rU323QAAAk4"] [Sat Aug 29 05:06:07.001753 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.220.204.93:64926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/f35.php"] [unique_id "apK9HyJcY4fy7tP-rU324AAAAow"] [Sat Aug 29 05:06:07.022403 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.151.200.44:64873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/ah24.php"] [unique_id "apK9HyJcY4fy7tP-rU325AAAApM"] [Sat Aug 29 05:06:07.043242 2026] [security2:error] [pid 1017536:tid 1017685] [client 168.107.94.195:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9HyJcY4fy7tP-rU326AAAAic"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:07.054973 2026] [security2:error] [pid 1017536:tid 1017670] [client 40.83.93.50:8051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/meta.php"] [unique_id "apK9HyJcY4fy7tP-rU327AAAAhg"] [Sat Aug 29 05:06:07.085783 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.251.3:61194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/sgd.php"] [unique_id "apK9HyJcY4fy7tP-rU328AAAAiU"] [Sat Aug 29 05:06:07.092685 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.251.3:33342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/bootstrap.php"] [unique_id "apK9HzAh5Y1i2tUxg4HurQAABcg"] [Sat Aug 29 05:06:07.100335 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.48.250.41:65126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/inege.php"] [unique_id "apK9HzAh5Y1i2tUxg4HurgAABjY"] [Sat Aug 29 05:06:07.109098 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.151.200.44:47386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/7logs.php"] [unique_id "apK9HzAh5Y1i2tUxg4HurwAABjQ"] [Sat Aug 29 05:06:07.120146 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.250.41:60727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/class.php"] [unique_id "apK9HyJcY4fy7tP-rU329QAAAlc"] [Sat Aug 29 05:06:07.120580 2026] [security2:error] [pid 1017536:tid 1017726] [client 68.155.159.216:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9HyJcY4fy7tP-rU329gAAAlA"] [Sat Aug 29 05:06:07.122684 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.18.15:7012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/goods.php"] [unique_id "apK9HyJcY4fy7tP-rU32-AAAAi0"] [Sat Aug 29 05:06:07.137072 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.52.41.200:1784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/shell.php"] [unique_id "apK9HyJcY4fy7tP-rU32-wAAAjo"] [Sat Aug 29 05:06:07.146738 2026] [security2:error] [pid 1017536:tid 1017681] [client 158.158.54.35:8959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "apK9HyJcY4fy7tP-rU32_gAAAiM"] [Sat Aug 29 05:06:07.150250 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.196.209.81:15091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK9HyJcY4fy7tP-rU32_wAAAj0"] [Sat Aug 29 05:06:07.154134 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.151.200.44:65474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/ztv.php"] [unique_id "apK9HzAh5Y1i2tUxg4HusQAABeE"] [Sat Aug 29 05:06:07.157481 2026] [security2:error] [pid 1018003:tid 1018078] [remote 74.7.227.189:45882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pinnacleforms.com"] [uri "/OeCustInfo.php"] [unique_id "apK9HzAh5Y1i2tUxg4HusgAGAjk"], referer: https://mail.pinnacleforms.com/ [Sat Aug 29 05:06:07.158027 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.18.15:23360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ws55.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuswAABbk"] [Sat Aug 29 05:06:07.170715 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.151.200.44:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/h02ugyh.php"] [unique_id "apK9HzAh5Y1i2tUxg4HutQAABgc"] [Sat Aug 29 05:06:07.172096 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:50074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9HzAh5Y1i2tUxg4HutwAABc8"] [Sat Aug 29 05:06:07.180710 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.220.204.93:64326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wen.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuuAAABd4"] [Sat Aug 29 05:06:07.195316 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.147.79:30645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/content.php"] [unique_id "apK9HyJcY4fy7tP-rU33AQAAAlg"] [Sat Aug 29 05:06:07.215763 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.18.15:13151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/indo.php"] [unique_id "apK9HyJcY4fy7tP-rU33BAAAApA"] [Sat Aug 29 05:06:07.218497 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.251.3:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/fleen.php"] [unique_id "apK9HyJcY4fy7tP-rU33BQAAAmg"] [Sat Aug 29 05:06:07.247642 2026] [security2:error] [pid 1017536:tid 1017721] [client 4.205.62.107:61787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/classsmtps.php"] [unique_id "apK9HyJcY4fy7tP-rU33CQAAAks"] [Sat Aug 29 05:06:07.251267 2026] [security2:error] [pid 1018003:tid 1018202] [client 40.83.93.50:12426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuuwAABes"] [Sat Aug 29 05:06:07.261612 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.250.41:65034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wp-link10.php"] [unique_id "apK9HyJcY4fy7tP-rU33CwAAAj4"] [Sat Aug 29 05:06:07.285568 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.151.200.44:47340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/sf.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuvAAABcU"] [Sat Aug 29 05:06:07.289641 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.48.250.41:62569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/8.php"] [unique_id "apK9HyJcY4fy7tP-rU33DQAAApM"] [Sat Aug 29 05:06:07.291070 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.18.15:23516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/drykl.php"] [unique_id "apK9HyJcY4fy7tP-rU33DgAAAis"] [Sat Aug 29 05:06:07.315190 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.104.18.15:8136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/biufile.php"] [unique_id "apK9HyJcY4fy7tP-rU33EAAAAmI"] [Sat Aug 29 05:06:07.315607 2026] [security2:error] [pid 1017536:tid 1017703] [client 52.139.37.240:17445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/aged.php"] [unique_id "apK9HyJcY4fy7tP-rU33EQAAAjk"] [Sat Aug 29 05:06:07.347436 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.18.15:7143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/alfa.php"] [unique_id "apK9HyJcY4fy7tP-rU33EgAAAjs"] [Sat Aug 29 05:06:07.348582 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.48.251.3:62104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/upload.form.php"] [unique_id "apK9HyJcY4fy7tP-rU33EwAAAiI"] [Sat Aug 29 05:06:07.354918 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.18.15:13137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/sign.php"] [unique_id "apK9HyJcY4fy7tP-rU33FAAAAlc"] [Sat Aug 29 05:06:07.378111 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.220.204.93:64957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/inc.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuvQAABd0"] [Sat Aug 29 05:06:07.381753 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.104.18.15:36797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/ah.php"] [unique_id "apK9HyJcY4fy7tP-rU33FgAAAnI"] [Sat Aug 29 05:06:07.392129 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.151.200.44:65506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/kure.php"] [unique_id "apK9HyJcY4fy7tP-rU33FwAAApI"] [Sat Aug 29 05:06:07.422891 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.151.200.44:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/super.php"] [unique_id "apK9HyJcY4fy7tP-rU33GAAAAiE"] [Sat Aug 29 05:06:07.422911 2026] [security2:error] [pid 1017536:tid 1017737] [client 168.107.94.195:52631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9HyJcY4fy7tP-rU33GQAAAls"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:07.430105 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.250.41:65110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ww.php"] [unique_id "apK9HyJcY4fy7tP-rU33GgAAAmY"] [Sat Aug 29 05:06:07.431859 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.48.250.41:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/0x0x.php"] [unique_id "apK9HyJcY4fy7tP-rU33GwAAAik"] [Sat Aug 29 05:06:07.454397 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.49.130:51341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/wp-css.php"] [unique_id "apK9HyJcY4fy7tP-rU33HAAAAj8"] [Sat Aug 29 05:06:07.477174 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.48.251.3:62082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws_auth.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuwAAABiM"] [Sat Aug 29 05:06:07.482300 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.18.15:7070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/33.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuwQAABcQ"] [Sat Aug 29 05:06:07.485991 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.18.15:13240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wnnjpsby.php"] [unique_id "apK9HyJcY4fy7tP-rU33HQAAApM"] [Sat Aug 29 05:06:07.491701 2026] [security2:error] [pid 1017536:tid 1017770] [client 4.205.62.107:22486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/product.php"] [unique_id "apK9HyJcY4fy7tP-rU33HgAAAnw"] [Sat Aug 29 05:06:07.514515 2026] [security2:error] [pid 1017536:tid 1017768] [client 52.139.37.240:17441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/essexec.php"] [unique_id "apK9HyJcY4fy7tP-rU33IAAAAno"] [Sat Aug 29 05:06:07.518550 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.18.15:23448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/backup.php"] [unique_id "apK9HyJcY4fy7tP-rU33IQAAAhs"] [Sat Aug 29 05:06:07.519598 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.151.200.44:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/shelp.php"] [unique_id "apK9HyJcY4fy7tP-rU33IgAAAig"] [Sat Aug 29 05:06:07.522304 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.220.204.93:64946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/6bcwiqwj.php"] [unique_id "apK9HyJcY4fy7tP-rU33IwAAAns"] [Sat Aug 29 05:06:07.524730 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.104.18.15:8067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/blacks.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuwgAABc4"] [Sat Aug 29 05:06:07.531709 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.104.18.15:36762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/ws55.php"] [unique_id "apK9HyJcY4fy7tP-rU33JAAAAkw"] [Sat Aug 29 05:06:07.536450 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.104.49.130:39050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/v2.php"] [unique_id "apK9HyJcY4fy7tP-rU33JQAAAmI"] [Sat Aug 29 05:06:07.550092 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.196.209.81:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK9HyJcY4fy7tP-rU33JgAAAko"] [Sat Aug 29 05:06:07.551170 2026] [security2:error] [pid 1017536:tid 1017548] [remote 34.138.144.127:57754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "old.theenprogroup.com"] [uri "/@fs/root/.env"] [unique_id "apK9HyJcY4fy7tP-rU33KgACOQs"] [Sat Aug 29 05:06:07.559677 2026] [security2:error] [pid 1017536:tid 1017736] [client 4.205.62.107:21620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-content/maintenance.php"] [unique_id "apK9HyJcY4fy7tP-rU33LQAAAlo"] [Sat Aug 29 05:06:07.567660 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.250.41:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/w1px.php"] [unique_id "apK9HyJcY4fy7tP-rU33LgAAAmQ"] [Sat Aug 29 05:06:07.568527 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.151.200.44:47414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/lufix1.php"] [unique_id "apK9HyJcY4fy7tP-rU33LwAAAkI"] [Sat Aug 29 05:06:07.578695 2026] [security2:error] [pid 1017536:tid 1017683] [client 4.205.62.107:9165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/services.php"] [unique_id "apK9HyJcY4fy7tP-rU33MAAAAiU"] [Sat Aug 29 05:06:07.580805 2026] [security2:error] [pid 1018003:tid 1018257] [client 4.205.62.107:26629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/asa.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuwwAABiE"] [Sat Aug 29 05:06:07.584622 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.52.41.200:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/elp.php"] [unique_id "apK9HyJcY4fy7tP-rU33MQAAAos"] [Sat Aug 29 05:06:07.587488 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.158.54.35:16062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/gifclass.php"] [unique_id "apK9HyJcY4fy7tP-rU33MgAAAjE"] [Sat Aug 29 05:06:07.589589 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.250.41:62496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/166.php"] [unique_id "apK9HyJcY4fy7tP-rU33MwAAAlc"] [Sat Aug 29 05:06:07.607432 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.48.251.3:61676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/hiquido.com/index.php"] [unique_id "apK9HyJcY4fy7tP-rU33NAAAAoQ"] [Sat Aug 29 05:06:07.616209 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.151.200.44:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/cafe.php"] [unique_id "apK9HyJcY4fy7tP-rU33NQAAAnM"] [Sat Aug 29 05:06:07.628462 2026] [security2:error] [pid 1017536:tid 1017764] [client 40.83.93.50:7752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/dxc.php"] [unique_id "apK9HyJcY4fy7tP-rU33NwAAAnY"] [Sat Aug 29 05:06:07.632618 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.104.18.15:7031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/133.php"] [unique_id "apK9HyJcY4fy7tP-rU33OAAAAo4"] [Sat Aug 29 05:06:07.634845 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.104.18.15:13129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/gigi.php"] [unique_id "apK9HyJcY4fy7tP-rU33OQAAAok"] [Sat Aug 29 05:06:07.670815 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.220.204.93:64370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/easy.php"] [unique_id "apK9HyJcY4fy7tP-rU33OgAAAlY"] [Sat Aug 29 05:06:07.671763 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.197.61.180:5857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-comments-post.php"] [unique_id "apK9HyJcY4fy7tP-rU33OwAAAo8"] [Sat Aug 29 05:06:07.672800 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.151.200.44:65526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/13ede.php"] [unique_id "apK9HyJcY4fy7tP-rU33PAAAAkU"] [Sat Aug 29 05:06:07.681546 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.18.15:8068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/beck.php"] [unique_id "apK9HyJcY4fy7tP-rU33PgAAAkk"] [Sat Aug 29 05:06:07.687060 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.18.15:23443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/indo.php"] [unique_id "apK9HyJcY4fy7tP-rU33PwAAAmM"] [Sat Aug 29 05:06:07.700730 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.18.15:36823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/drykl.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuxgAABis"] [Sat Aug 29 05:06:07.703772 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.250.41:65038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/to.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuxwAABjU"] [Sat Aug 29 05:06:07.704674 2026] [security2:error] [pid 1017536:tid 1017717] [client 52.139.37.240:63367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/fw.php"] [unique_id "apK9HyJcY4fy7tP-rU33QQAAAkc"] [Sat Aug 29 05:06:07.720112 2026] [security2:error] [pid 1018003:tid 1018263] [client 40.83.93.50:22224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-blog-header.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuyQAABic"] [Sat Aug 29 05:06:07.732856 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.250.41:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/h2a2ck.php"] [unique_id "apK9HyJcY4fy7tP-rU33RwAAAkA"] [Sat Aug 29 05:06:07.734329 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.48.251.3:62106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ws79.php"] [unique_id "apK9HyJcY4fy7tP-rU33SAAAAio"] [Sat Aug 29 05:06:07.744070 2026] [security2:error] [pid 1017536:tid 1017687] [client 68.155.159.216:51442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9HyJcY4fy7tP-rU33SQAAAik"] [Sat Aug 29 05:06:07.747395 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.104.49.130:53657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/berlin.php"] [unique_id "apK9HyJcY4fy7tP-rU33SgAAAk4"] [Sat Aug 29 05:06:07.773802 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.18.15:7167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/sym.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuzAAABcc"] [Sat Aug 29 05:06:07.775786 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.151.200.44:46645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/hack.php"] [unique_id "apK9HyJcY4fy7tP-rU33TAAAAoE"] [Sat Aug 29 05:06:07.804224 2026] [security2:error] [pid 1017536:tid 1017693] [client 168.107.94.195:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9HyJcY4fy7tP-rU33TgAAAi8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:07.809254 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.220.204.93:64917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/fresh3.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuzQAABhk"] [Sat Aug 29 05:06:07.817079 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.18.15:13136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/info.php/new.php"] [unique_id "apK9HyJcY4fy7tP-rU33TwAAApM"] [Sat Aug 29 05:06:07.818042 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.151.200.44:64929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/k8.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuzgAABeg"] [Sat Aug 29 05:06:07.821325 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.104.18.15:23370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/sign.php"] [unique_id "apK9HzAh5Y1i2tUxg4HuzwAABcs"] [Sat Aug 29 05:06:07.833762 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.104.18.15:8014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/t3.php"] [unique_id "apK9HyJcY4fy7tP-rU33UAAAAmw"] [Sat Aug 29 05:06:07.857042 2026] [security2:error] [pid 1017536:tid 1017643] [remote 34.138.144.127:57754] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "old.theenprogroup.com"] [uri "/_image"] [unique_id "apK9HyJcY4fy7tP-rU33UQACOWo"] [Sat Aug 29 05:06:07.857174 2026] [security2:error] [pid 1018003:tid 1018205] [client 20.104.18.15:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/backup.php"] [unique_id "apK9HzAh5Y1i2tUxg4Hu0AAABe4"] [Sat Aug 29 05:06:07.858150 2026] [security2:error] [pid 1017536:tid 1017678] [client 4.205.62.107:21856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/broadcasting.php"] [unique_id "apK9HyJcY4fy7tP-rU33UgAAAiA"] [Sat Aug 29 05:06:07.861981 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.48.250.41:64328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/thui.php"] [unique_id "apK9HzAh5Y1i2tUxg4Hu0QAABdU"] [Sat Aug 29 05:06:07.862138 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.251.3:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/public/wp-blog.php"] [unique_id "apK9HyJcY4fy7tP-rU33UwAAAig"] [Sat Aug 29 05:06:07.863342 2026] [security2:error] [pid 1017536:tid 1017769] [client 68.155.159.216:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wzy.php"] [unique_id "apK9HyJcY4fy7tP-rU33VAAAAns"] [Sat Aug 29 05:06:07.873175 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.48.250.41:62477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/error_log.php"] [unique_id "apK9HzAh5Y1i2tUxg4Hu0gAABhw"] [Sat Aug 29 05:06:07.898089 2026] [security2:error] [pid 1017536:tid 1017767] [client 52.139.37.240:17456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/zwso.php"] [unique_id "apK9HyJcY4fy7tP-rU33VgAAAnk"] [Sat Aug 29 05:06:07.936675 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.151.200.44:47373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/155.php"] [unique_id "apK9HyJcY4fy7tP-rU33WAAAAjE"] [Sat Aug 29 05:06:07.943721 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.196.209.81:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/security.php"] [unique_id "apK9HyJcY4fy7tP-rU33WQAAAlU"] [Sat Aug 29 05:06:07.963222 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.18.15:6996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/8.php"] [unique_id "apK9HyJcY4fy7tP-rU33WwAAAiM"] [Sat Aug 29 05:06:07.966011 2026] [security2:error] [pid 1017536:tid 1017681] [client 4.205.62.107:56023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/localconf.php"] [unique_id "apK9HyJcY4fy7tP-rU33XQAAAiM"] [Sat Aug 29 05:06:07.966571 2026] [security2:error] [pid 1017536:tid 1017757] [client 68.155.159.216:18379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/file5.php"] [unique_id "apK9HyJcY4fy7tP-rU33XgAAAm8"] [Sat Aug 29 05:06:07.976547 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.151.200.44:64848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/eval.php"] [unique_id "apK9HyJcY4fy7tP-rU33YAAAAnY"] [Sat Aug 29 05:06:07.979077 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.23.147.79:63001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/index.php"] [unique_id "apK9HyJcY4fy7tP-rU33YQAAAo4"] [Sat Aug 29 05:06:07.984978 2026] [security2:error] [pid 1017536:tid 1017783] [client 68.155.159.216:52766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9HyJcY4fy7tP-rU33YgAAAok"] [Sat Aug 29 05:06:07.988403 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.18.15:8018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp.php"] [unique_id "apK9HyJcY4fy7tP-rU33YwAAAmg"] [Sat Aug 29 05:06:07.990116 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.251.3:61682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/php-details.php"] [unique_id "apK9HyJcY4fy7tP-rU33ZAAAAnc"] [Sat Aug 29 05:06:07.999836 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.104.18.15:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/indo.php"] [unique_id "apK9HyJcY4fy7tP-rU33ZQAAAkY"] [Sat Aug 29 05:06:08.003624 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.23.147.79:30594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9ICJcY4fy7tP-rU33ZgAAAlY"] [Sat Aug 29 05:06:08.014029 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.104.18.15:23465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wnnjpsby.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu0wAABgE"] [Sat Aug 29 05:06:08.015059 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.151.200.44:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/alog.php"] [unique_id "apK9ICJcY4fy7tP-rU33aAAAAkU"] [Sat Aug 29 05:06:08.024933 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.52.41.200:1737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/cong.php"] [unique_id "apK9ICJcY4fy7tP-rU33agAAAic"] [Sat Aug 29 05:06:08.043860 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.18.15:13279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/w.php"] [unique_id "apK9ICJcY4fy7tP-rU33bQAAAms"] [Sat Aug 29 05:06:08.044542 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.250.41:64348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/Jcrop.php"] [unique_id "apK9ICJcY4fy7tP-rU33bgAAAjw"] [Sat Aug 29 05:06:08.046640 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.250.41:62551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/403.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu1QAABco"] [Sat Aug 29 05:06:08.053078 2026] [security2:error] [pid 1017536:tid 1017743] [client 68.155.159.216:24575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/makeasmtp.php"] [unique_id "apK9ICJcY4fy7tP-rU33bwAAAmE"] [Sat Aug 29 05:06:08.053837 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.147.79:32704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/file17.php"] [unique_id "apK9ICJcY4fy7tP-rU33cAAAAk4"] [Sat Aug 29 05:06:08.069400 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.151.200.44:46624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/mcd.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu2QAABcg"] [Sat Aug 29 05:06:08.093963 2026] [security2:error] [pid 1018003:tid 1018269] [client 52.139.37.240:17408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/admin/function.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu2gAABi0"] [Sat Aug 29 05:06:08.094493 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.220.204.93:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/bgymj.php"] [unique_id "apK9ICJcY4fy7tP-rU33cwAAAj8"] [Sat Aug 29 05:06:08.103756 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.147.79:25566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu2wAABf8"] [Sat Aug 29 05:06:08.109900 2026] [security2:error] [pid 1018003:tid 1018236] [client 40.83.93.50:16615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/wp-2019.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu3AAABgw"] [Sat Aug 29 05:06:08.118225 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.251.3:62119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/routes.php"] [unique_id "apK9ICJcY4fy7tP-rU33dAAAAmw"] [Sat Aug 29 05:06:08.120929 2026] [security2:error] [pid 1017536:tid 1017678] [client 68.155.159.216:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9ICJcY4fy7tP-rU33dQAAAiA"] [Sat Aug 29 05:06:08.125887 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.18.15:7141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/goods.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu3QAABgI"] [Sat Aug 29 05:06:08.151102 2026] [security2:error] [pid 1017536:tid 1017770] [client 66.248.203.2:54442] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/page/17/"] [unique_id "apK9ICJcY4fy7tP-rU33eQAAAnw"] [Sat Aug 29 05:06:08.153415 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.18.15:36759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/sign.php"] [unique_id "apK9ICJcY4fy7tP-rU33egAAAko"] [Sat Aug 29 05:06:08.159505 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.18.15:23398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/gigi.php"] [unique_id "apK9ICJcY4fy7tP-rU33ewAAAnk"] [Sat Aug 29 05:06:08.170514 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.147.79:35834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9ICJcY4fy7tP-rU33fQAAAjs"] [Sat Aug 29 05:06:08.178060 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:8101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/abcd.php"] [unique_id "apK9ICJcY4fy7tP-rU33fgAAAh0"] [Sat Aug 29 05:06:08.179882 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.158.54.35:10742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9ICJcY4fy7tP-rU33fwAAAos"] [Sat Aug 29 05:06:08.185807 2026] [security2:error] [pid 1017536:tid 1017747] [client 168.107.94.195:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ICJcY4fy7tP-rU33gAAAAmU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:08.189144 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.18.15:13290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/x.php"] [unique_id "apK9ICJcY4fy7tP-rU33gQAAAjE"] [Sat Aug 29 05:06:08.195827 2026] [security2:error] [pid 1017536:tid 1017717] [client 40.83.93.50:5915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-blogs.php"] [unique_id "apK9ICJcY4fy7tP-rU33ggAAAkc"] [Sat Aug 29 05:06:08.243086 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.48.251.3:61668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aww.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu4wAABig"] [Sat Aug 29 05:06:08.243403 2026] [security2:error] [pid 1017536:tid 1017783] [client 68.155.159.216:16152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/content.php"] [unique_id "apK9ICJcY4fy7tP-rU33hgAAAok"] [Sat Aug 29 05:06:08.245423 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.250.41:65030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ws58.php"] [unique_id "apK9ICJcY4fy7tP-rU33iQAAAmg"] [Sat Aug 29 05:06:08.253318 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.151.200.44:46615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/waw.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu5AAABek"] [Sat Aug 29 05:06:08.254694 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.48.250.41:62556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/cytyr.php"] [unique_id "apK9ICJcY4fy7tP-rU33iwAAAoo"] [Sat Aug 29 05:06:08.257320 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.18.15:7133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ah.php"] [unique_id "apK9ICJcY4fy7tP-rU33jAAAAjI"] [Sat Aug 29 05:06:08.260828 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.151.200.44:64859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/sao.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu5QAABiw"] [Sat Aug 29 05:06:08.287210 2026] [security2:error] [pid 1017536:tid 1017715] [client 158.23.147.79:50104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9ICJcY4fy7tP-rU33jQAAAkU"] [Sat Aug 29 05:06:08.290927 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.18.15:23510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/info.php/new.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu5wAABfw"] [Sat Aug 29 05:06:08.301951 2026] [security2:error] [pid 1017536:tid 1017685] [client 158.23.147.79:30678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/goat.php"] [unique_id "apK9ICJcY4fy7tP-rU33jgAAAic"] [Sat Aug 29 05:06:08.302089 2026] [security2:error] [pid 1018003:tid 1018251] [client 52.139.37.240:17412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/zoom1.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu6AAABhs"] [Sat Aug 29 05:06:08.302643 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.104.62:43039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu6QAABh8"] [Sat Aug 29 05:06:08.315113 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.104.49.130:57481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/100.php"] [unique_id "apK9ICJcY4fy7tP-rU33kgAAAmc"] [Sat Aug 29 05:06:08.318475 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.18.15:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ssla.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu6gAABbw"] [Sat Aug 29 05:06:08.332677 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.18.15:8075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/nofile.php"] [unique_id "apK9ICJcY4fy7tP-rU33kwAAAjw"] [Sat Aug 29 05:06:08.333149 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.220.204.93:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ws69.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu6wAABcU"] [Sat Aug 29 05:06:08.334605 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.151.200.44:64927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/adin.php"] [unique_id "apK9ICJcY4fy7tP-rU33lQAAAkA"] [Sat Aug 29 05:06:08.336778 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.196.209.81:5559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9ICJcY4fy7tP-rU33lgAAAnM"] [Sat Aug 29 05:06:08.337222 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.104.104.62:10485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/msy.php"] [unique_id "apK9ICJcY4fy7tP-rU33lwAAAio"] [Sat Aug 29 05:06:08.338145 2026] [cgid:error] [pid 1017536:tid 1017619] [remote 74.7.241.131:46466] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/scottewe/public_html/404.shtml [Sat Aug 29 05:06:08.338231 2026] [security2:error] [pid 1017536:tid 1017674] [client 74.7.241.131:46466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "jof.tvy.mybluehost.me"] [uri "/404.shtml"] [unique_id "apK9ICJcY4fy7tP-rU33lAACHFI"] [Sat Aug 29 05:06:08.367365 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.48.251.3:61235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/maxro.php"] [unique_id "apK9ICJcY4fy7tP-rU33mwAAAlM"] [Sat Aug 29 05:06:08.381007 2026] [security2:error] [pid 1017536:tid 1017709] [client 4.205.62.107:64295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/cache-compat.php"] [unique_id "apK9ICJcY4fy7tP-rU33nAAAAj8"] [Sat Aug 29 05:06:08.381215 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.197.61.180:5846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-config.php"] [unique_id "apK9ICJcY4fy7tP-rU33nQAAAjQ"] [Sat Aug 29 05:06:08.381728 2026] [security2:error] [pid 1017536:tid 1017689] [client 45.205.1.124:50751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "votespring-ford.com"] [uri "/assets/plugins/file-uploader/server/php/index.php"] [unique_id "apK9ICJcY4fy7tP-rU33ngAAAis"] [Sat Aug 29 05:06:08.388928 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.104.18.15:5365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/robot.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu7gAABhM"] [Sat Aug 29 05:06:08.390168 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.104.104.62:41610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/wp-gzone.php"] [unique_id "apK9ICJcY4fy7tP-rU33oAAAAmw"] [Sat Aug 29 05:06:08.393917 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.250.41:65122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/xs.php"] [unique_id "apK9ICJcY4fy7tP-rU33oQAAAjA"] [Sat Aug 29 05:06:08.409428 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.104.18.15:7080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ws55.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu7wAABfg"] [Sat Aug 29 05:06:08.420081 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.250.41:60678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/galer.php"] [unique_id "apK9ICJcY4fy7tP-rU33ogAAAkI"] [Sat Aug 29 05:06:08.421388 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.104.62:48483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/blnux.php"] [unique_id "apK9ICJcY4fy7tP-rU33owAAAiI"] [Sat Aug 29 05:06:08.431234 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.18.15:36862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wnnjpsby.php"] [unique_id "apK9ICJcY4fy7tP-rU33pgAAAko"] [Sat Aug 29 05:06:08.436679 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.104.62:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu8QAABgM"] [Sat Aug 29 05:06:08.439187 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.151.200.44:64877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/uuu.php"] [unique_id "apK9ICJcY4fy7tP-rU33pwAAAjs"] [Sat Aug 29 05:06:08.452742 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:13128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apK9ICJcY4fy7tP-rU33qAAAAh0"] [Sat Aug 29 05:06:08.461074 2026] [security2:error] [pid 1017536:tid 1017695] [client 68.155.159.216:50345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/index.php"] [unique_id "apK9ICJcY4fy7tP-rU33qQAAAjE"] [Sat Aug 29 05:06:08.469352 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.52.41.200:1235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu8gAABfk"] [Sat Aug 29 05:06:08.470542 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.104.104.62:44544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/siln.php"] [unique_id "apK9ICJcY4fy7tP-rU33qgAAAkc"] [Sat Aug 29 05:06:08.476387 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.104.104.62:20812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/1945.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu9AAABho"] [Sat Aug 29 05:06:08.493975 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.251.3:62085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/brc.php"] [unique_id "apK9ICJcY4fy7tP-rU33rgAAAm8"] [Sat Aug 29 05:06:08.497320 2026] [security2:error] [pid 1017536:tid 1017683] [client 52.139.37.240:17465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/about.php7"] [unique_id "apK9ICJcY4fy7tP-rU33rwAAAiU"] [Sat Aug 29 05:06:08.527836 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.104.62:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/str.php"] [unique_id "apK9ICJcY4fy7tP-rU33sQAAAmg"] [Sat Aug 29 05:06:08.532073 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.250.41:65088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/zu.php"] [unique_id "apK9ICJcY4fy7tP-rU33sgAAAho"] [Sat Aug 29 05:06:08.543281 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.18.15:8025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/run.php"] [unique_id "apK9ICJcY4fy7tP-rU33swAAAjI"] [Sat Aug 29 05:06:08.543737 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.18.15:7145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/drykl.php"] [unique_id "apK9ICJcY4fy7tP-rU33tAAAAlY"] [Sat Aug 29 05:06:08.565855 2026] [security2:error] [pid 1017536:tid 1017719] [client 168.107.94.195:53426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ICJcY4fy7tP-rU33tQAAAkk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:08.568439 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.151.200.44:46623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/x23.php"] [unique_id "apK9ICJcY4fy7tP-rU33tgAAAmo"] [Sat Aug 29 05:06:08.568772 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.104.104.62:23403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/fh26.php"] [unique_id "apK9ICJcY4fy7tP-rU33uAAAAhg"] [Sat Aug 29 05:06:08.573668 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.220.204.93:65000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ccs.php"] [unique_id "apK9ICJcY4fy7tP-rU33uQAAAmM"] [Sat Aug 29 05:06:08.584057 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.18.15:13132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-aothait.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu9gAABi8"] [Sat Aug 29 05:06:08.590962 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.18.15:36700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/gigi.php"] [unique_id "apK9ICJcY4fy7tP-rU33ugAAAks"] [Sat Aug 29 05:06:08.601500 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:56363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/revo.php"] [unique_id "apK9ICJcY4fy7tP-rU33uwAAAkA"] [Sat Aug 29 05:06:08.601837 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:10481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/f-401.php"] [unique_id "apK9ICJcY4fy7tP-rU33vAAAAnM"] [Sat Aug 29 05:06:08.605331 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.151.200.44:64258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/private.php"] [unique_id "apK9ICJcY4fy7tP-rU33vQAAAkM"] [Sat Aug 29 05:06:08.621429 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.250.41:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/baixy.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu9wAABcE"] [Sat Aug 29 05:06:08.621497 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.48.251.3:62111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/vx.php"] [unique_id "apK9ICJcY4fy7tP-rU33vgAAAik"] [Sat Aug 29 05:06:08.625312 2026] [security2:error] [pid 1017536:tid 1017704] [client 158.158.54.35:19490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/css/index.php"] [unique_id "apK9ICJcY4fy7tP-rU33vwAAAjo"] [Sat Aug 29 05:06:08.626236 2026] [security2:error] [pid 1017536:tid 1017767] [client 40.83.93.50:14438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/menu.php"] [unique_id "apK9ICJcY4fy7tP-rU33wAAAAnk"] [Sat Aug 29 05:06:08.628886 2026] [security2:error] [pid 1018003:tid 1018196] [client 4.205.62.107:22259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/public/wp-blog.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu-AAABeU"] [Sat Aug 29 05:06:08.636091 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.104.62:43030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/baee.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu-QAABis"] [Sat Aug 29 05:06:08.663172 2026] [core:error] [pid 1017536:tid 1017792] [client 20.104.18.15:23507] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:08.663187 2026] [core:error] [pid 1017536:tid 1017792] [client 20.104.18.15:23507] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:08.667679 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.104.62:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/mega.php"] [unique_id "apK9ICJcY4fy7tP-rU33wgAAAhY"] [Sat Aug 29 05:06:08.672714 2026] [security2:error] [pid 1018003:tid 1018263] [client 20.104.18.15:7068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/backup.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu-gAABic"] [Sat Aug 29 05:06:08.689444 2026] [security2:error] [pid 1018003:tid 1018257] [client 52.139.37.240:17459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/cron.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu_QAABiE"] [Sat Aug 29 05:06:08.697796 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.250.41:64293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/lanka.php"] [unique_id "apK9ICJcY4fy7tP-rU33wwAAAjQ"] [Sat Aug 29 05:06:08.709219 2026] [security2:error] [pid 1017536:tid 1017784] [client 40.83.93.50:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-comments-post.php"] [unique_id "apK9ICJcY4fy7tP-rU33xAAAAoo"] [Sat Aug 29 05:06:08.709910 2026] [security2:error] [pid 1017536:tid 1017689] [client 4.205.62.107:22493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/upload.form.php"] [unique_id "apK9ICJcY4fy7tP-rU33xQAAAis"] [Sat Aug 29 05:06:08.713654 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.220.204.93:63853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/mar.php"] [unique_id "apK9ICJcY4fy7tP-rU33xgAAAmw"] [Sat Aug 29 05:06:08.719516 2026] [security2:error] [pid 1018003:tid 1018252] [client 4.205.62.107:26632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/radio.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu_gAABhw"] [Sat Aug 29 05:06:08.719840 2026] [security2:error] [pid 1017536:tid 1017678] [client 4.205.62.107:53404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/log.php"] [unique_id "apK9ICJcY4fy7tP-rU33yAAAAiA"] [Sat Aug 29 05:06:08.720144 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.18.15:13147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-includes/index.php"] [unique_id "apK9ICJcY4fy7tP-rU33yQAAAn8"] [Sat Aug 29 05:06:08.720863 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.49.130:52340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/666.php"] [unique_id "apK9IDAh5Y1i2tUxg4Hu_wAABhY"] [Sat Aug 29 05:06:08.727453 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.104.62:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wos.php"] [unique_id "apK9ICJcY4fy7tP-rU33zAAAAkI"] [Sat Aug 29 05:06:08.733131 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.18.15:8064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/new.php"] [unique_id "apK9ICJcY4fy7tP-rU33zQAAAko"] [Sat Aug 29 05:06:08.733310 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.196.209.81:5197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/system.php"] [unique_id "apK9ICJcY4fy7tP-rU33zgAAAmI"] [Sat Aug 29 05:06:08.733467 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.104.104.62:10439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/hq.php"] [unique_id "apK9ICJcY4fy7tP-rU33zwAAAmQ"] [Sat Aug 29 05:06:08.733668 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.18.15:36769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/info.php/new.php"] [unique_id "apK9ICJcY4fy7tP-rU330AAAAjs"] [Sat Aug 29 05:06:08.736920 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.48.251.3:14045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/G-in.php"] [unique_id "apK9ICJcY4fy7tP-rU330QAAApA"] [Sat Aug 29 05:06:08.748263 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.48.251.3:62138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ty.php"] [unique_id "apK9ICJcY4fy7tP-rU330gAAAj4"] [Sat Aug 29 05:06:08.763198 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.104.18.15:23514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/w.php"] [unique_id "apK9ICJcY4fy7tP-rU330wAAAl8"] [Sat Aug 29 05:06:08.770956 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.104.18.15:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/birrs.php"] [unique_id "apK9ICJcY4fy7tP-rU331AAAAkc"] [Sat Aug 29 05:06:08.780400 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:4818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/d12.php"] [unique_id "apK9ICJcY4fy7tP-rU333AAAAiU"] [Sat Aug 29 05:06:08.805206 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.250.41:59269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ava.php"] [unique_id "apK9ICJcY4fy7tP-rU333QAAAho"] [Sat Aug 29 05:06:08.811452 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.151.200.44:47333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/ws66.php"] [unique_id "apK9ICJcY4fy7tP-rU334AAAAnc"] [Sat Aug 29 05:06:08.822222 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.104.62:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/ww3.php"] [unique_id "apK9ICJcY4fy7tP-rU334QAAAoc"] [Sat Aug 29 05:06:08.826720 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.104.62:52041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/fgd.php"] [unique_id "apK9ICJcY4fy7tP-rU334gAAAl4"] [Sat Aug 29 05:06:08.852139 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.151.200.44:64222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/sf9.php"] [unique_id "apK9ICJcY4fy7tP-rU335QAAAkk"] [Sat Aug 29 05:06:08.866464 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.104.104.62:10830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/mh.php"] [unique_id "apK9ICJcY4fy7tP-rU336AAAAlU"] [Sat Aug 29 05:06:08.868340 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.18.15:7071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/indo.php"] [unique_id "apK9IDAh5Y1i2tUxg4HvAgAABfA"] [Sat Aug 29 05:06:08.869760 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.220.204.93:64936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ccu.php"] [unique_id "apK9ICJcY4fy7tP-rU336QAAAmc"] [Sat Aug 29 05:06:08.870124 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.147.79:24491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/mah.php"] [unique_id "apK9ICJcY4fy7tP-rU336gAAAlo"] [Sat Aug 29 05:06:08.871729 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.18.15:8137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/inx.php"] [unique_id "apK9ICJcY4fy7tP-rU336wAAAks"] [Sat Aug 29 05:06:08.874930 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.251.3:61224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apK9ICJcY4fy7tP-rU337AAAAkA"] [Sat Aug 29 05:06:08.881017 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:65120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/gettest.php"] [unique_id "apK9ICJcY4fy7tP-rU337QAAAnw"] [Sat Aug 29 05:06:08.890452 2026] [security2:error] [pid 1018003:tid 1018177] [client 52.139.37.240:17435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/wp-2019.php"] [unique_id "apK9IDAh5Y1i2tUxg4HvBAAABdI"] [Sat Aug 29 05:06:08.895902 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.151.200.44:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/lfi.php"] [unique_id "apK9ICJcY4fy7tP-rU337gAAAjo"] [Sat Aug 29 05:06:08.915447 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.52.41.200:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-mail.php"] [unique_id "apK9IDAh5Y1i2tUxg4HvBQAABg4"] [Sat Aug 29 05:06:08.941254 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.104.18.15:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/file31.php"] [unique_id "apK9ICJcY4fy7tP-rU338QAAAjk"] [Sat Aug 29 05:06:08.946284 2026] [security2:error] [pid 1017536:tid 1017689] [client 168.107.94.195:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ICJcY4fy7tP-rU338gAAAis"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:08.946853 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.104.62:43046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/yyy.php"] [unique_id "apK9ICJcY4fy7tP-rU338wAAApM"] [Sat Aug 29 05:06:08.946928 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.104.104.62:40216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wso-2.5.php"] [unique_id "apK9ICJcY4fy7tP-rU339AAAAmw"] [Sat Aug 29 05:06:08.953289 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.18.15:23454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/x.php"] [unique_id "apK9ICJcY4fy7tP-rU339QAAAjA"] [Sat Aug 29 05:06:08.957067 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.49.130:47831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/new.php"] [unique_id "apK9IDAh5Y1i2tUxg4HvBwAABgw"] [Sat Aug 29 05:06:08.971349 2026] [security2:error] [pid 1018003:tid 1018150] [client 20.104.104.62:22692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/sko.php"] [unique_id "apK9IDAh5Y1i2tUxg4HvCAAABbc"] [Sat Aug 29 05:06:08.979420 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:5950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/sss.php"] [unique_id "apK9IDAh5Y1i2tUxg4HvCQAABeE"] [Sat Aug 29 05:06:08.985587 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.151.200.44:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/Cok.php"] [unique_id "apK9ICJcY4fy7tP-rU33-AAAAmI"] [Sat Aug 29 05:06:08.994373 2026] [core:error] [pid 1017536:tid 1017733] [client 74.7.244.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:08.994386 2026] [core:error] [pid 1017536:tid 1017733] [client 74.7.244.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:08.994496 2026] [security2:error] [pid 1017536:tid 1017733] [client 74.7.244.18:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK9ICJcY4fy7tP-rU33-QAAAlc"] [Sat Aug 29 05:06:08.994683 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.104.104.62:44579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/f2r4.php"] [unique_id "apK9ICJcY4fy7tP-rU33-gAAAmQ"] [Sat Aug 29 05:06:08.999173 2026] [security2:error] [pid 1018003:tid 1018227] [client 68.155.159.216:14235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9IDAh5Y1i2tUxg4HvCwAABgQ"] [Sat Aug 29 05:06:08.999606 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.18.15:7031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/sign.php"] [unique_id "apK9ICJcY4fy7tP-rU33-wAAAos"] [Sat Aug 29 05:06:09.001423 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.48.251.3:62088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/phpi.php"] [unique_id "apK9ISJcY4fy7tP-rU33_AAAAh0"] [Sat Aug 29 05:06:09.005782 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.104.18.15:8170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/vpn.php"] [unique_id "apK9ISJcY4fy7tP-rU33_QAAAkw"] [Sat Aug 29 05:06:09.006739 2026] [security2:error] [pid 1017536:tid 1017747] [client 4.205.62.107:22217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/aws_config.php"] [unique_id "apK9ISJcY4fy7tP-rU33_gAAAmU"] [Sat Aug 29 05:06:09.008690 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.250.41:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/gdn.php"] [unique_id "apK9ISJcY4fy7tP-rU33_wAAAjE"] [Sat Aug 29 05:06:09.018537 2026] [security2:error] [pid 1017536:tid 1017777] [client 74.7.244.18:49062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "apK9ICJcY4fy7tP-rU333gACgyE"] [Sat Aug 29 05:06:09.019623 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.220.204.93:64955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ak.php"] [unique_id "apK9ISJcY4fy7tP-rU34AwAAAiU"] [Sat Aug 29 05:06:09.020695 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.104.104.62:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/inject.php"] [unique_id "apK9ISJcY4fy7tP-rU34BAAAAo4"] [Sat Aug 29 05:06:09.036177 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.151.200.44:64854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/quoys.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvDAAABgI"] [Sat Aug 29 05:06:09.054047 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.23.147.79:48176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/login.php"] [unique_id "apK9ISJcY4fy7tP-rU34BQAAAjI"] [Sat Aug 29 05:06:09.068069 2026] [security2:error] [pid 1017536:tid 1017679] [client 158.23.147.79:37806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9ISJcY4fy7tP-rU34BgAAAiE"] [Sat Aug 29 05:06:09.068827 2026] [security2:error] [pid 1018003:tid 1018197] [client 158.158.54.35:12811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-cron.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvDQAABeY"] [Sat Aug 29 05:06:09.073042 2026] [security2:error] [pid 1017536:tid 1017715] [client 68.155.159.216:18177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/file88.php"] [unique_id "apK9ISJcY4fy7tP-rU34CAAAAkU"] [Sat Aug 29 05:06:09.077597 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.197.61.180:16342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-configs.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvDgAABjE"] [Sat Aug 29 05:06:09.080347 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.104.104.62:56331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/bgymj.php"] [unique_id "apK9ISJcY4fy7tP-rU34CgAAAic"] [Sat Aug 29 05:06:09.083236 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.23.147.79:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvDwAABdw"] [Sat Aug 29 05:06:09.085769 2026] [security2:error] [pid 1017536:tid 1017768] [client 52.139.37.240:17409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/gecko-new.php"] [unique_id "apK9ISJcY4fy7tP-rU34CwAAAno"] [Sat Aug 29 05:06:09.089136 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.104.18.15:13221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/dk.php"] [unique_id "apK9ISJcY4fy7tP-rU34DAAAAhg"] [Sat Aug 29 05:06:09.100028 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.250.41:65093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/35.php"] [unique_id "apK9ISJcY4fy7tP-rU34DQAAAlU"] [Sat Aug 29 05:06:09.102832 2026] [security2:error] [pid 1017536:tid 1017736] [client 4.205.62.107:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/bengi.php"] [unique_id "apK9ISJcY4fy7tP-rU34DwAAAlo"] [Sat Aug 29 05:06:09.111513 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.104.62:46007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/zoz.php"] [unique_id "apK9ISJcY4fy7tP-rU34EAAAAjw"] [Sat Aug 29 05:06:09.112210 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.18.15:23415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ssla.php"] [unique_id "apK9ISJcY4fy7tP-rU34EQAAAnM"] [Sat Aug 29 05:06:09.118519 2026] [security2:error] [pid 1018003:tid 1018264] [client 158.23.147.79:30703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvEAAABig"] [Sat Aug 29 05:06:09.125311 2026] [security2:error] [pid 1017536:tid 1017712] [client 40.83.93.50:8019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/alfa.php"] [unique_id "apK9ISJcY4fy7tP-rU34EgAAAkI"] [Sat Aug 29 05:06:09.127148 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.48.251.3:61694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvEQAABek"] [Sat Aug 29 05:06:09.128583 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.196.209.81:23673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/test.php"] [unique_id "apK9ISJcY4fy7tP-rU34FAAAAjs"] [Sat Aug 29 05:06:09.133194 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.104.104.62:10472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/sadis.php"] [unique_id "apK9ISJcY4fy7tP-rU34FQAAAjo"] [Sat Aug 29 05:06:09.161317 2026] [security2:error] [pid 1018003:tid 1018185] [client 68.155.159.216:24458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvEwAABdo"] [Sat Aug 29 05:06:09.173394 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.104.18.15:7009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wnnjpsby.php"] [unique_id "apK9ISJcY4fy7tP-rU34GgAAAmw"] [Sat Aug 29 05:06:09.176847 2026] [security2:error] [pid 1018003:tid 1018251] [client 158.23.147.79:32705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/file5.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvFAAABhs"] [Sat Aug 29 05:06:09.177712 2026] [security2:error] [pid 1017536:tid 1017707] [client 40.83.93.50:12471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-config.php"] [unique_id "apK9ISJcY4fy7tP-rU34HAAAAj0"] [Sat Aug 29 05:06:09.179703 2026] [core:error] [pid 1017536:tid 1017750] [client 20.104.18.15:36751] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:09.179715 2026] [core:error] [pid 1017536:tid 1017750] [client 20.104.18.15:36751] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:09.203849 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.18.15:57176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apK9ISJcY4fy7tP-rU34HgAAAko"] [Sat Aug 29 05:06:09.208548 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:8158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/shiny.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvFQAABcA"] [Sat Aug 29 05:06:09.210556 2026] [security2:error] [pid 1017536:tid 1017744] [client 158.23.147.79:25514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/admin.php"] [unique_id "apK9ISJcY4fy7tP-rU34HwAAAmI"] [Sat Aug 29 05:06:09.212448 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.151.200.44:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/lte7.php"] [unique_id "apK9ISJcY4fy7tP-rU34IAAAAos"] [Sat Aug 29 05:06:09.213690 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.104.62:4851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/fh26.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvFgAABcU"] [Sat Aug 29 05:06:09.223521 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.151.200.44:64313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/vbbn.php"] [unique_id "apK9ISJcY4fy7tP-rU34IgAAAh0"] [Sat Aug 29 05:06:09.228813 2026] [security2:error] [pid 1017536:tid 1017708] [client 68.155.159.216:51537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9ISJcY4fy7tP-rU34IwAAAj4"] [Sat Aug 29 05:06:09.229648 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.104.18.15:13247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/ta.php"] [unique_id "apK9ISJcY4fy7tP-rU34JAAAAkw"] [Sat Aug 29 05:06:09.234304 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.220.204.93:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/lib.php"] [unique_id "apK9ISJcY4fy7tP-rU34KAAAAmU"] [Sat Aug 29 05:06:09.238640 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.250.41:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/f2.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvFwAABcI"] [Sat Aug 29 05:06:09.243414 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.104.18.15:23446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apK9ISJcY4fy7tP-rU34KwAAAnI"] [Sat Aug 29 05:06:09.247074 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.18.15:36842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/w.php"] [unique_id "apK9ISJcY4fy7tP-rU34LAAAAlY"] [Sat Aug 29 05:06:09.248002 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.151.200.44:47305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/X7T6.php"] [unique_id "apK9ISJcY4fy7tP-rU34LQAAAnY"] [Sat Aug 29 05:06:09.254530 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.104.62:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/mmm.php"] [unique_id "apK9ISJcY4fy7tP-rU34LgAAAoM"] [Sat Aug 29 05:06:09.255373 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.48.251.3:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/myfile.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvGQAABhU"] [Sat Aug 29 05:06:09.266242 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.104.62:64706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/ngacir88.php"] [unique_id "apK9ISJcY4fy7tP-rU34LwAAAjI"] [Sat Aug 29 05:06:09.267768 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.104.104.62:44588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/xcre1.php"] [unique_id "apK9ISJcY4fy7tP-rU34MAAAAho"] [Sat Aug 29 05:06:09.276165 2026] [security2:error] [pid 1017536:tid 1017733] [client 52.139.37.240:17447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/add_actualites.php"] [unique_id "apK9ISJcY4fy7tP-rU34MQAAAlc"] [Sat Aug 29 05:06:09.277780 2026] [security2:error] [pid 1017536:tid 1017751] [client 158.23.147.79:35779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/chosen.php"] [unique_id "apK9ISJcY4fy7tP-rU34MgAAAmk"] [Sat Aug 29 05:06:09.321312 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.104.18.15:6978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/gigi.php"] [unique_id "apK9ISJcY4fy7tP-rU34NAAAAlU"] [Sat Aug 29 05:06:09.326037 2026] [security2:error] [pid 1017536:tid 1017736] [client 168.107.94.195:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ISJcY4fy7tP-rU34NQAAAlo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:09.346392 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.104.62:36949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/mga.php"] [unique_id "apK9ISJcY4fy7tP-rU34NwAAAjs"] [Sat Aug 29 05:06:09.350005 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.251.3:13959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/apikeys.php"] [unique_id "apK9ISJcY4fy7tP-rU34OAAAAjo"] [Sat Aug 29 05:06:09.352172 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.104.104.62:4815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/fgd.php"] [unique_id "apK9ISJcY4fy7tP-rU34OQAAAjo"] [Sat Aug 29 05:06:09.360404 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.104.62:48669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/pentest.php"] [unique_id "apK9ISJcY4fy7tP-rU34OwAAApI"] [Sat Aug 29 05:06:09.371685 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.18.15:23388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-aothait.php"] [unique_id "apK9ISJcY4fy7tP-rU34PAAAAhY"] [Sat Aug 29 05:06:09.378819 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.52.41.200:1728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvHAAABio"] [Sat Aug 29 05:06:09.381082 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.151.200.44:64261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/rfi.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvHQAABbo"] [Sat Aug 29 05:06:09.381760 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.18.15:8080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/goods.php"] [unique_id "apK9ISJcY4fy7tP-rU34QAAAAj8"] [Sat Aug 29 05:06:09.383594 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.48.251.3:62112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/lm15.php"] [unique_id "apK9ISJcY4fy7tP-rU34QQAAAlM"] [Sat Aug 29 05:06:09.388349 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.151.200.44:47347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/see.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvHwAABd0"] [Sat Aug 29 05:06:09.391798 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.18.15:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/bo.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvIAAABiU"] [Sat Aug 29 05:06:09.396164 2026] [security2:error] [pid 1018003:tid 1018151] [client 158.23.147.79:50136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvIQAABbg"] [Sat Aug 29 05:06:09.399798 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.104.62:22677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/advanced.php"] [unique_id "apK9ISJcY4fy7tP-rU34QwAAAkE"] [Sat Aug 29 05:06:09.409691 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.18.15:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/x.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvIgAABhI"] [Sat Aug 29 05:06:09.412246 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.104.62:44550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/motu.php"] [unique_id "apK9ISJcY4fy7tP-rU34RQAAApM"] [Sat Aug 29 05:06:09.413907 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.49.130:30059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/memberfuns.php"] [unique_id "apK9ISJcY4fy7tP-rU34RgAAAiA"] [Sat Aug 29 05:06:09.432366 2026] [security2:error] [pid 1018003:tid 1018209] [client 158.23.147.79:30718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvIwAABfI"] [Sat Aug 29 05:06:09.433565 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.220.204.93:64934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wp-style.php"] [unique_id "apK9ISJcY4fy7tP-rU34RwAAAk0"] [Sat Aug 29 05:06:09.456436 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.104.18.15:5402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/xmini4.php"] [unique_id "apK9ISJcY4fy7tP-rU34SAAAAj4"] [Sat Aug 29 05:06:09.470835 2026] [security2:error] [pid 1018003:tid 1018216] [client 52.139.37.240:17422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/browse.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvJAAABfk"] [Sat Aug 29 05:06:09.472958 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.104.18.15:7006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/info.php/new.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvJQAABfY"] [Sat Aug 29 05:06:09.485248 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.104.62:40234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/&heker!.php"] [unique_id "apK9ISJcY4fy7tP-rU34SgAAAoM"] [Sat Aug 29 05:06:09.489074 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.104.104.62:52041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/inwp.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvJgAABiM"] [Sat Aug 29 05:06:09.493392 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.104.49.130:46081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/red.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvJwAABd8"] [Sat Aug 29 05:06:09.504602 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/inject.php"] [unique_id "apK9ISJcY4fy7tP-rU34SwAAAiU"] [Sat Aug 29 05:06:09.510729 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.251.3:61238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/test.config.php"] [unique_id "apK9ISJcY4fy7tP-rU34TAAAAo4"] [Sat Aug 29 05:06:09.513332 2026] [security2:error] [pid 1017536:tid 1017742] [client 158.158.54.35:10702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-block.php"] [unique_id "apK9ISJcY4fy7tP-rU34TQAAAmA"] [Sat Aug 29 05:06:09.518948 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.18.15:8048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/alfa.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvKAAABis"] [Sat Aug 29 05:06:09.519524 2026] [security2:error] [pid 1018003:tid 1018277] [client 4.205.62.107:64233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/aws_keys.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvKQAABjU"] [Sat Aug 29 05:06:09.538397 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.18.15:13255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/44.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvKwAABb0"] [Sat Aug 29 05:06:09.539236 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.104.62:22686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/blox.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvLAAABiA"] [Sat Aug 29 05:06:09.544104 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.151.200.44:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/horeg.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvLQAABcc"] [Sat Aug 29 05:06:09.544647 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.104.104.62:10493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/wefile.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvLgAABhk"] [Sat Aug 29 05:06:09.556938 2026] [security2:error] [pid 1018003:tid 1018205] [client 20.104.18.15:36744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/ssla.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvLwAABe4"] [Sat Aug 29 05:06:09.564475 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.151.200.44:64276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/tanjiro.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvMAAABdU"] [Sat Aug 29 05:06:09.564877 2026] [security2:error] [pid 1018003:tid 1018252] [client 68.155.159.216:50201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/about/function.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvMQAABhw"] [Sat Aug 29 05:06:09.575151 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.104.18.15:23500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-includes/index.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvMgAABjI"] [Sat Aug 29 05:06:09.582260 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.151.200.44:64908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/tajj.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvMwAABds"] [Sat Aug 29 05:06:09.601473 2026] [security2:error] [pid 1017536:tid 1017744] [client 40.83.93.50:16618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK9ISJcY4fy7tP-rU34UQAAAmI"] [Sat Aug 29 05:06:09.614375 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.18.15:5329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/gulu.php"] [unique_id "apK9ISJcY4fy7tP-rU34UgAAAhc"] [Sat Aug 29 05:06:09.622293 2026] [security2:error] [pid 1017536:tid 1017674] [client 57.141.14.28:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/"] [unique_id "apK9ISJcY4fy7tP-rU34VAAAAhw"] [Sat Aug 29 05:06:09.632696 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.220.204.93:65010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/browse.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvOQAABf8"] [Sat Aug 29 05:06:09.637278 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.48.251.3:62084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/gecko-litespeed.php"] [unique_id "apK9ISJcY4fy7tP-rU34VgAAAiY"] [Sat Aug 29 05:06:09.648782 2026] [security2:error] [pid 1018003:tid 1018173] [client 40.83.93.50:12473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-configs.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvOgAABc4"] [Sat Aug 29 05:06:09.654432 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.104.18.15:8116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/33.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvOwAABgQ"] [Sat Aug 29 05:06:09.658606 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.196.209.81:5238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/user/f35.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvPAAABbk"] [Sat Aug 29 05:06:09.674190 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.151.200.44:45990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/basic.php"] [unique_id "apK9ISJcY4fy7tP-rU34WAAAAhg"] [Sat Aug 29 05:06:09.674536 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.104.62:41650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/kcs.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvPQAABew"] [Sat Aug 29 05:06:09.677254 2026] [security2:error] [pid 1017536:tid 1017713] [client 52.139.37.240:18127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/contentloader1.php"] [unique_id "apK9ISJcY4fy7tP-rU34WQAAAkM"] [Sat Aug 29 05:06:09.678098 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.104.104.62:44590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/EM.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvPgAABeY"] [Sat Aug 29 05:06:09.683658 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.104.18.15:13120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/h2.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvPwAABgE"] [Sat Aug 29 05:06:09.686058 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.104.104.62:43053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/mga.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvQAAABjE"] [Sat Aug 29 05:06:09.704729 2026] [security2:error] [pid 1017536:tid 1017731] [client 168.107.94.195:54677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ISJcY4fy7tP-rU34XAAAAlU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:09.706939 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.104.18.15:23541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/file31.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvQQAABig"] [Sat Aug 29 05:06:09.711000 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.104.62:23395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/ad1.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvQgAABek"] [Sat Aug 29 05:06:09.711484 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.151.200.44:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/grsiuk.php"] [unique_id "apK9ISJcY4fy7tP-rU34XgAAAms"] [Sat Aug 29 05:06:09.720974 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.104.62:47611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/shellv3.php"] [unique_id "apK9ISJcY4fy7tP-rU34YQAAAik"] [Sat Aug 29 05:06:09.730280 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.18.15:36821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apK9ISJcY4fy7tP-rU34YgAAAjw"] [Sat Aug 29 05:06:09.764746 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.48.251.3:61664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/goods.php"] [unique_id "apK9ISJcY4fy7tP-rU34ZQAAAns"] [Sat Aug 29 05:06:09.769055 2026] [security2:error] [pid 1017536:tid 1017704] [client 4.205.62.107:22344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/test.php"] [unique_id "apK9ISJcY4fy7tP-rU34ZgAAAjo"] [Sat Aug 29 05:06:09.786197 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.18.15:5319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/replace.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvRwAABiY"] [Sat Aug 29 05:06:09.796629 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.197.61.180:16995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-conflg.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvSAAABhg"] [Sat Aug 29 05:06:09.798772 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.104.18.15:8070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/133.php"] [unique_id "apK9ISJcY4fy7tP-rU34agAAAhY"] [Sat Aug 29 05:06:09.802262 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.151.200.44:47325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/monso.php"] [unique_id "apK9ISJcY4fy7tP-rU34awAAAlM"] [Sat Aug 29 05:06:09.808418 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.104.104.62:10487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/ca4.php"] [unique_id "apK9ISJcY4fy7tP-rU34bAAAAoE"] [Sat Aug 29 05:06:09.816349 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.18.15:13149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apK9ISJcY4fy7tP-rU34bQAAAnk"] [Sat Aug 29 05:06:09.818919 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.104.62:43016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/inwp.php"] [unique_id "apK9ISJcY4fy7tP-rU34bgAAAkE"] [Sat Aug 29 05:06:09.820336 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.104.104.62:22661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/wsz.php"] [unique_id "apK9ISJcY4fy7tP-rU34bwAAAjk"] [Sat Aug 29 05:06:09.833109 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.52.41.200:1765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "apK9ISJcY4fy7tP-rU34cAAAAoY"] [Sat Aug 29 05:06:09.838506 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.18.15:23444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/dk.php"] [unique_id "apK9ISJcY4fy7tP-rU34cQAAAis"] [Sat Aug 29 05:06:09.847236 2026] [security2:error] [pid 1017536:tid 1017754] [client 4.205.62.107:22245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/v3.php"] [unique_id "apK9ISJcY4fy7tP-rU34cgAAAmw"] [Sat Aug 29 05:06:09.856659 2026] [security2:error] [pid 1018003:tid 1018266] [client 4.205.62.107:65517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/xa.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvSwAABio"] [Sat Aug 29 05:06:09.857071 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.151.200.44:64926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/Rk41.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvTAAABbo"] [Sat Aug 29 05:06:09.863633 2026] [security2:error] [pid 1018003:tid 1018278] [client 20.151.200.44:64891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/ahy66.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvTgAABjY"] [Sat Aug 29 05:06:09.868698 2026] [security2:error] [pid 1017536:tid 1017694] [client 4.205.62.107:53347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/btx25.php"] [unique_id "apK9ISJcY4fy7tP-rU34cwAAAjA"] [Sat Aug 29 05:06:09.871993 2026] [security2:error] [pid 1017536:tid 1017734] [client 52.139.37.240:63363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/upfile.php"] [unique_id "apK9ISJcY4fy7tP-rU34dAAAAlg"] [Sat Aug 29 05:06:09.877231 2026] [security2:error] [pid 1018003:tid 1018226] [client 68.155.159.216:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvTwAABgM"] [Sat Aug 29 05:06:09.893096 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.48.251.3:62086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/loxi-o.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvUAAABd0"] [Sat Aug 29 05:06:09.901079 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.18.15:36718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-aothait.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvUQAABiU"] [Sat Aug 29 05:06:09.909886 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.104.18.15:6994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/w.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvUgAABbg"] [Sat Aug 29 05:06:09.912862 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.104.62:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/1vbqo.php"] [unique_id "apK9ISJcY4fy7tP-rU34dQAAAk0"] [Sat Aug 29 05:06:09.914729 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.220.204.93:64341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/zoo.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvUwAABhI"] [Sat Aug 29 05:06:09.929466 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.104.18.15:5344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/c4.php"] [unique_id "apK9ISJcY4fy7tP-rU34dgAAAj4"] [Sat Aug 29 05:06:09.936779 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.104.62:10866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/x0x.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvVwAABdg"] [Sat Aug 29 05:06:09.941500 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.104.18.15:8069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/sym.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvWAAABd8"] [Sat Aug 29 05:06:09.944432 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.104.104.62:48691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/6y7t.php"] [unique_id "apK9ISJcY4fy7tP-rU34dwAAAmU"] [Sat Aug 29 05:06:09.955126 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.104.62:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/msy.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvWQAABeU"] [Sat Aug 29 05:06:09.959640 2026] [security2:error] [pid 1017536:tid 1017784] [client 158.158.54.35:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apK9ISJcY4fy7tP-rU34eAAAAoo"] [Sat Aug 29 05:06:09.960784 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.104.104.62:64661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/ad1.php"] [unique_id "apK9ISJcY4fy7tP-rU34eQAAAnI"] [Sat Aug 29 05:06:09.963926 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.151.200.44:47309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/rce.php"] [unique_id "apK9ISJcY4fy7tP-rU34egAAAnY"] [Sat Aug 29 05:06:09.972340 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.18.15:23486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/ta.php"] [unique_id "apK9ISJcY4fy7tP-rU34fAAAAiU"] [Sat Aug 29 05:06:09.987164 2026] [security2:error] [pid 1017536:tid 1017737] [client 197.219.150.206:58600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9ISJcY4fy7tP-rU34fgAAAls"] [Sat Aug 29 05:06:09.987270 2026] [security2:error] [pid 1017536:tid 1017737] [client 197.219.150.206:58600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9ISJcY4fy7tP-rU34fgAAAls"] [Sat Aug 29 05:06:09.989387 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.147.79:24481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-blog-header.php"] [unique_id "apK9ITAh5Y1i2tUxg4HvXAAABdQ"] [Sat Aug 29 05:06:10.016403 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.18.15:13306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/sao.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvXgAABiA"] [Sat Aug 29 05:06:10.020824 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.251.3:61247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/f35.php"] [unique_id "apK9IiJcY4fy7tP-rU34gAAAAlc"] [Sat Aug 29 05:06:10.049670 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.18.15:36790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-includes/index.php"] [unique_id "apK9IiJcY4fy7tP-rU34gwAAApA"] [Sat Aug 29 05:06:10.053024 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.196.209.81:23643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/user/min.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvYAAABho"] [Sat Aug 29 05:06:10.066642 2026] [security2:error] [pid 1017536:tid 1017748] [client 52.139.37.240:18117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/form.php"] [unique_id "apK9IiJcY4fy7tP-rU34hAAAAmY"] [Sat Aug 29 05:06:10.069439 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.104.104.62:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.americanvarietyradio.net"] [uri "/fesa.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvYQAABhw"] [Sat Aug 29 05:06:10.078602 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.151.200.44:64257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/gaje.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvYgAABjI"] [Sat Aug 29 05:06:10.084311 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.18.15:64511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/rxr.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvYwAABds"] [Sat Aug 29 05:06:10.085974 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.104.62:22719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/siln.php"] [unique_id "apK9IiJcY4fy7tP-rU34hQAAAhc"] [Sat Aug 29 05:06:10.088959 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.18.15:7025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/x.php"] [unique_id "apK9IiJcY4fy7tP-rU34hgAAAkU"] [Sat Aug 29 05:06:10.095878 2026] [security2:error] [pid 1018003:tid 1018271] [client 40.83.93.50:16612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/inputs.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvZAAABi8"] [Sat Aug 29 05:06:10.097148 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.104.104.62:42688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/h02ugyh.php"] [unique_id "apK9IiJcY4fy7tP-rU34hwAAAiY"] [Sat Aug 29 05:06:10.103796 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.104.104.62:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/1vbqo.php"] [unique_id "apK9IiJcY4fy7tP-rU34igAAAk4"] [Sat Aug 29 05:06:10.104953 2026] [security2:error] [pid 1018003:tid 1018207] [client 168.107.94.195:55037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvZQAABfA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:10.105498 2026] [security2:error] [pid 1017536:tid 1017768] [client 20.104.18.15:8176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/8.php"] [unique_id "apK9IiJcY4fy7tP-rU34iwAAAno"] [Sat Aug 29 05:06:10.109843 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.151.200.44:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/exec.php"] [unique_id "apK9IiJcY4fy7tP-rU34jAAAAkM"] [Sat Aug 29 05:06:10.116943 2026] [security2:error] [pid 1017536:tid 1017732] [client 40.83.93.50:22249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-conflg.php"] [unique_id "apK9IiJcY4fy7tP-rU34jQAAAlY"] [Sat Aug 29 05:06:10.143431 2026] [security2:error] [pid 1018003:tid 1018221] [client 68.155.159.216:52765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/file.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvZwAABf4"] [Sat Aug 29 05:06:10.144317 2026] [security2:error] [pid 1018003:tid 1018212] [client 68.155.159.216:14239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvaAAABfU"] [Sat Aug 29 05:06:10.150509 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/api.php"] [unique_id "apK9IiJcY4fy7tP-rU34jwAAAjw"] [Sat Aug 29 05:06:10.154638 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.18.15:13138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/dapa.php"] [unique_id "apK9IiJcY4fy7tP-rU34kQAAAjs"] [Sat Aug 29 05:06:10.160110 2026] [security2:error] [pid 1017536:tid 1017769] [client 4.205.62.107:22256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/dialog.php"] [unique_id "apK9IiJcY4fy7tP-rU34kgAAAns"] [Sat Aug 29 05:06:10.160917 2026] [security2:error] [pid 1017536:tid 1017704] [client 158.23.147.79:48242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/hehehehe.php"] [unique_id "apK9IiJcY4fy7tP-rU34kwAAAjo"] [Sat Aug 29 05:06:10.162833 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.63.81.20:60536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9IiJcY4fy7tP-rU34lAAAAiM"] [Sat Aug 29 05:06:10.165497 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.151.200.44:64913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/7logs.php"] [unique_id "apK9IiJcY4fy7tP-rU34lQAAAhY"] [Sat Aug 29 05:06:10.179741 2026] [security2:error] [pid 1017536:tid 1017673] [client 68.155.159.216:18429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/NewFile.php/"] [unique_id "apK9IiJcY4fy7tP-rU34lwAAAhs"] [Sat Aug 29 05:06:10.198418 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.18.15:23402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/bo.php"] [unique_id "apK9IiJcY4fy7tP-rU34mwAAAjQ"] [Sat Aug 29 05:06:10.217345 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.147.79:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9IiJcY4fy7tP-rU34nQAAAlo"] [Sat Aug 29 05:06:10.218857 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.104.104.62:41634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/f-401.php"] [unique_id "apK9IiJcY4fy7tP-rU34ngAAAoQ"] [Sat Aug 29 05:06:10.223780 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:56351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thaipavilionskokie.com"] [uri "/reviall.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvawAABeE"] [Sat Aug 29 05:06:10.225344 2026] [security2:error] [pid 1017536:tid 1017686] [client 158.23.147.79:63016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/about.php"] [unique_id "apK9IiJcY4fy7tP-rU34oAAAAig"] [Sat Aug 29 05:06:10.227436 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.147.79:30631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9IiJcY4fy7tP-rU34oQAAAi0"] [Sat Aug 29 05:06:10.228495 2026] [security2:error] [pid 1017536:tid 1017742] [client 60.243.207.176:61240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9IiJcY4fy7tP-rU34ogAAAmA"] [Sat Aug 29 05:06:10.228596 2026] [security2:error] [pid 1017536:tid 1017742] [client 60.243.207.176:61240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9IiJcY4fy7tP-rU34ogAAAmA"] [Sat Aug 29 05:06:10.231211 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.104.62:48469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/0xs.php"] [unique_id "apK9IiJcY4fy7tP-rU34owAAAko"] [Sat Aug 29 05:06:10.234784 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.18.15:36763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/file31.php"] [unique_id "apK9IiJcY4fy7tP-rU34pAAAAjE"] [Sat Aug 29 05:06:10.239163 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.104.62:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/h02ugyh.php"] [unique_id "apK9IiJcY4fy7tP-rU34pQAAAos"] [Sat Aug 29 05:06:10.241919 2026] [security2:error] [pid 1017536:tid 1017723] [client 4.205.62.107:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/i.php"] [unique_id "apK9IiJcY4fy7tP-rU34pgAAAk0"] [Sat Aug 29 05:06:10.248807 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.104.18.15:8019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/goods.php"] [unique_id "apK9IiJcY4fy7tP-rU34pwAAAj4"] [Sat Aug 29 05:06:10.257292 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.220.204.93:63230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/elp.php"] [unique_id "apK9IiJcY4fy7tP-rU34qAAAAmU"] [Sat Aug 29 05:06:10.257292 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.151.200.44:46603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/dbc.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvbAAABew"] [Sat Aug 29 05:06:10.258507 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.104.18.15:7040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ssla.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvbQAABeY"] [Sat Aug 29 05:06:10.259689 2026] [security2:error] [pid 1017536:tid 1017757] [client 52.139.37.240:18113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/wp-sigunq.php"] [unique_id "apK9IiJcY4fy7tP-rU34qQAAAm8"] [Sat Aug 29 05:06:10.266812 2026] [security2:error] [pid 1017536:tid 1017743] [client 68.155.159.216:24565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9IiJcY4fy7tP-rU34qgAAAmE"] [Sat Aug 29 05:06:10.271009 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:65085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/maraz.php"] [unique_id "apK9IiJcY4fy7tP-rU34qwAAAls"] [Sat Aug 29 05:06:10.279552 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.48.251.3:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/temp.php"] [unique_id "apK9IiJcY4fy7tP-rU34rgAAAkY"] [Sat Aug 29 05:06:10.281522 2026] [security2:error] [pid 1017536:tid 1017740] [client 158.23.147.79:32654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/file88.php"] [unique_id "apK9IiJcY4fy7tP-rU34rwAAAl4"] [Sat Aug 29 05:06:10.283241 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:13127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-content/l.php"] [unique_id "apK9IiJcY4fy7tP-rU34sAAAAkA"] [Sat Aug 29 05:06:10.288503 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.151.200.44:64834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/wp-admin/zwso.php"] [unique_id "apK9IiJcY4fy7tP-rU34sQAAAmY"] [Sat Aug 29 05:06:10.293480 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.52.41.200:1225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/css/wp-login.php"] [unique_id "apK9IiJcY4fy7tP-rU34sgAAAms"] [Sat Aug 29 05:06:10.298085 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.63.81.20:60524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9IiJcY4fy7tP-rU34swAAAho"] [Sat Aug 29 05:06:10.329642 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.104.18.15:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/44.php"] [unique_id "apK9IiJcY4fy7tP-rU34tgAAAlU"] [Sat Aug 29 05:06:10.334623 2026] [security2:error] [pid 1017536:tid 1017761] [client 68.155.159.216:51778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9IiJcY4fy7tP-rU34twAAAnM"] [Sat Aug 29 05:06:10.335289 2026] [security2:error] [pid 1017536:tid 1017687] [client 158.23.147.79:25507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/xmlrpc.php"] [unique_id "apK9IiJcY4fy7tP-rU34uAAAAik"] [Sat Aug 29 05:06:10.363000 2026] [security2:error] [pid 1017536:tid 1017668] [client 68.155.159.216:24466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9IiJcY4fy7tP-rU34uQAAAhY"] [Sat Aug 29 05:06:10.367342 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.104.62:64685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/shelp.php"] [unique_id "apK9IiJcY4fy7tP-rU34ugAAAj8"] [Sat Aug 29 05:06:10.368869 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.104.62:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/hq.php"] [unique_id "apK9IiJcY4fy7tP-rU34uwAAApI"] [Sat Aug 29 05:06:10.378607 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.104.18.15:36785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/dk.php"] [unique_id "apK9IiJcY4fy7tP-rU34vAAAAlM"] [Sat Aug 29 05:06:10.383696 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.18.15:8115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ah.php"] [unique_id "apK9IiJcY4fy7tP-rU34vQAAAmM"] [Sat Aug 29 05:06:10.390135 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.151.200.44:64849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/sf.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvbgAABjQ"] [Sat Aug 29 05:06:10.391803 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.158.54.35:33001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/m.php"] [unique_id "apK9IiJcY4fy7tP-rU34wAAAAh0"] [Sat Aug 29 05:06:10.399993 2026] [security2:error] [pid 1017536:tid 1017760] [client 34.7.216.49:43430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.216.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/configuration.php.bak"] [unique_id "apK9IiJcY4fy7tP-rU34wwAAAnI"] [Sat Aug 29 05:06:10.401462 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.220.204.93:63811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/666.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvdAAABdo"] [Sat Aug 29 05:06:10.406118 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.49.130:46573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/tiny2.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvdwAABhQ"] [Sat Aug 29 05:06:10.409903 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.251.3:61663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/fm.php"] [unique_id "apK9IiJcY4fy7tP-rU34ygAAAj0"] [Sat Aug 29 05:06:10.425878 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.49.130:34899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/js.php"] [unique_id "apK9IiJcY4fy7tP-rU34zgAAAlg"] [Sat Aug 29 05:06:10.425913 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.151.200.44:64253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/Contrller.php"] [unique_id "apK9IiJcY4fy7tP-rU34zQAAAoQ"] [Sat Aug 29 05:06:10.431582 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.18.15:7152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apK9IiJcY4fy7tP-rU34zwAAAig"] [Sat Aug 29 05:06:10.431586 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.48.250.41:65026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/kbfr.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvegAABbw"] [Sat Aug 29 05:06:10.449271 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.196.209.81:5890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/users.php"] [unique_id "apK9IiJcY4fy7tP-rU340AAAAhg"] [Sat Aug 29 05:06:10.450948 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.63.81.20:60461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/ser.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvewAABjM"] [Sat Aug 29 05:06:10.451412 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.18.15:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-admin/w.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvfAAABdk"] [Sat Aug 29 05:06:10.452668 2026] [security2:error] [pid 1017536:tid 1017703] [client 52.139.37.240:63360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carlpipescustomhomes.com"] [uri "/07.php"] [unique_id "apK9IiJcY4fy7tP-rU340QAAAjk"] [Sat Aug 29 05:06:10.461260 2026] [security2:error] [pid 1017536:tid 1017780] [client 52.139.37.240:12543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/ahax.php"] [unique_id "apK9IiJcY4fy7tP-rU340gAAAoY"] [Sat Aug 29 05:06:10.465146 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.196.209.81:16204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/post.php"] [unique_id "apK9IiJcY4fy7tP-rU340wAAAj4"] [Sat Aug 29 05:06:10.476584 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.104.104.62:64709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/UnknownSec.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvfwAABhg"] [Sat Aug 29 05:06:10.486023 2026] [security2:error] [pid 1017536:tid 1017788] [client 168.107.94.195:55425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9IiJcY4fy7tP-rU341AAAAo4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:10.501526 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.104.18.15:23311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/h2.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvgAAABhM"] [Sat Aug 29 05:06:10.507790 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.104.62:22706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/mh.php"] [unique_id "apK9IiJcY4fy7tP-rU341QAAAmk"] [Sat Aug 29 05:06:10.513441 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.104.62:52059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/shelp.php"] [unique_id "apK9IiJcY4fy7tP-rU341gAAAlc"] [Sat Aug 29 05:06:10.524230 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.197.61.180:13028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content.php"] [unique_id "apK9IiJcY4fy7tP-rU341wAAApA"] [Sat Aug 29 05:06:10.531261 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.18.15:36829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/ta.php"] [unique_id "apK9IiJcY4fy7tP-rU342AAAAmY"] [Sat Aug 29 05:06:10.537274 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.18.15:8132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ws55.php"] [unique_id "apK9IiJcY4fy7tP-rU342QAAAms"] [Sat Aug 29 05:06:10.538988 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.251.3:62121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/tinyfilemanager.php"] [unique_id "apK9IiJcY4fy7tP-rU342gAAAmI"] [Sat Aug 29 05:06:10.544927 2026] [security2:error] [pid 1017536:tid 1017685] [client 20.151.200.44:46576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/wp-wlx.php"] [unique_id "apK9IiJcY4fy7tP-rU342wAAAic"] [Sat Aug 29 05:06:10.545141 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.151.200.44:64884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/super.php"] [unique_id "apK9IiJcY4fy7tP-rU343AAAAkk"] [Sat Aug 29 05:06:10.547274 2026] [security2:error] [pid 1017536:tid 1017768] [client 20.104.104.62:64671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/13ede.php"] [unique_id "apK9IiJcY4fy7tP-rU343QAAAno"] [Sat Aug 29 05:06:10.547350 2026] [security2:error] [pid 1018003:tid 1018278] [client 158.23.147.79:30699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/dropdown.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvggAABjY"] [Sat Aug 29 05:06:10.564867 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.151.200.44:64841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/Zeiss.php"] [unique_id "apK9IiJcY4fy7tP-rU343gAAAlY"] [Sat Aug 29 05:06:10.575997 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.23.147.79:50173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9IiJcY4fy7tP-rU344AAAAkE"] [Sat Aug 29 05:06:10.580765 2026] [security2:error] [pid 1018003:tid 1018151] [client 20.104.104.62:48593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/waf.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvhQAABbg"] [Sat Aug 29 05:06:10.583425 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.63.81.20:56900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/431.php"] [unique_id "apK9IiJcY4fy7tP-rU344QAAAk8"] [Sat Aug 29 05:06:10.586915 2026] [security2:error] [pid 1018003:tid 1018255] [client 40.83.93.50:7753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvhgAABh8"] [Sat Aug 29 05:06:10.591221 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.104.62:25620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/wp-content/index.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvhwAABfs"] [Sat Aug 29 05:06:10.609156 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.18.15:13193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-content/k.php"] [unique_id "apK9IiJcY4fy7tP-rU344gAAAmM"] [Sat Aug 29 05:06:10.612015 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.104.18.15:7075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-aothait.php"] [unique_id "apK9IiJcY4fy7tP-rU344wAAAnI"] [Sat Aug 29 05:06:10.614601 2026] [security2:error] [pid 1017536:tid 1017695] [client 40.83.93.50:22213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content.php"] [unique_id "apK9IiJcY4fy7tP-rU345AAAAjE"] [Sat Aug 29 05:06:10.632319 2026] [security2:error] [pid 1018003:tid 1018220] [client 20.104.18.15:23406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apK9IjAh5Y1i2tUxg4HviAAABf0"] [Sat Aug 29 05:06:10.648827 2026] [security2:error] [pid 1017536:tid 1017681] [client 52.139.37.240:63353] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "carlpipescustomhomes.com"] [uri "/c99.php"] [unique_id "apK9IiJcY4fy7tP-rU345gAAAiM"] [Sat Aug 29 05:06:10.659128 2026] [security2:error] [pid 1017536:tid 1017783] [client 4.205.62.107:64909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/umgebung.php"] [unique_id "apK9IiJcY4fy7tP-rU345wAAAok"] [Sat Aug 29 05:06:10.666572 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.48.251.3:62123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/05.php"] [unique_id "apK9IiJcY4fy7tP-rU346AAAAko"] [Sat Aug 29 05:06:10.667172 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.104.104.62:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/f2r4.php"] [unique_id "apK9IiJcY4fy7tP-rU346QAAAos"] [Sat Aug 29 05:06:10.672693 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.104.18.15:8072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/drykl.php"] [unique_id "apK9IiJcY4fy7tP-rU347gAAAjk"] [Sat Aug 29 05:06:10.674702 2026] [security2:error] [pid 1017536:tid 1017723] [client 68.155.159.216:50186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9IiJcY4fy7tP-rU347wAAAk0"] [Sat Aug 29 05:06:10.676268 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.104.62:20802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/cilik.php"] [unique_id "apK9IjAh5Y1i2tUxg4HviQAABeU"] [Sat Aug 29 05:06:10.677062 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:36861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/bo.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvigAABcA"] [Sat Aug 29 05:06:10.679921 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.220.204.93:64299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/knmt.php"] [unique_id "apK9IiJcY4fy7tP-rU348AAAAmU"] [Sat Aug 29 05:06:10.697867 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:43025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/k8.php"] [unique_id "apK9IiJcY4fy7tP-rU348gAAAiU"] [Sat Aug 29 05:06:10.707576 2026] [security2:error] [pid 1017536:tid 1017773] [client 52.139.37.240:12879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/breads1.php"] [unique_id "apK9IiJcY4fy7tP-rU349QAAAn8"] [Sat Aug 29 05:06:10.713120 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.63.81.20:60495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/rxr.php"] [unique_id "apK9IiJcY4fy7tP-rU349gAAAnw"] [Sat Aug 29 05:06:10.725988 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.251.3:14005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/zaza.php"] [unique_id "apK9IiJcY4fy7tP-rU349wAAAnc"] [Sat Aug 29 05:06:10.738563 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.52.41.200:1744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/images/index.php"] [unique_id "apK9IiJcY4fy7tP-rU34-QAAAj8"] [Sat Aug 29 05:06:10.748034 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.104.18.15:7045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-includes/index.php"] [unique_id "apK9IiJcY4fy7tP-rU34_QAAAmI"] [Sat Aug 29 05:06:10.751078 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.104.18.15:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/os.php"] [unique_id "apK9IiJcY4fy7tP-rU34_gAAAmo"] [Sat Aug 29 05:06:10.756014 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.151.200.44:64872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/ww2.php"] [unique_id "apK9IiJcY4fy7tP-rU34_wAAAiA"] [Sat Aug 29 05:06:10.765649 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.18.15:23385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/sao.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvjAAABiA"] [Sat Aug 29 05:06:10.769369 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.151.200.44:46542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/attack.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvjQAABcc"] [Sat Aug 29 05:06:10.784756 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.104.104.62:48596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/bnnof6.php"] [unique_id "apK9IiJcY4fy7tP-rU35AQAAAlU"] [Sat Aug 29 05:06:10.800316 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:3363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-blog.php"] [unique_id "apK9IiJcY4fy7tP-rU35AgAAAjw"] [Sat Aug 29 05:06:10.801273 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.104.62:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/sadis.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvjwAABcU"] [Sat Aug 29 05:06:10.822115 2026] [security2:error] [pid 1017536:tid 1017684] [client 103.240.76.112:43460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9IiJcY4fy7tP-rU35BAAAAiY"] [Sat Aug 29 05:06:10.822259 2026] [security2:error] [pid 1017536:tid 1017684] [client 103.240.76.112:43460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9IiJcY4fy7tP-rU35BAAAAiY"] [Sat Aug 29 05:06:10.828224 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.158.54.35:8691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/css/wp-login.php"] [unique_id "apK9IiJcY4fy7tP-rU35BQAAAm8"] [Sat Aug 29 05:06:10.832734 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.220.204.93:64924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/sbhu.php"] [unique_id "apK9IiJcY4fy7tP-rU35BgAAAhc"] [Sat Aug 29 05:06:10.835253 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.18.15:36713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/44.php"] [unique_id "apK9IiJcY4fy7tP-rU35BwAAApI"] [Sat Aug 29 05:06:10.838634 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.18.15:8031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/backup.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvkAAABds"] [Sat Aug 29 05:06:10.839914 2026] [security2:error] [pid 1018003:tid 1018235] [client 216.244.66.243:51840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scottportfolio.com"] [uri "/userfiles/figurka-labubu.xml"] [unique_id "apK9IjAh5Y1i2tUxg4HvkQAABgs"] [Sat Aug 29 05:06:10.840010 2026] [security2:error] [pid 1018003:tid 1018235] [client 216.244.66.243:51840] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scottportfolio.com"] [uri "/userfiles/figurka-labubu.xml"] [unique_id "apK9IjAh5Y1i2tUxg4HvkQAABgs"] [Sat Aug 29 05:06:10.841327 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.104.104.62:4853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/alog.php"] [unique_id "apK9IiJcY4fy7tP-rU35CAAAAlM"] [Sat Aug 29 05:06:10.842752 2026] [security2:error] [pid 1018003:tid 1018170] [client 52.139.37.240:17453] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "carlpipescustomhomes.com"] [uri "/c99.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvkgAABcs"] [Sat Aug 29 05:06:10.846757 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.196.209.81:15057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK9IiJcY4fy7tP-rU35CQAAAo4"] [Sat Aug 29 05:06:10.849947 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.63.81.20:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/csst.php"] [unique_id "apK9IiJcY4fy7tP-rU35CgAAAnk"] [Sat Aug 29 05:06:10.866858 2026] [security2:error] [pid 1017536:tid 1017745] [client 168.107.94.195:55801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9IiJcY4fy7tP-rU35CwAAAmM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:10.868762 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.104.62:36953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/13ede.php"] [unique_id "apK9IiJcY4fy7tP-rU35DAAAAjQ"] [Sat Aug 29 05:06:10.877929 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.104.104.62:25600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9IiJcY4fy7tP-rU35DQAAAmg"] [Sat Aug 29 05:06:10.891257 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.104.104.62:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/zxcok.php"] [unique_id "apK9IiJcY4fy7tP-rU35EAAAAiE"] [Sat Aug 29 05:06:10.894245 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.151.200.44:64305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/anz.php"] [unique_id "apK9IiJcY4fy7tP-rU35EQAAAlo"] [Sat Aug 29 05:06:10.901188 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.18.15:23312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/dapa.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvkwAABi8"] [Sat Aug 29 05:06:10.904483 2026] [security2:error] [pid 1018003:tid 1018182] [client 52.139.37.240:12533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/must.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvlAAABdc"] [Sat Aug 29 05:06:10.905052 2026] [security2:error] [pid 1018003:tid 1018234] [client 4.205.62.107:22389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/txets.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvlQAABgo"] [Sat Aug 29 05:06:10.914385 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.104.18.15:7164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/file31.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvlgAABg4"] [Sat Aug 29 05:06:10.915848 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.104.18.15:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/htio.php"] [unique_id "apK9IiJcY4fy7tP-rU35EwAAAkc"] [Sat Aug 29 05:06:10.921607 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.196.209.81:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/flower.php"] [unique_id "apK9IiJcY4fy7tP-rU35FAAAAlc"] [Sat Aug 29 05:06:10.939167 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.104.62:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/xcre1.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvlwAABf4"] [Sat Aug 29 05:06:10.943750 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.151.200.44:47405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/file66.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvmAAABf8"] [Sat Aug 29 05:06:10.946805 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.48.251.3:61056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/erty.php"] [unique_id "apK9IiJcY4fy7tP-rU35FQAAAhg"] [Sat Aug 29 05:06:10.977617 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.18.15:8104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/indo.php"] [unique_id "apK9IiJcY4fy7tP-rU35GAAAAkI"] [Sat Aug 29 05:06:10.978696 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.104.62:43017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/adin.php"] [unique_id "apK9IiJcY4fy7tP-rU35GQAAAkU"] [Sat Aug 29 05:06:10.979051 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.63.81.20:60523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apK9IiJcY4fy7tP-rU35GgAAAkQ"] [Sat Aug 29 05:06:10.983242 2026] [security2:error] [pid 1017536:tid 1017691] [client 171.61.160.196:5924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9IiJcY4fy7tP-rU35GwAAAi0"] [Sat Aug 29 05:06:10.983388 2026] [security2:error] [pid 1017536:tid 1017691] [client 171.61.160.196:5924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9IiJcY4fy7tP-rU35GwAAAi0"] [Sat Aug 29 05:06:10.985996 2026] [security2:error] [pid 1018003:tid 1018192] [client 4.205.62.107:22261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/sale.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvmwAABeE"] [Sat Aug 29 05:06:10.991457 2026] [security2:error] [pid 1018003:tid 1018193] [client 4.205.62.107:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ws61.php"] [unique_id "apK9IjAh5Y1i2tUxg4HvnAAABeI"] [Sat Aug 29 05:06:11.007200 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.104.62:48644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/ah24.php"] [unique_id "apK9IyJcY4fy7tP-rU35HAAAAnc"] [Sat Aug 29 05:06:11.032187 2026] [security2:error] [pid 1018003:tid 1018173] [client 195.178.110.247:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lawrencevillecosmeticdentists.com"] [uri "/index.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvoQAABc4"] [Sat Aug 29 05:06:11.036508 2026] [security2:error] [pid 1017536:tid 1017683] [client 52.139.37.240:17436] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "carlpipescustomhomes.com"] [uri "/c99.php"] [unique_id "apK9IyJcY4fy7tP-rU35HgAAAiU"] [Sat Aug 29 05:06:11.042142 2026] [security2:error] [pid 1017536:tid 1017753] [client 4.205.62.107:53424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/guk.php"] [unique_id "apK9IyJcY4fy7tP-rU35HwAAAms"] [Sat Aug 29 05:06:11.074740 2026] [security2:error] [pid 1017536:tid 1017778] [client 40.83.93.50:7796] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/1.php7"] [unique_id "apK9IyJcY4fy7tP-rU35IAAAAoQ"] [Sat Aug 29 05:06:11.074823 2026] [security2:error] [pid 1017536:tid 1017778] [client 40.83.93.50:7796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/1.php7"] [unique_id "apK9IyJcY4fy7tP-rU35IAAAAoQ"] [Sat Aug 29 05:06:11.074827 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.151.200.44:64883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/bge.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvogAABbk"] [Sat Aug 29 05:06:11.074984 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.151.200.44:46616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/zafir1.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvowAABjM"] [Sat Aug 29 05:06:11.075064 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.48.251.3:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-config.backup.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvpAAABiY"] [Sat Aug 29 05:06:11.080450 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.104.62:22693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/motu.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvpQAABdk"] [Sat Aug 29 05:06:11.082124 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.104.62:20800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-supports.php"] [unique_id "apK9IyJcY4fy7tP-rU35IgAAAkk"] [Sat Aug 29 05:06:11.086970 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.220.204.93:64344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/a332.php"] [unique_id "apK9IyJcY4fy7tP-rU35IwAAAiI"] [Sat Aug 29 05:06:11.088636 2026] [security2:error] [pid 1017536:tid 1017768] [client 158.23.147.79:24387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9IyJcY4fy7tP-rU35JAAAAno"] [Sat Aug 29 05:06:11.100121 2026] [security2:error] [pid 1018003:tid 1018155] [client 52.139.37.240:12878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/up.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvpgAABbw"] [Sat Aug 29 05:06:11.115691 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.63.81.20:56896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apK9IyJcY4fy7tP-rU35JQAAAks"] [Sat Aug 29 05:06:11.130686 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.104.104.62:43066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/sf9.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvpwAABhg"] [Sat Aug 29 05:06:11.177921 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.104.104.62:52057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/k8.php"] [unique_id "apK9IyJcY4fy7tP-rU35KAAAAk8"] [Sat Aug 29 05:06:11.181059 2026] [cgid:error] [pid 1017536:tid 1017740] [client 20.52.41.200:1249] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:11.188899 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.147.79:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvqAAABbo"] [Sat Aug 29 05:06:11.196755 2026] [security2:error] [pid 1018003:tid 1018225] [client 195.178.110.247:45520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lawrencevillecosmeticdentists.com"] [uri "/index.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvqQAABgI"] [Sat Aug 29 05:06:11.197644 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.104.104.62:48576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/ztv.php"] [unique_id "apK9IyJcY4fy7tP-rU35KgAAAlM"] [Sat Aug 29 05:06:11.204598 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.251.3:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/edit.php"] [unique_id "apK9IyJcY4fy7tP-rU35KwAAAo4"] [Sat Aug 29 05:06:11.208610 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.104.62:25851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/403.php"] [unique_id "apK9IyJcY4fy7tP-rU35LAAAAnk"] [Sat Aug 29 05:06:11.214312 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.104.62:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/wefile.php"] [unique_id "apK9IyJcY4fy7tP-rU35LgAAAmM"] [Sat Aug 29 05:06:11.244861 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.220.204.93:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ws66.php"] [unique_id "apK9IyJcY4fy7tP-rU35MgAAAl8"] [Sat Aug 29 05:06:11.245285 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.63.81.20:60430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9IyJcY4fy7tP-rU35MwAAAiE"] [Sat Aug 29 05:06:11.247056 2026] [security2:error] [pid 1018003:tid 1018205] [client 168.107.94.195:56067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvqwAABe4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:11.270370 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.196.209.81:5911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK9IyJcY4fy7tP-rU35NAAAAlU"] [Sat Aug 29 05:06:11.275502 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.158.54.35:8679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/222.php"] [unique_id "apK9IyJcY4fy7tP-rU35NQAAAlY"] [Sat Aug 29 05:06:11.280869 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:48350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9IyJcY4fy7tP-rU35NwAAAkc"] [Sat Aug 29 05:06:11.284466 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.104.104.62:64699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/lte7.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvrwAABd8"] [Sat Aug 29 05:06:11.285269 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.151.200.44:47404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/console.php"] [unique_id "apK9IyJcY4fy7tP-rU35OAAAAok"] [Sat Aug 29 05:06:11.293121 2026] [security2:error] [pid 1017536:tid 1017733] [client 40.83.93.50:5916] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "termoenvases.net"] [uri "/wp-content/1.php"] [unique_id "apK9IyJcY4fy7tP-rU35OQAAAlc"] [Sat Aug 29 05:06:11.293215 2026] [security2:error] [pid 1017536:tid 1017733] [client 40.83.93.50:5916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/1.php"] [unique_id "apK9IyJcY4fy7tP-rU35OQAAAlc"] [Sat Aug 29 05:06:11.299706 2026] [security2:error] [pid 1018003:tid 1018267] [client 4.205.62.107:22478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/phpinfo01.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvsAAABis"] [Sat Aug 29 05:06:11.308116 2026] [security2:error] [pid 1017536:tid 1017764] [client 68.155.159.216:18413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/dropdown.php"] [unique_id "apK9IyJcY4fy7tP-rU35OwAAAnY"] [Sat Aug 29 05:06:11.313750 2026] [security2:error] [pid 1017536:tid 1017703] [client 20.151.200.44:64932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/wp-ana.php"] [unique_id "apK9IyJcY4fy7tP-rU35PQAAAjk"] [Sat Aug 29 05:06:11.320980 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.196.209.81:11531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/meta.php"] [unique_id "apK9IyJcY4fy7tP-rU35PwAAAiY"] [Sat Aug 29 05:06:11.326579 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.52.41.200:1249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/inputs.php"] [unique_id "apK9IyJcY4fy7tP-rU35QAAAAoY"] [Sat Aug 29 05:06:11.329716 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.104.104.62:20863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/bkv74.php"] [unique_id "apK9IyJcY4fy7tP-rU35QQAAAj4"] [Sat Aug 29 05:06:11.330220 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.147.79:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9IyJcY4fy7tP-rU35QgAAAn8"] [Sat Aug 29 05:06:11.346502 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.48.251.3:61632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/8.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvswAABcA"] [Sat Aug 29 05:06:11.350286 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.104.104.62:22695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/EM.php"] [unique_id "apK9IyJcY4fy7tP-rU35RAAAAkQ"] [Sat Aug 29 05:06:11.351898 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.104.104.62:23380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/alog.php"] [unique_id "apK9IyJcY4fy7tP-rU35RQAAAnw"] [Sat Aug 29 05:06:11.360235 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.147.79:30623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/sad/about.php"] [unique_id "apK9IyJcY4fy7tP-rU35RwAAAi0"] [Sat Aug 29 05:06:11.372643 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.63.81.20:60515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/haxor.php"] [unique_id "apK9IyJcY4fy7tP-rU35SAAAAnc"] [Sat Aug 29 05:06:11.373457 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.104.49.130:58049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/users.php"] [unique_id "apK9IyJcY4fy7tP-rU35SQAAAoo"] [Sat Aug 29 05:06:11.376349 2026] [security2:error] [pid 1018003:tid 1018215] [client 20.220.204.93:64926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ws68.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvtAAABfg"] [Sat Aug 29 05:06:11.383251 2026] [security2:error] [pid 1017536:tid 1017751] [client 52.139.37.240:12905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-content/155.php"] [unique_id "apK9IyJcY4fy7tP-rU35SgAAAmk"] [Sat Aug 29 05:06:11.387554 2026] [security2:error] [pid 1018003:tid 1018156] [client 4.205.62.107:55939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/guk.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvtQAABb0"] [Sat Aug 29 05:06:11.404456 2026] [security2:error] [pid 1017536:tid 1017715] [client 20.104.104.62:25641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/ava.php"] [unique_id "apK9IyJcY4fy7tP-rU35TAAAAkU"] [Sat Aug 29 05:06:11.418911 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.104.62:48762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/kure.php"] [unique_id "apK9IyJcY4fy7tP-rU35TQAAAms"] [Sat Aug 29 05:06:11.420725 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.104.104.62:56339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/tanjiro.php"] [unique_id "apK9IyJcY4fy7tP-rU35TgAAAmo"] [Sat Aug 29 05:06:11.441965 2026] [security2:error] [pid 1017536:tid 1017777] [client 68.155.159.216:51868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin.php"] [unique_id "apK9IyJcY4fy7tP-rU35TwAAAoM"] [Sat Aug 29 05:06:11.453437 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.147.79:32652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/NewFile.php/"] [unique_id "apK9IzAh5Y1i2tUxg4HvtgAABeM"] [Sat Aug 29 05:06:11.453705 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.147.79:25578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/atomlib.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvtwAABco"] [Sat Aug 29 05:06:11.467997 2026] [security2:error] [pid 1018003:tid 1018163] [client 68.155.159.216:24469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvuAAABcQ"] [Sat Aug 29 05:06:11.473295 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.251.3:61693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/thui.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvuQAABdc"] [Sat Aug 29 05:06:11.479705 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.104.62:20826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/css/java.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvugAABgo"] [Sat Aug 29 05:06:11.489226 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.151.200.44:47344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/blnux.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvuwAABfA"] [Sat Aug 29 05:06:11.490192 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.197.61.180:16272] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/1.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvvAAABg4"] [Sat Aug 29 05:06:11.490199 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.104.62:41608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/ca4.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvvQAABdI"] [Sat Aug 29 05:06:11.490268 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.197.61.180:16272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/1.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvvAAABg4"] [Sat Aug 29 05:06:11.501379 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.63.81.20:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/google.php"] [unique_id "apK9IyJcY4fy7tP-rU35UAAAAjs"] [Sat Aug 29 05:06:11.518046 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.151.200.44:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/secret.php"] [unique_id "apK9IyJcY4fy7tP-rU35UQAAAhY"] [Sat Aug 29 05:06:11.520519 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.220.204.93:64932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/users.php"] [unique_id "apK9IyJcY4fy7tP-rU35UgAAAl4"] [Sat Aug 29 05:06:11.543292 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.104.62:36948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/adin.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvwAAABeE"] [Sat Aug 29 05:06:11.563582 2026] [security2:error] [pid 1017536:tid 1017729] [client 138.199.19.170:39492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK9IyJcY4fy7tP-rU35VQAAAlM"] [Sat Aug 29 05:06:11.566033 2026] [security2:error] [pid 1018003:tid 1018256] [client 40.83.93.50:9554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/ds.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvwgAABiA"] [Sat Aug 29 05:06:11.566090 2026] [security2:error] [pid 1018003:tid 1018264] [client 20.48.250.41:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wp-act.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvwwAABig"] [Sat Aug 29 05:06:11.569607 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.48.251.3:33340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/u88.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvxAAABek"] [Sat Aug 29 05:06:11.579848 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.104.62:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/Rk41.php"] [unique_id "apK9IyJcY4fy7tP-rU35VgAAAmM"] [Sat Aug 29 05:06:11.592331 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.104.104.62:48679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/cafe.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvxQAABjQ"] [Sat Aug 29 05:06:11.599972 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.251.3:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/file21.php"] [unique_id "apK9IyJcY4fy7tP-rU35WAAAAjE"] [Sat Aug 29 05:06:11.602084 2026] [security2:error] [pid 1018003:tid 1018150] [client 20.104.104.62:25810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/info.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvxgAABbc"] [Sat Aug 29 05:06:11.606512 2026] [security2:error] [pid 1017536:tid 1017757] [client 52.139.37.240:12507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-update.php"] [unique_id "apK9IyJcY4fy7tP-rU35WQAAAm8"] [Sat Aug 29 05:06:11.611678 2026] [security2:error] [pid 1017536:tid 1017778] [client 34.21.253.104:29884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.replenishink.com"] [uri "/wp-config.php.bak"] [unique_id "apK9IyJcY4fy7tP-rU35WwAAAoQ"] [Sat Aug 29 05:06:11.611714 2026] [security2:error] [pid 1017536:tid 1017678] [client 34.21.253.104:29848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.253.21.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.replenishink.com"] [uri "/wp-config.php"] [unique_id "apK9IyJcY4fy7tP-rU35WgAAAiA"] [Sat Aug 29 05:06:11.624821 2026] [security2:error] [pid 1017536:tid 1017719] [client 34.21.253.104:29878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.253.21.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.replenishink.com"] [uri "/config.php.bak"] [unique_id "apK9IyJcY4fy7tP-rU35XwAAAkk"] [Sat Aug 29 05:06:11.625128 2026] [security2:error] [pid 1018003:tid 1018252] [client 34.21.253.104:29864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/config/database.yml"] [unique_id "apK9IzAh5Y1i2tUxg4HvygAABhw"] [Sat Aug 29 05:06:11.625235 2026] [security2:error] [pid 1018003:tid 1018180] [client 34.21.253.104:29852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.replenishink.com"] [uri "/wp-config.php.old"] [unique_id "apK9IzAh5Y1i2tUxg4HvywAABdU"] [Sat Aug 29 05:06:11.627643 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/x0x.php"] [unique_id "apK9IyJcY4fy7tP-rU35YAAAAlo"] [Sat Aug 29 05:06:11.629125 2026] [security2:error] [pid 1018003:tid 1018186] [client 34.21.253.104:29856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.253.21.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.replenishink.com"] [uri "/config.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvzAAABds"] [Sat Aug 29 05:06:11.629215 2026] [security2:error] [pid 1018003:tid 1018186] [client 34.21.253.104:29856] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "cpanel.replenishink.com"] [uri "/config.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvzAAABds"] [Sat Aug 29 05:06:11.629302 2026] [security2:error] [pid 1017536:tid 1017722] [client 168.107.94.195:56403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9IyJcY4fy7tP-rU35YgAAAkw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:11.630623 2026] [proxy_http:error] [pid 1017536:tid 1017789] (20014)Internal error (specific information not available): [client 34.21.253.104:29790] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:11.630636 2026] [proxy:error] [pid 1017536:tid 1017789] [client 34.21.253.104:29790] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/id_rsa [Sat Aug 29 05:06:11.631273 2026] [proxy_http:error] [pid 1018003:tid 1018164] (20014)Internal error (specific information not available): [client 34.21.253.104:29822] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:11.631280 2026] [proxy:error] [pid 1018003:tid 1018164] [client 34.21.253.104:29822] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/key.pem [Sat Aug 29 05:06:11.634715 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.63.81.20:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apK9IzAh5Y1i2tUxg4HvzgAABb4"] [Sat Aug 29 05:06:11.637163 2026] [proxy_http:error] [pid 1017536:tid 1017789] (20014)Internal error (specific information not available): [client 34.21.253.104:29790] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:11.637172 2026] [proxy:error] [pid 1017536:tid 1017789] [client 34.21.253.104:29790] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:06:11.638423 2026] [proxy_http:error] [pid 1018003:tid 1018274] (20014)Internal error (specific information not available): [client 34.21.253.104:29824] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:11.638436 2026] [proxy:error] [pid 1018003:tid 1018274] [client 34.21.253.104:29824] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/server.key [Sat Aug 29 05:06:11.644757 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.147.79:37794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv0AAABiY"] [Sat Aug 29 05:06:11.661814 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.151.200.44:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/pro.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv0gAABdk"] [Sat Aug 29 05:06:11.665995 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.196.209.81:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/wp-load.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv0wAABeg"] [Sat Aug 29 05:06:11.680936 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.104.49.130:30003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/az.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv1AAABd4"] [Sat Aug 29 05:06:11.697070 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.104.62:20813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/edit-video.php"] [unique_id "apK9IyJcY4fy7tP-rU35ZQAAAlc"] [Sat Aug 29 05:06:11.709108 2026] [security2:error] [pid 1018003:tid 1018165] [client 20.220.204.93:64967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/bzjdlofz.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv1gAABcY"] [Sat Aug 29 05:06:11.710007 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.104.62:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/7logs.php"] [unique_id "apK9IyJcY4fy7tP-rU35ZgAAAko"] [Sat Aug 29 05:06:11.713317 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.250.41:65082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/24.php"] [unique_id "apK9IyJcY4fy7tP-rU35ZwAAAos"] [Sat Aug 29 05:06:11.718615 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.158.54.35:8938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/mini.php"] [unique_id "apK9IyJcY4fy7tP-rU35aAAAAhs"] [Sat Aug 29 05:06:11.729263 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.48.251.3:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/mcebraed.php"] [unique_id "apK9IyJcY4fy7tP-rU35aQAAAi8"] [Sat Aug 29 05:06:11.746557 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.196.209.81:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/randkeyword.php"] [unique_id "apK9IyJcY4fy7tP-rU35bQAAAjo"] [Sat Aug 29 05:06:11.762634 2026] [security2:error] [pid 1018003:tid 1018278] [client 68.155.159.216:9323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/file17.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv2wAABjY"] [Sat Aug 29 05:06:11.762731 2026] [security2:error] [pid 1017536:tid 1017781] [client 40.83.93.50:12441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/about.php"] [unique_id "apK9IyJcY4fy7tP-rU35bgAAAoc"] [Sat Aug 29 05:06:11.764334 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.63.81.20:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/robots.php"] [unique_id "apK9IyJcY4fy7tP-rU35bwAAAi0"] [Sat Aug 29 05:06:11.765296 2026] [security2:error] [pid 1017536:tid 1017754] [client 68.155.159.216:14229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9IyJcY4fy7tP-rU35cAAAAmw"] [Sat Aug 29 05:06:11.768573 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.104.62:55005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hannahstamp.com"] [uri "/fesa.php"] [unique_id "apK9IyJcY4fy7tP-rU35cQAAAnc"] [Sat Aug 29 05:06:11.772485 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.52.41.200:1263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/alfa.php"] [unique_id "apK9IyJcY4fy7tP-rU35cgAAAiE"] [Sat Aug 29 05:06:11.787412 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.151.200.44:47369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/pentest.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv3QAABfs"] [Sat Aug 29 05:06:11.797807 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.104.62:48758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/eval.php"] [unique_id "apK9IyJcY4fy7tP-rU35dAAAAoM"] [Sat Aug 29 05:06:11.798836 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.151.200.44:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/999.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv3gAABc8"] [Sat Aug 29 05:06:11.800436 2026] [security2:error] [pid 1017536:tid 1017685] [client 4.205.62.107:65005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/old_phpinfo.php"] [unique_id "apK9IyJcY4fy7tP-rU35dQAAAic"] [Sat Aug 29 05:06:11.804338 2026] [security2:error] [pid 1017536:tid 1017747] [client 52.139.37.240:12531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/xmrlpc.php"] [unique_id "apK9IyJcY4fy7tP-rU35dgAAAmU"] [Sat Aug 29 05:06:11.810319 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:50255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/index.php"] [unique_id "apK9IyJcY4fy7tP-rU35dwAAAks"] [Sat Aug 29 05:06:11.812753 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:60457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/sf9.php"] [unique_id "apK9IyJcY4fy7tP-rU35eAAAAnM"] [Sat Aug 29 05:06:11.816169 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.151.200.44:64226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/lufix1.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv4AAABjU"] [Sat Aug 29 05:06:11.816720 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.104.104.62:25652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv4QAABi0"] [Sat Aug 29 05:06:11.858842 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.104.62:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/sf.php"] [unique_id "apK9IyJcY4fy7tP-rU35ewAAAjs"] [Sat Aug 29 05:06:11.858923 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.48.251.3:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/server-info.php"] [unique_id "apK9IyJcY4fy7tP-rU35egAAAns"] [Sat Aug 29 05:06:11.893971 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.63.81.20:60496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv5QAABc0"] [Sat Aug 29 05:06:11.895669 2026] [security2:error] [pid 1018003:tid 1018166] [client 138.199.19.170:39498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.19.199.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.sankomold.com"] [uri "/xmlrpc.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv5AAABcc"] [Sat Aug 29 05:06:11.915963 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.48.250.41:65115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/155.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv5gAABcQ"] [Sat Aug 29 05:06:11.917978 2026] [security2:error] [pid 1018003:tid 1018207] [client 35.198.240.194:10680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.240.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.omni-staffing.com"] [uri "/pi.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv6gAABfA"] [Sat Aug 29 05:06:11.919741 2026] [security2:error] [pid 1017536:tid 1017708] [client 34.7.40.70:7618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/public/.env"] [unique_id "apK9IyJcY4fy7tP-rU35fQAAAj4"] [Sat Aug 29 05:06:11.922495 2026] [cgid:error] [pid 1017536:tid 1017784] [client 34.7.40.70:7650] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.922911 2026] [cgid:error] [pid 1017536:tid 1017696] [client 34.7.40.70:7696] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.923177 2026] [security2:error] [pid 1018003:tid 1018221] [client 35.198.240.194:10670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.240.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.omni-staffing.com"] [uri "/i.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv7AAABf4"] [Sat Aug 29 05:06:11.924552 2026] [cgid:error] [pid 1017536:tid 1017743] [client 34.7.40.70:7628] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.930906 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.151.200.44:46644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/6y7t.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv8AAABf8"] [Sat Aug 29 05:06:11.931179 2026] [security2:error] [pid 1017536:tid 1017715] [client 34.7.40.70:7726] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/root/.aws/config"] [unique_id "apK9IyJcY4fy7tP-rU35iQAAAkU"] [Sat Aug 29 05:06:11.931753 2026] [authz_core:error] [pid 1018003:tid 1018175] [client 35.198.240.194:10664] AH01630: client denied by server configuration: /home4/stellar2/public_html/omnistaffing/.htpasswd [Sat Aug 29 05:06:11.934011 2026] [cgid:error] [pid 1017536:tid 1017672] [client 34.7.40.70:7756] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.934743 2026] [cgid:error] [pid 1018003:tid 1018225] [client 34.7.40.70:7642] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.934951 2026] [cgid:error] [pid 1017536:tid 1017753] [client 34.7.40.70:7710] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.935267 2026] [security2:error] [pid 1018003:tid 1018175] [client 35.198.240.194:10664] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/403.html"] [unique_id "apK9IzAh5Y1i2tUxg4Hv6wAABdA"] [Sat Aug 29 05:06:11.935722 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.104.104.62:20858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/.well-known/up.php"] [unique_id "apK9IyJcY4fy7tP-rU35iwAAAl8"] [Sat Aug 29 05:06:11.938581 2026] [cgid:error] [pid 1017536:tid 1017687] [client 34.7.40.70:7680] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.940775 2026] [cgid:error] [pid 1018003:tid 1018151] [client 34.7.40.70:7750] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.942903 2026] [security2:error] [pid 1017536:tid 1017751] [client 34.7.40.70:7666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.github/.env"] [unique_id "apK9IyJcY4fy7tP-rU35hwAAAmk"] [Sat Aug 29 05:06:11.943622 2026] [cgid:error] [pid 1017536:tid 1017688] [client 34.7.40.70:7742] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.943716 2026] [cgid:error] [pid 1018003:tid 1018242] [client 34.7.40.70:7782] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.948499 2026] [security2:error] [pid 1018003:tid 1018242] [client 34.7.40.70:7782] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9IzAh5Y1i2tUxg4Hv7wAABhI"] [Sat Aug 29 05:06:11.949030 2026] [security2:error] [pid 1017536:tid 1017715] [client 35.198.240.194:10702] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/gradle.properties"] [unique_id "apK9IyJcY4fy7tP-rU35jQAAAkU"] [Sat Aug 29 05:06:11.950249 2026] [cgid:error] [pid 1017536:tid 1017748] [client 34.7.40.70:7768] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.954010 2026] [security2:error] [pid 1017536:tid 1017678] [client 35.198.240.194:10688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9IyJcY4fy7tP-rU35gQAAAiA"] [Sat Aug 29 05:06:11.955769 2026] [cgid:error] [pid 1017536:tid 1017744] [client 34.7.40.70:7798] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.955870 2026] [cgid:error] [pid 1017536:tid 1017683] [client 34.7.40.70:7734] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:11.955893 2026] [security2:error] [pid 1017536:tid 1017744] [client 34.7.40.70:7798] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9IyJcY4fy7tP-rU35igAAAmI"] [Sat Aug 29 05:06:11.965403 2026] [security2:error] [pid 1018003:tid 1018249] [client 158.23.147.79:30662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/admin.php"] [unique_id "apK9IzAh5Y1i2tUxg4Hv8gAABhk"] [Sat Aug 29 05:06:11.976838 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.151.200.44:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/sef.php"] [unique_id "apK9IyJcY4fy7tP-rU35jwAAAo8"] [Sat Aug 29 05:06:11.977680 2026] [security2:error] [pid 1017536:tid 1017731] [client 35.198.240.194:10740] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/_next/../.env"] [unique_id "apK9IyJcY4fy7tP-rU35kAAAAlU"] [Sat Aug 29 05:06:11.979488 2026] [security2:error] [pid 1018003:tid 1018233] [client 35.198.240.194:10730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.env~"] [unique_id "apK9IzAh5Y1i2tUxg4Hv8wAABgk"] [Sat Aug 29 05:06:11.988149 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.220.204.93:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/selesai.php"] [unique_id "apK9IyJcY4fy7tP-rU35kgAAAmA"] [Sat Aug 29 05:06:11.993875 2026] [security2:error] [pid 1017536:tid 1017681] [client 195.178.110.247:4630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lbttech.com"] [uri "/index.php"] [unique_id "apK9IyJcY4fy7tP-rU35kwAAAiM"] [Sat Aug 29 05:06:11.994386 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.251.3:62108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/gk.php"] [unique_id "apK9IyJcY4fy7tP-rU35lAAAAmc"] [Sat Aug 29 05:06:11.997597 2026] [security2:error] [pid 1018003:tid 1018252] [client 35.198.240.194:10752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/_next/.env"] [unique_id "apK9IzAh5Y1i2tUxg4Hv9QAABhw"] [Sat Aug 29 05:06:11.997650 2026] [security2:error] [pid 1018003:tid 1018180] [client 35.198.240.194:10768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/.bash_history"] [unique_id "apK9IzAh5Y1i2tUxg4Hv9gAABdU"] [Sat Aug 29 05:06:11.997670 2026] [security2:error] [pid 1018003:tid 1018252] [client 35.198.240.194:10752] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.omni-staffing.com"] [uri "/_next/.env"] [unique_id "apK9IzAh5Y1i2tUxg4Hv9QAABhw"] [Sat Aug 29 05:06:11.997710 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.104.62:48478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/sao.php"] [unique_id "apK9IyJcY4fy7tP-rU35lQAAAlY"] [Sat Aug 29 05:06:11.997741 2026] [security2:error] [pid 1018003:tid 1018180] [client 35.198.240.194:10768] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.omni-staffing.com"] [uri "/.bash_history"] [unique_id "apK9IzAh5Y1i2tUxg4Hv9gAABdU"] [Sat Aug 29 05:06:12.009834 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.104.104.62:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/super.php"] [unique_id "apK9JCJcY4fy7tP-rU35lwAAAko"] [Sat Aug 29 05:06:12.009856 2026] [security2:error] [pid 1017536:tid 1017785] [client 168.107.94.195:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9JCJcY4fy7tP-rU35lgAAAos"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:12.019706 2026] [security2:error] [pid 1017536:tid 1017741] [client 52.139.37.240:12916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/about/function.php"] [unique_id "apK9JCJcY4fy7tP-rU35mQAAAl8"] [Sat Aug 29 05:06:12.020694 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.104.104.62:25662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/wp-content/plugins/about.php"] [unique_id "apK9JCJcY4fy7tP-rU35mgAAAj0"] [Sat Aug 29 05:06:12.024963 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.63.81.20:60509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apK9JCJcY4fy7tP-rU35mwAAAi8"] [Sat Aug 29 05:06:12.031014 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.104.62:52074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/lte7.php"] [unique_id "apK9JCJcY4fy7tP-rU35nQAAAoY"] [Sat Aug 29 05:06:12.036233 2026] [security2:error] [pid 1017536:tid 1017745] [client 40.83.93.50:9551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/GOD.php"] [unique_id "apK9JCJcY4fy7tP-rU35ngAAAmM"] [Sat Aug 29 05:06:12.042549 2026] [security2:error] [pid 1017536:tid 1017704] [client 4.205.62.107:22244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/cxc.php"] [unique_id "apK9JCJcY4fy7tP-rU35nwAAAjo"] [Sat Aug 29 05:06:12.063546 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.104.49.130:60929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/ab.php"] [unique_id "apK9JCJcY4fy7tP-rU35oAAAAnw"] [Sat Aug 29 05:06:12.069188 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.151.200.44:47298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/0xs.php"] [unique_id "apK9JCJcY4fy7tP-rU35oQAAAi0"] [Sat Aug 29 05:06:12.084507 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.196.209.81:15061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK9JCJcY4fy7tP-rU35owAAAhg"] [Sat Aug 29 05:06:12.084525 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.250.41:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/file.php"] [unique_id "apK9JCJcY4fy7tP-rU35pAAAAhw"] [Sat Aug 29 05:06:12.092731 2026] [security2:error] [pid 1018003:tid 1018257] [client 34.143.179.161:9166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/client_secret.json"] [unique_id "apK9JDAh5Y1i2tUxg4Hv-wAABiE"] [Sat Aug 29 05:06:12.109470 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.104.62:40199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/.well-known/shell.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwAQAABbw"] [Sat Aug 29 05:06:12.110185 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.151.200.44:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/admin123.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwAgAABd4"] [Sat Aug 29 05:06:12.120938 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:61201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/god.php"] [unique_id "apK9JCJcY4fy7tP-rU35pgAAAjw"] [Sat Aug 29 05:06:12.122491 2026] [security2:error] [pid 1017536:tid 1017705] [client 4.205.62.107:22356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-content/themes/luJMF.php"] [unique_id "apK9JCJcY4fy7tP-rU35pwAAAjs"] [Sat Aug 29 05:06:12.127840 2026] [security2:error] [pid 1017536:tid 1017736] [client 34.143.179.161:9182] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.harnessenergyusa.com"] [uri "/google-service-account.json"] [unique_id "apK9JCJcY4fy7tP-rU35qQAAAlo"] [Sat Aug 29 05:06:12.131631 2026] [core:error] [pid 1017536:tid 1017725] [client 57.141.14.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:12.131647 2026] [core:error] [pid 1017536:tid 1017725] [client 57.141.14.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:12.133967 2026] [security2:error] [pid 1018003:tid 1018273] [client 4.205.62.107:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/xza.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwBQAABjE"] [Sat Aug 29 05:06:12.142118 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.196.209.81:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/goods.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwBgAABds"] [Sat Aug 29 05:06:12.153564 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.104.62:43028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/lufix1.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwCAAABhA"] [Sat Aug 29 05:06:12.155530 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.63.81.20:60503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwCQAABhY"] [Sat Aug 29 05:06:12.168900 2026] [security2:error] [pid 1017536:tid 1017783] [client 195.178.110.247:45530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lbttech.com"] [uri "/index.php"] [unique_id "apK9JCJcY4fy7tP-rU35rgAAAok"] [Sat Aug 29 05:06:12.172937 2026] [security2:error] [pid 1018003:tid 1018270] [client 103.171.189.88:53831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwCwAABi4"] [Sat Aug 29 05:06:12.173042 2026] [security2:error] [pid 1018003:tid 1018270] [client 103.171.189.88:53831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwCwAABi4"] [Sat Aug 29 05:06:12.176919 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.158.54.35:22295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/aa.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwDAAABjM"] [Sat Aug 29 05:06:12.182815 2026] [security2:error] [pid 1017536:tid 1017760] [client 4.205.62.107:53313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/7.php"] [unique_id "apK9JCJcY4fy7tP-rU35sAAAAnI"] [Sat Aug 29 05:06:12.213167 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.104.62:48464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/uuu.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwDQAABgc"] [Sat Aug 29 05:06:12.216943 2026] [security2:error] [pid 1018003:tid 1018206] [client 52.139.37.240:12516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/an.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwDgAABe8"] [Sat Aug 29 05:06:12.217337 2026] [security2:error] [pid 1018003:tid 1018165] [client 20.104.104.62:25658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwDwAABcY"] [Sat Aug 29 05:06:12.218764 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.197.61.180:17015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/about.php"] [unique_id "apK9JCJcY4fy7tP-rU35sQAAAiI"] [Sat Aug 29 05:06:12.225144 2026] [security2:error] [pid 1018003:tid 1018205] [client 20.220.204.93:64267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/shlo.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwEQAABe4"] [Sat Aug 29 05:06:12.227129 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.151.200.44:46572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/waf.php"] [unique_id "apK9JCJcY4fy7tP-rU35sgAAAkI"] [Sat Aug 29 05:06:12.235752 2026] [security2:error] [pid 1017536:tid 1017776] [client 40.83.93.50:22245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/admin-header.php"] [unique_id "apK9JCJcY4fy7tP-rU35swAAAoI"] [Sat Aug 29 05:06:12.236150 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.250.41:65101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9JCJcY4fy7tP-rU35tAAAAk4"] [Sat Aug 29 05:06:12.238678 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.52.41.200:1780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/403.php"] [unique_id "apK9JCJcY4fy7tP-rU35tQAAAmU"] [Sat Aug 29 05:06:12.248335 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.251.3:61213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/fff.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwEwAABjU"] [Sat Aug 29 05:06:12.251541 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.104.104.62:36957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/tanjiro.php"] [unique_id "apK9JCJcY4fy7tP-rU35uAAAAio"] [Sat Aug 29 05:06:12.277749 2026] [security2:error] [pid 1018003:tid 1018190] [client 66.248.203.2:54444] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2017/04/01/the-universe-is-speaking/"] [unique_id "apK9JDAh5Y1i2tUxg4HwFQAABd8"] [Sat Aug 29 05:06:12.284102 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.63.81.20:56951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwFgAABcI"] [Sat Aug 29 05:06:12.287795 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.104.62:56354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/hack.php"] [unique_id "apK9JCJcY4fy7tP-rU35ugAAAiA"] [Sat Aug 29 05:06:12.294724 2026] [security2:error] [pid 1017536:tid 1017722] [client 158.23.184.117:1058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/update/da222.php"] [unique_id "apK9JCJcY4fy7tP-rU35uwAAAkw"] [Sat Aug 29 05:06:12.295098 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.151.200.44:64939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/7h.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwFwAABgY"] [Sat Aug 29 05:06:12.296998 2026] [security2:error] [pid 1017536:tid 1017789] [client 158.23.147.79:26547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9JCJcY4fy7tP-rU35vAAAAo8"] [Sat Aug 29 05:06:12.353605 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.104.62:48680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/private.php"] [unique_id "apK9JCJcY4fy7tP-rU35vQAAAhs"] [Sat Aug 29 05:06:12.353916 2026] [security2:error] [pid 1018003:tid 1018195] [client 149.34.210.141:21996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwGAAABeQ"] [Sat Aug 29 05:06:12.353991 2026] [security2:error] [pid 1018003:tid 1018195] [client 149.34.210.141:21996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwGAAABeQ"] [Sat Aug 29 05:06:12.358904 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.151.200.44:46602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/bnnof6.php"] [unique_id "apK9JCJcY4fy7tP-rU35vgAAAnY"] [Sat Aug 29 05:06:12.378230 2026] [security2:error] [pid 1017536:tid 1017693] [client 20.48.251.3:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/autogooey.php"] [unique_id "apK9JCJcY4fy7tP-rU35vwAAAi8"] [Sat Aug 29 05:06:12.389956 2026] [security2:error] [pid 1017536:tid 1017780] [client 168.107.94.195:57118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9JCJcY4fy7tP-rU35wAAAAoY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:12.391182 2026] [security2:error] [pid 1018003:tid 1018236] [client 138.199.19.170:39510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9JDAh5Y1i2tUxg4HwGQAABgw"] [Sat Aug 29 05:06:12.395722 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.104.62:64713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/.well-known/.dha.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwGgAABcg"] [Sat Aug 29 05:06:12.395867 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.23.147.79:48270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/admin.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwGwAABcM"] [Sat Aug 29 05:06:12.405566 2026] [security2:error] [pid 1018003:tid 1018163] [client 52.139.37.240:12436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/asw.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwHAAABcQ"] [Sat Aug 29 05:06:12.411817 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:35799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/goods.php"] [unique_id "apK9JCJcY4fy7tP-rU35wQAAApI"] [Sat Aug 29 05:06:12.412919 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.104.104.62:25812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meterphoneusa.horseweblog.com"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "apK9JCJcY4fy7tP-rU35wgAAAl8"] [Sat Aug 29 05:06:12.415602 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.63.81.20:60489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apK9JCJcY4fy7tP-rU35wwAAAjo"] [Sat Aug 29 05:06:12.432820 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:18308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/.well-known/index.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwHQAABdc"] [Sat Aug 29 05:06:12.437571 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.250.41:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/06.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwHgAABf4"] [Sat Aug 29 05:06:12.437803 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.147.79:62619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/themes.php"] [unique_id "apK9JCJcY4fy7tP-rU35xAAAAi0"] [Sat Aug 29 05:06:12.438023 2026] [security2:error] [pid 1017536:tid 1017765] [client 4.205.62.107:22368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/cxc.php"] [unique_id "apK9JCJcY4fy7tP-rU35xQAAAnc"] [Sat Aug 29 05:06:12.438315 2026] [security2:error] [pid 1017536:tid 1017703] [client 158.23.184.117:1035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/xmr.php"] [unique_id "apK9JCJcY4fy7tP-rU35xgAAAjk"] [Sat Aug 29 05:06:12.475815 2026] [security2:error] [pid 1017536:tid 1017777] [client 158.23.147.79:30569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9JCJcY4fy7tP-rU35xwAAAoM"] [Sat Aug 29 05:06:12.483973 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.196.209.81:5211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK9JCJcY4fy7tP-rU35yAAAAj0"] [Sat Aug 29 05:06:12.502638 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.250.41:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/grsiuk.php"] [unique_id "apK9JCJcY4fy7tP-rU35ygAAAmQ"] [Sat Aug 29 05:06:12.508672 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.251.3:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/sdsa.php"] [unique_id "apK9JCJcY4fy7tP-rU35ywAAAls"] [Sat Aug 29 05:06:12.524516 2026] [security2:error] [pid 1017536:tid 1017773] [client 61.9.8.35:7285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9JCJcY4fy7tP-rU35yQAAAn8"] [Sat Aug 29 05:06:12.524660 2026] [security2:error] [pid 1017536:tid 1017773] [client 61.9.8.35:7285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9JCJcY4fy7tP-rU35yQAAAn8"] [Sat Aug 29 05:06:12.528458 2026] [security2:error] [pid 1017536:tid 1017723] [client 4.205.62.107:56034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/config_dev.php"] [unique_id "apK9JCJcY4fy7tP-rU35zAAAAk0"] [Sat Aug 29 05:06:12.543748 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.220.204.93:64938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/asax.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwHwAABek"] [Sat Aug 29 05:06:12.548067 2026] [security2:error] [pid 1018003:tid 1018150] [client 68.155.159.216:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwIAAABbc"] [Sat Aug 29 05:06:12.553910 2026] [security2:error] [pid 1018003:tid 1018207] [client 40.83.93.50:9556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/ggfi.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwIQAABfA"] [Sat Aug 29 05:06:12.554111 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.63.81.20:60467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwIgAABhM"] [Sat Aug 29 05:06:12.565139 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.196.209.81:16230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/hehe.php"] [unique_id "apK9JCJcY4fy7tP-rU35zQAAAnw"] [Sat Aug 29 05:06:12.565683 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.147.79:32738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/dropdown.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwIwAABhw"] [Sat Aug 29 05:06:12.577011 2026] [security2:error] [pid 1018003:tid 1018180] [client 158.23.147.79:25584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/lv.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwJAAABdU"] [Sat Aug 29 05:06:12.584120 2026] [security2:error] [pid 1018003:tid 1018173] [client 68.155.159.216:24528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwJQAABc4"] [Sat Aug 29 05:06:12.586425 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.23.184.117:1046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9JCJcY4fy7tP-rU35zgAAAnM"] [Sat Aug 29 05:06:12.603869 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.48.250.41:65031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/class.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwJgAABb4"] [Sat Aug 29 05:06:12.611008 2026] [security2:error] [pid 1018003:tid 1018233] [client 52.139.37.240:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/item.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwJwAABgk"] [Sat Aug 29 05:06:12.621200 2026] [security2:error] [pid 1017536:tid 1017684] [client 158.158.54.35:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/c.php"] [unique_id "apK9JCJcY4fy7tP-rU35zwAAAiY"] [Sat Aug 29 05:06:12.624991 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.48.251.3:14065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/config/laravolt/css/index.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwKAAABcw"] [Sat Aug 29 05:06:12.640412 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.251.3:62099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/sale.php"] [unique_id "apK9JCJcY4fy7tP-rU350AAAAoE"] [Sat Aug 29 05:06:12.658918 2026] [security2:error] [pid 1018003:tid 1018251] [client 20.48.250.41:62568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wp-scr1pts.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwKQAABhs"] [Sat Aug 29 05:06:12.683835 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.63.81.20:60462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/650.php"] [unique_id "apK9JCJcY4fy7tP-rU350QAAAnI"] [Sat Aug 29 05:06:12.693526 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.52.41.200:1218] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpsl-ggc.org"] [uri "/1.php"] [unique_id "apK9JCJcY4fy7tP-rU350gAAAkE"] [Sat Aug 29 05:06:12.693609 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.52.41.200:1218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/1.php"] [unique_id "apK9JCJcY4fy7tP-rU350gAAAkE"] [Sat Aug 29 05:06:12.702442 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.220.204.93:64909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/fetch.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwLwAABdQ"] [Sat Aug 29 05:06:12.732162 2026] [security2:error] [pid 1018003:tid 1018240] [client 138.199.19.170:39520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9JDAh5Y1i2tUxg4HwMAAABhA"] [Sat Aug 29 05:06:12.736472 2026] [security2:error] [pid 1018003:tid 1018170] [client 158.23.184.117:1413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-act.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwMQAABcs"] [Sat Aug 29 05:06:12.744347 2026] [security2:error] [pid 1018003:tid 1018203] [client 40.83.93.50:12479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/admin.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwMgAABew"] [Sat Aug 29 05:06:12.746472 2026] [security2:error] [pid 1017536:tid 1017751] [client 158.23.147.79:50139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9JCJcY4fy7tP-rU351gAAAmk"] [Sat Aug 29 05:06:12.769321 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.251.3:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-class.php"] [unique_id "apK9JCJcY4fy7tP-rU352QAAAnk"] [Sat Aug 29 05:06:12.771810 2026] [security2:error] [pid 1017536:tid 1017719] [client 168.107.94.195:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9JCJcY4fy7tP-rU352gAAAkk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:12.782419 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.250.41:64325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/8.php"] [unique_id "apK9JCJcY4fy7tP-rU352wAAAmA"] [Sat Aug 29 05:06:12.809972 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.63.81.20:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/nakrip.php"] [unique_id "apK9JCJcY4fy7tP-rU353AAAAlc"] [Sat Aug 29 05:06:12.815596 2026] [security2:error] [pid 1017536:tid 1017748] [client 52.139.37.240:12532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/jga.php"] [unique_id "apK9JCJcY4fy7tP-rU353QAAAmY"] [Sat Aug 29 05:06:12.854624 2026] [security2:error] [pid 1017536:tid 1017741] [client 20.220.204.93:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/vx.php"] [unique_id "apK9JCJcY4fy7tP-rU353gAAAl8"] [Sat Aug 29 05:06:12.863927 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:51479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/about.php"] [unique_id "apK9JCJcY4fy7tP-rU353wAAAjo"] [Sat Aug 29 05:06:12.873401 2026] [security2:error] [pid 1018003:tid 1018231] [client 68.155.159.216:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwMwAABgc"] [Sat Aug 29 05:06:12.879996 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.196.209.81:5199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-blog-header.php"] [unique_id "apK9JCJcY4fy7tP-rU354QAAAmE"] [Sat Aug 29 05:06:12.881520 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.184.117:1026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/fff.php"] [unique_id "apK9JCJcY4fy7tP-rU354gAAApA"] [Sat Aug 29 05:06:12.882563 2026] [security2:error] [pid 1017536:tid 1017703] [client 68.155.159.216:9217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/file5.php"] [unique_id "apK9JCJcY4fy7tP-rU354wAAAjk"] [Sat Aug 29 05:06:12.898103 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.48.251.3:61210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/database.php"] [unique_id "apK9JCJcY4fy7tP-rU355AAAAmw"] [Sat Aug 29 05:06:12.919918 2026] [security2:error] [pid 1018003:tid 1018196] [client 68.155.159.216:50210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwNQAABeU"] [Sat Aug 29 05:06:12.935776 2026] [security2:error] [pid 1017536:tid 1017685] [client 4.205.62.107:64998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aquaink.net"] [uri "/wp-act.php"] [unique_id "apK9JCJcY4fy7tP-rU355QAAAic"] [Sat Aug 29 05:06:12.939118 2026] [security2:error] [pid 1017536:tid 1017716] [client 20.63.81.20:60504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apK9JCJcY4fy7tP-rU355gAAAkY"] [Sat Aug 29 05:06:12.945849 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.197.61.180:16993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/admin-header.php"] [unique_id "apK9JCJcY4fy7tP-rU355wAAAjE"] [Sat Aug 29 05:06:12.968886 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.196.209.81:11571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/wp-admin/class-db.php"] [unique_id "apK9JDAh5Y1i2tUxg4HwNgAABhg"] [Sat Aug 29 05:06:13.010437 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.220.204.93:64318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/global.php"] [unique_id "apK9JSJcY4fy7tP-rU356QAAAms"] [Sat Aug 29 05:06:13.014791 2026] [security2:error] [pid 1017536:tid 1017746] [client 52.139.37.240:12500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/mac.php"] [unique_id "apK9JSJcY4fy7tP-rU356gAAAmQ"] [Sat Aug 29 05:06:13.026122 2026] [security2:error] [pid 1017536:tid 1017723] [client 158.23.184.117:1079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/.tmb/dropdown.php"] [unique_id "apK9JSJcY4fy7tP-rU356wAAAk0"] [Sat Aug 29 05:06:13.028035 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:61068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/atex1.php"] [unique_id "apK9JSJcY4fy7tP-rU357AAAAjw"] [Sat Aug 29 05:06:13.062676 2026] [security2:error] [pid 1017536:tid 1017705] [client 138.199.19.170:39528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9JSJcY4fy7tP-rU357gAAAjs"] [Sat Aug 29 05:06:13.062774 2026] [security2:error] [pid 1017536:tid 1017709] [client 40.83.93.50:16634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/alfa-rex.php"] [unique_id "apK9JSJcY4fy7tP-rU357QAAAj8"] [Sat Aug 29 05:06:13.066229 2026] [security2:error] [pid 1018003:tid 1018269] [client 158.158.54.35:7908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/f.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwNwAABi0"] [Sat Aug 29 05:06:13.070442 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.63.81.20:56858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/xcc.php"] [unique_id "apK9JSJcY4fy7tP-rU357wAAAlo"] [Sat Aug 29 05:06:13.072991 2026] [security2:error] [pid 1017536:tid 1017725] [client 158.23.147.79:30687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9JSJcY4fy7tP-rU358AAAAk8"] [Sat Aug 29 05:06:13.152125 2026] [cgid:error] [pid 1018003:tid 1018166] [client 20.52.41.200:1234] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:13.155443 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.251.3:61193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws_sdk_settings.php"] [unique_id "apK9JSJcY4fy7tP-rU358QAAAm8"] [Sat Aug 29 05:06:13.170017 2026] [security2:error] [pid 1017536:tid 1017708] [client 158.23.184.117:1085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/robots.php"] [unique_id "apK9JSJcY4fy7tP-rU358gAAAj4"] [Sat Aug 29 05:06:13.175474 2026] [security2:error] [pid 1018003:tid 1018195] [client 168.107.94.195:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwOQAABeQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:13.184052 2026] [security2:error] [pid 1017536:tid 1017696] [client 4.205.62.107:21825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/gjm.php"] [unique_id "apK9JSJcY4fy7tP-rU358wAAAjI"] [Sat Aug 29 05:06:13.204412 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.63.81.20:56919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwOgAABh8"] [Sat Aug 29 05:06:13.217477 2026] [security2:error] [pid 1017536:tid 1017769] [client 40.83.93.50:22253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK9JSJcY4fy7tP-rU359AAAAns"] [Sat Aug 29 05:06:13.218629 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.220.204.93:64912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/fs.php"] [unique_id "apK9JSJcY4fy7tP-rU359QAAAoI"] [Sat Aug 29 05:06:13.218932 2026] [security2:error] [pid 1017536:tid 1017711] [client 52.139.37.240:12417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9JSJcY4fy7tP-rU359gAAAkE"] [Sat Aug 29 05:06:13.260977 2026] [security2:error] [pid 1018003:tid 1018167] [client 4.205.62.107:22260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/packed.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwOwAABcg"] [Sat Aug 29 05:06:13.274973 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.196.209.81:5247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-blogs.php"] [unique_id "apK9JSJcY4fy7tP-rU35-gAAAoo"] [Sat Aug 29 05:06:13.281342 2026] [security2:error] [pid 1018003:tid 1018163] [client 4.205.62.107:65500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ms-edit.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwPAAABcQ"] [Sat Aug 29 05:06:13.284436 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.251.3:61647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/setup-config.php"] [unique_id "apK9JSJcY4fy7tP-rU35-wAAAmA"] [Sat Aug 29 05:06:13.302146 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.52.41.200:1234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/s.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwPQAABdc"] [Sat Aug 29 05:06:13.313382 2026] [security2:error] [pid 1017536:tid 1017731] [client 158.23.184.117:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/.well-known/install.php"] [unique_id "apK9JSJcY4fy7tP-rU35_QAAAlU"] [Sat Aug 29 05:06:13.320814 2026] [security2:error] [pid 1017536:tid 1017788] [client 65.111.27.152:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9JSJcY4fy7tP-rU35_AAAAo4"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:13.335666 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.205.62.107:53397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "apK9JSJcY4fy7tP-rU36AAAAAlY"] [Sat Aug 29 05:06:13.345320 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.81.20:60419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apK9JSJcY4fy7tP-rU36AQAAAkc"] [Sat Aug 29 05:06:13.360373 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.251.3:14062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/87.php"] [unique_id "apK9JSJcY4fy7tP-rU36BAAAAmY"] [Sat Aug 29 05:06:13.363629 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.196.209.81:4450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/wp-contentt.php"] [unique_id "apK9JSJcY4fy7tP-rU36BQAAAmk"] [Sat Aug 29 05:06:13.401341 2026] [security2:error] [pid 1017536:tid 1017741] [client 138.199.19.170:39544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK9JSJcY4fy7tP-rU36BgAAAl8"] [Sat Aug 29 05:06:13.414691 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.251.3:61203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-admin/sc.php"] [unique_id "apK9JSJcY4fy7tP-rU36BwAAAoc"] [Sat Aug 29 05:06:13.420317 2026] [security2:error] [pid 1017536:tid 1017720] [client 52.139.37.240:12522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9JSJcY4fy7tP-rU36CAAAAko"] [Sat Aug 29 05:06:13.473965 2026] [security2:error] [pid 1017536:tid 1017754] [client 20.63.81.20:56897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-settings.php"] [unique_id "apK9JSJcY4fy7tP-rU36CgAAAmw"] [Sat Aug 29 05:06:13.477709 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.220.204.93:64965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ioxi.php"] [unique_id "apK9JSJcY4fy7tP-rU36DAAAAkA"] [Sat Aug 29 05:06:13.504702 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.184.117:1418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-admin/about.php"] [unique_id "apK9JSJcY4fy7tP-rU36DgAAAls"] [Sat Aug 29 05:06:13.522732 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.158.54.35:16029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/av.php"] [unique_id "apK9JSJcY4fy7tP-rU36EAAAAoY"] [Sat Aug 29 05:06:13.533572 2026] [security2:error] [pid 1017536:tid 1017687] [client 158.23.147.79:35804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9JSJcY4fy7tP-rU36EQAAAik"] [Sat Aug 29 05:06:13.542581 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.251.3:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/debug.php"] [unique_id "apK9JSJcY4fy7tP-rU36EgAAAk0"] [Sat Aug 29 05:06:13.544922 2026] [security2:error] [pid 1017536:tid 1017706] [client 68.155.159.216:18277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9JSJcY4fy7tP-rU36EwAAAjw"] [Sat Aug 29 05:06:13.549247 2026] [security2:error] [pid 1018003:tid 1018225] [client 40.83.93.50:7747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/cookie.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwQQAABgI"] [Sat Aug 29 05:06:13.556739 2026] [security2:error] [pid 1017536:tid 1017668] [client 158.23.147.79:62978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-mail.php"] [unique_id "apK9JSJcY4fy7tP-rU36FQAAAhY"] [Sat Aug 29 05:06:13.566828 2026] [security2:error] [pid 1017536:tid 1017747] [client 168.107.94.195:58364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9JSJcY4fy7tP-rU36FgAAAmU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:13.573981 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.23.184.117:1064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/update/da222.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwRAAABhM"] [Sat Aug 29 05:06:13.580126 2026] [security2:error] [pid 1017536:tid 1017729] [client 4.205.62.107:22332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/oiko6u.php"] [unique_id "apK9JSJcY4fy7tP-rU36FwAAAlM"] [Sat Aug 29 05:06:13.580292 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.147.79:30556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/classwithtostring.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwRQAABhw"] [Sat Aug 29 05:06:13.612312 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.63.81.20:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-signup.php"] [unique_id "apK9JSJcY4fy7tP-rU36GAAAAok"] [Sat Aug 29 05:06:13.616901 2026] [security2:error] [pid 1017536:tid 1017761] [client 52.139.37.240:12872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/zafir1.php"] [unique_id "apK9JSJcY4fy7tP-rU36GQAAAnM"] [Sat Aug 29 05:06:13.648991 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.23.184.117:1087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/backup.php"] [unique_id "apK9JSJcY4fy7tP-rU36GgAAAjQ"] [Sat Aug 29 05:06:13.663237 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.23.147.79:32653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/.well-known/index.php"] [unique_id "apK9JSJcY4fy7tP-rU36GwAAAm8"] [Sat Aug 29 05:06:13.670303 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.220.204.93:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/bootstrap.php"] [unique_id "apK9JSJcY4fy7tP-rU36HAAAAjI"] [Sat Aug 29 05:06:13.670336 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.196.209.81:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-comments-post.php"] [unique_id "apK9JSJcY4fy7tP-rU36HQAAAnw"] [Sat Aug 29 05:06:13.671032 2026] [security2:error] [pid 1017536:tid 1017672] [client 4.205.62.107:56031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/aws_credentials.php"] [unique_id "apK9JSJcY4fy7tP-rU36HgAAAho"] [Sat Aug 29 05:06:13.671369 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.48.251.3:61095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/nzv.php"] [unique_id "apK9JSJcY4fy7tP-rU36HwAAAiI"] [Sat Aug 29 05:06:13.671845 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.197.61.180:13032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/admin.php"] [unique_id "apK9JSJcY4fy7tP-rU36IAAAAmE"] [Sat Aug 29 05:06:13.680050 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.251.3:13995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/plss3.php"] [unique_id "apK9JSJcY4fy7tP-rU36IQAAAoI"] [Sat Aug 29 05:06:13.683471 2026] [security2:error] [pid 1017536:tid 1017688] [client 158.23.147.79:25545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9JSJcY4fy7tP-rU36IgAAAio"] [Sat Aug 29 05:06:13.687678 2026] [security2:error] [pid 1017536:tid 1017694] [client 68.155.159.216:24514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/asd.php"] [unique_id "apK9JSJcY4fy7tP-rU36IwAAAjA"] [Sat Aug 29 05:06:13.703076 2026] [security2:error] [pid 1017536:tid 1017746] [client 40.83.93.50:12440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK9JSJcY4fy7tP-rU36JAAAAmQ"] [Sat Aug 29 05:06:13.721562 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.23.184.117:1080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/xmr.php"] [unique_id "apK9JSJcY4fy7tP-rU36JQAAAkI"] [Sat Aug 29 05:06:13.740274 2026] [security2:error] [pid 1018003:tid 1018226] [client 192.145.125.70:52260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK9JTAh5Y1i2tUxg4HwSAAABgM"] [Sat Aug 29 05:06:13.742220 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.63.81.20:56917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-conffg.php"] [unique_id "apK9JSJcY4fy7tP-rU36JgAAAos"] [Sat Aug 29 05:06:13.746734 2026] [security2:error] [pid 1017536:tid 1017689] [client 138.199.19.170:39546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9JSJcY4fy7tP-rU36JwAAAis"] [Sat Aug 29 05:06:13.757995 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.52.41.200:1162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/test1.php"] [unique_id "apK9JSJcY4fy7tP-rU36KAAAAig"] [Sat Aug 29 05:06:13.794647 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.184.117:1068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/.well-known/aa.php"] [unique_id "apK9JSJcY4fy7tP-rU36KwAAAhs"] [Sat Aug 29 05:06:13.799519 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.251.3:3328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/66.php"] [unique_id "apK9JSJcY4fy7tP-rU36LAAAAjo"] [Sat Aug 29 05:06:13.806863 2026] [security2:error] [pid 1017536:tid 1017708] [client 20.196.209.81:16202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/theme.php"] [unique_id "apK9JSJcY4fy7tP-rU36LQAAAj4"] [Sat Aug 29 05:06:13.813170 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.48.250.41:59391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/num.php"] [unique_id "apK9JSJcY4fy7tP-rU36LgAAAi0"] [Sat Aug 29 05:06:13.814783 2026] [security2:error] [pid 1017536:tid 1017764] [client 52.139.37.240:12870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/abc.php"] [unique_id "apK9JSJcY4fy7tP-rU36LwAAAnY"] [Sat Aug 29 05:06:13.861789 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.147.79:49817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/packed.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwSQAABbo"] [Sat Aug 29 05:06:13.866599 2026] [security2:error] [pid 1017536:tid 1017740] [client 158.23.184.117:1043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9JSJcY4fy7tP-rU36MQAAAl4"] [Sat Aug 29 05:06:13.877215 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.63.81.20:56922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-validate.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwSgAABcw"] [Sat Aug 29 05:06:13.886132 2026] [security2:error] [pid 1017536:tid 1017670] [client 20.48.251.3:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aws.php"] [unique_id "apK9JSJcY4fy7tP-rU36NAAAAhg"] [Sat Aug 29 05:06:13.900999 2026] [security2:error] [pid 1017536:tid 1017734] [client 209.50.170.5:28169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.170.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9JSJcY4fy7tP-rU36MgAAAlg"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:13.918396 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.48.250.41:65027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/0x0x.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwSwAABiE"] [Sat Aug 29 05:06:13.931617 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.48.251.3:61690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/admin.php"] [unique_id "apK9JTAh5Y1i2tUxg4HwTAAABgo"] [Sat Aug 29 05:06:13.938462 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.220.204.93:64960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/export.php"] [unique_id "apK9JSJcY4fy7tP-rU36NQAAAnk"] [Sat Aug 29 05:06:13.947353 2026] [security2:error] [pid 1017536:tid 1017723] [client 168.107.94.195:58668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9JSJcY4fy7tP-rU36NgAAAk0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:13.956843 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.158.54.35:16060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/file.php"] [unique_id "apK9JSJcY4fy7tP-rU36NwAAAmc"] [Sat Aug 29 05:06:13.968581 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.184.117:1467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9JSJcY4fy7tP-rU36OAAAAks"] [Sat Aug 29 05:06:13.972333 2026] [security2:error] [pid 1017536:tid 1017668] [client 68.155.159.216:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/index.php"] [unique_id "apK9JSJcY4fy7tP-rU36OQAAAhY"] [Sat Aug 29 05:06:13.974809 2026] [security2:error] [pid 1017536:tid 1017725] [client 68.155.159.216:14248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9JSJcY4fy7tP-rU36OgAAAk8"] [Sat Aug 29 05:06:13.979473 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.48.250.41:62543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/a4.php"] [unique_id "apK9JSJcY4fy7tP-rU36OwAAAmU"] [Sat Aug 29 05:06:13.981108 2026] [security2:error] [pid 1017536:tid 1017729] [client 68.155.159.216:51210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9JSJcY4fy7tP-rU36PAAAAlM"] [Sat Aug 29 05:06:14.011485 2026] [security2:error] [pid 1017536:tid 1017687] [client 52.139.37.240:12902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/c1.php"] [unique_id "apK9JiJcY4fy7tP-rU36PwAAAik"] [Sat Aug 29 05:06:14.012515 2026] [security2:error] [pid 1017536:tid 1017684] [client 20.63.81.20:60463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/700.php"] [unique_id "apK9JiJcY4fy7tP-rU36QAAAAiY"] [Sat Aug 29 05:06:14.018210 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.184.117:1372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-act.php"] [unique_id "apK9JiJcY4fy7tP-rU36QQAAAlo"] [Sat Aug 29 05:06:14.024921 2026] [security2:error] [pid 1017536:tid 1017775] [client 68.155.159.216:50317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/about.php"] [unique_id "apK9JiJcY4fy7tP-rU36QgAAAoE"] [Sat Aug 29 05:06:14.047834 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.23.147.79:54378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9JiJcY4fy7tP-rU36QwAAAjI"] [Sat Aug 29 05:06:14.061960 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.251.3:61241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/png.php"] [unique_id "apK9JiJcY4fy7tP-rU36RAAAAho"] [Sat Aug 29 05:06:14.065775 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.196.209.81:5185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-config.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwTgAABjE"] [Sat Aug 29 05:06:14.068120 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:65149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/166.php"] [unique_id "apK9JiJcY4fy7tP-rU36RQAAAmE"] [Sat Aug 29 05:06:14.076272 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.251.3:13980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/app.default.php"] [unique_id "apK9JiJcY4fy7tP-rU36RgAAAkE"] [Sat Aug 29 05:06:14.099388 2026] [security2:error] [pid 1018003:tid 1018150] [client 111.235.68.106:1395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwUAAABbc"] [Sat Aug 29 05:06:14.099501 2026] [security2:error] [pid 1018003:tid 1018150] [client 111.235.68.106:1395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwUAAABbc"] [Sat Aug 29 05:06:14.101617 2026] [security2:error] [pid 1018003:tid 1018189] [client 138.199.19.170:47900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9JjAh5Y1i2tUxg4HwUQAABd4"] [Sat Aug 29 05:06:14.102001 2026] [security2:error] [pid 1018003:tid 1018216] [client 40.83.93.50:9562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/NewFile.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwUgAABfk"] [Sat Aug 29 05:06:14.113064 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.184.117:1431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwUwAABhA"] [Sat Aug 29 05:06:14.115192 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.250.41:62522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/tfm.php"] [unique_id "apK9JiJcY4fy7tP-rU36RwAAAmA"] [Sat Aug 29 05:06:14.134707 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.220.204.93:63829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/gk.php"] [unique_id "apK9JiJcY4fy7tP-rU36SAAAAkc"] [Sat Aug 29 05:06:14.143594 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.63.81.20:56937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/c4.php"] [unique_id "apK9JiJcY4fy7tP-rU36SgAAAmY"] [Sat Aug 29 05:06:14.150660 2026] [security2:error] [pid 1017536:tid 1017773] [client 103.162.125.59:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9JiJcY4fy7tP-rU36SQAAAn8"] [Sat Aug 29 05:06:14.150739 2026] [security2:error] [pid 1017536:tid 1017773] [client 103.162.125.59:53036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9JiJcY4fy7tP-rU36SQAAAn8"] [Sat Aug 29 05:06:14.159686 2026] [security2:error] [pid 1018003:tid 1018170] [client 68.155.159.216:51541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/lock.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwVAAABcs"] [Sat Aug 29 05:06:14.161770 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.184.117:1354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/fff.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwVQAABfU"] [Sat Aug 29 05:06:14.181424 2026] [security2:error] [pid 1018003:tid 1018270] [client 158.23.147.79:30677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/install.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwVgAABi4"] [Sat Aug 29 05:06:14.189386 2026] [security2:error] [pid 1017536:tid 1017760] [client 40.83.93.50:5899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9JiJcY4fy7tP-rU36SwAAAnI"] [Sat Aug 29 05:06:14.190710 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.48.251.3:61223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/chosen.php"] [unique_id "apK9JiJcY4fy7tP-rU36TAAAAnY"] [Sat Aug 29 05:06:14.200369 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.196.209.81:16767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/alumni_reg.php"] [unique_id "apK9JiJcY4fy7tP-rU36TQAAAns"] [Sat Aug 29 05:06:14.206009 2026] [security2:error] [pid 1017536:tid 1017686] [client 52.139.37.240:12514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/index.php/feed/atom/"] [unique_id "apK9JiJcY4fy7tP-rU36TgAAAig"] [Sat Aug 29 05:06:14.206427 2026] [security2:error] [pid 1017536:tid 1017710] [client 158.23.147.79:24513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9JiJcY4fy7tP-rU36TwAAAkA"] [Sat Aug 29 05:06:14.207650 2026] [security2:error] [pid 1018003:tid 1018106] [remote 162.241.144.20:34468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.144.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sitestage.biz"] [uri "/wp-login.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwVwAGIlU"] [Sat Aug 29 05:06:14.209978 2026] [http2:warn] [pid 1017536:tid 1017791] [client 57.141.14.6:58642] h2_stream(1017536-30-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:06:14.213279 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.52.41.200:1233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/ws.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwWAAABhY"] [Sat Aug 29 05:06:14.262805 2026] [core:error] [pid 1017536:tid 1017681] [client 193.189.100.204:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:14.262824 2026] [core:error] [pid 1017536:tid 1017681] [client 193.189.100.204:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:14.272482 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.63.81.20:56841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-tymanage.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwXAAABec"] [Sat Aug 29 05:06:14.294929 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.220.204.93:64288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/logs1.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwXgAABeg"] [Sat Aug 29 05:06:14.305225 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.184.117:1412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/test.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwXwAABfs"] [Sat Aug 29 05:06:14.305635 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.184.117:1429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9JiJcY4fy7tP-rU36VQAAAj0"] [Sat Aug 29 05:06:14.324713 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.251.3:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/admin-ajax.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwYgAABeU"] [Sat Aug 29 05:06:14.328598 2026] [security2:error] [pid 1018003:tid 1018239] [client 168.107.94.195:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwZAAABg8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:14.335370 2026] [security2:error] [pid 1017536:tid 1017789] [client 4.205.62.107:22264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apK9JiJcY4fy7tP-rU36VwAAAo8"] [Sat Aug 29 05:06:14.337913 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.251.3:13982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/app_local.php"] [unique_id "apK9JiJcY4fy7tP-rU36WAAAAmg"] [Sat Aug 29 05:06:14.351863 2026] [security2:error] [pid 1017536:tid 1017770] [client 192.145.125.70:48028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.125.145.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/xmlrpc.php"] [unique_id "apK9JiJcY4fy7tP-rU36WgAAAnw"] [Sat Aug 29 05:06:14.396418 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.197.61.180:6054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwZgAABbw"] [Sat Aug 29 05:06:14.398289 2026] [security2:error] [pid 1017536:tid 1017705] [client 4.205.62.107:22342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/phpi.php"] [unique_id "apK9JiJcY4fy7tP-rU36WwAAAjs"] [Sat Aug 29 05:06:14.404637 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.63.81.20:60490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/ajfto.php"] [unique_id "apK9JiJcY4fy7tP-rU36XAAAAhY"] [Sat Aug 29 05:06:14.406287 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.158.54.35:8652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9JiJcY4fy7tP-rU36XQAAAow"] [Sat Aug 29 05:06:14.409119 2026] [security2:error] [pid 1017536:tid 1017729] [client 4.205.62.107:65444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/lmfi2.php"] [unique_id "apK9JiJcY4fy7tP-rU36XgAAAlM"] [Sat Aug 29 05:06:14.410264 2026] [security2:error] [pid 1018003:tid 1018217] [client 52.139.37.240:12429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/root.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwZwAABfo"] [Sat Aug 29 05:06:14.440722 2026] [security2:error] [pid 1018003:tid 1018197] [client 138.199.19.170:47912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9JjAh5Y1i2tUxg4HwaAAABeY"] [Sat Aug 29 05:06:14.451718 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.184.117:1466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/mani.php"] [unique_id "apK9JiJcY4fy7tP-rU36YQAAAks"] [Sat Aug 29 05:06:14.453770 2026] [security2:error] [pid 1017536:tid 1017725] [client 158.23.184.117:1427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/robots.php"] [unique_id "apK9JiJcY4fy7tP-rU36YgAAAk8"] [Sat Aug 29 05:06:14.453795 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.48.251.3:61088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ms.php"] [unique_id "apK9JiJcY4fy7tP-rU36YwAAAok"] [Sat Aug 29 05:06:14.475362 2026] [security2:error] [pid 1017536:tid 1017757] [client 4.205.62.107:53402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/app.default.php"] [unique_id "apK9JiJcY4fy7tP-rU36ZAAAAm8"] [Sat Aug 29 05:06:14.489997 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.196.209.81:15040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-configs.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwaQAABcI"] [Sat Aug 29 05:06:14.509174 2026] [security2:error] [pid 1017536:tid 1017752] [client 158.23.147.79:48298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/xmlrpc.php"] [unique_id "apK9JiJcY4fy7tP-rU36ZQAAAmo"] [Sat Aug 29 05:06:14.531476 2026] [security2:error] [pid 1018003:tid 1018174] [client 65.111.24.162:32625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwawAABc8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:14.535364 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.63.81.20:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apK9JiJcY4fy7tP-rU36ZgAAAjA"] [Sat Aug 29 05:06:14.559266 2026] [security2:error] [pid 1018003:tid 1018242] [client 158.23.147.79:26526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwbAAABhI"] [Sat Aug 29 05:06:14.579860 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.251.3:62105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/fucku.php"] [unique_id "apK9JiJcY4fy7tP-rU36ZwAAAmM"] [Sat Aug 29 05:06:14.580661 2026] [security2:error] [pid 1017536:tid 1017687] [client 40.83.93.50:7781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/config.php"] [unique_id "apK9JiJcY4fy7tP-rU36aAAAAik"] [Sat Aug 29 05:06:14.582950 2026] [security2:error] [pid 1017536:tid 1017678] [client 68.155.159.216:33692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/makeasmtp.php"] [unique_id "apK9JiJcY4fy7tP-rU36aQAAAiA"] [Sat Aug 29 05:06:14.593676 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.220.204.93:63819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/inege.php"] [unique_id "apK9JiJcY4fy7tP-rU36agAAAkM"] [Sat Aug 29 05:06:14.595190 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.184.117:1405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/Test.php"] [unique_id "apK9JiJcY4fy7tP-rU36awAAAiU"] [Sat Aug 29 05:06:14.595241 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.196.209.81:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/colors.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwbQAABcg"] [Sat Aug 29 05:06:14.599753 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.104.49.130:63578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/abcd.php"] [unique_id "apK9JiJcY4fy7tP-rU36bAAAAmA"] [Sat Aug 29 05:06:14.601507 2026] [security2:error] [pid 1017536:tid 1017669] [client 158.23.184.117:1417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/.well-known/install.php"] [unique_id "apK9JiJcY4fy7tP-rU36bQAAAhc"] [Sat Aug 29 05:06:14.603352 2026] [security2:error] [pid 1017536:tid 1017790] [client 52.139.37.240:12496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/shell.php"] [unique_id "apK9JiJcY4fy7tP-rU36bgAAApA"] [Sat Aug 29 05:06:14.658078 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.52.41.200:1164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-themes.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwbgAABf4"] [Sat Aug 29 05:06:14.658157 2026] [security2:error] [pid 1018003:tid 1018182] [client 40.83.93.50:5929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/config.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwbwAABdc"] [Sat Aug 29 05:06:14.669368 2026] [security2:error] [pid 1018003:tid 1018066] [remote 52.167.144.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwcAAGHC0"] [Sat Aug 29 05:06:14.676153 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.63.81.20:60441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apK9JiJcY4fy7tP-rU36cAAAAoc"] [Sat Aug 29 05:06:14.693601 2026] [security2:error] [pid 1018003:tid 1018173] [client 158.23.147.79:30647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwcgAABc4"] [Sat Aug 29 05:06:14.703399 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.48.251.3:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/error_log.php"] [unique_id "apK9JiJcY4fy7tP-rU36cQAAAnI"] [Sat Aug 29 05:06:14.708079 2026] [security2:error] [pid 1017536:tid 1017764] [client 168.107.94.195:59406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9JiJcY4fy7tP-rU36cgAAAnY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:14.715682 2026] [security2:error] [pid 1017536:tid 1017754] [client 158.23.147.79:35836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9JiJcY4fy7tP-rU36cwAAAmw"] [Sat Aug 29 05:06:14.717333 2026] [security2:error] [pid 1017536:tid 1017777] [client 4.205.62.107:22322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/fraro.php"] [unique_id "apK9JiJcY4fy7tP-rU36dAAAAoM"] [Sat Aug 29 05:06:14.742646 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.184.117:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/pomo.php"] [unique_id "apK9JiJcY4fy7tP-rU36dgAAAi0"] [Sat Aug 29 05:06:14.749787 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.147.79:63039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/cgi-bin/index.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwdAAABgM"] [Sat Aug 29 05:06:14.772675 2026] [security2:error] [pid 1017536:tid 1017720] [client 158.23.147.79:32737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9JiJcY4fy7tP-rU36eAAAAko"] [Sat Aug 29 05:06:14.791693 2026] [security2:error] [pid 1017536:tid 1017767] [client 138.199.19.170:47914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK9JiJcY4fy7tP-rU36ewAAAnk"] [Sat Aug 29 05:06:14.793184 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.147.79:25519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/content.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwdQAABiY"] [Sat Aug 29 05:06:14.795726 2026] [security2:error] [pid 1018003:tid 1018274] [client 158.23.184.117:1409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-admin/about.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwdwAABjI"] [Sat Aug 29 05:06:14.808991 2026] [security2:error] [pid 1018003:tid 1018251] [client 4.205.62.107:55983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/aws-credentials.php"] [unique_id "apK9JjAh5Y1i2tUxg4HweAAABhs"] [Sat Aug 29 05:06:14.811397 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.63.81.20:60421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apK9JiJcY4fy7tP-rU36fQAAAk0"] [Sat Aug 29 05:06:14.813391 2026] [security2:error] [pid 1017536:tid 1017670] [client 52.139.37.240:12883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9JiJcY4fy7tP-rU36fwAAAhg"] [Sat Aug 29 05:06:14.827165 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:61675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/phina.php"] [unique_id "apK9JiJcY4fy7tP-rU36gQAAAjw"] [Sat Aug 29 05:06:14.838428 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.220.204.93:65020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wp-link10.php"] [unique_id "apK9JiJcY4fy7tP-rU36ggAAAmc"] [Sat Aug 29 05:06:14.846694 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.48.251.3:14003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/ws62.php"] [unique_id "apK9JjAh5Y1i2tUxg4HweQAABdQ"] [Sat Aug 29 05:06:14.859315 2026] [security2:error] [pid 1017536:tid 1017769] [client 158.158.54.35:22301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/gmo.php"] [unique_id "apK9JiJcY4fy7tP-rU36gwAAAns"] [Sat Aug 29 05:06:14.883598 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.196.209.81:5598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-conflg.php"] [unique_id "apK9JiJcY4fy7tP-rU36hgAAAiM"] [Sat Aug 29 05:06:14.945788 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.23.184.117:1363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/backup.php"] [unique_id "apK9JjAh5Y1i2tUxg4HwewAABiw"] [Sat Aug 29 05:06:14.947308 2026] [security2:error] [pid 1018003:tid 1018200] [client 192.145.125.70:48040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9JjAh5Y1i2tUxg4HwfAAABek"] [Sat Aug 29 05:06:14.954998 2026] [security2:error] [pid 1017536:tid 1017725] [client 20.48.251.3:61070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/koiy.php"] [unique_id "apK9JiJcY4fy7tP-rU36igAAAk8"] [Sat Aug 29 05:06:14.957197 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.63.81.20:60525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-mini.php"] [unique_id "apK9JiJcY4fy7tP-rU36iwAAAnM"] [Sat Aug 29 05:06:14.992226 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.49.130:51339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/100.php"] [unique_id "apK9JiJcY4fy7tP-rU36jAAAAjI"] [Sat Aug 29 05:06:14.994527 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.220.204.93:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ww.php"] [unique_id "apK9JiJcY4fy7tP-rU36jQAAAho"] [Sat Aug 29 05:06:14.999813 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.184.117:1666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-admin/link-add.php"] [unique_id "apK9JiJcY4fy7tP-rU36jwAAAmE"] [Sat Aug 29 05:06:15.004237 2026] [security2:error] [pid 1017536:tid 1017731] [client 213.202.253.4:51133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/schallfuns.php"] [unique_id "apK9JyJcY4fy7tP-rU36kAAAAlU"], referer: www.google.com [Sat Aug 29 05:06:15.007701 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.104.49.130:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/red.php"] [unique_id "apK9JyJcY4fy7tP-rU36kQAAAkw"] [Sat Aug 29 05:06:15.019747 2026] [security2:error] [pid 1017536:tid 1017711] [client 68.155.159.216:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/goat.php"] [unique_id "apK9JyJcY4fy7tP-rU36kgAAAkE"] [Sat Aug 29 05:06:15.019826 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.196.209.81:16761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/Js.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwfQAABgE"] [Sat Aug 29 05:06:15.026826 2026] [security2:error] [pid 1017536:tid 1017775] [client 52.139.37.240:12494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK9JyJcY4fy7tP-rU36kwAAAoE"] [Sat Aug 29 05:06:15.057165 2026] [security2:error] [pid 1018003:tid 1018192] [client 40.83.93.50:9577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/22.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwfgAABeE"] [Sat Aug 29 05:06:15.077263 2026] [security2:error] [pid 1017536:tid 1017732] [client 68.155.159.216:51457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/themes.php"] [unique_id "apK9JyJcY4fy7tP-rU36lAAAAlY"] [Sat Aug 29 05:06:15.083545 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.48.251.3:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/queue.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwfwAABd4"] [Sat Aug 29 05:06:15.084888 2026] [security2:error] [pid 1018003:tid 1018216] [client 68.155.159.216:12197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/themes/index.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwgAAABfk"] [Sat Aug 29 05:06:15.087981 2026] [security2:error] [pid 1018003:tid 1018240] [client 168.107.94.195:59743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwggAABhA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:15.090436 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.63.81.20:60528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/xmini4.php"] [unique_id "apK9JyJcY4fy7tP-rU36lQAAAis"] [Sat Aug 29 05:06:15.090752 2026] [security2:error] [pid 1017536:tid 1017785] [client 68.155.159.216:14264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/packed.php"] [unique_id "apK9JyJcY4fy7tP-rU36lgAAAos"] [Sat Aug 29 05:06:15.096139 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.184.117:1694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/.well-known/aa.php"] [unique_id "apK9JyJcY4fy7tP-rU36lwAAAiA"] [Sat Aug 29 05:06:15.112208 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.147.79:50078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/packed.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwgwAABfU"] [Sat Aug 29 05:06:15.113222 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.52.41.200:1761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-trackback.php"] [unique_id "apK9JyJcY4fy7tP-rU36mAAAAjQ"] [Sat Aug 29 05:06:15.121401 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.197.61.180:16992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK9JyJcY4fy7tP-rU36mQAAAow"] [Sat Aug 29 05:06:15.121450 2026] [security2:error] [pid 1017536:tid 1017714] [client 138.199.19.170:47920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9JyJcY4fy7tP-rU36mgAAAkQ"] [Sat Aug 29 05:06:15.126962 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.220.204.93:64381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/w1px.php"] [unique_id "apK9JyJcY4fy7tP-rU36mwAAAnc"] [Sat Aug 29 05:06:15.128834 2026] [security2:error] [pid 1018003:tid 1018152] [client 209.50.174.211:36639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.174.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwgQAABbk"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:15.131732 2026] [security2:error] [pid 1017536:tid 1017760] [client 68.155.159.216:50176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9JyJcY4fy7tP-rU36nAAAAnI"] [Sat Aug 29 05:06:15.146218 2026] [security2:error] [pid 1017536:tid 1017757] [client 40.83.93.50:24088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/cong.php"] [unique_id "apK9JyJcY4fy7tP-rU36ngAAAm8"] [Sat Aug 29 05:06:15.154022 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.184.117:1677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/Text.php"] [unique_id "apK9JyJcY4fy7tP-rU36nwAAAn8"] [Sat Aug 29 05:06:15.167277 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.147.79:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/simple.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwhgAABhY"] [Sat Aug 29 05:06:15.206307 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.251.3:33316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/paypal.php"] [unique_id "apK9JyJcY4fy7tP-rU36oQAAAjE"] [Sat Aug 29 05:06:15.215793 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.63.81.20:56942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/reop3.php"] [unique_id "apK9JyJcY4fy7tP-rU36pAAAAo8"] [Sat Aug 29 05:06:15.220990 2026] [security2:error] [pid 1017536:tid 1017691] [client 52.139.37.240:12523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-header-json.php"] [unique_id "apK9JyJcY4fy7tP-rU36pQAAAi0"] [Sat Aug 29 05:06:15.243677 2026] [security2:error] [pid 1018003:tid 1018278] [client 158.23.184.117:1360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwiAAABjY"] [Sat Aug 29 05:06:15.262585 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.250.41:59353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/Geforce.php"] [unique_id "apK9JyJcY4fy7tP-rU36pgAAAk0"] [Sat Aug 29 05:06:15.267757 2026] [security2:error] [pid 1017536:tid 1017706] [client 68.155.159.216:51859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/index/function.php"] [unique_id "apK9JyJcY4fy7tP-rU36pwAAAjw"] [Sat Aug 29 05:06:15.268662 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.220.204.93:63837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/to.php"] [unique_id "apK9JyJcY4fy7tP-rU36qAAAAmc"] [Sat Aug 29 05:06:15.276099 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.196.209.81:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwiQAABew"] [Sat Aug 29 05:06:15.299369 2026] [security2:error] [pid 1018003:tid 1018202] [client 158.158.54.35:32964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/classwithtostring.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwiwAABes"] [Sat Aug 29 05:06:15.299949 2026] [security2:error] [pid 1017536:tid 1017767] [client 158.23.184.117:1364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-trackback.php"] [unique_id "apK9JyJcY4fy7tP-rU36rQAAAnk"] [Sat Aug 29 05:06:15.304213 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.48.250.41:64266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/h2a2ck.php"] [unique_id "apK9JyJcY4fy7tP-rU36rgAAAok"] [Sat Aug 29 05:06:15.326789 2026] [security2:error] [pid 1018003:tid 1018269] [client 158.23.184.117:4523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/update/da222.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwjQAABi0"] [Sat Aug 29 05:06:15.352343 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.63.81.20:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-mail.php"] [unique_id "apK9JyJcY4fy7tP-rU36sAAAAiI"] [Sat Aug 29 05:06:15.368303 2026] [security2:error] [pid 1017536:tid 1017688] [client 158.23.147.79:24399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9JyJcY4fy7tP-rU36sgAAAio"] [Sat Aug 29 05:06:15.390023 2026] [security2:error] [pid 1017536:tid 1017731] [client 158.23.184.117:1406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9JyJcY4fy7tP-rU36tQAAAlU"] [Sat Aug 29 05:06:15.391322 2026] [security2:error] [pid 1017536:tid 1017711] [client 57.141.14.83:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/"] [unique_id "apK9JyJcY4fy7tP-rU36tAAAAkE"] [Sat Aug 29 05:06:15.399450 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.250.41:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/click.php"] [unique_id "apK9JyJcY4fy7tP-rU36tgAAApI"] [Sat Aug 29 05:06:15.405615 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.220.204.93:65021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/thui.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwjgAABdI"] [Sat Aug 29 05:06:15.418161 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.196.209.81:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/access.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwkAAABhg"] [Sat Aug 29 05:06:15.426016 2026] [security2:error] [pid 1017536:tid 1017687] [client 87.199.194.213:60378] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.194.213" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.vineyardroots.com"] [uri "/wp-comments-post.php"] [unique_id "apK9JyJcY4fy7tP-rU36twAAAik"], referer: http://www.vineyardroots.com/2017/08/08/the-world-has-too-much-busyness/ [Sat Aug 29 05:06:15.426078 2026] [security2:error] [pid 1017536:tid 1017687] [client 87.199.194.213:60378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.vineyardroots.com"] [uri "/wp-comments-post.php"] [unique_id "apK9JyJcY4fy7tP-rU36twAAAik"], referer: http://www.vineyardroots.com/2017/08/08/the-world-has-too-much-busyness/ [Sat Aug 29 05:06:15.428377 2026] [security2:error] [pid 1017536:tid 1017776] [client 52.139.37.240:12495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/zup.php"] [unique_id "apK9JyJcY4fy7tP-rU36uAAAAoI"] [Sat Aug 29 05:06:15.442282 2026] [security2:error] [pid 1017536:tid 1017683] [client 138.199.19.170:47924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9JyJcY4fy7tP-rU36uQAAAiU"] [Sat Aug 29 05:06:15.450043 2026] [security2:error] [pid 1017536:tid 1017775] [client 158.23.184.117:1674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-admin/maint.php"] [unique_id "apK9JyJcY4fy7tP-rU36ugAAAoE"] [Sat Aug 29 05:06:15.468263 2026] [security2:error] [pid 1018003:tid 1018255] [client 168.107.94.195:60140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwkQAABh8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:15.470193 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.184.117:4821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/xmr.php"] [unique_id "apK9JyJcY4fy7tP-rU36uwAAAnw"] [Sat Aug 29 05:06:15.472525 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.251.3:14026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/userfuns.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwkgAABgw"] [Sat Aug 29 05:06:15.474195 2026] [security2:error] [pid 1018003:tid 1018197] [client 20.48.250.41:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/error_log.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwkwAABeY"] [Sat Aug 29 05:06:15.483211 2026] [security2:error] [pid 1018003:tid 1018161] [client 4.205.62.107:22220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/bigdump.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwlQAABcI"] [Sat Aug 29 05:06:15.488022 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.63.81.20:60540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-conffg.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwlgAABcQ"] [Sat Aug 29 05:06:15.506722 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.151.200.44:64318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/wp-gzone.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwlwAABis"] [Sat Aug 29 05:06:15.534127 2026] [security2:error] [pid 1018003:tid 1018180] [client 4.205.62.107:22393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/config_dev.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwmgAABdU"] [Sat Aug 29 05:06:15.547691 2026] [security2:error] [pid 1018003:tid 1018250] [client 4.205.62.107:26646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/wpver.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwmwAABho"] [Sat Aug 29 05:06:15.561509 2026] [security2:error] [pid 1017536:tid 1017740] [client 192.145.125.70:48046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9JyJcY4fy7tP-rU36wgAAAl4"] [Sat Aug 29 05:06:15.564889 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.251.3:3336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/doc.php"] [unique_id "apK9JyJcY4fy7tP-rU36wwAAAj0"] [Sat Aug 29 05:06:15.574115 2026] [cgid:error] [pid 1017536:tid 1017745] [client 20.52.41.200:1236] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:15.584546 2026] [security2:error] [pid 1017536:tid 1017789] [client 158.23.184.117:1375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/test.php"] [unique_id "apK9JyJcY4fy7tP-rU36xQAAAo8"] [Sat Aug 29 05:06:15.595986 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.184.117:1352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/num.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwnQAABfw"] [Sat Aug 29 05:06:15.596965 2026] [security2:error] [pid 1018003:tid 1018274] [client 20.48.250.41:60687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ms.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwngAABjI"] [Sat Aug 29 05:06:15.609134 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.151.200.44:47377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/ah24.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwnwAABgs"] [Sat Aug 29 05:06:15.613910 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.147.79:48316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/atomlib.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwoAAABgo"] [Sat Aug 29 05:06:15.614946 2026] [security2:error] [pid 1017536:tid 1017742] [client 40.83.93.50:16635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/bak.phps"] [unique_id "apK9JyJcY4fy7tP-rU36xwAAAmA"] [Sat Aug 29 05:06:15.615351 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.184.117:4802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwoQAABgM"] [Sat Aug 29 05:06:15.619225 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.63.81.20:60474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/filefuns.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwogAABdg"] [Sat Aug 29 05:06:15.622570 2026] [security2:error] [pid 1017536:tid 1017669] [client 40.83.93.50:22216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/content.php"] [unique_id "apK9JyJcY4fy7tP-rU36yAAAAhc"] [Sat Aug 29 05:06:15.635679 2026] [security2:error] [pid 1018003:tid 1018265] [client 52.139.37.240:12428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/a9.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwowAABik"] [Sat Aug 29 05:06:15.643315 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.48.250.41:65083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/403.php"] [unique_id "apK9JyJcY4fy7tP-rU36ygAAAks"] [Sat Aug 29 05:06:15.644441 2026] [security2:error] [pid 1017536:tid 1017720] [client 4.205.62.107:53401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/8.php"] [unique_id "apK9JyJcY4fy7tP-rU36ywAAAko"] [Sat Aug 29 05:06:15.654908 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.151.200.44:64265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/str.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwpQAABiw"] [Sat Aug 29 05:06:15.664920 2026] [security2:error] [pid 1018003:tid 1018187] [client 34.7.216.49:43596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/api/v2/config"] [unique_id "apK9JzAh5Y1i2tUxg4HwqQAABdw"] [Sat Aug 29 05:06:15.665133 2026] [security2:error] [pid 1018003:tid 1018175] [client 45.3.36.65:49269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.36.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwpAAABdA"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:15.666722 2026] [security2:error] [pid 1018003:tid 1018213] [client 34.7.216.49:43516] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/build/manifest.json"] [unique_id "apK9JzAh5Y1i2tUxg4HwrQAABfY"] [Sat Aug 29 05:06:15.671745 2026] [security2:error] [pid 1018003:tid 1018252] [client 34.7.216.49:43710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.216.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bridgewaycentretrust.org"] [uri "/config/aws.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwswAABhw"] [Sat Aug 29 05:06:15.683694 2026] [security2:error] [pid 1017536:tid 1017790] [client 195.178.110.105:42128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landonrian.com"] [uri "/wp/index.php"] [unique_id "apK9JyJcY4fy7tP-rU36zAAAApA"] [Sat Aug 29 05:06:15.694146 2026] [security2:error] [pid 1018003:tid 1018240] [client 87.199.194.213:60399] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.194.213" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.vineyardroots.com"] [uri "/wp-comments-post.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwtAAABhA"], referer: http://www.vineyardroots.com/2017/08/08/the-world-has-too-much-busyness/ [Sat Aug 29 05:06:15.694232 2026] [security2:error] [pid 1018003:tid 1018240] [client 87.199.194.213:60399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.vineyardroots.com"] [uri "/wp-comments-post.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwtAAABhA"], referer: http://www.vineyardroots.com/2017/08/08/the-world-has-too-much-busyness/ [Sat Aug 29 05:06:15.694834 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.48.251.3:62101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/css.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwtQAABf8"] [Sat Aug 29 05:06:15.721136 2026] [security2:error] [pid 1017536:tid 1017783] [client 20.52.41.200:1236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/222.php"] [unique_id "apK9JyJcY4fy7tP-rU364AAAAok"] [Sat Aug 29 05:06:15.730290 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.184.117:1357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/mani.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwtgAABeE"] [Sat Aug 29 05:06:15.731388 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.48.250.41:60743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/zxekqlxb.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwtwAABjQ"] [Sat Aug 29 05:06:15.742570 2026] [security2:error] [pid 1018003:tid 1018170] [client 158.23.184.117:1689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/identity.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwuAAABcs"] [Sat Aug 29 05:06:15.743926 2026] [security2:error] [pid 1018003:tid 1018193] [client 20.151.200.44:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/hack.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwuQAABeI"] [Sat Aug 29 05:06:15.759348 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.158.54.35:6243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/404.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwugAABbo"] [Sat Aug 29 05:06:15.759423 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.184.117:4829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-act.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwuwAABbk"] [Sat Aug 29 05:06:15.761717 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.63.81.20:60537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-cron.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwvAAABd0"] [Sat Aug 29 05:06:15.787283 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.251.3:13952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/mamzi.php"] [unique_id "apK9JyJcY4fy7tP-rU364wAAAmE"] [Sat Aug 29 05:06:15.791290 2026] [security2:error] [pid 1018003:tid 1018278] [client 138.199.19.170:47928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9JzAh5Y1i2tUxg4HwvgAABjY"] [Sat Aug 29 05:06:15.811253 2026] [security2:error] [pid 1018003:tid 1018185] [client 158.23.147.79:30627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwwQAABdo"] [Sat Aug 29 05:06:15.812972 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.196.209.81:12974] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/1.php"] [unique_id "apK9JyJcY4fy7tP-rU365AAAAjA"] [Sat Aug 29 05:06:15.813051 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.196.209.81:12974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/1.php"] [unique_id "apK9JyJcY4fy7tP-rU365AAAAjA"] [Sat Aug 29 05:06:15.819931 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.220.204.93:63814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/Jcrop.php"] [unique_id "apK9JyJcY4fy7tP-rU365QAAAlU"] [Sat Aug 29 05:06:15.822619 2026] [security2:error] [pid 1018003:tid 1018269] [client 158.23.147.79:35814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/file.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwwgAABi0"] [Sat Aug 29 05:06:15.826530 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.196.209.81:11520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/classsmtps.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwwwAABd4"] [Sat Aug 29 05:06:15.829856 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.251.3:3346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/php_info.php"] [unique_id "apK9JyJcY4fy7tP-rU365gAAAkE"] [Sat Aug 29 05:06:15.843186 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.197.61.180:16984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9JyJcY4fy7tP-rU365wAAAmc"] [Sat Aug 29 05:06:15.847516 2026] [security2:error] [pid 1018003:tid 1018242] [client 195.178.110.105:42142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "landonrian.com"] [uri "/wp/index.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwxAAABhI"] [Sat Aug 29 05:06:15.848162 2026] [security2:error] [pid 1018003:tid 1018215] [client 168.107.94.195:60577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwxQAABfg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:15.849337 2026] [security2:error] [pid 1018003:tid 1018218] [client 52.139.37.240:12432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/admin/index.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwxgAABfs"] [Sat Aug 29 05:06:15.850724 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.147.79:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwxwAABeM"] [Sat Aug 29 05:06:15.870844 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.48.250.41:64347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/cytyr.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwyAAABfo"] [Sat Aug 29 05:06:15.871169 2026] [security2:error] [pid 1018003:tid 1018197] [client 4.205.62.107:22305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/thui.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwyQAABeY"] [Sat Aug 29 05:06:15.871474 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.250.41:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/init.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwygAABcI"] [Sat Aug 29 05:06:15.872803 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.184.117:1417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/Test.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwywAABco"] [Sat Aug 29 05:06:15.878443 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.147.79:32748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/radio.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwzAAABis"] [Sat Aug 29 05:06:15.890252 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.23.184.117:1394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/Radio.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwzQAABdI"] [Sat Aug 29 05:06:15.894738 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.63.81.20:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/lock360.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwzgAABdU"] [Sat Aug 29 05:06:15.903091 2026] [security2:error] [pid 1018003:tid 1018248] [client 158.23.184.117:4801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/fff.php"] [unique_id "apK9JzAh5Y1i2tUxg4HwzwAABhg"] [Sat Aug 29 05:06:15.949032 2026] [security2:error] [pid 1017536:tid 1017775] [client 4.205.62.107:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/4563.php"] [unique_id "apK9JyJcY4fy7tP-rU366wAAAoE"] [Sat Aug 29 05:06:15.960532 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.48.251.3:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/session.php"] [unique_id "apK9JzAh5Y1i2tUxg4Hw0AAABgs"] [Sat Aug 29 05:06:16.008932 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.48.250.41:62521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/term.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw0QAABik"] [Sat Aug 29 05:06:16.015002 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.251.3:14046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/public/rip.php.php"] [unique_id "apK9KCJcY4fy7tP-rU367AAAAjE"] [Sat Aug 29 05:06:16.016366 2026] [security2:error] [pid 1018003:tid 1018257] [client 158.23.184.117:1355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/pomo.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw0gAABiE"] [Sat Aug 29 05:06:16.028316 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.63.81.20:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-theme.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw0wAABiw"] [Sat Aug 29 05:06:16.046007 2026] [security2:error] [pid 1017536:tid 1017689] [client 52.139.37.240:12537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/makeasmtp.php"] [unique_id "apK9KCJcY4fy7tP-rU367QAAAis"] [Sat Aug 29 05:06:16.063911 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.184.117:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9KCJcY4fy7tP-rU367gAAAho"] [Sat Aug 29 05:06:16.085864 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.184.117:1711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/Requests/Exception/file.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw1QAABdA"] [Sat Aug 29 05:06:16.089990 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.220.204.93:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ws58.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw1gAABhw"] [Sat Aug 29 05:06:16.091963 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.251.3:61671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/h.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw1wAABcg"] [Sat Aug 29 05:06:16.094446 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.49.130:53704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/x1da.php"] [unique_id "apK9KCJcY4fy7tP-rU367wAAAiM"] [Sat Aug 29 05:06:16.113277 2026] [security2:error] [pid 1017536:tid 1017683] [client 40.83.93.50:9593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/install.php"] [unique_id "apK9KCJcY4fy7tP-rU368AAAAiU"] [Sat Aug 29 05:06:16.115013 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.250.41:64301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/galer.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw2AAABfU"] [Sat Aug 29 05:06:16.116033 2026] [security2:error] [pid 1017536:tid 1017729] [client 138.199.19.170:47936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9KCJcY4fy7tP-rU368QAAAlM"] [Sat Aug 29 05:06:16.126687 2026] [security2:error] [pid 1018003:tid 1018159] [client 68.155.159.216:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw2QAABcA"] [Sat Aug 29 05:06:16.143016 2026] [security2:error] [pid 1018003:tid 1018234] [client 40.83.93.50:24097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/core.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw2gAABgo"] [Sat Aug 29 05:06:16.161535 2026] [security2:error] [pid 1018003:tid 1018255] [client 192.145.125.70:48060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9KDAh5Y1i2tUxg4Hw3AAABh8"] [Sat Aug 29 05:06:16.162683 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.63.81.20:60501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/2d7433/index.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw3QAABhY"] [Sat Aug 29 05:06:16.170515 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.104.49.130:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/load.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw3gAABcs"] [Sat Aug 29 05:06:16.171096 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.52.41.200:1240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/x.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw3wAABds"] [Sat Aug 29 05:06:16.174930 2026] [security2:error] [pid 1017536:tid 1017707] [client 104.207.42.91:16613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9KCJcY4fy7tP-rU369QAAAj0"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:16.183353 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.250.41:62472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/aaa.php"] [unique_id "apK9KCJcY4fy7tP-rU369wAAAjQ"] [Sat Aug 29 05:06:16.193184 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.251.3:13977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/environment.php"] [unique_id "apK9KCJcY4fy7tP-rU36-QAAAkQ"] [Sat Aug 29 05:06:16.220430 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.251.3:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/bootstrap.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw4QAABbo"] [Sat Aug 29 05:06:16.220506 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.158.54.35:8927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/php.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw4gAABgE"] [Sat Aug 29 05:06:16.222350 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.196.209.81:16704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/contentloader1.php"] [unique_id "apK9KCJcY4fy7tP-rU36_AAAAjw"] [Sat Aug 29 05:06:16.229270 2026] [security2:error] [pid 1017536:tid 1017737] [client 168.107.94.195:60983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9KCJcY4fy7tP-rU36_QAAAls"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:16.231650 2026] [security2:error] [pid 1017536:tid 1017770] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9KCJcY4fy7tP-rU368gACfCM"] [Sat Aug 29 05:06:16.235897 2026] [security2:error] [pid 1018003:tid 1018193] [client 52.139.37.240:12491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/paku.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw5AAABeI"] [Sat Aug 29 05:06:16.236787 2026] [core:error] [pid 1017536:tid 1017783] [client 20.197.61.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:16.236803 2026] [core:error] [pid 1017536:tid 1017783] [client 20.197.61.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:16.237811 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/themes.php"] [unique_id "apK9KCJcY4fy7tP-rU37AAAAAjI"] [Sat Aug 29 05:06:16.238195 2026] [security2:error] [pid 1017536:tid 1017709] [client 66.248.203.2:3430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2012/06/03/college/"] [unique_id "apK9KCJcY4fy7tP-rU37AQAAAj8"] [Sat Aug 29 05:06:16.248252 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.196.209.81:12983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/about.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw5QAABf8"] [Sat Aug 29 05:06:16.249419 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.184.117:4521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/robots.php"] [unique_id "apK9KCJcY4fy7tP-rU37AwAAAow"] [Sat Aug 29 05:06:16.250724 2026] [security2:error] [pid 1017536:tid 1017679] [client 20.220.204.93:64316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/xs.php"] [unique_id "apK9KCJcY4fy7tP-rU37BAAAAiE"] [Sat Aug 29 05:06:16.271210 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.23.184.117:1389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-admin/link-add.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw5gAABg4"] [Sat Aug 29 05:06:16.279779 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.184.117:1383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-admin/add.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw5wAABiU"] [Sat Aug 29 05:06:16.309955 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.250.41:63827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/baixy.php"] [unique_id "apK9KCJcY4fy7tP-rU37BwAAAkA"] [Sat Aug 29 05:06:16.314439 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.147.79:37797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-admin/about.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw6QAABiY"] [Sat Aug 29 05:06:16.328986 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.63.81.20:60508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-login.php"] [unique_id "apK9KCJcY4fy7tP-rU37BgAAAn8"] [Sat Aug 29 05:06:16.335788 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.250.41:60739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/xsox.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw6gAABes"] [Sat Aug 29 05:06:16.336486 2026] [security2:error] [pid 1018003:tid 1018182] [client 87.219.197.128:53126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw6wAABdc"] [Sat Aug 29 05:06:16.336559 2026] [security2:error] [pid 1018003:tid 1018182] [client 87.219.197.128:53126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw6wAABdc"] [Sat Aug 29 05:06:16.350628 2026] [security2:error] [pid 1018003:tid 1018269] [client 20.48.251.3:61686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/333.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw7QAABi0"] [Sat Aug 29 05:06:16.352068 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.147.79:30532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9KCJcY4fy7tP-rU37CAAAAmc"] [Sat Aug 29 05:06:16.371314 2026] [security2:error] [pid 1017536:tid 1017750] [client 20.48.251.3:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aws_secret_config.php"] [unique_id "apK9KCJcY4fy7tP-rU37CgAAAmg"] [Sat Aug 29 05:06:16.371757 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.147.79:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9KCJcY4fy7tP-rU37CwAAAk4"] [Sat Aug 29 05:06:16.372636 2026] [security2:error] [pid 1017536:tid 1017751] [client 68.155.159.216:51872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/.well-known/content.php"] [unique_id "apK9KCJcY4fy7tP-rU37DAAAAmk"] [Sat Aug 29 05:06:16.399719 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.184.117:4814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/.well-known/install.php"] [unique_id "apK9KCJcY4fy7tP-rU37DgAAAh0"] [Sat Aug 29 05:06:16.422887 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.23.184.117:1392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/Text.php"] [unique_id "apK9KCJcY4fy7tP-rU37EAAAAoY"] [Sat Aug 29 05:06:16.428973 2026] [security2:error] [pid 1017536:tid 1017705] [client 52.139.37.240:12493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/rtx.php"] [unique_id "apK9KCJcY4fy7tP-rU37EQAAAjs"] [Sat Aug 29 05:06:16.437206 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.23.184.117:1374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/assets/about.php"] [unique_id "apK9KCJcY4fy7tP-rU37EgAAAkI"] [Sat Aug 29 05:06:16.449618 2026] [security2:error] [pid 1017536:tid 1017733] [client 138.199.19.170:47938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9KCJcY4fy7tP-rU37EwAAAlc"] [Sat Aug 29 05:06:16.465831 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.63.81.20:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/images.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw8QAABcQ"] [Sat Aug 29 05:06:16.478333 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.251.3:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/G-in.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw8gAABcI"] [Sat Aug 29 05:06:16.479743 2026] [security2:error] [pid 1017536:tid 1017741] [client 158.23.147.79:24391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9KCJcY4fy7tP-rU37FAAAAl8"] [Sat Aug 29 05:06:16.480833 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.250.41:65098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ava.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw8wAABco"] [Sat Aug 29 05:06:16.483073 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.147.79:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-l0gin.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw9AAABis"] [Sat Aug 29 05:06:16.503063 2026] [security2:error] [pid 1018003:tid 1018173] [client 20.48.251.3:14028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/snq.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw9QAABc4"] [Sat Aug 29 05:06:16.520363 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.220.204.93:64308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/zu.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw9gAABio"] [Sat Aug 29 05:06:16.539733 2026] [security2:error] [pid 1017536:tid 1017742] [client 20.48.250.41:59265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/lkui.php"] [unique_id "apK9KCJcY4fy7tP-rU37FQAAAmA"] [Sat Aug 29 05:06:16.552130 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.197.61.180:16983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/config.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw-QAABiM"] [Sat Aug 29 05:06:16.574751 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.184.117:1346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-trackback.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw_AAABfw"] [Sat Aug 29 05:06:16.587240 2026] [security2:error] [pid 1018003:tid 1018274] [client 158.23.184.117:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/themes/twentytwentythree.php"] [unique_id "apK9KDAh5Y1i2tUxg4Hw_wAABjI"] [Sat Aug 29 05:06:16.588505 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.63.81.20:60527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/ops.php"] [unique_id "apK9KCJcY4fy7tP-rU37GgAAAls"] [Sat Aug 29 05:06:16.592947 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.23.184.117:4508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-admin/about.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxAAAABjU"] [Sat Aug 29 05:06:16.603691 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.251.3:61089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/apikeys.php"] [unique_id "apK9KCJcY4fy7tP-rU37GwAAAnw"] [Sat Aug 29 05:06:16.610497 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.250.41:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/gdn.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxAQAABcg"] [Sat Aug 29 05:06:16.610785 2026] [security2:error] [pid 1018003:tid 1018264] [client 168.107.94.195:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxAgAABig"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:16.614902 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.52.41.200:1228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/new.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxAwAABfo"] [Sat Aug 29 05:06:16.617757 2026] [security2:error] [pid 1018003:tid 1018236] [client 40.83.93.50:5926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/db-status.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxBAAABgw"] [Sat Aug 29 05:06:16.625086 2026] [security2:error] [pid 1017536:tid 1017679] [client 4.205.62.107:22253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/channels.php"] [unique_id "apK9KCJcY4fy7tP-rU37HQAAAiE"] [Sat Aug 29 05:06:16.625168 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.196.209.81:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/al.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxBgAABdU"] [Sat Aug 29 05:06:16.640671 2026] [security2:error] [pid 1018003:tid 1018268] [client 52.139.37.240:12481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/update/da222.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxBwAABiw"] [Sat Aug 29 05:06:16.643503 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.196.209.81:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/admin-header.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxCAAABho"] [Sat Aug 29 05:06:16.667509 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.158.54.35:32982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/init.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxCQAABiA"] [Sat Aug 29 05:06:16.673301 2026] [security2:error] [pid 1017536:tid 1017764] [client 4.205.62.107:22378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/oc460l3x.php"] [unique_id "apK9KCJcY4fy7tP-rU37HgAAAnY"] [Sat Aug 29 05:06:16.683378 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.250.41:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9KCJcY4fy7tP-rU37HwAAAk0"] [Sat Aug 29 05:06:16.684674 2026] [security2:error] [pid 1017536:tid 1017753] [client 4.205.62.107:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ah25.php"] [unique_id "apK9KCJcY4fy7tP-rU37IAAAAms"] [Sat Aug 29 05:06:16.685630 2026] [security2:error] [pid 1017536:tid 1017715] [client 103.185.242.143:61869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9KCJcY4fy7tP-rU37IQAAAkU"] [Sat Aug 29 05:06:16.685722 2026] [security2:error] [pid 1017536:tid 1017715] [client 103.185.242.143:61869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9KCJcY4fy7tP-rU37IQAAAkU"] [Sat Aug 29 05:06:16.714156 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.63.81.20:60535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK9KCJcY4fy7tP-rU37IwAAAn8"] [Sat Aug 29 05:06:16.716503 2026] [security2:error] [pid 1017536:tid 1017683] [client 45.3.35.186:51657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9KCJcY4fy7tP-rU37IgAAAiU"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:16.716913 2026] [security2:error] [pid 1017536:tid 1017716] [client 158.23.147.79:48360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/lv.php"] [unique_id "apK9KCJcY4fy7tP-rU37JAAAAkY"] [Sat Aug 29 05:06:16.717933 2026] [security2:error] [pid 1017536:tid 1017680] [client 158.23.184.117:1378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-admin/maint.php"] [unique_id "apK9KCJcY4fy7tP-rU37JQAAAiI"] [Sat Aug 29 05:06:16.728488 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.251.3:61643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/motu.php"] [unique_id "apK9KCJcY4fy7tP-rU37JgAAAmk"] [Sat Aug 29 05:06:16.733140 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.251.3:14020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-access.php"] [unique_id "apK9KCJcY4fy7tP-rU37JwAAAjo"] [Sat Aug 29 05:06:16.737167 2026] [security2:error] [pid 1017536:tid 1017694] [client 158.23.184.117:4826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/backup.php"] [unique_id "apK9KCJcY4fy7tP-rU37KgAAAjA"] [Sat Aug 29 05:06:16.740832 2026] [security2:error] [pid 1017536:tid 1017793] [client 68.155.159.216:33639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9KCJcY4fy7tP-rU37KwAAApM"] [Sat Aug 29 05:06:16.741845 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.220.204.93:64357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/lanka.php"] [unique_id "apK9KCJcY4fy7tP-rU37LAAAAhY"] [Sat Aug 29 05:06:16.744929 2026] [security2:error] [pid 1018003:tid 1018155] [client 192.145.125.70:48070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9KDAh5Y1i2tUxg4HxCgAABbw"] [Sat Aug 29 05:06:16.748101 2026] [security2:error] [pid 1017536:tid 1017695] [client 40.83.93.50:7746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/colour.php"] [unique_id "apK9KCJcY4fy7tP-rU37LgAAAjE"] [Sat Aug 29 05:06:16.768672 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.250.41:65033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/f2.php"] [unique_id "apK9KCJcY4fy7tP-rU37MAAAAoE"] [Sat Aug 29 05:06:16.784288 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.184.117:1345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/languages/themes/num.php"] [unique_id "apK9KCJcY4fy7tP-rU37MQAAAjs"] [Sat Aug 29 05:06:16.796634 2026] [security2:error] [pid 1017536:tid 1017740] [client 138.199.19.170:47942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9KCJcY4fy7tP-rU37MgAAAl4"] [Sat Aug 29 05:06:16.811797 2026] [security2:error] [pid 1017536:tid 1017745] [client 68.155.159.216:24489] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "drjrae.managemymood.com"] [uri "/1.php"] [unique_id "apK9KCJcY4fy7tP-rU37MwAAAmM"] [Sat Aug 29 05:06:16.811870 2026] [security2:error] [pid 1017536:tid 1017745] [client 68.155.159.216:24489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/1.php"] [unique_id "apK9KCJcY4fy7tP-rU37MwAAAmM"] [Sat Aug 29 05:06:16.824413 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.250.41:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/motu.php"] [unique_id "apK9KCJcY4fy7tP-rU37NAAAAlo"] [Sat Aug 29 05:06:16.859801 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.48.251.3:61221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/public/mah.php.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxDQAABgI"] [Sat Aug 29 05:06:16.866940 2026] [security2:error] [pid 1017536:tid 1017741] [client 158.23.184.117:1368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/num.php"] [unique_id "apK9KCJcY4fy7tP-rU37NwAAAl8"] [Sat Aug 29 05:06:16.874618 2026] [security2:error] [pid 1017536:tid 1017769] [client 68.155.159.216:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/simple.php"] [unique_id "apK9KCJcY4fy7tP-rU37OAAAAns"] [Sat Aug 29 05:06:16.877835 2026] [security2:error] [pid 1017536:tid 1017687] [client 4.205.62.107:8991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/agg.php"] [unique_id "apK9KCJcY4fy7tP-rU37OgAAAik"] [Sat Aug 29 05:06:16.879481 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.63.81.20:60425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK9KCJcY4fy7tP-rU37OwAAAmU"] [Sat Aug 29 05:06:16.887814 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.184.117:4811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/.well-known/aa.php"] [unique_id "apK9KCJcY4fy7tP-rU37PAAAAi0"] [Sat Aug 29 05:06:16.898920 2026] [security2:error] [pid 1017536:tid 1017743] [client 195.178.110.247:4632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lbustersdrivingschool.com"] [uri "/index.php"] [unique_id "apK9KCJcY4fy7tP-rU37PgAAAmE"] [Sat Aug 29 05:06:16.901535 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.250.41:65080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/grsiuk.php"] [unique_id "apK9KCJcY4fy7tP-rU37PwAAAnk"] [Sat Aug 29 05:06:16.915983 2026] [security2:error] [pid 1017536:tid 1017711] [client 52.139.37.240:12519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-admin/min.php"] [unique_id "apK9KCJcY4fy7tP-rU37QQAAAkE"] [Sat Aug 29 05:06:16.917110 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.147.79:30563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-login.php"] [unique_id "apK9KCJcY4fy7tP-rU37QwAAAmc"] [Sat Aug 29 05:06:16.931008 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.48.251.3:14054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/otuz1.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxDgAABcc"] [Sat Aug 29 05:06:16.933259 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.184.117:60890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp.php"] [unique_id "apK9KCJcY4fy7tP-rU37RAAAAiA"] [Sat Aug 29 05:06:16.934138 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.147.79:25550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxDwAABd4"] [Sat Aug 29 05:06:16.934152 2026] [security2:error] [pid 1018003:tid 1018165] [client 158.23.147.79:35741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/file17.php"] [unique_id "apK9KDAh5Y1i2tUxg4HxEAAABcY"] [Sat Aug 29 05:06:16.985997 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.147.79:32650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9KCJcY4fy7tP-rU37SAAAAhs"] [Sat Aug 29 05:06:16.986307 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.251.3:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/zaza.php"] [unique_id "apK9KCJcY4fy7tP-rU37SQAAAoE"] [Sat Aug 29 05:06:16.991854 2026] [security2:error] [pid 1017536:tid 1017748] [client 168.107.94.195:61635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9KCJcY4fy7tP-rU37SwAAAmY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:17.006849 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.250.41:62549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/Ov-Simple1.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxEgAABcI"] [Sat Aug 29 05:06:17.006967 2026] [security2:error] [pid 1017536:tid 1017705] [client 4.205.62.107:22283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/lala.php"] [unique_id "apK9KSJcY4fy7tP-rU37TAAAAjs"] [Sat Aug 29 05:06:17.014365 2026] [security2:error] [pid 1017536:tid 1017719] [client 158.23.184.117:1378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/identity.php"] [unique_id "apK9KSJcY4fy7tP-rU37TgAAAkk"] [Sat Aug 29 05:06:17.029190 2026] [security2:error] [pid 1018003:tid 1018196] [client 34.7.40.70:7824] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/secrets.json"] [unique_id "apK9KTAh5Y1i2tUxg4HxEwAABeU"] [Sat Aug 29 05:06:17.031058 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.250.41:64320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wp-scr1pts.php"] [unique_id "apK9KSJcY4fy7tP-rU37TwAAAho"] [Sat Aug 29 05:06:17.031788 2026] [security2:error] [pid 1017536:tid 1017714] [client 34.7.40.70:7854] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/settings.json"] [unique_id "apK9KSJcY4fy7tP-rU37UAAAAkQ"] [Sat Aug 29 05:06:17.032310 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.184.117:4803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9KSJcY4fy7tP-rU37UQAAAh0"] [Sat Aug 29 05:06:17.033954 2026] [cgid:error] [pid 1018003:tid 1018203] [client 34.7.40.70:7860] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.034377 2026] [cgid:error] [pid 1018003:tid 1018239] [client 34.7.40.70:7874] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.035059 2026] [cgid:error] [pid 1017536:tid 1017790] [client 34.7.40.70:7816] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.035247 2026] [cgid:error] [pid 1018003:tid 1018258] [client 34.7.40.70:7832] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.035434 2026] [security2:error] [pid 1018003:tid 1018258] [client 34.7.40.70:7832] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9KTAh5Y1i2tUxg4HxFgAABiI"] [Sat Aug 29 05:06:17.036713 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.63.81.20:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/about.php"] [unique_id "apK9KSJcY4fy7tP-rU37WAAAAlo"] [Sat Aug 29 05:06:17.036759 2026] [cgid:error] [pid 1018003:tid 1018198] [client 34.7.40.70:7840] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.036840 2026] [security2:error] [pid 1017536:tid 1017709] [client 34.7.40.70:7952] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/firebase-adminsdk.json"] [unique_id "apK9KSJcY4fy7tP-rU37WQAAAj8"] [Sat Aug 29 05:06:17.036923 2026] [cgid:error] [pid 1017536:tid 1017706] [client 34.7.40.70:7918] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.037520 2026] [cgid:error] [pid 1017536:tid 1017669] [client 34.7.40.70:7884] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.037825 2026] [cgid:error] [pid 1018003:tid 1018185] [client 34.7.40.70:7976] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.038165 2026] [cgid:error] [pid 1017536:tid 1017698] [client 34.7.40.70:7808] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.038380 2026] [cgid:error] [pid 1018003:tid 1018263] [client 34.7.40.70:7906] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.038384 2026] [cgid:error] [pid 1018003:tid 1018230] [client 34.7.40.70:7894] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.038387 2026] [cgid:error] [pid 1017536:tid 1017737] [client 34.7.40.70:7936] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.038524 2026] [cgid:error] [pid 1018003:tid 1018251] [client 34.7.40.70:7940] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.038669 2026] [cgid:error] [pid 1017536:tid 1017707] [client 34.7.40.70:7834] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.039285 2026] [security2:error] [pid 1017536:tid 1017764] [client 20.196.209.81:19439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/global.php"] [unique_id "apK9KSJcY4fy7tP-rU37WwAAAnY"] [Sat Aug 29 05:06:17.039422 2026] [cgid:error] [pid 1017536:tid 1017765] [client 34.7.40.70:7912] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.041218 2026] [cgid:error] [pid 1017536:tid 1017786] [client 34.7.40.70:7978] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.042228 2026] [cgid:error] [pid 1017536:tid 1017754] [client 34.7.40.70:7982] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.042666 2026] [cgid:error] [pid 1017536:tid 1017744] [client 34.7.40.70:7942] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.042858 2026] [cgid:error] [pid 1018003:tid 1018202] [client 34.7.40.70:7968] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.043327 2026] [security2:error] [pid 1017536:tid 1017713] [client 34.7.40.70:8016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.ssh/id_rsa"] [unique_id "apK9KSJcY4fy7tP-rU37YQAAAkM"] [Sat Aug 29 05:06:17.043514 2026] [cgid:error] [pid 1017536:tid 1017777] [client 34.7.40.70:7922] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.044908 2026] [cgid:error] [pid 1017536:tid 1017722] [client 34.7.40.70:8006] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.045038 2026] [cgid:error] [pid 1018003:tid 1018182] [client 34.7.40.70:7998] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.045134 2026] [security2:error] [pid 1018003:tid 1018182] [client 34.7.40.70:7998] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9KTAh5Y1i2tUxg4HxHQAABdc"] [Sat Aug 29 05:06:17.045875 2026] [cgid:error] [pid 1017536:tid 1017686] [client 34.7.40.70:8030] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.046077 2026] [cgid:error] [pid 1017536:tid 1017757] [client 34.7.40.70:8004] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.054927 2026] [cgid:error] [pid 1017536:tid 1017688] [client 34.7.40.70:8038] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.055254 2026] [security2:error] [pid 1018003:tid 1018191] [client 34.7.40.70:8048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.ssh/id_dsa"] [unique_id "apK9KTAh5Y1i2tUxg4HxHgAABeA"] [Sat Aug 29 05:06:17.056506 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.196.209.81:5612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/admin.php"] [unique_id "apK9KSJcY4fy7tP-rU37ZgAAAlU"] [Sat Aug 29 05:06:17.057181 2026] [cgid:error] [pid 1017536:tid 1017753] [client 34.7.40.70:8050] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.060348 2026] [cgid:error] [pid 1017536:tid 1017715] [client 34.7.40.70:8062] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:17.067706 2026] [security2:error] [pid 1017536:tid 1017723] [client 195.178.110.247:45550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lbustersdrivingschool.com"] [uri "/index.php"] [unique_id "apK9KSJcY4fy7tP-rU37aAAAAk0"] [Sat Aug 29 05:06:17.072764 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.52.41.200:1259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/menu.php"] [unique_id "apK9KSJcY4fy7tP-rU37aQAAAn8"] [Sat Aug 29 05:06:17.099990 2026] [security2:error] [pid 1017536:tid 1017747] [client 4.205.62.107:56037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/cp2.php"] [unique_id "apK9KSJcY4fy7tP-rU37agAAAmU"] [Sat Aug 29 05:06:17.101636 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.48.251.3:14057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/channels.php"] [unique_id "apK9KSJcY4fy7tP-rU37awAAAi0"] [Sat Aug 29 05:06:17.109662 2026] [security2:error] [pid 1017536:tid 1017789] [client 52.139.37.240:12867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK9KSJcY4fy7tP-rU37bAAAAo8"] [Sat Aug 29 05:06:17.113233 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.48.251.3:61066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/u88.php"] [unique_id "apK9KSJcY4fy7tP-rU37bQAAAlM"] [Sat Aug 29 05:06:17.113775 2026] [security2:error] [pid 1018003:tid 1018194] [client 40.83.93.50:23494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxIAAABeM"] [Sat Aug 29 05:06:17.125212 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.184.117:1404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/xmlrpc.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxHwAABis"] [Sat Aug 29 05:06:17.139292 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.220.204.93:63850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/gettest.php"] [unique_id "apK9KSJcY4fy7tP-rU37bgAAAmc"] [Sat Aug 29 05:06:17.143095 2026] [security2:error] [pid 1017536:tid 1017761] [client 138.199.19.170:47958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9KSJcY4fy7tP-rU37bwAAAnM"] [Sat Aug 29 05:06:17.144271 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.48.250.41:62527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/wp-blogs.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxIQAABgk"] [Sat Aug 29 05:06:17.147993 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.158.54.35:22306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "apK9KSJcY4fy7tP-rU37cAAAAoY"] [Sat Aug 29 05:06:17.157594 2026] [security2:error] [pid 1018003:tid 1018114] [remote 162.241.144.20:34468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.144.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sitestage.biz"] [uri "/wp-login.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxIgAGKl0"], referer: https://mail.sitestage.biz/wp-login.php [Sat Aug 29 05:06:17.169209 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.81.20:60482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/admin.php/admin.php"] [unique_id "apK9KSJcY4fy7tP-rU37cgAAAlY"] [Sat Aug 29 05:06:17.176152 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.23.184.117:4852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9KSJcY4fy7tP-rU37cwAAAkE"] [Sat Aug 29 05:06:17.190856 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.48.250.41:64269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/num.php"] [unique_id "apK9KSJcY4fy7tP-rU37dAAAAlg"] [Sat Aug 29 05:06:17.206851 2026] [security2:error] [pid 1017536:tid 1017775] [client 158.23.184.117:1388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/Radio.php"] [unique_id "apK9KSJcY4fy7tP-rU37dQAAAoE"] [Sat Aug 29 05:06:17.236143 2026] [security2:error] [pid 1017536:tid 1017733] [client 68.155.159.216:16070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9KSJcY4fy7tP-rU37dgAAAlc"] [Sat Aug 29 05:06:17.239216 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.48.251.3:61657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apK9KSJcY4fy7tP-rU37dwAAAho"] [Sat Aug 29 05:06:17.244220 2026] [security2:error] [pid 1018003:tid 1018173] [client 40.83.93.50:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/OK.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxJAAABc4"] [Sat Aug 29 05:06:17.244276 2026] [security2:error] [pid 1017536:tid 1017745] [client 68.155.159.216:14154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/packed.php"] [unique_id "apK9KSJcY4fy7tP-rU37eQAAAmM"] [Sat Aug 29 05:06:17.249298 2026] [security2:error] [pid 1018003:tid 1018218] [client 68.155.159.216:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-mail.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxJQAABfs"] [Sat Aug 29 05:06:17.251813 2026] [security2:error] [pid 1018003:tid 1018207] [client 104.207.34.219:59029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxIwAABfA"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:17.262165 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.197.61.180:17011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/cong.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxJgAABco"] [Sat Aug 29 05:06:17.267749 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.184.117:1673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/app.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxJwAABik"] [Sat Aug 29 05:06:17.273551 2026] [security2:error] [pid 1017536:tid 1017737] [client 68.155.159.216:12263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/about.php"] [unique_id "apK9KSJcY4fy7tP-rU37fAAAAls"] [Sat Aug 29 05:06:17.277872 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:62486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/mini.php"] [unique_id "apK9KSJcY4fy7tP-rU37fQAAAj0"] [Sat Aug 29 05:06:17.285591 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.251.3:33332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/asdf.php"] [unique_id "apK9KSJcY4fy7tP-rU37fgAAAow"] [Sat Aug 29 05:06:17.286746 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.220.204.93:64348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/35.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxKAAABjE"] [Sat Aug 29 05:06:17.302613 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.63.81.20:60460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/media.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxKQAABfw"] [Sat Aug 29 05:06:17.318133 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.49.130:60986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/well.php"] [unique_id "apK9KSJcY4fy7tP-rU37gQAAAig"] [Sat Aug 29 05:06:17.322126 2026] [security2:error] [pid 1017536:tid 1017709] [client 52.139.37.240:12534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK9KSJcY4fy7tP-rU37ggAAAj8"] [Sat Aug 29 05:06:17.328315 2026] [security2:error] [pid 1018003:tid 1018198] [client 192.145.125.70:48074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9KTAh5Y1i2tUxg4HxKgAABec"] [Sat Aug 29 05:06:17.344735 2026] [security2:error] [pid 1017536:tid 1017688] [client 68.155.159.216:50192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-mail.php"] [unique_id "apK9KSJcY4fy7tP-rU37gwAAAio"] [Sat Aug 29 05:06:17.364816 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.251.3:61219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/87.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxLQAABfY"] [Sat Aug 29 05:06:17.371405 2026] [security2:error] [pid 1017536:tid 1017715] [client 168.107.94.195:62030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9KSJcY4fy7tP-rU37hQAAAkU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:17.407293 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.48.250.41:65045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/a4.php"] [unique_id "apK9KSJcY4fy7tP-rU37iAAAAn8"] [Sat Aug 29 05:06:17.419205 2026] [security2:error] [pid 1017536:tid 1017760] [client 158.23.184.117:1676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/Requests/Exception/file.php"] [unique_id "apK9KSJcY4fy7tP-rU37iQAAAnI"] [Sat Aug 29 05:06:17.422931 2026] [security2:error] [pid 1018003:tid 1018199] [client 158.23.184.117:1395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/aaa.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxLgAABeg"] [Sat Aug 29 05:06:17.432138 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.63.81.20:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/mac.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxLwAABc0"] [Sat Aug 29 05:06:17.441754 2026] [security2:error] [pid 1017536:tid 1017681] [client 158.23.184.117:4836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/test.php"] [unique_id "apK9KSJcY4fy7tP-rU37igAAAiM"] [Sat Aug 29 05:06:17.448022 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.220.204.93:64973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/maraz.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxMAAABcg"] [Sat Aug 29 05:06:17.448441 2026] [security2:error] [pid 1018003:tid 1018264] [client 158.23.147.79:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxMQAABig"] [Sat Aug 29 05:06:17.452198 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.196.209.81:15076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxMgAABc8"] [Sat Aug 29 05:06:17.478793 2026] [security2:error] [pid 1017536:tid 1017687] [client 68.155.159.216:51416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/cong.php"] [unique_id "apK9KSJcY4fy7tP-rU37jAAAAik"] [Sat Aug 29 05:06:17.479609 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:60680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/amp.php"] [unique_id "apK9KSJcY4fy7tP-rU37jQAAAnw"] [Sat Aug 29 05:06:17.483130 2026] [security2:error] [pid 1017536:tid 1017743] [client 138.199.19.170:47964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sankomold.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK9KSJcY4fy7tP-rU37jwAAAmE"] [Sat Aug 29 05:06:17.491683 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.48.251.3:61200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/plss3.php"] [unique_id "apK9KSJcY4fy7tP-rU37kAAAAo8"] [Sat Aug 29 05:06:17.499700 2026] [security2:error] [pid 1018003:tid 1018276] [client 158.23.147.79:58067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/content.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxNAAABjQ"] [Sat Aug 29 05:06:17.514269 2026] [security2:error] [pid 1017536:tid 1017741] [client 52.139.37.240:12877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK9KSJcY4fy7tP-rU37kQAAAl8"] [Sat Aug 29 05:06:17.516858 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.52.41.200:1268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9KSJcY4fy7tP-rU37kgAAAoQ"] [Sat Aug 29 05:06:17.532042 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.196.209.81:16739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/update.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxNQAABdk"] [Sat Aug 29 05:06:17.532488 2026] [security2:error] [pid 1018003:tid 1018252] [client 195.178.110.155:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.greathairkc.com"] [uri "/index.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxNgAABhw"] [Sat Aug 29 05:06:17.543278 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.48.250.41:64317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/tfm.php"] [unique_id "apK9KSJcY4fy7tP-rU37kwAAAoY"] [Sat Aug 29 05:06:17.565618 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.63.81.20:56870] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/1.php"] [unique_id "apK9KSJcY4fy7tP-rU37lAAAAnk"] [Sat Aug 29 05:06:17.565682 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.63.81.20:56870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/1.php"] [unique_id "apK9KSJcY4fy7tP-rU37lAAAAnk"] [Sat Aug 29 05:06:17.581348 2026] [security2:error] [pid 1017536:tid 1017785] [client 40.83.93.50:22244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/f35.php"] [unique_id "apK9KSJcY4fy7tP-rU37lQAAAos"] [Sat Aug 29 05:06:17.586902 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.23.184.117:4488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/mani.php"] [unique_id "apK9KSJcY4fy7tP-rU37lgAAAnM"] [Sat Aug 29 05:06:17.602104 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.23.147.79:24473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/goat1.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxNwAABh8"] [Sat Aug 29 05:06:17.616022 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.251.3:61085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws.php"] [unique_id "apK9KSJcY4fy7tP-rU37lwAAAiU"] [Sat Aug 29 05:06:17.626776 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.250.41:60684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/cc13.php"] [unique_id "apK9KSJcY4fy7tP-rU37mAAAAjA"] [Sat Aug 29 05:06:17.648682 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.251.3:13997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/hochladen.form.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxOQAABds"] [Sat Aug 29 05:06:17.676854 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.184.117:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/hehe.php"] [unique_id "apK9KSJcY4fy7tP-rU37mwAAAks"] [Sat Aug 29 05:06:17.681180 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.23.184.117:60888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-admin/add.php"] [unique_id "apK9KSJcY4fy7tP-rU37nAAAAmY"] [Sat Aug 29 05:06:17.688384 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.48.250.41:65139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/Geforce.php"] [unique_id "apK9KSJcY4fy7tP-rU37nQAAAkk"] [Sat Aug 29 05:06:17.692469 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.63.81.20:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/classwithtostring.php"] [unique_id "apK9KSJcY4fy7tP-rU37ngAAAis"] [Sat Aug 29 05:06:17.730005 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.184.117:4825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/Test.php"] [unique_id "apK9KSJcY4fy7tP-rU37oAAAAjs"] [Sat Aug 29 05:06:17.734697 2026] [security2:error] [pid 1018003:tid 1018269] [client 158.23.147.79:50056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxOgAABi0"] [Sat Aug 29 05:06:17.740975 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.48.251.3:3359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/app.default.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxOwAABd4"] [Sat Aug 29 05:06:17.749939 2026] [security2:error] [pid 1018003:tid 1018161] [client 168.107.94.195:62513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxPAAABcI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:17.761684 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.48.250.41:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/aa.php"] [unique_id "apK9KSJcY4fy7tP-rU37ogAAApA"] [Sat Aug 29 05:06:17.766445 2026] [security2:error] [pid 1018003:tid 1018203] [client 4.205.62.107:22407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/ws79.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxPwAABew"] [Sat Aug 29 05:06:17.775736 2026] [security2:error] [pid 1017536:tid 1017760] [client 52.139.37.240:12876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9KSJcY4fy7tP-rU37owAAAnI"] [Sat Aug 29 05:06:17.788520 2026] [security2:error] [pid 1017536:tid 1017704] [client 40.83.93.50:8000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sharonandgerry.strangeworx.com"] [uri "/aaa.php"] [unique_id "apK9KSJcY4fy7tP-rU37pQAAAjo"] [Sat Aug 29 05:06:17.813462 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.205.62.107:22270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-content/plugin-install.php"] [unique_id "apK9KSJcY4fy7tP-rU37pgAAAi0"] [Sat Aug 29 05:06:17.819157 2026] [security2:error] [pid 1018003:tid 1018271] [client 65.111.20.69:40203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxQAAABi8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:17.824028 2026] [security2:error] [pid 1017536:tid 1017769] [client 158.23.147.79:48395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9KSJcY4fy7tP-rU37pwAAAns"] [Sat Aug 29 05:06:17.824885 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.251.3:13832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/pouhg.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxQQAABgY"] [Sat Aug 29 05:06:17.827933 2026] [security2:error] [pid 1017536:tid 1017741] [client 4.205.62.107:26624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/groceries/index.php"] [unique_id "apK9KSJcY4fy7tP-rU37qAAAAl8"] [Sat Aug 29 05:06:17.829543 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.63.81.20:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-ws68.php"] [unique_id "apK9KSJcY4fy7tP-rU37qQAAAoY"] [Sat Aug 29 05:06:17.829560 2026] [security2:error] [pid 1017536:tid 1017687] [client 158.23.184.117:1399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "apK9KSJcY4fy7tP-rU37qgAAAik"] [Sat Aug 29 05:06:17.832070 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.23.184.117:60867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/assets/about.php"] [unique_id "apK9KSJcY4fy7tP-rU37qwAAAjI"] [Sat Aug 29 05:06:17.840517 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.250.41:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/click.php"] [unique_id "apK9KSJcY4fy7tP-rU37rAAAAjA"] [Sat Aug 29 05:06:17.844423 2026] [security2:error] [pid 1018003:tid 1018193] [client 20.196.209.81:5593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxQgAABeI"] [Sat Aug 29 05:06:17.864225 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.220.204.93:65012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/kbfr.php"] [unique_id "apK9KSJcY4fy7tP-rU37rQAAAoE"] [Sat Aug 29 05:06:17.868405 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.48.251.3:62089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/app_local.php"] [unique_id "apK9KSJcY4fy7tP-rU37rgAAAks"] [Sat Aug 29 05:06:17.876827 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.184.117:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/pomo.php"] [unique_id "apK9KSJcY4fy7tP-rU37rwAAAmc"] [Sat Aug 29 05:06:17.902399 2026] [security2:error] [pid 1018003:tid 1018171] [client 158.158.54.35:18672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-content/admin.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxQwAABcw"] [Sat Aug 29 05:06:17.912452 2026] [security2:error] [pid 1018003:tid 1018235] [client 192.145.125.70:48088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9KTAh5Y1i2tUxg4HxRAAABgs"] [Sat Aug 29 05:06:17.921779 2026] [security2:error] [pid 1017536:tid 1017737] [client 68.155.159.216:24574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/ws.php"] [unique_id "apK9KSJcY4fy7tP-rU37sAAAAls"] [Sat Aug 29 05:06:17.934955 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.104.49.130:51131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/1xmomo.php"] [unique_id "apK9KSJcY4fy7tP-rU37sQAAAkM"] [Sat Aug 29 05:06:17.936862 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.250.41:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/s1.php"] [unique_id "apK9KSJcY4fy7tP-rU37sgAAAow"] [Sat Aug 29 05:06:17.952592 2026] [security2:error] [pid 1017536:tid 1017686] [client 158.23.147.79:30595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9KSJcY4fy7tP-rU37swAAAig"] [Sat Aug 29 05:06:17.965953 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.196.209.81:19400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/blog.php"] [unique_id "apK9KSJcY4fy7tP-rU37tAAAAhY"] [Sat Aug 29 05:06:17.976210 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.63.81.20:60465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/simple.php"] [unique_id "apK9KSJcY4fy7tP-rU37tQAAAio"] [Sat Aug 29 05:06:17.978952 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.184.117:1722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/themes/twentytwentythree.php"] [unique_id "apK9KSJcY4fy7tP-rU37twAAAnc"] [Sat Aug 29 05:06:17.980822 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:49161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-admin/about.php"] [unique_id "apK9KSJcY4fy7tP-rU37uAAAAms"] [Sat Aug 29 05:06:17.982699 2026] [cgid:error] [pid 1017536:tid 1017789] [client 20.52.41.200:1217] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:17.983443 2026] [security2:error] [pid 1018003:tid 1018226] [client 52.139.37.240:12538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-info.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxRQAABgM"] [Sat Aug 29 05:06:17.984741 2026] [security2:error] [pid 1018003:tid 1018188] [client 87.199.194.213:60580] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.194.213" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.theverystuff.com"] [uri "/wp-comments-post.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxRgAABd0"], referer: https://www.theverystuff.com/the-clarity-of-love/ [Sat Aug 29 05:06:17.984811 2026] [security2:error] [pid 1018003:tid 1018188] [client 87.199.194.213:60580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.theverystuff.com"] [uri "/wp-comments-post.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxRgAABd0"], referer: https://www.theverystuff.com/the-clarity-of-love/ [Sat Aug 29 05:06:17.985684 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.184.117:1721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/admin/alfa-rex.php"] [unique_id "apK9KSJcY4fy7tP-rU37uQAAAj0"] [Sat Aug 29 05:06:17.990209 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.197.61.180:5831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/content.php"] [unique_id "apK9KSJcY4fy7tP-rU37ugAAAo4"] [Sat Aug 29 05:06:17.997028 2026] [security2:error] [pid 1018003:tid 1018263] [client 34.21.253.104:16988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/v1/graphql"] [unique_id "apK9KTAh5Y1i2tUxg4HxRwAABic"] [Sat Aug 29 05:06:17.998039 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.251.3:61191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/ws62.php"] [unique_id "apK9KSJcY4fy7tP-rU37vQAAAmQ"] [Sat Aug 29 05:06:17.999586 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.220.204.93:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wp-act.php"] [unique_id "apK9KTAh5Y1i2tUxg4HxSAAABco"] [Sat Aug 29 05:06:18.005055 2026] [proxy_http:error] [pid 1017536:tid 1017729] (20014)Internal error (specific information not available): [client 34.21.253.104:17028] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.005067 2026] [proxy:error] [pid 1017536:tid 1017729] [client 34.21.253.104:17028] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.hermes/.env [Sat Aug 29 05:06:18.011086 2026] [proxy_http:error] [pid 1017536:tid 1017712] (20014)Internal error (specific information not available): [client 34.21.253.104:17018] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.011123 2026] [proxy:error] [pid 1017536:tid 1017712] [client 34.21.253.104:17018] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.anthropic/config.json [Sat Aug 29 05:06:18.011301 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.48.251.3:14049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/product.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxTgAABiM"] [Sat Aug 29 05:06:18.012073 2026] [proxy_http:error] [pid 1018003:tid 1018164] (20014)Internal error (specific information not available): [client 34.21.253.104:16976] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.012085 2026] [proxy:error] [pid 1018003:tid 1018164] [client 34.21.253.104:16976] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/actuator/mappings [Sat Aug 29 05:06:18.013697 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.250.41:64287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ms.php"] [unique_id "apK9KiJcY4fy7tP-rU37zAAAAjw"] [Sat Aug 29 05:06:18.015787 2026] [security2:error] [pid 1018003:tid 1018265] [client 68.155.159.216:9343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/file88.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxVAAABik"] [Sat Aug 29 05:06:18.018165 2026] [security2:error] [pid 1017536:tid 1017790] [client 4.205.62.107:8973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/cp2.php"] [unique_id "apK9KiJcY4fy7tP-rU370AAAApA"] [Sat Aug 29 05:06:18.019496 2026] [proxy_http:error] [pid 1018003:tid 1018170] (20014)Internal error (specific information not available): [client 34.21.253.104:16962] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.019514 2026] [proxy:error] [pid 1018003:tid 1018170] [client 34.21.253.104:16962] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/graphql [Sat Aug 29 05:06:18.025808 2026] [proxy_http:error] [pid 1018003:tid 1018164] (20014)Internal error (specific information not available): [client 34.21.253.104:16976] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.025820 2026] [proxy:error] [pid 1018003:tid 1018164] [client 34.21.253.104:16976] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:06:18.026883 2026] [security2:error] [pid 1017536:tid 1017695] [client 195.178.110.155:40818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new.greathairkc.com"] [uri "/index.php"] [unique_id "apK9KiJcY4fy7tP-rU370wAAAjE"] [Sat Aug 29 05:06:18.030014 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.147.79:25569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/goat.php"] [unique_id "apK9KiJcY4fy7tP-rU371AAAAhw"] [Sat Aug 29 05:06:18.031970 2026] [proxy_http:error] [pid 1018003:tid 1018233] (20014)Internal error (specific information not available): [client 34.21.253.104:17098] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.031988 2026] [proxy:error] [pid 1018003:tid 1018233] [client 34.21.253.104:17098] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.claude/settings.json [Sat Aug 29 05:06:18.032602 2026] [proxy_http:error] [pid 1017536:tid 1017675] (20014)Internal error (specific information not available): [client 34.21.253.104:16910] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.032615 2026] [proxy:error] [pid 1017536:tid 1017675] [client 34.21.253.104:16910] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/docker-compose.yaml [Sat Aug 29 05:06:18.038427 2026] [proxy_http:error] [pid 1018003:tid 1018266] (20014)Internal error (specific information not available): [client 34.21.253.104:17126] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.038439 2026] [proxy:error] [pid 1018003:tid 1018266] [client 34.21.253.104:17126] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/__env.js [Sat Aug 29 05:06:18.039830 2026] [proxy_http:error] [pid 1017536:tid 1017717] (20014)Internal error (specific information not available): [client 34.21.253.104:17046] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.039845 2026] [proxy:error] [pid 1017536:tid 1017717] [client 34.21.253.104:17046] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.hermes/auth.json [Sat Aug 29 05:06:18.043807 2026] [proxy_http:error] [pid 1018003:tid 1018170] (20014)Internal error (specific information not available): [client 34.21.253.104:16962] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.043819 2026] [proxy:error] [pid 1018003:tid 1018170] [client 34.21.253.104:16962] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:06:18.046026 2026] [proxy_http:error] [pid 1017536:tid 1017751] (20014)Internal error (specific information not available): [client 34.21.253.104:17194] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.046040 2026] [proxy:error] [pid 1017536:tid 1017751] [client 34.21.253.104:17194] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.vite/manifest.json [Sat Aug 29 05:06:18.058006 2026] [proxy_http:error] [pid 1017536:tid 1017785] (20014)Internal error (specific information not available): [client 34.21.253.104:17086] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.058021 2026] [proxy:error] [pid 1017536:tid 1017785] [client 34.21.253.104:17086] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.openclaw/openclaw.json [Sat Aug 29 05:06:18.059707 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.147.79:35716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/file5.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxVwAABec"] [Sat Aug 29 05:06:18.062989 2026] [proxy_http:error] [pid 1017536:tid 1017793] (20014)Internal error (specific information not available): [client 34.21.253.104:17186] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.063000 2026] [proxy:error] [pid 1017536:tid 1017793] [client 34.21.253.104:17186] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.js [Sat Aug 29 05:06:18.063508 2026] [security2:error] [pid 1017536:tid 1017736] [client 40.83.93.50:5925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/index.php"] [unique_id "apK9KiJcY4fy7tP-rU371QAAAlo"] [Sat Aug 29 05:06:18.083554 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.48.250.41:60762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/0byte.php"] [unique_id "apK9KiJcY4fy7tP-rU371wAAAik"] [Sat Aug 29 05:06:18.085420 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.23.147.79:30716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9KiJcY4fy7tP-rU372AAAAjI"] [Sat Aug 29 05:06:18.094557 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.147.79:32711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/makeasmtp.php"] [unique_id "apK9KiJcY4fy7tP-rU372QAAAhs"] [Sat Aug 29 05:06:18.118347 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.63.81.20:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/aaa.php"] [unique_id "apK9KiJcY4fy7tP-rU372gAAAoI"] [Sat Aug 29 05:06:18.126628 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.251.3:61231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/grsiuk.php"] [unique_id "apK9KiJcY4fy7tP-rU373AAAAjs"] [Sat Aug 29 05:06:18.130438 2026] [security2:error] [pid 1017536:tid 1017737] [client 168.107.94.195:63076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9KiJcY4fy7tP-rU373gAAAls"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:18.133805 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.52.41.200:1217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/lite.php"] [unique_id "apK9KiJcY4fy7tP-rU374AAAAoM"] [Sat Aug 29 05:06:18.139779 2026] [security2:error] [pid 1018003:tid 1018270] [client 158.23.184.117:4843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-admin/link-add.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxXQAABi4"] [Sat Aug 29 05:06:18.143176 2026] [security2:error] [pid 1017536:tid 1017686] [client 4.205.62.107:22316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/public/bnn_.php.php"] [unique_id "apK9KiJcY4fy7tP-rU374QAAAig"] [Sat Aug 29 05:06:18.151887 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.184.117:1698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/export.php"] [unique_id "apK9KiJcY4fy7tP-rU374gAAAks"] [Sat Aug 29 05:06:18.155913 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:26603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/simple.php"] [unique_id "apK9KiJcY4fy7tP-rU375AAAApI"] [Sat Aug 29 05:06:18.159864 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.48.250.41:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/zxekqlxb.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxXwAABeE"] [Sat Aug 29 05:06:18.166487 2026] [security2:error] [pid 1017536:tid 1017746] [client 35.198.240.194:14848] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9KiJcY4fy7tP-rU376wAAAmQ"] [Sat Aug 29 05:06:18.166683 2026] [security2:error] [pid 1017536:tid 1017723] [client 35.198.240.194:14864] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9KiJcY4fy7tP-rU377gAAAk0"] [Sat Aug 29 05:06:18.166850 2026] [security2:error] [pid 1017536:tid 1017752] [client 35.198.240.194:14896] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9KiJcY4fy7tP-rU377wAAAmo"] [Sat Aug 29 05:06:18.171242 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.220.204.93:64371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/24.php"] [unique_id "apK9KiJcY4fy7tP-rU378AAAAoQ"] [Sat Aug 29 05:06:18.174019 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.184.117:60886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/languages/themes/num.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxZAAABiA"] [Sat Aug 29 05:06:18.176240 2026] [security2:error] [pid 1018003:tid 1018236] [client 52.139.37.240:12889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxZQAABgw"] [Sat Aug 29 05:06:18.178976 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.251.3:13831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/fun.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxZwAABh8"] [Sat Aug 29 05:06:18.184145 2026] [proxy_http:error] [pid 1017536:tid 1017710] (20014)Internal error (specific information not available): [client 34.21.253.104:16896] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:18.184159 2026] [proxy:error] [pid 1017536:tid 1017710] [client 34.21.253.104:16896] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/docker-compose.yml [Sat Aug 29 05:06:18.201317 2026] [security2:error] [pid 1017536:tid 1017714] [client 35.198.240.194:15004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/client/.env"] [unique_id "apK9KiJcY4fy7tP-rU379QAAAkQ"] [Sat Aug 29 05:06:18.206428 2026] [security2:error] [pid 1017536:tid 1017678] [client 35.198.240.194:15038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/staging/.env"] [unique_id "apK9KiJcY4fy7tP-rU37-AAAAiA"] [Sat Aug 29 05:06:18.208114 2026] [security2:error] [pid 1017536:tid 1017704] [client 35.198.240.194:15070] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9KiJcY4fy7tP-rU379wAAAjo"] [Sat Aug 29 05:06:18.208218 2026] [security2:error] [pid 1017536:tid 1017743] [client 35.198.240.194:15060] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "apK9KiJcY4fy7tP-rU37-gAAAmE"] [Sat Aug 29 05:06:18.209826 2026] [security2:error] [pid 1017536:tid 1017724] [client 35.198.240.194:15086] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9KiJcY4fy7tP-rU37-QAAAk4"] [Sat Aug 29 05:06:18.211219 2026] [security2:error] [pid 1017536:tid 1017747] [client 35.198.240.194:15022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/production/.env"] [unique_id "apK9KiJcY4fy7tP-rU37_AAAAmU"] [Sat Aug 29 05:06:18.211583 2026] [security2:error] [pid 1017536:tid 1017769] [client 35.198.240.194:15008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/backup/.env"] [unique_id "apK9KiJcY4fy7tP-rU37_QAAAns"] [Sat Aug 29 05:06:18.212035 2026] [security2:error] [pid 1017536:tid 1017773] [client 35.198.240.194:15032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/dev/.env"] [unique_id "apK9KiJcY4fy7tP-rU37_gAAAn8"] [Sat Aug 29 05:06:18.236315 2026] [security2:error] [pid 1017536:tid 1017705] [client 4.205.62.107:55971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/xda.php"] [unique_id "apK9KiJcY4fy7tP-rU38AwAAAjs"] [Sat Aug 29 05:06:18.245103 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.196.209.81:5631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxbQAABc8"] [Sat Aug 29 05:06:18.253117 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.250.41:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/xr.php"] [unique_id "apK9KiJcY4fy7tP-rU38BgAAAm8"] [Sat Aug 29 05:06:18.256802 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.48.251.3:61105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/paypal.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxbgAABhk"] [Sat Aug 29 05:06:18.284845 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.23.184.117:4483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/Text.php"] [unique_id "apK9KiJcY4fy7tP-rU38CAAAAjQ"] [Sat Aug 29 05:06:18.286323 2026] [core:error] [pid 1017536:tid 1017765] [client 45.148.10.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:18.286338 2026] [core:error] [pid 1017536:tid 1017765] [client 45.148.10.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:18.295773 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.184.117:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/new.php"] [unique_id "apK9KiJcY4fy7tP-rU38CQAAAow"] [Sat Aug 29 05:06:18.317339 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.250.41:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/init.php"] [unique_id "apK9KiJcY4fy7tP-rU38CgAAAlU"] [Sat Aug 29 05:06:18.319250 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.184.117:1703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp.php"] [unique_id "apK9KiJcY4fy7tP-rU38DAAAApI"] [Sat Aug 29 05:06:18.351367 2026] [security2:error] [pid 1017536:tid 1017770] [client 104.207.44.232:24045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.44.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9KiJcY4fy7tP-rU38EAAAAnw"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:18.354213 2026] [security2:error] [pid 1017536:tid 1017760] [client 68.155.159.216:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9KiJcY4fy7tP-rU38FAAAAnI"] [Sat Aug 29 05:06:18.363204 2026] [security2:error] [pid 1017536:tid 1017722] [client 52.139.37.240:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/ws49.php"] [unique_id "apK9KiJcY4fy7tP-rU38FQAAAkw"] [Sat Aug 29 05:06:18.374403 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.48.251.3:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/kedi.php"] [unique_id "apK9KiJcY4fy7tP-rU38GAAAAh0"] [Sat Aug 29 05:06:18.377166 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.196.209.81:19410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/bypass.php"] [unique_id "apK9KiJcY4fy7tP-rU38GgAAAoM"] [Sat Aug 29 05:06:18.380428 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.158.54.35:6227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-configs.php"] [unique_id "apK9KiJcY4fy7tP-rU38GwAAAmY"] [Sat Aug 29 05:06:18.381318 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.251.3:61207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/userfuns.php"] [unique_id "apK9KiJcY4fy7tP-rU38HAAAAos"] [Sat Aug 29 05:06:18.383825 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.220.204.93:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/155.php"] [unique_id "apK9KiJcY4fy7tP-rU38HQAAApM"] [Sat Aug 29 05:06:18.386255 2026] [security2:error] [pid 1018003:tid 1018269] [client 68.155.159.216:12180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxcwAABi0"] [Sat Aug 29 05:06:18.405783 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.63.81.20:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/shiny.php"] [unique_id "apK9KiJcY4fy7tP-rU38HwAAAiI"] [Sat Aug 29 05:06:18.408816 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.250.41:60688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/h02ugyh.php"] [unique_id "apK9KiJcY4fy7tP-rU38IAAAAjo"] [Sat Aug 29 05:06:18.412821 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.104.49.130:63431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/Jcrop.php"] [unique_id "apK9KiJcY4fy7tP-rU38IQAAAk4"] [Sat Aug 29 05:06:18.457815 2026] [security2:error] [pid 1017536:tid 1017712] [client 158.23.184.117:1717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/plugins/revslider/admin.php"] [unique_id "apK9KiJcY4fy7tP-rU38JAAAAkI"] [Sat Aug 29 05:06:18.462931 2026] [security2:error] [pid 1017536:tid 1017747] [client 158.23.184.117:60871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/xmlrpc.php"] [unique_id "apK9KiJcY4fy7tP-rU38JQAAAmU"] [Sat Aug 29 05:06:18.480946 2026] [security2:error] [pid 1017536:tid 1017775] [client 20.48.250.41:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/term.php"] [unique_id "apK9KiJcY4fy7tP-rU38JgAAAoE"] [Sat Aug 29 05:06:18.504343 2026] [security2:error] [pid 1017536:tid 1017736] [client 192.145.125.70:48102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9KiJcY4fy7tP-rU38KAAAAlo"] [Sat Aug 29 05:06:18.506456 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.251.3:61098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/mamzi.php"] [unique_id "apK9KiJcY4fy7tP-rU38KQAAAj0"] [Sat Aug 29 05:06:18.510384 2026] [security2:error] [pid 1017536:tid 1017721] [client 168.107.94.195:63475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9KiJcY4fy7tP-rU38KgAAAks"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:18.523785 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.48.251.3:14011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/oc460l3x.php"] [unique_id "apK9KiJcY4fy7tP-rU38LAAAAj8"] [Sat Aug 29 05:06:18.531698 2026] [security2:error] [pid 1017536:tid 1017751] [client 158.23.184.117:4487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-trackback.php"] [unique_id "apK9KiJcY4fy7tP-rU38LQAAAmk"] [Sat Aug 29 05:06:18.532290 2026] [security2:error] [pid 1018003:tid 1018156] [client 40.83.93.50:5895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/install.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxdgAABb0"] [Sat Aug 29 05:06:18.539738 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.63.81.20:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/goods.php"] [unique_id "apK9KiJcY4fy7tP-rU38LgAAAjQ"] [Sat Aug 29 05:06:18.552417 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.147.79:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9KiJcY4fy7tP-rU38LwAAAow"] [Sat Aug 29 05:06:18.553447 2026] [security2:error] [pid 1017536:tid 1017744] [client 52.139.37.240:12502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/xxx.php"] [unique_id "apK9KiJcY4fy7tP-rU38MAAAAmI"] [Sat Aug 29 05:06:18.577433 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.52.41.200:1220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/term.php"] [unique_id "apK9KiJcY4fy7tP-rU38MQAAAn8"] [Sat Aug 29 05:06:18.600422 2026] [security2:error] [pid 1017536:tid 1017731] [client 114.119.135.182:54131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_info.php/cPath/4/products_id/948/action/notify/osCsid/f6d9065f9a23bae493264dcebafa97ba"] [unique_id "apK9KiJcY4fy7tP-rU38NAAAAlU"], referer: http://www.classiclightingusa.com/catalog/product_info.php/cPath/4/products_id/948/osCsid/f6d9065f9a23bae493264dcebafa97ba [Sat Aug 29 05:06:18.602629 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.250.41:62511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/xxw.php"] [unique_id "apK9KiJcY4fy7tP-rU38NQAAApI"] [Sat Aug 29 05:06:18.603626 2026] [security2:error] [pid 1017536:tid 1017746] [client 158.23.184.117:1688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/images/uploads/admin.php"] [unique_id "apK9KiJcY4fy7tP-rU38NgAAAmQ"] [Sat Aug 29 05:06:18.610183 2026] [security2:error] [pid 1018003:tid 1018225] [client 87.199.194.213:60625] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.194.213" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.theverystuff.com"] [uri "/wp-comments-post.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxdwAABgI"], referer: https://www.theverystuff.com/the-clarity-of-love/ [Sat Aug 29 05:06:18.610261 2026] [security2:error] [pid 1018003:tid 1018225] [client 87.199.194.213:60625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.theverystuff.com"] [uri "/wp-comments-post.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxdwAABgI"], referer: https://www.theverystuff.com/the-clarity-of-love/ [Sat Aug 29 05:06:18.615928 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/aaa.php"] [unique_id "apK9KiJcY4fy7tP-rU38OAAAAmM"] [Sat Aug 29 05:06:18.618336 2026] [security2:error] [pid 1018003:tid 1018197] [client 158.23.147.79:62718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxeAAABeY"] [Sat Aug 29 05:06:18.620169 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.184.117:60875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/app.php"] [unique_id "apK9KiJcY4fy7tP-rU38OQAAApA"] [Sat Aug 29 05:06:18.640139 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.251.3:3331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/public/rip.php.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxeQAABcI"] [Sat Aug 29 05:06:18.653658 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.49.130:60969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/forum.php"] [unique_id "apK9KiJcY4fy7tP-rU38PAAAAh0"] [Sat Aug 29 05:06:18.666470 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.196.209.81:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/config.php"] [unique_id "apK9KiJcY4fy7tP-rU38PgAAAio"] [Sat Aug 29 05:06:18.670739 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.63.81.20:60521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/000.php/index.php"] [unique_id "apK9KiJcY4fy7tP-rU38PwAAAmY"] [Sat Aug 29 05:06:18.676959 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.184.117:4647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-admin/maint.php"] [unique_id "apK9KiJcY4fy7tP-rU38QAAAAi0"] [Sat Aug 29 05:06:18.712583 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.197.61.180:5870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/core.php"] [unique_id "apK9KiJcY4fy7tP-rU38QQAAAjA"] [Sat Aug 29 05:06:18.722690 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.251.3:14069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-info.php"] [unique_id "apK9KiJcY4fy7tP-rU38QgAAAnk"] [Sat Aug 29 05:06:18.734069 2026] [security2:error] [pid 1017536:tid 1017706] [client 158.23.147.79:24502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9KiJcY4fy7tP-rU38QwAAAjw"] [Sat Aug 29 05:06:18.745879 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.250.41:64373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/xsox.php"] [unique_id "apK9KiJcY4fy7tP-rU38RAAAAig"] [Sat Aug 29 05:06:18.753309 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.23.184.117:1699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/tools.php"] [unique_id "apK9KiJcY4fy7tP-rU38RQAAAkQ"] [Sat Aug 29 05:06:18.768584 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.251.3:62104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/environment.php"] [unique_id "apK9KiJcY4fy7tP-rU38RgAAAmc"] [Sat Aug 29 05:06:18.768668 2026] [security2:error] [pid 1018003:tid 1018258] [client 52.139.37.240:12887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/0x.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxegAABiI"] [Sat Aug 29 05:06:18.787945 2026] [security2:error] [pid 1017536:tid 1017687] [client 158.23.184.117:1706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/aaa.php"] [unique_id "apK9KiJcY4fy7tP-rU38RwAAAik"] [Sat Aug 29 05:06:18.800763 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.63.81.20:56899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/Jcrop.php"] [unique_id "apK9KiJcY4fy7tP-rU38SgAAAj8"] [Sat Aug 29 05:06:18.823417 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.23.184.117:4496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/num.php"] [unique_id "apK9KiJcY4fy7tP-rU38TwAAAm8"] [Sat Aug 29 05:06:18.863245 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.196.209.81:4463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/extractable-loader-head.php"] [unique_id "apK9KiJcY4fy7tP-rU38UQAAAnw"] [Sat Aug 29 05:06:18.864303 2026] [security2:error] [pid 1017536:tid 1017740] [client 158.158.54.35:29419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/index.php"] [unique_id "apK9KiJcY4fy7tP-rU38UgAAAl4"] [Sat Aug 29 05:06:18.866787 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.48.251.3:33308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/fns.php"] [unique_id "apK9KiJcY4fy7tP-rU38UwAAAms"] [Sat Aug 29 05:06:18.867970 2026] [security2:error] [pid 1017536:tid 1017781] [client 68.155.159.216:33789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9KiJcY4fy7tP-rU38VAAAAoc"] [Sat Aug 29 05:06:18.867994 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.250.41:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/bolt.php"] [unique_id "apK9KiJcY4fy7tP-rU38VQAAAlU"] [Sat Aug 29 05:06:18.868462 2026] [security2:error] [pid 1017536:tid 1017680] [client 104.207.44.219:19717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.44.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9KiJcY4fy7tP-rU38UAAAAiI"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:18.871248 2026] [security2:error] [pid 1017536:tid 1017734] [client 68.155.159.216:51561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/cgi-bin/index.php"] [unique_id "apK9KiJcY4fy7tP-rU38VgAAAlg"] [Sat Aug 29 05:06:18.895070 2026] [security2:error] [pid 1018003:tid 1018173] [client 168.107.94.195:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxfQAABc4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:18.897072 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.251.3:62103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws_secret_config.php"] [unique_id "apK9KiJcY4fy7tP-rU38VwAAAkE"] [Sat Aug 29 05:06:18.897436 2026] [security2:error] [pid 1017536:tid 1017752] [client 158.23.184.117:1691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-content/uploads/my.php"] [unique_id "apK9KiJcY4fy7tP-rU38WAAAAmo"] [Sat Aug 29 05:06:18.899057 2026] [security2:error] [pid 1017536:tid 1017776] [client 68.155.159.216:14190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-l0gin.php"] [unique_id "apK9KiJcY4fy7tP-rU38WQAAAoI"] [Sat Aug 29 05:06:18.903352 2026] [security2:error] [pid 1017536:tid 1017745] [client 4.205.62.107:22353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/sys.php"] [unique_id "apK9KiJcY4fy7tP-rU38WgAAAmM"] [Sat Aug 29 05:06:18.926723 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.48.250.41:64380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/lkui.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxfgAABik"] [Sat Aug 29 05:06:18.932507 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.23.147.79:48326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/content.php"] [unique_id "apK9KiJcY4fy7tP-rU38WwAAAos"] [Sat Aug 29 05:06:18.943943 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.63.81.20:60510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxgAAABis"] [Sat Aug 29 05:06:18.945637 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.151.200.44:46639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/ztv.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxgQAABeM"] [Sat Aug 29 05:06:18.950308 2026] [security2:error] [pid 1018003:tid 1018160] [client 4.205.62.107:22263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/paypal.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxggAABcE"] [Sat Aug 29 05:06:18.952038 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.104.49.130:46565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/v2.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxgwAABcs"] [Sat Aug 29 05:06:18.956461 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:50306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/cgi-bin/index.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxhAAABgk"] [Sat Aug 29 05:06:18.962555 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.23.147.79:49846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxhQAABio"] [Sat Aug 29 05:06:18.962556 2026] [security2:error] [pid 1017536:tid 1017737] [client 52.139.37.240:12539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/CDX1.php"] [unique_id "apK9KiJcY4fy7tP-rU38XQAAAls"] [Sat Aug 29 05:06:18.962984 2026] [security2:error] [pid 1017536:tid 1017769] [client 4.205.62.107:26626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/konfig.php"] [unique_id "apK9KiJcY4fy7tP-rU38XgAAAns"] [Sat Aug 29 05:06:18.971784 2026] [security2:error] [pid 1018003:tid 1018259] [client 158.23.184.117:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/identity.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxhgAABiM"] [Sat Aug 29 05:06:18.987327 2026] [security2:error] [pid 1018003:tid 1018190] [client 158.23.184.117:1686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/hehe.php"] [unique_id "apK9KjAh5Y1i2tUxg4HxhwAABd8"] [Sat Aug 29 05:06:19.021110 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:60716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/rtx.php"] [unique_id "apK9KyJcY4fy7tP-rU38YAAAAj0"] [Sat Aug 29 05:06:19.025056 2026] [security2:error] [pid 1018003:tid 1018184] [client 68.155.159.216:24539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxiAAABdk"] [Sat Aug 29 05:06:19.026274 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.251.3:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/snq.php"] [unique_id "apK9KyJcY4fy7tP-rU38YQAAAmk"] [Sat Aug 29 05:06:19.030467 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.251.3:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/gjm.php"] [unique_id "apK9KyJcY4fy7tP-rU38YwAAAnw"] [Sat Aug 29 05:06:19.030682 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.52.41.200:1219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/config.php"] [unique_id "apK9KyJcY4fy7tP-rU38ZAAAAho"] [Sat Aug 29 05:06:19.040515 2026] [autoindex:error] [pid 1017536:tid 1017761] [client 40.83.93.50:12445] AH01276: Cannot serve directory /home1/termoenv/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:19.043280 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.184.117:60870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/themes/uploads/config.php"] [unique_id "apK9KyJcY4fy7tP-rU38ZQAAAkM"] [Sat Aug 29 05:06:19.058289 2026] [security2:error] [pid 1017536:tid 1017688] [client 20.48.250.41:65037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9KyJcY4fy7tP-rU38ZgAAAio"] [Sat Aug 29 05:06:19.060494 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.196.209.81:23620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/cong.php"] [unique_id "apK9KyJcY4fy7tP-rU38ZwAAAjE"] [Sat Aug 29 05:06:19.066927 2026] [security2:error] [pid 1018003:tid 1018236] [client 158.23.147.79:30587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxiQAABgw"] [Sat Aug 29 05:06:19.077519 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.63.81.20:56905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/btx25.php"] [unique_id "apK9KyJcY4fy7tP-rU38aAAAAoM"] [Sat Aug 29 05:06:19.104687 2026] [security2:error] [pid 1018003:tid 1018193] [client 192.145.125.70:48112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9KzAh5Y1i2tUxg4HxigAABeI"] [Sat Aug 29 05:06:19.133345 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.184.117:55509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/PHPMailer.php"] [unique_id "apK9KyJcY4fy7tP-rU38agAAAkc"] [Sat Aug 29 05:06:19.140626 2026] [security2:error] [pid 1018003:tid 1018169] [client 62.60.130.128:59489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xyzece.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxjAAABco"] [Sat Aug 29 05:06:19.144790 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:52756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/NewFile.php/"] [unique_id "apK9KzAh5Y1i2tUxg4HxjQAABbw"] [Sat Aug 29 05:06:19.151144 2026] [security2:error] [pid 1017536:tid 1017714] [client 158.23.147.79:25536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9KyJcY4fy7tP-rU38bAAAAkQ"] [Sat Aug 29 05:06:19.155295 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.48.251.3:62142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-access.php"] [unique_id "apK9KyJcY4fy7tP-rU38bQAAAmU"] [Sat Aug 29 05:06:19.165594 2026] [security2:error] [pid 1017536:tid 1017775] [client 158.23.147.79:35803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/file88.php"] [unique_id "apK9KyJcY4fy7tP-rU38cAAAAoE"] [Sat Aug 29 05:06:19.168277 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.184.117:4519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/Radio.php"] [unique_id "apK9KyJcY4fy7tP-rU38cwAAAmE"] [Sat Aug 29 05:06:19.170734 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.205.62.107:8992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/error_log.php"] [unique_id "apK9KyJcY4fy7tP-rU38dAAAAlY"] [Sat Aug 29 05:06:19.175008 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.48.250.41:62488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/ckk.php"] [unique_id "apK9KyJcY4fy7tP-rU38dQAAAhs"] [Sat Aug 29 05:06:19.180994 2026] [security2:error] [pid 1017536:tid 1017767] [client 52.139.37.240:12873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/akcc.php"] [unique_id "apK9KyJcY4fy7tP-rU38dgAAAnk"] [Sat Aug 29 05:06:19.183685 2026] [security2:error] [pid 1017536:tid 1017706] [client 158.23.184.117:55511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/av.php"] [unique_id "apK9KyJcY4fy7tP-rU38dwAAAjw"] [Sat Aug 29 05:06:19.187113 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.151.200.44:46654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/kure.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxjgAABcg"] [Sat Aug 29 05:06:19.199953 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.48.251.3:14001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/configuration.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxjwAABe8"] [Sat Aug 29 05:06:19.203553 2026] [security2:error] [pid 1017536:tid 1017757] [client 40.83.93.50:12445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/languages/about.php"] [unique_id "apK9KyJcY4fy7tP-rU38eQAAAm8"] [Sat Aug 29 05:06:19.221785 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.48.250.41:64318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/motu.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxkQAABc8"] [Sat Aug 29 05:06:19.222345 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.63.81.20:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/radio.php"] [unique_id "apK9KyJcY4fy7tP-rU38ewAAAl4"] [Sat Aug 29 05:06:19.274845 2026] [security2:error] [pid 1017536:tid 1017729] [client 168.107.94.195:64330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9KyJcY4fy7tP-rU38fgAAAlM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:19.279662 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.184.117:60896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "apK9KyJcY4fy7tP-rU38fwAAAoc"] [Sat Aug 29 05:06:19.282569 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.48.251.3:62110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/otuz1.php"] [unique_id "apK9KyJcY4fy7tP-rU38gAAAApA"] [Sat Aug 29 05:06:19.282867 2026] [security2:error] [pid 1017536:tid 1017760] [client 4.205.62.107:22487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/wsws.php"] [unique_id "apK9KyJcY4fy7tP-rU38gQAAAnI"] [Sat Aug 29 05:06:19.308546 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.158.54.35:33022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin/a.php"] [unique_id "apK9KyJcY4fy7tP-rU38gwAAAmc"] [Sat Aug 29 05:06:19.328029 2026] [security2:error] [pid 1017536:tid 1017789] [client 20.196.209.81:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/defaults.php"] [unique_id "apK9KyJcY4fy7tP-rU38hQAAAo8"] [Sat Aug 29 05:06:19.361123 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.48.250.41:59351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.harnessmeasurement.com"] [uri "/R57.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxlQAABb0"] [Sat Aug 29 05:06:19.364406 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.63.81.20:60522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/dex.php"] [unique_id "apK9KyJcY4fy7tP-rU38hgAAAhw"] [Sat Aug 29 05:06:19.366644 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.184.117:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/Requests/Exception/file.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxlgAABgI"] [Sat Aug 29 05:06:19.383178 2026] [security2:error] [pid 1017536:tid 1017704] [client 4.205.62.107:53273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/pinfo.php"] [unique_id "apK9KyJcY4fy7tP-rU38hwAAAjo"] [Sat Aug 29 05:06:19.390828 2026] [security2:error] [pid 1017536:tid 1017785] [client 52.139.37.240:12875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9KyJcY4fy7tP-rU38iAAAAos"] [Sat Aug 29 05:06:19.399219 2026] [security2:error] [pid 1018003:tid 1018245] [client 158.23.184.117:55501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-includes/ID3/file.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxlwAABhU"] [Sat Aug 29 05:06:19.402529 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.48.250.41:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/Ov-Simple1.php"] [unique_id "apK9KyJcY4fy7tP-rU38jwAAAks"] [Sat Aug 29 05:06:19.410050 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.251.3:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/update.php"] [unique_id "apK9KyJcY4fy7tP-rU38lAAAAiM"] [Sat Aug 29 05:06:19.416231 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.197.61.180:5339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/db-status.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxmwAABbk"] [Sat Aug 29 05:06:19.424963 2026] [security2:error] [pid 1017536:tid 1017668] [client 158.23.184.117:60901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/admin/alfa-rex.php"] [unique_id "apK9KyJcY4fy7tP-rU38lgAAAhY"] [Sat Aug 29 05:06:19.428180 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.251.3:13973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/cu.php"] [unique_id "apK9KyJcY4fy7tP-rU38mAAAAig"] [Sat Aug 29 05:06:19.429573 2026] [security2:error] [pid 1018003:tid 1018261] [client 216.26.251.131:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.251.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxmgAABiU"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:19.430474 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.430489 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.434398 2026] [security2:error] [pid 1017536:tid 1017587] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9KyJcY4fy7tP-rU38mwACfzI"] [Sat Aug 29 05:06:19.434795 2026] [core:error] [pid 1017536:tid 1017775] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.434804 2026] [core:error] [pid 1017536:tid 1017775] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.434838 2026] [core:error] [pid 1017536:tid 1017743] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.434846 2026] [core:error] [pid 1017536:tid 1017743] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.438106 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.438121 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.447895 2026] [security2:error] [pid 1018003:tid 1018239] [client 68.155.159.216:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/dropdown.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxnAAABg8"] [Sat Aug 29 05:06:19.460053 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.460068 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.462224 2026] [security2:error] [pid 1017536:tid 1017736] [client 68.155.159.216:56887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9KyJcY4fy7tP-rU38oAAAAlo"] [Sat Aug 29 05:06:19.470199 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.52.41.200:1409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxngAABd4"] [Sat Aug 29 05:06:19.479732 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.220.204.93:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/file.php"] [unique_id "apK9KyJcY4fy7tP-rU38oQAAAoY"] [Sat Aug 29 05:06:19.483249 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.196.209.81:5196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/content.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxoAAABhI"] [Sat Aug 29 05:06:19.486787 2026] [security2:error] [pid 1017536:tid 1017745] [client 68.155.159.216:12131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/themes.php"] [unique_id "apK9KyJcY4fy7tP-rU38owAAAmM"] [Sat Aug 29 05:06:19.488291 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.488302 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.498084 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.151.200.44:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/cafe.php"] [unique_id "apK9KyJcY4fy7tP-rU38pgAAApA"] [Sat Aug 29 05:06:19.498283 2026] [core:error] [pid 1017536:tid 1017713] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.498292 2026] [core:error] [pid 1017536:tid 1017713] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.501717 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.63.81.20:60439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/giodywky.php"] [unique_id "apK9KyJcY4fy7tP-rU38pwAAAkw"] [Sat Aug 29 05:06:19.514767 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.63.81.20:46876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxogAABgc"] [Sat Aug 29 05:06:19.525966 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.151.200.44:64920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/mega.php"] [unique_id "apK9KyJcY4fy7tP-rU38qQAAAkA"] [Sat Aug 29 05:06:19.538638 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.251.3:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/channels.php"] [unique_id "apK9KyJcY4fy7tP-rU38qgAAAjA"] [Sat Aug 29 05:06:19.542546 2026] [security2:error] [pid 1017536:tid 1017729] [client 158.23.184.117:60893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acrylic-alchemy.allgooddays.org"] [uri "/wp-admin/css/fff.php"] [unique_id "apK9KyJcY4fy7tP-rU38qwAAAlM"] [Sat Aug 29 05:06:19.550634 2026] [security2:error] [pid 1017536:tid 1017664] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9KyJcY4fy7tP-rU38swACX38"] [Sat Aug 29 05:06:19.552902 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.552925 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.557538 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.184.117:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-admin/add.php"] [unique_id "apK9KyJcY4fy7tP-rU38uAAAAls"] [Sat Aug 29 05:06:19.560714 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.23.147.79:26458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/about.php"] [unique_id "apK9KyJcY4fy7tP-rU38uQAAAm8"] [Sat Aug 29 05:06:19.568919 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.184.117:55513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/export.php"] [unique_id "apK9KyJcY4fy7tP-rU38ugAAAi0"] [Sat Aug 29 05:06:19.570765 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.250.41:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/wp-blogs.php"] [unique_id "apK9KyJcY4fy7tP-rU38uwAAAmk"] [Sat Aug 29 05:06:19.573699 2026] [core:error] [pid 1017536:tid 1017723] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.573714 2026] [core:error] [pid 1017536:tid 1017723] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.576944 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.576959 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.579781 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.579794 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.580774 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.580796 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.583733 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.583745 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.586772 2026] [security2:error] [pid 1017536:tid 1017793] [client 52.139.37.240:12880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/s.php"] [unique_id "apK9KyJcY4fy7tP-rU38wAAAApM"] [Sat Aug 29 05:06:19.589223 2026] [security2:error] [pid 1017536:tid 1017541] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9KyJcY4fy7tP-rU38wQACXwQ"] [Sat Aug 29 05:06:19.601995 2026] [security2:error] [pid 1017536:tid 1017563] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9KyJcY4fy7tP-rU38xQACXxo"] [Sat Aug 29 05:06:19.603323 2026] [core:error] [pid 1017536:tid 1017604] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.603336 2026] [core:error] [pid 1017536:tid 1017604] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.613915 2026] [security2:error] [pid 1017536:tid 1017722] [client 68.155.159.216:51494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9KyJcY4fy7tP-rU38xgAAAkw"] [Sat Aug 29 05:06:19.621785 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.621799 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.633860 2026] [core:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.633872 2026] [core:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.639542 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.63.81.20:60433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-kz.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxrAAABhA"] [Sat Aug 29 05:06:19.641577 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.63.81.20:46962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9KyJcY4fy7tP-rU38zQAAAjA"] [Sat Aug 29 05:06:19.653218 2026] [core:error] [pid 1017536:tid 1017729] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.653229 2026] [core:error] [pid 1017536:tid 1017729] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.654727 2026] [security2:error] [pid 1017536:tid 1017696] [client 168.107.94.195:64669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9KyJcY4fy7tP-rU380AAAAjI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:19.668830 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.48.251.3:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/zz.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxrgAABdU"] [Sat Aug 29 05:06:19.673945 2026] [security2:error] [pid 1018003:tid 1018200] [client 40.83.93.50:22220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxrwAABek"] [Sat Aug 29 05:06:19.675395 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.23.147.79:53762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/chosen.php"] [unique_id "apK9KyJcY4fy7tP-rU380QAAAm8"] [Sat Aug 29 05:06:19.700762 2026] [security2:error] [pid 1017536:tid 1017748] [client 192.145.125.70:48118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9KyJcY4fy7tP-rU380gAAAmY"] [Sat Aug 29 05:06:19.715590 2026] [security2:error] [pid 1017536:tid 1017583] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9KyJcY4fy7tP-rU381AACKi4"] [Sat Aug 29 05:06:19.716164 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.48.250.41:64351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/mini.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxtwAABiw"] [Sat Aug 29 05:06:19.717291 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.184.117:60914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/new.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxuAAABdQ"] [Sat Aug 29 05:06:19.725988 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.196.209.81:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/post.php"] [unique_id "apK9KyJcY4fy7tP-rU382gAAAoQ"] [Sat Aug 29 05:06:19.727052 2026] [security2:error] [pid 1017536:tid 1017552] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9KyJcY4fy7tP-rU382wACKg8"] [Sat Aug 29 05:06:19.730427 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.23.184.117:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/assets/about.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxuwAABfk"] [Sat Aug 29 05:06:19.732992 2026] [security2:error] [pid 1017536:tid 1017600] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9KyJcY4fy7tP-rU383AACKj8"] [Sat Aug 29 05:06:19.742707 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.23.147.79:63009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxvQAABh8"] [Sat Aug 29 05:06:19.747073 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.747093 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.766197 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.63.81.20:56911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxvwAABhQ"] [Sat Aug 29 05:06:19.770606 2026] [core:error] [pid 1017536:tid 1017789] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.770623 2026] [core:error] [pid 1017536:tid 1017789] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.783673 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.783689 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.787055 2026] [core:error] [pid 1017536:tid 1017675] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.787069 2026] [core:error] [pid 1017536:tid 1017675] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.787717 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.787730 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.790009 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.63.81.20:44481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ap.php"] [unique_id "apK9KyJcY4fy7tP-rU387wAAAjA"] [Sat Aug 29 05:06:19.791619 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.791632 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.794223 2026] [security2:error] [pid 1018003:tid 1018276] [client 52.139.37.240:12874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/sagax.php"] [unique_id "apK9KzAh5Y1i2tUxg4HxxQAABjQ"] [Sat Aug 29 05:06:19.817100 2026] [core:error] [pid 1017536:tid 1017769] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.817115 2026] [core:error] [pid 1017536:tid 1017769] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.817536 2026] [core:error] [pid 1017536:tid 1017696] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.817551 2026] [core:error] [pid 1017536:tid 1017696] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.818398 2026] [core:error] [pid 1017536:tid 1017720] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.818414 2026] [core:error] [pid 1017536:tid 1017720] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.830870 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.830885 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.843006 2026] [core:error] [pid 1018003:tid 1018261] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.843021 2026] [core:error] [pid 1018003:tid 1018261] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.849154 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.147.79:24467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9KyJcY4fy7tP-rU38-AAAAnw"] [Sat Aug 29 05:06:19.864500 2026] [security2:error] [pid 1017536:tid 1017714] [client 20.48.250.41:64361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/amp.php"] [unique_id "apK9KyJcY4fy7tP-rU38-QAAAkQ"] [Sat Aug 29 05:06:19.873281 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.23.184.117:4841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/themes/twentytwentythree.php"] [unique_id "apK9KyJcY4fy7tP-rU38-wAAAjQ"] [Sat Aug 29 05:06:19.877813 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.196.209.81:5625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/core.php"] [unique_id "apK9KzAh5Y1i2tUxg4Hx0gAABfU"] [Sat Aug 29 05:06:19.902984 2026] [core:error] [pid 1017536:tid 1017767] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.903000 2026] [core:error] [pid 1017536:tid 1017767] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.903994 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.63.81.20:60487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/session.php"] [unique_id "apK9KyJcY4fy7tP-rU38_QAAAiI"] [Sat Aug 29 05:06:19.918204 2026] [security2:error] [pid 1017536:tid 1017709] [client 158.158.54.35:22317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9KyJcY4fy7tP-rU38_gAAAj8"] [Sat Aug 29 05:06:19.931997 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.52.41.200:1768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-good.php"] [unique_id "apK9KyJcY4fy7tP-rU38_wAAAl4"] [Sat Aug 29 05:06:19.932301 2026] [security2:error] [pid 1018003:tid 1018251] [client 158.23.184.117:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/plugins/revslider/admin.php"] [unique_id "apK9KzAh5Y1i2tUxg4Hx1gAABhs"] [Sat Aug 29 05:06:19.939774 2026] [security2:error] [pid 1017536:tid 1017593] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/.env.php"] [unique_id "apK9KyJcY4fy7tP-rU39AgACQjg"] [Sat Aug 29 05:06:19.941452 2026] [security2:error] [pid 1017536:tid 1017570] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9KyJcY4fy7tP-rU39AQACQiE"] [Sat Aug 29 05:06:19.953146 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.63.81.20:46924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/media.php"] [unique_id "apK9KyJcY4fy7tP-rU39BgAAAmQ"] [Sat Aug 29 05:06:19.966525 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.220.204.93:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9KyJcY4fy7tP-rU39CQAAAjs"] [Sat Aug 29 05:06:19.970727 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.970746 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.973586 2026] [security2:error] [pid 1017536:tid 1017749] [client 68.155.159.216:33743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9KyJcY4fy7tP-rU39CgAAAmc"] [Sat Aug 29 05:06:19.976883 2026] [security2:error] [pid 1017536:tid 1017781] [client 68.155.159.216:51446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9KyJcY4fy7tP-rU39CwAAAoc"] [Sat Aug 29 05:06:19.984244 2026] [core:error] [pid 1017536:tid 1017781] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:19.984261 2026] [core:error] [pid 1017536:tid 1017781] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.004550 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.004565 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.014264 2026] [security2:error] [pid 1017536:tid 1017545] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9LCJcY4fy7tP-rU39EQACQgg"] [Sat Aug 29 05:06:20.014776 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.250.41:64353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/cc13.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx3wAABcU"] [Sat Aug 29 05:06:20.019127 2026] [security2:error] [pid 1017536:tid 1017648] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9LCJcY4fy7tP-rU39FwACQm8"] [Sat Aug 29 05:06:20.030072 2026] [security2:error] [pid 1018003:tid 1018152] [client 216.26.244.202:16359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.244.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx2wAABbk"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:20.035464 2026] [security2:error] [pid 1017536:tid 1017761] [client 168.107.94.195:65077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9LCJcY4fy7tP-rU39HAAAAnM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:20.036106 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.23.147.79:48371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9LCJcY4fy7tP-rU39HQAAApM"] [Sat Aug 29 05:06:20.040760 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.63.81.20:60514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/eagle.php"] [unique_id "apK9LCJcY4fy7tP-rU39HgAAAns"] [Sat Aug 29 05:06:20.042885 2026] [security2:error] [pid 1017536:tid 1017696] [client 4.205.62.107:22312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/dragonshell.php"] [unique_id "apK9LCJcY4fy7tP-rU39IQAAAjI"] [Sat Aug 29 05:06:20.043383 2026] [core:error] [pid 1017536:tid 1017757] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.043397 2026] [core:error] [pid 1017536:tid 1017757] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.043401 2026] [core:error] [pid 1017536:tid 1017719] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.043417 2026] [core:error] [pid 1017536:tid 1017719] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.043457 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.043472 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.047249 2026] [core:error] [pid 1017536:tid 1017674] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.047260 2026] [core:error] [pid 1017536:tid 1017674] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.049636 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.049650 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.050349 2026] [core:error] [pid 1018003:tid 1018199] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.050372 2026] [core:error] [pid 1018003:tid 1018199] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.056828 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.056840 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.061703 2026] [security2:error] [pid 1017536:tid 1017751] [client 52.139.37.240:12484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-content/plugins/ftde.php"] [unique_id "apK9LCJcY4fy7tP-rU39IwAAAmk"] [Sat Aug 29 05:06:20.062424 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:50286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9LCJcY4fy7tP-rU39JAAAAks"] [Sat Aug 29 05:06:20.065547 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.23.184.117:4526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/languages/themes/num.php"] [unique_id "apK9LCJcY4fy7tP-rU39JQAAAmY"] [Sat Aug 29 05:06:20.077320 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:60889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/images/uploads/admin.php"] [unique_id "apK9LCJcY4fy7tP-rU39JwAAAjE"] [Sat Aug 29 05:06:20.085844 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.63.81.20:44500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/adminfuns.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx6wAABd0"] [Sat Aug 29 05:06:20.088491 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.205.62.107:22311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/chosen.php"] [unique_id "apK9LCJcY4fy7tP-rU39KQAAAlY"] [Sat Aug 29 05:06:20.093884 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.147.79:50142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/ans.php"] [unique_id "apK9LCJcY4fy7tP-rU39KgAAAnw"] [Sat Aug 29 05:06:20.096896 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.220.204.93:59108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx7QAABgM"] [Sat Aug 29 05:06:20.102489 2026] [security2:error] [pid 1017536:tid 1017731] [client 57.141.14.95:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/2/"] [unique_id "apK9LCJcY4fy7tP-rU39KwAAAlU"] [Sat Aug 29 05:06:20.112759 2026] [autoindex:error] [pid 1017536:tid 1017605] [remote 87.58.197.202:64340] AH01276: Cannot serve directory /home3/zjtdvzmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:20.114503 2026] [security2:error] [pid 1017536:tid 1017668] [client 4.205.62.107:65455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/paths.php"] [unique_id "apK9LCJcY4fy7tP-rU39LgAAAhY"] [Sat Aug 29 05:06:20.126459 2026] [security2:error] [pid 1018003:tid 1018153] [client 68.155.159.216:49209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx8AAABbo"] [Sat Aug 29 05:06:20.129619 2026] [security2:error] [pid 1017536:tid 1017713] [client 68.155.159.216:24491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9LCJcY4fy7tP-rU39NAAAAkM"] [Sat Aug 29 05:06:20.137208 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.197.61.180:16965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx8wAABhI"] [Sat Aug 29 05:06:20.142392 2026] [security2:error] [pid 1018003:tid 1018165] [client 40.83.93.50:22240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/languages/index.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx9AAABcY"] [Sat Aug 29 05:06:20.143243 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.151.200.44:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/155.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx9QAABb4"] [Sat Aug 29 05:06:20.143882 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.196.209.81:16751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/csv.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx9gAABgQ"] [Sat Aug 29 05:06:20.147091 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.147106 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.156617 2026] [core:error] [pid 1017536:tid 1017793] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.156631 2026] [core:error] [pid 1017536:tid 1017793] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.159059 2026] [core:error] [pid 1017536:tid 1017769] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.159079 2026] [core:error] [pid 1017536:tid 1017769] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.181915 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.63.81.20:56936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/up-kon.php"] [unique_id "apK9LDAh5Y1i2tUxg4Hx-gAABhY"] [Sat Aug 29 05:06:20.197094 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.197110 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.198294 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.220.204.93:64292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9LCJcY4fy7tP-rU39RAAAAi0"] [Sat Aug 29 05:06:20.198540 2026] [security2:error] [pid 1018003:tid 1018131] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/.env.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyAAAGD24"] [Sat Aug 29 05:06:20.205433 2026] [security2:error] [pid 1017536:tid 1017645] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9LCJcY4fy7tP-rU39RwACTmw"] [Sat Aug 29 05:06:20.207842 2026] [security2:error] [pid 1017536:tid 1017614] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9LCJcY4fy7tP-rU39SgACTk0"] [Sat Aug 29 05:06:20.207920 2026] [security2:error] [pid 1017536:tid 1017623] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9LCJcY4fy7tP-rU39SQACTlY"] [Sat Aug 29 05:06:20.211701 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.184.117:4518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyAwAABdQ"] [Sat Aug 29 05:06:20.211868 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.48.250.41:64299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/aa.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyBAAABf8"] [Sat Aug 29 05:06:20.230004 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.230021 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.230902 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.63.81.20:46855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/classwithtostring.php"] [unique_id "apK9LCJcY4fy7tP-rU39UwAAAnw"] [Sat Aug 29 05:06:20.231196 2026] [core:error] [pid 1017536:tid 1017748] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.231209 2026] [core:error] [pid 1017536:tid 1017748] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.231856 2026] [core:error] [pid 1017536:tid 1017695] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.231868 2026] [core:error] [pid 1017536:tid 1017695] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.233399 2026] [security2:error] [pid 1018003:tid 1018191] [client 158.23.147.79:30617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyCQAABeA"] [Sat Aug 29 05:06:20.233825 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.233834 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.236270 2026] [core:error] [pid 1017536:tid 1017747] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.236287 2026] [core:error] [pid 1017536:tid 1017747] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.239374 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.23.184.117:55526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/tools.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyCwAABh8"] [Sat Aug 29 05:06:20.241164 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.241182 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.245247 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.245263 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.255563 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.147.79:30539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/radio.php"] [unique_id "apK9LCJcY4fy7tP-rU39WgAAAiU"] [Sat Aug 29 05:06:20.258247 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.139.37.240:12892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyDgAABdg"] [Sat Aug 29 05:06:20.271799 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.196.209.81:5608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/db-status.php"] [unique_id "apK9LCJcY4fy7tP-rU39XAAAAlg"] [Sat Aug 29 05:06:20.273331 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.273350 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.287929 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.49.130:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/amax.php"] [unique_id "apK9LCJcY4fy7tP-rU39XgAAAis"] [Sat Aug 29 05:06:20.289830 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.220.204.93:59030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ff1.php"] [unique_id "apK9LCJcY4fy7tP-rU39XwAAAhs"] [Sat Aug 29 05:06:20.295189 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.151.200.44:47327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/eval.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyEQAABgE"] [Sat Aug 29 05:06:20.304966 2026] [security2:error] [pid 1018003:tid 1018171] [client 192.145.125.70:48130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9LDAh5Y1i2tUxg4HyFwAABcw"] [Sat Aug 29 05:06:20.305024 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.147.79:35832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/NewFile.php/"] [unique_id "apK9LCJcY4fy7tP-rU39YQAAAls"] [Sat Aug 29 05:06:20.306334 2026] [security2:error] [pid 1017536:tid 1017761] [client 4.205.62.107:53332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apK9LCJcY4fy7tP-rU39YgAAAnM"] [Sat Aug 29 05:06:20.314131 2026] [security2:error] [pid 1018003:tid 1018195] [client 66.248.203.2:3434] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2021/01/27/"] [unique_id "apK9LDAh5Y1i2tUxg4HyGQAABeQ"] [Sat Aug 29 05:06:20.316564 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.63.81.20:56909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/tinny.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyGgAABeQ"] [Sat Aug 29 05:06:20.328909 2026] [core:error] [pid 1017536:tid 1017709] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.328930 2026] [core:error] [pid 1017536:tid 1017709] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.336947 2026] [security2:error] [pid 1017536:tid 1017720] [client 20.151.200.44:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/ww3.php"] [unique_id "apK9LCJcY4fy7tP-rU39aQAAAko"] [Sat Aug 29 05:06:20.354478 2026] [core:error] [pid 1017536:tid 1017717] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.354499 2026] [core:error] [pid 1017536:tid 1017717] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.355611 2026] [core:error] [pid 1017536:tid 1017733] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.355616 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.23.184.117:4847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/xmlrpc.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyIAAABcM"] [Sat Aug 29 05:06:20.355627 2026] [core:error] [pid 1017536:tid 1017733] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.363309 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.48.250.41:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/s1.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyJAAABiI"] [Sat Aug 29 05:06:20.364277 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.158.54.35:22277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.santarosairis.org"] [uri "/wp-admin.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyJgAABg4"] [Sat Aug 29 05:06:20.373407 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.63.81.20:46927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK9LCJcY4fy7tP-rU39cwAAAnw"] [Sat Aug 29 05:06:20.379136 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.379152 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.382738 2026] [security2:error] [pid 1017536:tid 1017719] [client 158.23.184.117:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-content/uploads/my.php"] [unique_id "apK9LCJcY4fy7tP-rU39dQAAAkk"] [Sat Aug 29 05:06:20.383184 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.52.41.200:1251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "apK9LCJcY4fy7tP-rU39dgAAAjE"] [Sat Aug 29 05:06:20.384301 2026] [core:error] [pid 1017536:tid 1017760] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.384317 2026] [core:error] [pid 1017536:tid 1017760] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.386562 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.386576 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.387139 2026] [core:error] [pid 1018003:tid 1018152] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.387147 2026] [core:error] [pid 1018003:tid 1018152] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.416181 2026] [security2:error] [pid 1017536:tid 1017668] [client 168.107.94.195:65462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9LCJcY4fy7tP-rU39fwAAAhY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:20.420789 2026] [security2:error] [pid 1017536:tid 1017674] [client 4.205.62.107:21838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/localconf.php"] [unique_id "apK9LCJcY4fy7tP-rU39hAAAAhw"] [Sat Aug 29 05:06:20.430967 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.220.204.93:59075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/t.php"] [unique_id "apK9LCJcY4fy7tP-rU39hwAAAmQ"] [Sat Aug 29 05:06:20.464343 2026] [core:error] [pid 1017536:tid 1017734] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.464373 2026] [core:error] [pid 1017536:tid 1017734] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.464748 2026] [core:error] [pid 1017536:tid 1017777] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.464763 2026] [core:error] [pid 1017536:tid 1017777] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.464762 2026] [core:error] [pid 1017536:tid 1017706] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.464777 2026] [core:error] [pid 1017536:tid 1017706] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.465714 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.465725 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.468036 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.468060 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.468445 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.63.81.20:60483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp-easy.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyNwAABgM"] [Sat Aug 29 05:06:20.470925 2026] [core:error] [pid 1018003:tid 1018188] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.471057 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.471064 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.470940 2026] [core:error] [pid 1018003:tid 1018188] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.498662 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.498679 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.498722 2026] [security2:error] [pid 1018003:tid 1018159] [client 158.23.184.117:4870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/app.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyPAAABcA"] [Sat Aug 29 05:06:20.504188 2026] [security2:error] [pid 1018003:tid 1018165] [client 20.151.200.44:64839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/sko.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyPQAABcY"] [Sat Aug 29 05:06:20.526455 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.63.81.20:44483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK9LCJcY4fy7tP-rU39lQAAAm8"] [Sat Aug 29 05:06:20.529621 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.184.117:60920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/themes/uploads/config.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyQQAABbo"] [Sat Aug 29 05:06:20.540958 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.540975 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.544532 2026] [security2:error] [pid 1017536:tid 1017744] [client 52.139.37.240:12865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/z.php"] [unique_id "apK9LCJcY4fy7tP-rU39nQAAAmI"] [Sat Aug 29 05:06:20.545884 2026] [security2:error] [pid 1017536:tid 1017788] [client 4.205.62.107:56008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/X57.php"] [unique_id "apK9LCJcY4fy7tP-rU39nwAAAo4"] [Sat Aug 29 05:06:20.550198 2026] [security2:error] [pid 1017536:tid 1017781] [client 52.139.37.240:30186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/aged.php"] [unique_id "apK9LCJcY4fy7tP-rU39oAAAAoc"] [Sat Aug 29 05:06:20.554955 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.48.250.41:65029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/0byte.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyRgAABiA"] [Sat Aug 29 05:06:20.565777 2026] [security2:error] [pid 1017536:tid 1017785] [client 68.155.159.216:58285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/log-mama/function.php"] [unique_id "apK9LCJcY4fy7tP-rU39oQAAAos"] [Sat Aug 29 05:06:20.573710 2026] [core:error] [pid 1017536:tid 1017678] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.573727 2026] [core:error] [pid 1017536:tid 1017678] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.576645 2026] [core:error] [pid 1017536:tid 1017792] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.576672 2026] [core:error] [pid 1017536:tid 1017792] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.577440 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.196.209.81:11549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/fox.php"] [unique_id "apK9LCJcY4fy7tP-rU39pQAAAmM"] [Sat Aug 29 05:06:20.584991 2026] [core:error] [pid 1017536:tid 1017680] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.585007 2026] [core:error] [pid 1017536:tid 1017680] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.590421 2026] [core:error] [pid 1017536:tid 1017778] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.590438 2026] [core:error] [pid 1017536:tid 1017778] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.593813 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.593829 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.603177 2026] [security2:error] [pid 1017536:tid 1017749] [client 45.3.40.242:22763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9LCJcY4fy7tP-rU39qwAAAmc"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:20.609582 2026] [security2:error] [pid 1017536:tid 1017721] [client 40.83.93.50:22264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/languages/min.php"] [unique_id "apK9LCJcY4fy7tP-rU39rAAAAks"] [Sat Aug 29 05:06:20.629028 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.63.81.20:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/d7.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyTwAABds"] [Sat Aug 29 05:06:20.629160 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.220.204.93:59079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/erty.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyUAAABgw"] [Sat Aug 29 05:06:20.633562 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.633578 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.643772 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.184.117:4761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/aaa.php"] [unique_id "apK9LCJcY4fy7tP-rU39tQAAAhs"] [Sat Aug 29 05:06:20.655211 2026] [security2:error] [pid 1017536:tid 1017769] [client 68.155.159.216:12173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-mail.php"] [unique_id "apK9LCJcY4fy7tP-rU39twAAAns"] [Sat Aug 29 05:06:20.660813 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.660830 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.664248 2026] [core:error] [pid 1017536:tid 1017747] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.664263 2026] [core:error] [pid 1017536:tid 1017747] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.665041 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.665055 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.665981 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.196.209.81:5242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK9LCJcY4fy7tP-rU39vQAAApA"] [Sat Aug 29 05:06:20.668160 2026] [core:error] [pid 1017536:tid 1017767] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.668173 2026] [core:error] [pid 1017536:tid 1017767] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.675555 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.184.117:55500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/av.php"] [unique_id "apK9LCJcY4fy7tP-rU39wAAAAho"] [Sat Aug 29 05:06:20.681824 2026] [core:error] [pid 1018003:tid 1018215] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.681841 2026] [core:error] [pid 1018003:tid 1018215] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.687203 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.48.250.41:64307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/xr.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyWAAABgE"] [Sat Aug 29 05:06:20.688749 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.63.81.20:46912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK9LCJcY4fy7tP-rU39wwAAAmI"] [Sat Aug 29 05:06:20.711206 2026] [core:error] [pid 1018003:tid 1018171] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.711225 2026] [core:error] [pid 1018003:tid 1018171] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.712027 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.712041 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.722758 2026] [security2:error] [pid 1018003:tid 1018195] [client 68.155.159.216:51430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-content/index.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyXAAABeQ"] [Sat Aug 29 05:06:20.727240 2026] [security2:error] [pid 1017536:tid 1017542] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9LCJcY4fy7tP-rU39xQACMAU"] [Sat Aug 29 05:06:20.727955 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.727967 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.739031 2026] [security2:error] [pid 1018003:tid 1018156] [client 52.139.37.240:12536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/f35.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyYgAABb0"] [Sat Aug 29 05:06:20.743381 2026] [security2:error] [pid 1018003:tid 1018259] [client 52.139.37.240:30009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/essexec.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyYwAABiM"] [Sat Aug 29 05:06:20.760585 2026] [security2:error] [pid 1017536:tid 1017745] [client 68.155.159.216:52803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/dropdown.php"] [unique_id "apK9LCJcY4fy7tP-rU39yQAAAmM"] [Sat Aug 29 05:06:20.762334 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.63.81.20:56875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/v5.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyZgAABiI"] [Sat Aug 29 05:06:20.776698 2026] [security2:error] [pid 1018003:tid 1018257] [client 20.220.204.93:59088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/0x.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyawAABiE"] [Sat Aug 29 05:06:20.780922 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:25520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9LCJcY4fy7tP-rU39zwAAAjE"] [Sat Aug 29 05:06:20.789461 2026] [security2:error] [pid 1017536:tid 1017752] [client 158.23.147.79:53817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/goods.php"] [unique_id "apK9LCJcY4fy7tP-rU390wAAAmo"] [Sat Aug 29 05:06:20.797993 2026] [security2:error] [pid 1017536:tid 1017721] [client 168.107.94.195:49368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9LCJcY4fy7tP-rU391AAAAks"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:20.807490 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.48.251.3:61638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/test.php"] [unique_id "apK9LCJcY4fy7tP-rU391QAAAnM"] [Sat Aug 29 05:06:20.820503 2026] [core:error] [pid 1017536:tid 1017786] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.820521 2026] [core:error] [pid 1017536:tid 1017786] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.827508 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.48.250.41:65132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/h02ugyh.php"] [unique_id "apK9LCJcY4fy7tP-rU392wAAAl4"] [Sat Aug 29 05:06:20.829860 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.52.41.200:1779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/abcd.php"] [unique_id "apK9LCJcY4fy7tP-rU393AAAAm8"] [Sat Aug 29 05:06:20.832443 2026] [security2:error] [pid 1017536:tid 1017751] [client 197.219.150.206:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9LCJcY4fy7tP-rU393QAAAmk"] [Sat Aug 29 05:06:20.832554 2026] [security2:error] [pid 1017536:tid 1017751] [client 197.219.150.206:59162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9LCJcY4fy7tP-rU393QAAAmk"] [Sat Aug 29 05:06:20.840714 2026] [core:error] [pid 1017536:tid 1017602] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.840734 2026] [core:error] [pid 1017536:tid 1017602] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.844849 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.844865 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.846723 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/index.php"] [unique_id "apK9LCJcY4fy7tP-rU396AAAAkc"] [Sat Aug 29 05:06:20.848559 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.81.20:46952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wsd.php"] [unique_id "apK9LCJcY4fy7tP-rU397wAAAkc"] [Sat Aug 29 05:06:20.849401 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.849426 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.849726 2026] [core:error] [pid 1017536:tid 1017765] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.849736 2026] [core:error] [pid 1017536:tid 1017765] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.849800 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.849815 2026] [core:error] [pid 1017536:tid 1017691] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.849817 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.849834 2026] [core:error] [pid 1017536:tid 1017691] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.853129 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.197.61.180:5839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/f35.php"] [unique_id "apK9LCJcY4fy7tP-rU398QAAAls"] [Sat Aug 29 05:06:20.870770 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.23.184.117:60899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-includes/ID3/file.php"] [unique_id "apK9LCJcY4fy7tP-rU398wAAAo4"] [Sat Aug 29 05:06:20.875178 2026] [core:error] [pid 1018003:tid 1018264] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.875202 2026] [core:error] [pid 1018003:tid 1018264] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.876684 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.876707 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.876709 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.876715 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.877168 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.877182 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.879703 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.879722 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.896328 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.63.81.20:56853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/az.php"] [unique_id "apK9LCJcY4fy7tP-rU399wAAAmM"] [Sat Aug 29 05:06:20.897880 2026] [security2:error] [pid 1017536:tid 1017732] [client 192.145.125.70:48144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9LCJcY4fy7tP-rU39-AAAAlY"] [Sat Aug 29 05:06:20.904555 2026] [security2:error] [pid 1017536:tid 1017680] [client 158.23.184.117:4646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/hehe.php"] [unique_id "apK9LCJcY4fy7tP-rU39-gAAAiI"] [Sat Aug 29 05:06:20.908045 2026] [security2:error] [pid 1018003:tid 1018225] [client 60.243.207.176:59359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyfwAABgI"] [Sat Aug 29 05:06:20.908160 2026] [security2:error] [pid 1018003:tid 1018225] [client 60.243.207.176:59359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyfwAABgI"] [Sat Aug 29 05:06:20.917550 2026] [core:error] [pid 1018003:tid 1018219] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.917571 2026] [core:error] [pid 1018003:tid 1018219] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.927340 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.220.204.93:59046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/66.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyggAABdc"] [Sat Aug 29 05:06:20.930928 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.930958 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.931213 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.151.200.44:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/zoz.php"] [unique_id "apK9LDAh5Y1i2tUxg4HygwAABdc"] [Sat Aug 29 05:06:20.932194 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.251.3:13825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/tax.php"] [unique_id "apK9LCJcY4fy7tP-rU39_gAAAkM"] [Sat Aug 29 05:06:20.940029 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.48.251.3:3141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/cloud.php"] [unique_id "apK9LDAh5Y1i2tUxg4HyhQAABeE"] [Sat Aug 29 05:06:20.949835 2026] [security2:error] [pid 1017536:tid 1017781] [client 52.139.37.240:12882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/file61.php"] [unique_id "apK9LCJcY4fy7tP-rU39_wAAAoc"] [Sat Aug 29 05:06:20.952262 2026] [security2:error] [pid 1017536:tid 1017712] [client 52.139.37.240:53184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/fw.php"] [unique_id "apK9LCJcY4fy7tP-rU3-AAAAAkI"] [Sat Aug 29 05:06:20.966253 2026] [core:error] [pid 1017536:tid 1017681] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.966273 2026] [core:error] [pid 1017536:tid 1017681] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.969145 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.969159 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:20.972947 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/xxw.php"] [unique_id "apK9LCJcY4fy7tP-rU3-BgAAAmE"] [Sat Aug 29 05:06:20.991729 2026] [security2:error] [pid 1017536:tid 1017596] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/.wp-config.php.swp"] [unique_id "apK9LCJcY4fy7tP-rU3-BwACazs"] [Sat Aug 29 05:06:20.996280 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.63.81.20:46951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/bulet.php"] [unique_id "apK9LCJcY4fy7tP-rU3-CAAAAoY"] [Sat Aug 29 05:06:21.013498 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.196.209.81:16756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/disagraeosc.php"] [unique_id "apK9LTAh5Y1i2tUxg4HykAAABeg"] [Sat Aug 29 05:06:21.026473 2026] [security2:error] [pid 1017536:tid 1017612] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-DwACQUs"] [Sat Aug 29 05:06:21.027401 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.63.81.20:56837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/js.php"] [unique_id "apK9LSJcY4fy7tP-rU3-EQAAAjQ"] [Sat Aug 29 05:06:21.028850 2026] [security2:error] [pid 1017536:tid 1017664] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-EgACQX8"] [Sat Aug 29 05:06:21.029418 2026] [security2:error] [pid 1017536:tid 1017769] [client 158.23.184.117:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jakeylequack.domusfennii.com"] [uri "/wp-admin/css/fff.php"] [unique_id "apK9LSJcY4fy7tP-rU3-EwAAAns"] [Sat Aug 29 05:06:21.033036 2026] [core:error] [pid 1017536:tid 1017548] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.033052 2026] [core:error] [pid 1017536:tid 1017548] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.033197 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.033207 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.033664 2026] [core:error] [pid 1017536:tid 1017603] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.033676 2026] [core:error] [pid 1017536:tid 1017603] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.038390 2026] [core:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.038406 2026] [core:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.051489 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.23.184.117:4648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/PHPMailer.php"] [unique_id "apK9LSJcY4fy7tP-rU3-GQAAAjI"] [Sat Aug 29 05:06:21.062314 2026] [security2:error] [pid 1018003:tid 1018207] [client 68.155.159.216:16238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/sad/about.php"] [unique_id "apK9LTAh5Y1i2tUxg4HylQAABfA"] [Sat Aug 29 05:06:21.063635 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.151.200.44:47409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/sao.php"] [unique_id "apK9LSJcY4fy7tP-rU3-GgAAAmY"] [Sat Aug 29 05:06:21.070011 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.251.3:61190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/asdf.php"] [unique_id "apK9LSJcY4fy7tP-rU3-HAAAAjs"] [Sat Aug 29 05:06:21.072854 2026] [core:error] [pid 1017536:tid 1017668] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.072872 2026] [core:error] [pid 1017536:tid 1017668] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.076154 2026] [core:error] [pid 1017536:tid 1017541] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.076173 2026] [core:error] [pid 1017536:tid 1017541] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.078716 2026] [core:error] [pid 1017536:tid 1017571] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.078734 2026] [core:error] [pid 1017536:tid 1017571] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.082392 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.220.204.93:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/f35.php"] [unique_id "apK9LTAh5Y1i2tUxg4HylwAABdQ"] [Sat Aug 29 05:06:21.083558 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.083570 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.087642 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.087658 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.089143 2026] [security2:error] [pid 1017536:tid 1017678] [client 40.83.93.50:5896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/languages/pk.php"] [unique_id "apK9LSJcY4fy7tP-rU3-IwAAAiA"] [Sat Aug 29 05:06:21.092333 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.196.209.81:5193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/f35.php"] [unique_id "apK9LSJcY4fy7tP-rU3-JAAAAow"] [Sat Aug 29 05:06:21.097478 2026] [security2:error] [pid 1017536:tid 1017563] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-JQACXho"] [Sat Aug 29 05:06:21.100649 2026] [security2:error] [pid 1017536:tid 1017736] [client 68.155.159.216:51499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/content.php"] [unique_id "apK9LSJcY4fy7tP-rU3-JgAAAlo"] [Sat Aug 29 05:06:21.104113 2026] [security2:error] [pid 1017536:tid 1017792] [client 68.155.159.216:33731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9LSJcY4fy7tP-rU3-JwAAApI"] [Sat Aug 29 05:06:21.112943 2026] [security2:error] [pid 1017536:tid 1017604] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-KAACPUM"] [Sat Aug 29 05:06:21.121117 2026] [security2:error] [pid 1017536:tid 1017595] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-KQACajo"] [Sat Aug 29 05:06:21.121123 2026] [security2:error] [pid 1017536:tid 1017567] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-KgACah4"] [Sat Aug 29 05:06:21.128811 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.63.81.20:46945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/av.php"] [unique_id "apK9LSJcY4fy7tP-rU3-KwAAAh0"] [Sat Aug 29 05:06:21.141692 2026] [security2:error] [pid 1018003:tid 1018157] [client 104.207.44.196:12131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.44.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9LTAh5Y1i2tUxg4HymgAABb4"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:21.143319 2026] [security2:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-LAACLQ0"] [Sat Aug 29 05:06:21.144365 2026] [security2:error] [pid 1017536:tid 1017723] [client 158.23.147.79:48285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/goat.php"] [unique_id "apK9LSJcY4fy7tP-rU3-LQAAAk0"] [Sat Aug 29 05:06:21.147879 2026] [security2:error] [pid 1017536:tid 1017713] [client 52.139.37.240:30187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/zwso.php"] [unique_id "apK9LSJcY4fy7tP-rU3-LgAAAkM"] [Sat Aug 29 05:06:21.148128 2026] [security2:error] [pid 1017536:tid 1017687] [client 213.202.253.4:61565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/schallfuns.php"] [unique_id "apK9LSJcY4fy7tP-rU3-LwAAAik"], referer: www.google.com [Sat Aug 29 05:06:21.150285 2026] [security2:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/.wp-config.php.swp"] [unique_id "apK9LTAh5Y1i2tUxg4HynQAGD0g"] [Sat Aug 29 05:06:21.157898 2026] [security2:error] [pid 1017536:tid 1017721] [client 52.139.37.240:12896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/mah.php"] [unique_id "apK9LSJcY4fy7tP-rU3-MgAAAks"] [Sat Aug 29 05:06:21.163915 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.63.81.20:60476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/hd.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyoQAABh8"] [Sat Aug 29 05:06:21.178119 2026] [security2:error] [pid 1017536:tid 1017709] [client 68.155.159.216:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/content.php"] [unique_id "apK9LSJcY4fy7tP-rU3-NAAAAj8"] [Sat Aug 29 05:06:21.180869 2026] [security2:error] [pid 1017536:tid 1017694] [client 168.107.94.195:49761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9LSJcY4fy7tP-rU3-NQAAAjA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:21.180874 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.220.204.93:65009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/06.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyowAABgw"] [Sat Aug 29 05:06:21.188904 2026] [core:error] [pid 1017536:tid 1017625] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.188923 2026] [core:error] [pid 1017536:tid 1017625] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.189885 2026] [security2:error] [pid 1017536:tid 1017643] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-NwACf2o"] [Sat Aug 29 05:06:21.190914 2026] [security2:error] [pid 1017536:tid 1017583] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-OAACfy4"] [Sat Aug 29 05:06:21.194466 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.48.250.41:64341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/bolt.php"] [unique_id "apK9LSJcY4fy7tP-rU3-OwAAAjs"] [Sat Aug 29 05:06:21.197893 2026] [security2:error] [pid 1017536:tid 1017668] [client 4.205.62.107:22240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/ws61.php"] [unique_id "apK9LSJcY4fy7tP-rU3-PAAAAhY"] [Sat Aug 29 05:06:21.199364 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.23.184.117:4525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "apK9LSJcY4fy7tP-rU3-PQAAAms"] [Sat Aug 29 05:06:21.199725 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.251.3:62094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apK9LTAh5Y1i2tUxg4HypQAABfs"] [Sat Aug 29 05:06:21.202304 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.48.251.3:13986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apK9LSJcY4fy7tP-rU3-QAAAAoM"] [Sat Aug 29 05:06:21.209207 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.147.79:32649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9LSJcY4fy7tP-rU3-RQAAAlg"] [Sat Aug 29 05:06:21.209368 2026] [http2:warn] [pid 1018003:tid 1018272] [client 57.141.14.67:61602] h2_stream(1018003-14-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:06:21.228967 2026] [security2:error] [pid 1017536:tid 1017785] [client 4.205.62.107:21591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/rum.or.php"] [unique_id "apK9LSJcY4fy7tP-rU3-TAAAAos"] [Sat Aug 29 05:06:21.236855 2026] [security2:error] [pid 1018003:tid 1018245] [client 68.155.159.216:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyrQAABhU"] [Sat Aug 29 05:06:21.238634 2026] [security2:error] [pid 1017536:tid 1017740] [client 68.155.159.216:24517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/cong.php"] [unique_id "apK9LSJcY4fy7tP-rU3-TgAAAl4"] [Sat Aug 29 05:06:21.242510 2026] [core:error] [pid 1018003:tid 1018269] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.242524 2026] [core:error] [pid 1018003:tid 1018269] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.244249 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.244262 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.245188 2026] [core:error] [pid 1018003:tid 1018171] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.245203 2026] [core:error] [pid 1018003:tid 1018171] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.255116 2026] [core:error] [pid 1017536:tid 1017717] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.255134 2026] [core:error] [pid 1017536:tid 1017717] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.259605 2026] [security2:error] [pid 1018003:tid 1018249] [client 4.205.62.107:26669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/olfclass.php"] [unique_id "apK9LTAh5Y1i2tUxg4HytgAABhk"] [Sat Aug 29 05:06:21.262007 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.262022 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.280052 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.52.41.200:1244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-access.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyuwAABc8"] [Sat Aug 29 05:06:21.282312 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.63.81.20:46859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/images.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyvQAABgk"] [Sat Aug 29 05:06:21.282757 2026] [security2:error] [pid 1017536:tid 1017719] [client 103.240.76.112:42690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9LSJcY4fy7tP-rU3-XQAAAkk"] [Sat Aug 29 05:06:21.282845 2026] [security2:error] [pid 1017536:tid 1017719] [client 103.240.76.112:42690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9LSJcY4fy7tP-rU3-XQAAAkk"] [Sat Aug 29 05:06:21.294863 2026] [core:error] [pid 1017536:tid 1017694] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.294879 2026] [core:error] [pid 1017536:tid 1017694] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.295901 2026] [core:error] [pid 1018003:tid 1018251] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.295919 2026] [core:error] [pid 1018003:tid 1018251] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.297203 2026] [security2:error] [pid 1017536:tid 1017668] [client 20.220.204.93:59131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wen.php"] [unique_id "apK9LSJcY4fy7tP-rU3-YgAAAhY"] [Sat Aug 29 05:06:21.301531 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.63.81.20:60505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/xl2023.php"] [unique_id "apK9LSJcY4fy7tP-rU3-YwAAAjw"] [Sat Aug 29 05:06:21.301787 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.301797 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.305332 2026] [core:error] [pid 1018003:tid 1018152] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.305347 2026] [core:error] [pid 1018003:tid 1018152] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.305886 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.305902 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.306015 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.306025 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.323814 2026] [core:error] [pid 1017536:tid 1017765] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.323829 2026] [core:error] [pid 1017536:tid 1017765] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.328165 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.48.251.3:61635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/hochladen.form.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyxgAABe8"] [Sat Aug 29 05:06:21.341170 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.151.200.44:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/mmm.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyygAABfw"] [Sat Aug 29 05:06:21.344585 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.147.79:30679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyywAABgM"] [Sat Aug 29 05:06:21.345092 2026] [security2:error] [pid 1017536:tid 1017769] [client 52.139.37.240:29997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/admin/function.php"] [unique_id "apK9LSJcY4fy7tP-rU3-agAAAns"] [Sat Aug 29 05:06:21.347964 2026] [security2:error] [pid 1017536:tid 1017689] [client 158.23.184.117:4501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/admin/alfa-rex.php"] [unique_id "apK9LSJcY4fy7tP-rU3-awAAAis"] [Sat Aug 29 05:06:21.348425 2026] [core:error] [pid 1017536:tid 1017789] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.348440 2026] [core:error] [pid 1017536:tid 1017789] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.350756 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.251.3:14006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/agg.php"] [unique_id "apK9LSJcY4fy7tP-rU3-bAAAAjo"] [Sat Aug 29 05:06:21.357391 2026] [security2:error] [pid 1018003:tid 1018261] [client 52.139.37.240:12430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/mini.php"] [unique_id "apK9LTAh5Y1i2tUxg4HyzQAABiU"] [Sat Aug 29 05:06:21.362432 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.48.250.41:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/rtx.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy0AAABhg"] [Sat Aug 29 05:06:21.385373 2026] [core:error] [pid 1017536:tid 1017785] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.385392 2026] [core:error] [pid 1017536:tid 1017785] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.407096 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:30549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9LSJcY4fy7tP-rU3-dQAAApI"] [Sat Aug 29 05:06:21.416811 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.196.209.81:19413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/about.php525"] [unique_id "apK9LTAh5Y1i2tUxg4Hy1wAABc0"] [Sat Aug 29 05:06:21.437021 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.220.204.93:59090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/inc.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy2gAABfA"] [Sat Aug 29 05:06:21.439728 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.63.81.20:60429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/V2.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy2wAABdQ"] [Sat Aug 29 05:06:21.445602 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.23.147.79:24404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy3gAABdk"] [Sat Aug 29 05:06:21.446176 2026] [core:error] [pid 1017536:tid 1017569] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.446188 2026] [core:error] [pid 1017536:tid 1017569] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.450174 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.63.81.20:46867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ops.php"] [unique_id "apK9LSJcY4fy7tP-rU3-fwAAAi0"] [Sat Aug 29 05:06:21.456947 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.456965 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.458005 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.251.3:61058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/debuggen.php"] [unique_id "apK9LSJcY4fy7tP-rU3-ggAAAmk"] [Sat Aug 29 05:06:21.459339 2026] [core:error] [pid 1017536:tid 1017723] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.459368 2026] [core:error] [pid 1017536:tid 1017723] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.459727 2026] [core:error] [pid 1018003:tid 1018222] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.459740 2026] [core:error] [pid 1018003:tid 1018222] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.460574 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.460590 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.460596 2026] [core:error] [pid 1017536:tid 1017624] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.460607 2026] [core:error] [pid 1017536:tid 1017624] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.460618 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.460628 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.461097 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.461109 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.461288 2026] [core:error] [pid 1017536:tid 1017626] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.461306 2026] [core:error] [pid 1017536:tid 1017626] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.463270 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.147.79:35722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/dropdown.php"] [unique_id "apK9LSJcY4fy7tP-rU3-iAAAAn8"] [Sat Aug 29 05:06:21.463798 2026] [security2:error] [pid 1017536:tid 1017631] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9LSJcY4fy7tP-rU3-igACWl4"] [Sat Aug 29 05:06:21.481348 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.48.251.3:14300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/124.php"] [unique_id "apK9LSJcY4fy7tP-rU3-jgAAAjE"] [Sat Aug 29 05:06:21.491195 2026] [security2:error] [pid 1018003:tid 1018235] [client 20.196.209.81:23652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/index.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy5QAABgs"] [Sat Aug 29 05:06:21.496756 2026] [security2:error] [pid 1017536:tid 1017760] [client 158.23.184.117:4504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/export.php"] [unique_id "apK9LSJcY4fy7tP-rU3-kQAAAnI"] [Sat Aug 29 05:06:21.502304 2026] [security2:error] [pid 1017536:tid 1017761] [client 192.145.125.70:48158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9LSJcY4fy7tP-rU3-lAAAAnM"] [Sat Aug 29 05:06:21.510290 2026] [security2:error] [pid 1017536:tid 1017765] [client 4.205.62.107:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/database.php"] [unique_id "apK9LSJcY4fy7tP-rU3-lgAAAnc"] [Sat Aug 29 05:06:21.542398 2026] [security2:error] [pid 1017536:tid 1017753] [client 52.139.37.240:30194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/zoom1.php"] [unique_id "apK9LSJcY4fy7tP-rU3-lwAAAms"] [Sat Aug 29 05:06:21.555317 2026] [security2:error] [pid 1017536:tid 1017777] [client 52.139.37.240:12524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/v.php"] [unique_id "apK9LSJcY4fy7tP-rU3-mAAAAoM"] [Sat Aug 29 05:06:21.557110 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.197.61.180:5859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/index.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy7AAABjQ"] [Sat Aug 29 05:06:21.558933 2026] [security2:error] [pid 1017536:tid 1017786] [client 40.83.93.50:12452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "termoenvases.net"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK9LSJcY4fy7tP-rU3-mQAAAow"] [Sat Aug 29 05:06:21.559992 2026] [security2:error] [pid 1018003:tid 1018224] [client 4.205.62.107:22279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/bengi.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy7QAABgE"] [Sat Aug 29 05:06:21.561351 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.250.41:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/ckk.php"] [unique_id "apK9LSJcY4fy7tP-rU3-mwAAAo4"] [Sat Aug 29 05:06:21.561427 2026] [security2:error] [pid 1017536:tid 1017737] [client 168.107.94.195:50173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9LSJcY4fy7tP-rU3-mgAAAls"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:21.565019 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.220.204.93:59077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/6bcwiqwj.php"] [unique_id "apK9LSJcY4fy7tP-rU3-nAAAAiA"] [Sat Aug 29 05:06:21.565326 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.565339 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.579397 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.63.81.20:60484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/mad.php"] [unique_id "apK9LSJcY4fy7tP-rU3-oAAAAho"] [Sat Aug 29 05:06:21.586609 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.63.81.20:46939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/coffexium.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy8gAABcM"] [Sat Aug 29 05:06:21.587525 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.48.251.3:62127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/pouhg.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy8wAABeQ"] [Sat Aug 29 05:06:21.591397 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.220.204.93:64377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/class.php"] [unique_id "apK9LSJcY4fy7tP-rU3-oQAAApI"] [Sat Aug 29 05:06:21.594520 2026] [core:error] [pid 1017536:tid 1017740] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.594537 2026] [core:error] [pid 1017536:tid 1017740] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.595739 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.49.130:53677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/reviall.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy9QAABfU"] [Sat Aug 29 05:06:21.599834 2026] [core:error] [pid 1017536:tid 1017681] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.599847 2026] [core:error] [pid 1017536:tid 1017681] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.600648 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.600660 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.613326 2026] [security2:error] [pid 1017536:tid 1017577] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-qwACWig"] [Sat Aug 29 05:06:21.639659 2026] [security2:error] [pid 1018003:tid 1018171] [client 158.23.184.117:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/new.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy-wAABcw"] [Sat Aug 29 05:06:21.642524 2026] [core:error] [pid 1017536:tid 1017644] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.642539 2026] [core:error] [pid 1017536:tid 1017644] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.642622 2026] [core:error] [pid 1017536:tid 1017651] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.642634 2026] [core:error] [pid 1017536:tid 1017651] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.642972 2026] [core:error] [pid 1017536:tid 1017554] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.642982 2026] [core:error] [pid 1017536:tid 1017554] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.646875 2026] [core:error] [pid 1018003:tid 1018259] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.646887 2026] [core:error] [pid 1018003:tid 1018259] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.653653 2026] [security2:error] [pid 1018003:tid 1018191] [client 171.61.160.196:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy_wAABeA"] [Sat Aug 29 05:06:21.653756 2026] [security2:error] [pid 1018003:tid 1018191] [client 171.61.160.196:22281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9LTAh5Y1i2tUxg4Hy_wAABeA"] [Sat Aug 29 05:06:21.680822 2026] [security2:error] [pid 1017536:tid 1017773] [client 68.155.159.216:58327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/bk/index.php"] [unique_id "apK9LSJcY4fy7tP-rU3-tgAAAn8"] [Sat Aug 29 05:06:21.683666 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.205.62.107:55945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/register.php"] [unique_id "apK9LSJcY4fy7tP-rU3-twAAAh0"] [Sat Aug 29 05:06:21.703132 2026] [security2:error] [pid 1017536:tid 1017760] [client 20.48.251.3:33283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wdf.php"] [unique_id "apK9LSJcY4fy7tP-rU3-uAAAAnI"] [Sat Aug 29 05:06:21.705724 2026] [core:error] [pid 1018003:tid 1018173] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.705742 2026] [core:error] [pid 1018003:tid 1018173] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.708969 2026] [core:error] [pid 1017536:tid 1017669] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.708986 2026] [core:error] [pid 1017536:tid 1017669] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.709371 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.63.81.20:60447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/st.php"] [unique_id "apK9LSJcY4fy7tP-rU3-uwAAAkE"] [Sat Aug 29 05:06:21.710158 2026] [security2:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzCAAGD3o"] [Sat Aug 29 05:06:21.710237 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.710254 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.715965 2026] [core:error] [pid 1017536:tid 1017747] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.715982 2026] [core:error] [pid 1017536:tid 1017747] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.716055 2026] [core:error] [pid 1017536:tid 1017765] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.716067 2026] [core:error] [pid 1017536:tid 1017765] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.716197 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.251.3:3329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/phpversion.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzCQAABd8"] [Sat Aug 29 05:06:21.716235 2026] [core:error] [pid 1017536:tid 1017734] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.716247 2026] [core:error] [pid 1017536:tid 1017734] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.718478 2026] [core:error] [pid 1017536:tid 1017704] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.718490 2026] [core:error] [pid 1017536:tid 1017704] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.721558 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.63.81.20:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/BDKR28WP.php"] [unique_id "apK9LSJcY4fy7tP-rU3-wQAAAoM"] [Sat Aug 29 05:06:21.730651 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.52.41.200:1248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/uploads/min.php"] [unique_id "apK9LSJcY4fy7tP-rU3-wgAAAkA"] [Sat Aug 29 05:06:21.733343 2026] [security2:error] [pid 1017536:tid 1017710] [client 145.239.10.137:50754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenglobalmall.com"] [uri "/admin.php"] [unique_id "apK9LSJcY4fy7tP-rU3-wwAAAkA"], referer: http://greenglobalmall.com/admin.php [Sat Aug 29 05:06:21.735099 2026] [security2:error] [pid 1018003:tid 1018231] [client 52.139.37.240:30199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/about.php7"] [unique_id "apK9LTAh5Y1i2tUxg4HzCwAABgc"] [Sat Aug 29 05:06:21.735591 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.250.41:65096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.dnichols4.com"] [uri "/R57.php"] [unique_id "apK9LSJcY4fy7tP-rU3-xAAAAm8"] [Sat Aug 29 05:06:21.752965 2026] [security2:error] [pid 1017536:tid 1017680] [client 52.139.37.240:12899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9LSJcY4fy7tP-rU3-xgAAAiI"] [Sat Aug 29 05:06:21.760396 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.104.49.130:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/js.php"] [unique_id "apK9LSJcY4fy7tP-rU3-xwAAAmM"] [Sat Aug 29 05:06:21.762011 2026] [security2:error] [pid 1017536:tid 1017689] [client 209.50.183.3:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.183.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9LSJcY4fy7tP-rU3-ugAAAis"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:21.763016 2026] [security2:error] [pid 1018003:tid 1018240] [client 68.155.159.216:12170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/cgi-bin/index.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzDQAABhA"] [Sat Aug 29 05:06:21.764031 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.151.200.44:64881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/advanced.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzDgAABgI"] [Sat Aug 29 05:06:21.765082 2026] [security2:error] [pid 1017536:tid 1017786] [client 74.7.241.152:35450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.xow.umh.mybluehost.me"] [uri "/robots.txt"] [unique_id "apK9LSJcY4fy7tP-rU3-yAACjGQ"] [Sat Aug 29 05:06:21.775305 2026] [core:error] [pid 1017536:tid 1017656] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.775323 2026] [core:error] [pid 1017536:tid 1017656] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.777685 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.220.204.93:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/easy.php"] [unique_id "apK9LSJcY4fy7tP-rU3-ygAAAmI"] [Sat Aug 29 05:06:21.787076 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.787096 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.787813 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.184.117:4817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/plugins/revslider/admin.php"] [unique_id "apK9LSJcY4fy7tP-rU3-zQAAAho"] [Sat Aug 29 05:06:21.795189 2026] [security2:error] [pid 1017536:tid 1017556] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/admin/phpinfo.php"] [unique_id "apK9LSJcY4fy7tP-rU3-zwACVhM"] [Sat Aug 29 05:06:21.795221 2026] [security2:error] [pid 1017536:tid 1017584] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/admin_phpinfo.php"] [unique_id "apK9LSJcY4fy7tP-rU3-0wACVi8"] [Sat Aug 29 05:06:21.797959 2026] [core:error] [pid 1017536:tid 1017622] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.797989 2026] [core:error] [pid 1017536:tid 1017622] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.798696 2026] [core:error] [pid 1017536:tid 1017641] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.798716 2026] [core:error] [pid 1017536:tid 1017641] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.799184 2026] [core:error] [pid 1017536:tid 1017649] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.799195 2026] [core:error] [pid 1017536:tid 1017649] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.814268 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.220.204.93:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/8.php"] [unique_id "apK9LSJcY4fy7tP-rU3-1AAAAks"] [Sat Aug 29 05:06:21.823021 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.184.117:59534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.dj/index.php"] [unique_id "apK9LSJcY4fy7tP-rU3-1gAAAn8"] [Sat Aug 29 05:06:21.826015 2026] [security2:error] [pid 1017536:tid 1017695] [client 68.155.159.216:51518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/about/function.php"] [unique_id "apK9LSJcY4fy7tP-rU3-1wAAAjE"] [Sat Aug 29 05:06:21.826909 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.196.209.81:16710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/spip.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzFQAABew"] [Sat Aug 29 05:06:21.839586 2026] [security2:error] [pid 1017536:tid 1017617] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-2AACc1A"] [Sat Aug 29 05:06:21.842053 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.63.81.20:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/alfanew.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzGgAABhY"] [Sat Aug 29 05:06:21.844756 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.251.3:61237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/adminfus.php"] [unique_id "apK9LSJcY4fy7tP-rU3-2QAAAkE"] [Sat Aug 29 05:06:21.859375 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.48.251.3:14311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/bb.php"] [unique_id "apK9LSJcY4fy7tP-rU3-2gAAAns"] [Sat Aug 29 05:06:21.862425 2026] [security2:error] [pid 1017536:tid 1017654] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-3AACF3U"] [Sat Aug 29 05:06:21.864344 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.63.81.20:46926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/sf.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzGwAABfY"] [Sat Aug 29 05:06:21.864759 2026] [security2:error] [pid 1017536:tid 1017609] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-3gACF0g"] [Sat Aug 29 05:06:21.865569 2026] [core:error] [pid 1017536:tid 1017663] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.865582 2026] [core:error] [pid 1017536:tid 1017663] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.869264 2026] [security2:error] [pid 1017536:tid 1017647] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9LSJcY4fy7tP-rU3-4AACO24"] [Sat Aug 29 05:06:21.872833 2026] [core:error] [pid 1017536:tid 1017576] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.872846 2026] [core:error] [pid 1017536:tid 1017576] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.888028 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.23.147.79:25591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9LSJcY4fy7tP-rU3-5AAAAo4"] [Sat Aug 29 05:06:21.888811 2026] [security2:error] [pid 1017536:tid 1017712] [client 68.155.159.216:52839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/.well-known/index.php"] [unique_id "apK9LSJcY4fy7tP-rU3-5QAAAkI"] [Sat Aug 29 05:06:21.892418 2026] [security2:error] [pid 1018003:tid 1018025] [remote 103.171.88.220:32886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.88.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muggoentertainment.com"] [uri "/xmlrpc.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzHwAFxgQ"] [Sat Aug 29 05:06:21.892614 2026] [security2:error] [pid 1018003:tid 1018165] [client 103.171.88.220:32886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muggoentertainment.com"] [uri "/xmlrpc.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzHwAFxgQ"] [Sat Aug 29 05:06:21.900079 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.196.209.81:5952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/install.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzIwAABds"] [Sat Aug 29 05:06:21.903743 2026] [core:error] [pid 1017536:tid 1017719] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.903761 2026] [core:error] [pid 1017536:tid 1017719] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.904164 2026] [security2:error] [pid 1017536:tid 1017777] [client 158.23.147.79:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9LSJcY4fy7tP-rU3-6QAAAoM"] [Sat Aug 29 05:06:21.905320 2026] [core:error] [pid 1017536:tid 1017704] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.905336 2026] [core:error] [pid 1017536:tid 1017704] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.917121 2026] [security2:error] [pid 1018003:tid 1018216] [client 34.7.40.70:62612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/id_rsa"] [unique_id "apK9LTAh5Y1i2tUxg4HzJgAABfk"] [Sat Aug 29 05:06:21.927159 2026] [security2:error] [pid 1017536:tid 1017723] [client 34.7.40.70:62682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/wp-config.php.bak"] [unique_id "apK9LSJcY4fy7tP-rU3-8gAAAk0"] [Sat Aug 29 05:06:21.927684 2026] [cgid:error] [pid 1017536:tid 1017686] [client 34.7.40.70:62674] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:21.927906 2026] [cgid:error] [pid 1017536:tid 1017743] [client 34.7.40.70:62724] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:21.927984 2026] [security2:error] [pid 1018003:tid 1018271] [client 34.7.40.70:62678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.40.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/wp-config.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzKQAABi8"] [Sat Aug 29 05:06:21.928266 2026] [security2:error] [pid 1017536:tid 1017748] [client 34.7.40.70:62696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/wp-config.php.old"] [unique_id "apK9LSJcY4fy7tP-rU3-9AAAAmY"] [Sat Aug 29 05:06:21.928677 2026] [security2:error] [pid 1017536:tid 1017751] [client 34.7.40.70:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.40.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/config.php"] [unique_id "apK9LSJcY4fy7tP-rU3-7AAAAmk"] [Sat Aug 29 05:06:21.928787 2026] [security2:error] [pid 1017536:tid 1017751] [client 34.7.40.70:62700] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/config.php"] [unique_id "apK9LSJcY4fy7tP-rU3-7AAAAmk"] [Sat Aug 29 05:06:21.928873 2026] [security2:error] [pid 1017536:tid 1017681] [client 34.7.40.70:62638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/key.pem"] [unique_id "apK9LSJcY4fy7tP-rU3-9QAAAiM"] [Sat Aug 29 05:06:21.932076 2026] [cgid:error] [pid 1017536:tid 1017691] [client 34.7.40.70:62616] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:21.934375 2026] [security2:error] [pid 1018003:tid 1018182] [client 34.7.40.70:62660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/privatekey.key"] [unique_id "apK9LTAh5Y1i2tUxg4HzJwAABdc"] [Sat Aug 29 05:06:21.934891 2026] [cgid:error] [pid 1017536:tid 1017722] [client 34.7.40.70:62738] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:21.935546 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.184.117:4633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/images/uploads/admin.php"] [unique_id "apK9LSJcY4fy7tP-rU3-9wAAAk4"] [Sat Aug 29 05:06:21.936709 2026] [security2:error] [pid 1017536:tid 1017686] [client 34.7.40.70:62674] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9LSJcY4fy7tP-rU3-6gAAAig"] [Sat Aug 29 05:06:21.937883 2026] [security2:error] [pid 1017536:tid 1017687] [client 34.7.40.70:62620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/id_dsa"] [unique_id "apK9LSJcY4fy7tP-rU3-8QAAAik"] [Sat Aug 29 05:06:21.938626 2026] [cgid:error] [pid 1017536:tid 1017713] [client 34.7.40.70:62632] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:21.940853 2026] [security2:error] [pid 1018003:tid 1018189] [client 52.139.37.240:30191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/cron.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzLAAABd4"] [Sat Aug 29 05:06:21.941457 2026] [cgid:error] [pid 1017536:tid 1017780] [client 34.7.40.70:62736] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:21.941707 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.220.204.93:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/fresh3.php"] [unique_id "apK9LSJcY4fy7tP-rU3--AAAAkM"] [Sat Aug 29 05:06:21.941969 2026] [core:error] [pid 1017536:tid 1017635] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.941985 2026] [core:error] [pid 1017536:tid 1017635] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.945568 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.104.49.130:58223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/wp-blogs.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzLQAABjE"] [Sat Aug 29 05:06:21.946625 2026] [cgid:error] [pid 1018003:tid 1018261] [client 34.7.40.70:62650] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:21.947231 2026] [security2:error] [pid 1017536:tid 1017734] [client 52.139.37.240:12901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apK9LSJcY4fy7tP-rU3--gAAAlg"] [Sat Aug 29 05:06:21.947481 2026] [core:error] [pid 1017536:tid 1017633] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.947500 2026] [core:error] [pid 1017536:tid 1017633] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.948452 2026] [security2:error] [pid 1018003:tid 1018262] [client 168.107.94.195:50490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzLgAABiY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:21.949024 2026] [security2:error] [pid 1018003:tid 1018192] [client 34.7.40.70:62710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.40.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/config.php.bak"] [unique_id "apK9LTAh5Y1i2tUxg4HzKAAABeE"] [Sat Aug 29 05:06:21.949853 2026] [core:error] [pid 1017536:tid 1017659] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.949864 2026] [core:error] [pid 1017536:tid 1017659] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.965328 2026] [core:error] [pid 1017536:tid 1017539] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.965350 2026] [core:error] [pid 1017536:tid 1017539] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.969236 2026] [core:error] [pid 1017536:tid 1017574] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.969254 2026] [core:error] [pid 1017536:tid 1017574] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.969508 2026] [core:error] [pid 1017536:tid 1017592] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.969524 2026] [core:error] [pid 1017536:tid 1017592] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.971582 2026] [security2:error] [pid 1017536:tid 1017710] [client 158.23.184.117:59560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.info.php"] [unique_id "apK9LSJcY4fy7tP-rU3_AQAAAkA"] [Sat Aug 29 05:06:21.973377 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.251.3:61197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/avim.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzMQAABjU"] [Sat Aug 29 05:06:21.978322 2026] [cgid:error] [pid 1017536:tid 1017740] [client 62.60.130.128:49162] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/protypeg/public_html/xyzece/404.shtml [Sat Aug 29 05:06:21.980900 2026] [security2:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/admin/phpinfo.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzMgAF2RY"] [Sat Aug 29 05:06:21.983827 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.63.81.20:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/ioxi.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzMwAABdg"] [Sat Aug 29 05:06:21.989893 2026] [security2:error] [pid 1017536:tid 1017591] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/api/info.php"] [unique_id "apK9LSJcY4fy7tP-rU3_AwACKzY"] [Sat Aug 29 05:06:21.991550 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.991567 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.992336 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.992346 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:21.998779 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.63.81.20:44443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/k.php"] [unique_id "apK9LTAh5Y1i2tUxg4HzNgAABcI"] [Sat Aug 29 05:06:22.017797 2026] [core:error] [pid 1017536:tid 1017579] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.017816 2026] [core:error] [pid 1017536:tid 1017579] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.018662 2026] [security2:error] [pid 1017536:tid 1017709] [client 68.155.159.216:14120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9LiJcY4fy7tP-rU3_CAAAAj8"] [Sat Aug 29 05:06:22.023785 2026] [core:error] [pid 1017536:tid 1017640] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.023814 2026] [core:error] [pid 1017536:tid 1017640] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.023909 2026] [autoindex:error] [pid 1018003:tid 1018054] [remote 74.7.243.205:57434] AH01276: Cannot serve directory /home3/xowumhmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:22.024984 2026] [core:error] [pid 1017536:tid 1017629] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.025000 2026] [core:error] [pid 1017536:tid 1017629] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.026094 2026] [core:error] [pid 1017536:tid 1017599] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.026108 2026] [core:error] [pid 1017536:tid 1017599] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.033380 2026] [security2:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/admin_phpinfo.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzOwAGFSM"] [Sat Aug 29 05:06:22.046161 2026] [security2:error] [pid 1018003:tid 1018195] [client 158.23.147.79:63018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/mah.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzPwAABeQ"] [Sat Aug 29 05:06:22.046690 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.046709 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.064578 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.220.204.93:64317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/0x0x.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzQAAABcg"] [Sat Aug 29 05:06:22.069971 2026] [security2:error] [pid 1017536:tid 1017546] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/api/phpinfo.php"] [unique_id "apK9LiJcY4fy7tP-rU3_DQACOgk"] [Sat Aug 29 05:06:22.072852 2026] [core:error] [pid 1017536:tid 1017537] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.072869 2026] [core:error] [pid 1017536:tid 1017537] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.087033 2026] [security2:error] [pid 1017536:tid 1017752] [client 192.145.125.70:48166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9LiJcY4fy7tP-rU3_DgAAAmo"] [Sat Aug 29 05:06:22.087507 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.220.204.93:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/bgymj.php"] [unique_id "apK9LiJcY4fy7tP-rU3_DwAAAm8"] [Sat Aug 29 05:06:22.119105 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.184.117:21541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.trash7206/index.php"] [unique_id "apK9LiJcY4fy7tP-rU3_EgAAAoI"] [Sat Aug 29 05:06:22.123191 2026] [security2:error] [pid 1017536:tid 1017777] [client 158.23.184.117:4627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/tools.php"] [unique_id "apK9LiJcY4fy7tP-rU3_FgAAAoM"] [Sat Aug 29 05:06:22.128094 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.63.81.20:60479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/TNT.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzRwAABcc"] [Sat Aug 29 05:06:22.133670 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:29965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/wp-2019.php"] [unique_id "apK9LiJcY4fy7tP-rU3_GwAAAiA"] [Sat Aug 29 05:06:22.146580 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.63.81.20:44505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/82.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzSgAABio"] [Sat Aug 29 05:06:22.147630 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.147647 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.148518 2026] [security2:error] [pid 1017536:tid 1017705] [client 52.139.37.240:12442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9LiJcY4fy7tP-rU3_IgAAAjs"] [Sat Aug 29 05:06:22.148538 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.148547 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.149493 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.149507 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.149587 2026] [core:error] [pid 1018003:tid 1018251] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.149598 2026] [core:error] [pid 1018003:tid 1018251] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.152087 2026] [core:error] [pid 1017536:tid 1017710] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.152100 2026] [core:error] [pid 1017536:tid 1017710] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.161538 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.151.200.44:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/blox.php"] [unique_id "apK9LiJcY4fy7tP-rU3_JgAAAlY"] [Sat Aug 29 05:06:22.164825 2026] [core:error] [pid 1018003:tid 1018150] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.164840 2026] [core:error] [pid 1018003:tid 1018150] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.173541 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/admin.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzVQAABd8"] [Sat Aug 29 05:06:22.173718 2026] [security2:error] [pid 1017536:tid 1017650] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_KAACTnE"] [Sat Aug 29 05:06:22.175763 2026] [core:error] [pid 1017536:tid 1017581] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.175778 2026] [core:error] [pid 1017536:tid 1017581] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.175971 2026] [core:error] [pid 1017536:tid 1017639] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.175981 2026] [core:error] [pid 1017536:tid 1017639] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.180644 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.180661 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.181649 2026] [core:error] [pid 1017536:tid 1017790] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.181677 2026] [core:error] [pid 1017536:tid 1017790] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.183253 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.52.41.200:1777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9LiJcY4fy7tP-rU3_KwAAAhc"] [Sat Aug 29 05:06:22.184148 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.184160 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.202146 2026] [security2:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/api/info.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzWwAGFTM"] [Sat Aug 29 05:06:22.202583 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.220.204.93:64963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/166.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzXAAABgI"] [Sat Aug 29 05:06:22.208776 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.147.79:26507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzXQAABgM"] [Sat Aug 29 05:06:22.219427 2026] [security2:error] [pid 1018003:tid 1018242] [client 68.155.159.216:33721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzXwAABhI"] [Sat Aug 29 05:06:22.224644 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.196.209.81:4448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/backup.php"] [unique_id "apK9LiJcY4fy7tP-rU3_MgAAAiU"] [Sat Aug 29 05:06:22.225425 2026] [security2:error] [pid 1017536:tid 1017573] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_MwACayQ"] [Sat Aug 29 05:06:22.248191 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.248207 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.249747 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.23.147.79:48346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9LiJcY4fy7tP-rU3_NwAAAjQ"] [Sat Aug 29 05:06:22.250206 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.197.61.180:17003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/install.php"] [unique_id "apK9LiJcY4fy7tP-rU3_OAAAAkE"] [Sat Aug 29 05:06:22.265439 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:60081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.trash7206/min.php"] [unique_id "apK9LiJcY4fy7tP-rU3_OgAAAjE"] [Sat Aug 29 05:06:22.266166 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.63.81.20:60526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/cd.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzZQAABhY"] [Sat Aug 29 05:06:22.266993 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.184.117:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-content/uploads/my.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzZgAABbo"] [Sat Aug 29 05:06:22.270918 2026] [core:error] [pid 1017536:tid 1017748] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.270932 2026] [core:error] [pid 1017536:tid 1017748] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.276314 2026] [core:error] [pid 1018003:tid 1018219] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.276337 2026] [core:error] [pid 1018003:tid 1018219] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.283782 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.63.81.20:46875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/dex.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzaAAABfA"] [Sat Aug 29 05:06:22.307864 2026] [security2:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/api/phpinfo.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzawAF-Tc"] [Sat Aug 29 05:06:22.323770 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.220.204.93:59020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ws69.php"] [unique_id "apK9LiJcY4fy7tP-rU3_RwAAAl4"] [Sat Aug 29 05:06:22.326026 2026] [security2:error] [pid 1018003:tid 1018172] [client 52.139.37.240:29967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/gecko-new.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzbgAABc0"] [Sat Aug 29 05:06:22.326040 2026] [security2:error] [pid 1018003:tid 1018173] [client 65.111.10.14:46805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzaQAABc4"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:22.327416 2026] [security2:error] [pid 1017536:tid 1017722] [client 168.107.94.195:50892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9LiJcY4fy7tP-rU3_SgAAAkw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:22.328584 2026] [security2:error] [pid 1018003:tid 1018271] [client 158.23.147.79:32755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzbwAABi8"] [Sat Aug 29 05:06:22.332367 2026] [security2:error] [pid 1017536:tid 1017673] [client 4.205.62.107:22299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/w.php"] [unique_id "apK9LiJcY4fy7tP-rU3_UAAAAhs"] [Sat Aug 29 05:06:22.342178 2026] [security2:error] [pid 1017536:tid 1017720] [client 68.155.159.216:49162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/chosen.php"] [unique_id "apK9LiJcY4fy7tP-rU3_WAAAAko"] [Sat Aug 29 05:06:22.343735 2026] [core:error] [pid 1017536:tid 1017680] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.343751 2026] [core:error] [pid 1017536:tid 1017680] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.348370 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.348388 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.353106 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.353120 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.358744 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.358757 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.359670 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.359682 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.363695 2026] [security2:error] [pid 1018003:tid 1018218] [client 4.205.62.107:22250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/loxi-o.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzdAAABfs"] [Sat Aug 29 05:06:22.364532 2026] [core:error] [pid 1017536:tid 1017721] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.364546 2026] [core:error] [pid 1017536:tid 1017721] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.366311 2026] [core:error] [pid 1017536:tid 1017773] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.366323 2026] [core:error] [pid 1017536:tid 1017773] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.366766 2026] [core:error] [pid 1017536:tid 1017669] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.366781 2026] [core:error] [pid 1017536:tid 1017669] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.367344 2026] [core:error] [pid 1018003:tid 1018188] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.367366 2026] [core:error] [pid 1018003:tid 1018188] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.368144 2026] [core:error] [pid 1017536:tid 1017790] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.368158 2026] [core:error] [pid 1017536:tid 1017790] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.369227 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.369241 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.369930 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.369944 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.379677 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.104.49.130:43593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/x1da.php"] [unique_id "apK9LiJcY4fy7tP-rU3_ZgAAAoQ"] [Sat Aug 29 05:06:22.394964 2026] [security2:error] [pid 1017536:tid 1017719] [client 4.205.62.107:65419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/gnmlc.php"] [unique_id "apK9LiJcY4fy7tP-rU3_ZwAAAkk"] [Sat Aug 29 05:06:22.399652 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.399669 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.404429 2026] [security2:error] [pid 1018003:tid 1018269] [client 52.139.37.240:12443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/wp-index.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzewAABi0"] [Sat Aug 29 05:06:22.406800 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.63.81.20:56915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/luuf.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzfgAABeQ"] [Sat Aug 29 05:06:22.412218 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.23.184.117:59548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known//index.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzgAAABjU"] [Sat Aug 29 05:06:22.414818 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.147.79:50170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/worksec.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzgQAABcQ"] [Sat Aug 29 05:06:22.419979 2026] [core:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.419999 2026] [core:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.423230 2026] [core:error] [pid 1017536:tid 1017541] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.423244 2026] [core:error] [pid 1017536:tid 1017541] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.430252 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.220.204.93:62587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/h2a2ck.php"] [unique_id "apK9LiJcY4fy7tP-rU3_awAAAkw"] [Sat Aug 29 05:06:22.431332 2026] [security2:error] [pid 1017536:tid 1017747] [client 158.23.184.117:4540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/themes/uploads/config.php"] [unique_id "apK9LiJcY4fy7tP-rU3_bAAAAmU"] [Sat Aug 29 05:06:22.446529 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.151.200.44:64958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/kcs.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzggAABjM"] [Sat Aug 29 05:06:22.466687 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.220.204.93:59080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ccs.php"] [unique_id "apK9LiJcY4fy7tP-rU3_cQAAAis"] [Sat Aug 29 05:06:22.476497 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.63.81.20:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/inso.php"] [unique_id "apK9LiJcY4fy7tP-rU3_cgAAAhw"] [Sat Aug 29 05:06:22.481689 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.196.209.81:5991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9LiJcY4fy7tP-rU3_cwAAAjw"] [Sat Aug 29 05:06:22.497227 2026] [fcgid:warn] [pid 1018003:tid 1018233] (70014)End of file found: [client 66.132.172.39:31018] mod_fcgid: can't get data from http client [Sat Aug 29 05:06:22.509555 2026] [core:error] [pid 1017536:tid 1017582] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.509576 2026] [core:error] [pid 1017536:tid 1017582] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.510096 2026] [security2:error] [pid 1017536:tid 1017563] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_egACGxo"] [Sat Aug 29 05:06:22.510629 2026] [core:error] [pid 1017536:tid 1017707] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.510643 2026] [core:error] [pid 1017536:tid 1017707] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.513240 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:30612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/login.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzjgAABc8"] [Sat Aug 29 05:06:22.514992 2026] [security2:error] [pid 1017536:tid 1017604] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_ewACG0M"] [Sat Aug 29 05:06:22.523467 2026] [core:error] [pid 1017536:tid 1017567] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.523481 2026] [core:error] [pid 1017536:tid 1017567] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.523630 2026] [core:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.523638 2026] [core:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.523760 2026] [core:error] [pid 1017536:tid 1017625] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.523768 2026] [core:error] [pid 1017536:tid 1017625] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.523924 2026] [core:error] [pid 1017536:tid 1017595] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.523932 2026] [core:error] [pid 1017536:tid 1017595] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.525562 2026] [security2:error] [pid 1017536:tid 1017680] [client 52.139.37.240:29958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/add_actualites.php"] [unique_id "apK9LiJcY4fy7tP-rU3_gAAAAiI"] [Sat Aug 29 05:06:22.529160 2026] [core:error] [pid 1017536:tid 1017643] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.529171 2026] [core:error] [pid 1017536:tid 1017643] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.529869 2026] [core:error] [pid 1017536:tid 1017583] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.529878 2026] [core:error] [pid 1017536:tid 1017583] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.538441 2026] [core:error] [pid 1017536:tid 1017765] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.538452 2026] [core:error] [pid 1017536:tid 1017765] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.542971 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.542983 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.543680 2026] [core:error] [pid 1017536:tid 1017572] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.543693 2026] [core:error] [pid 1017536:tid 1017572] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.545582 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.63.81.20:56901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/fex.php"] [unique_id "apK9LiJcY4fy7tP-rU3_hwAAAkI"] [Sat Aug 29 05:06:22.551693 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.147.79:24397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9LiJcY4fy7tP-rU3_iAAAAk4"] [Sat Aug 29 05:06:22.557548 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.184.117:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/about.php"] [unique_id "apK9LiJcY4fy7tP-rU3_iQAAAn8"] [Sat Aug 29 05:06:22.572830 2026] [security2:error] [pid 1017536:tid 1017709] [client 158.23.184.117:4622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/av.php"] [unique_id "apK9LiJcY4fy7tP-rU3_jAAAAj8"] [Sat Aug 29 05:06:22.573440 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.23.147.79:35715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/.well-known/index.php"] [unique_id "apK9LiJcY4fy7tP-rU3_jQAAAos"] [Sat Aug 29 05:06:22.586444 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.151.200.44:64858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/wsz.php"] [unique_id "apK9LiJcY4fy7tP-rU3_jgAAAjQ"] [Sat Aug 29 05:06:22.595960 2026] [core:error] [pid 1017536:tid 1017776] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.595977 2026] [core:error] [pid 1017536:tid 1017776] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.598228 2026] [security2:error] [pid 1017536:tid 1017788] [client 52.139.37.240:12422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/ww2.php"] [unique_id "apK9LiJcY4fy7tP-rU3_kgAAAo4"] [Sat Aug 29 05:06:22.605754 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.63.81.20:46919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/aa.php"] [unique_id "apK9LiJcY4fy7tP-rU3_kwAAAk0"] [Sat Aug 29 05:06:22.635161 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.220.204.93:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/mar.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzngAABhQ"] [Sat Aug 29 05:06:22.638133 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.220.204.93:63199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/error_log.php"] [unique_id "apK9LjAh5Y1i2tUxg4HznwAABiI"] [Sat Aug 29 05:06:22.647221 2026] [core:error] [pid 1017536:tid 1017737] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.647238 2026] [core:error] [pid 1017536:tid 1017737] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.648653 2026] [security2:error] [pid 1017536:tid 1017706] [client 4.205.62.107:9175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/png.php"] [unique_id "apK9LiJcY4fy7tP-rU3_mQAAAjw"] [Sat Aug 29 05:06:22.652459 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.52.41.200:1756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/bthil.php"] [unique_id "apK9LiJcY4fy7tP-rU3_mwAAAnk"] [Sat Aug 29 05:06:22.654541 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.196.209.81:19436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/haiterus.php"] [unique_id "apK9LiJcY4fy7tP-rU3_nAAAAlY"] [Sat Aug 29 05:06:22.664472 2026] [core:error] [pid 1017536:tid 1017619] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.664487 2026] [core:error] [pid 1017536:tid 1017619] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.675112 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.63.81.20:60516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/l.php"] [unique_id "apK9LiJcY4fy7tP-rU3_ogAAAiI"] [Sat Aug 29 05:06:22.678451 2026] [security2:error] [pid 1017536:tid 1017751] [client 192.145.125.70:48168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nicolaandstevenlochrane.strangeworx.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK9LiJcY4fy7tP-rU3_owAAAmk"] [Sat Aug 29 05:06:22.693321 2026] [core:error] [pid 1017536:tid 1017611] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.693339 2026] [core:error] [pid 1017536:tid 1017611] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.696227 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.696245 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.697441 2026] [security2:error] [pid 1017536:tid 1017710] [client 4.205.62.107:22247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/i.php"] [unique_id "apK9LiJcY4fy7tP-rU3_pwAAAkA"] [Sat Aug 29 05:06:22.698321 2026] [security2:error] [pid 1018003:tid 1018259] [client 103.171.189.88:54502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzpAAABiM"] [Sat Aug 29 05:06:22.698430 2026] [security2:error] [pid 1018003:tid 1018259] [client 103.171.189.88:54502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzpAAABiM"] [Sat Aug 29 05:06:22.705327 2026] [core:error] [pid 1017536:tid 1017558] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.705348 2026] [core:error] [pid 1017536:tid 1017558] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.708629 2026] [security2:error] [pid 1018003:tid 1018248] [client 168.107.94.195:51352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzpwAABhg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:22.712254 2026] [core:error] [pid 1017536:tid 1017618] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.712269 2026] [core:error] [pid 1017536:tid 1017618] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.726951 2026] [security2:error] [pid 1017536:tid 1017743] [client 52.139.37.240:29994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/browse.php"] [unique_id "apK9LiJcY4fy7tP-rU3_sQAAAmE"] [Sat Aug 29 05:06:22.727114 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.151.200.44:64836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/msy.php"] [unique_id "apK9LiJcY4fy7tP-rU3_sgAAAjs"] [Sat Aug 29 05:06:22.731362 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.731379 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.732248 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.732263 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.733797 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.733821 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.737027 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.737032 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.737045 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.737049 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.737054 2026] [core:error] [pid 1017536:tid 1017773] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.737064 2026] [core:error] [pid 1017536:tid 1017773] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.745796 2026] [core:error] [pid 1017536:tid 1017793] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.745814 2026] [core:error] [pid 1017536:tid 1017793] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.754019 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.184.117:60041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9LiJcY4fy7tP-rU3_uAAAAoI"] [Sat Aug 29 05:06:22.760786 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.63.81.20:44497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/img.php"] [unique_id "apK9LiJcY4fy7tP-rU3_uQAAAoQ"] [Sat Aug 29 05:06:22.764693 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.23.184.117:4810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-includes/ID3/file.php"] [unique_id "apK9LjAh5Y1i2tUxg4HztgAABh8"] [Sat Aug 29 05:06:22.778251 2026] [security2:error] [pid 1017536:tid 1017749] [client 68.155.159.216:58305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.heavenonearthgardens.com"] [uri "/first.php"] [unique_id "apK9LiJcY4fy7tP-rU3_vAAAAmc"] [Sat Aug 29 05:06:22.783697 2026] [security2:error] [pid 1018003:tid 1018246] [client 52.139.37.240:15275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/ahax.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzuwAABhY"] [Sat Aug 29 05:06:22.791710 2026] [core:error] [pid 1017536:tid 1017729] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.791726 2026] [core:error] [pid 1017536:tid 1017729] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.792845 2026] [security2:error] [pid 1018003:tid 1018165] [client 52.139.37.240:12520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/7logs.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzvAAABcY"] [Sat Aug 29 05:06:22.808171 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.63.81.20:60513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/xr.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzwgAABd0"] [Sat Aug 29 05:06:22.809250 2026] [security2:error] [pid 1017536:tid 1017777] [client 119.154.241.240:56523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.241.154.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "microprocesos.com"] [uri "/xmlrpc.php"] [unique_id "apK9LiJcY4fy7tP-rU3_vQAAAoM"] [Sat Aug 29 05:06:22.809343 2026] [security2:error] [pid 1017536:tid 1017777] [client 119.154.241.240:56523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "microprocesos.com"] [uri "/xmlrpc.php"] [unique_id "apK9LiJcY4fy7tP-rU3_vQAAAoM"] [Sat Aug 29 05:06:22.811439 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.811452 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.817392 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.220.204.93:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/403.php"] [unique_id "apK9LiJcY4fy7tP-rU3_wQAAAhw"] [Sat Aug 29 05:06:22.820617 2026] [security2:error] [pid 1017536:tid 1017752] [client 4.205.62.107:55944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/xqq.php"] [unique_id "apK9LiJcY4fy7tP-rU3_wgAAAmo"] [Sat Aug 29 05:06:22.845558 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.845578 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.864332 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.220.204.93:59021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ccu.php"] [unique_id "apK9LjAh5Y1i2tUxg4HzygAABgE"] [Sat Aug 29 05:06:22.873888 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.151.200.44:61955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/siln.php"] [unique_id "apK9LiJcY4fy7tP-rU3_yAAAAlc"] [Sat Aug 29 05:06:22.875502 2026] [security2:error] [pid 1017536:tid 1017724] [client 68.155.159.216:12100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9LiJcY4fy7tP-rU3_ywAAAk4"] [Sat Aug 29 05:06:22.875910 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.196.209.81:5120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK9LiJcY4fy7tP-rU3_zAAAAkM"] [Sat Aug 29 05:06:22.878880 2026] [security2:error] [pid 1017536:tid 1017631] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_zwACY14"] [Sat Aug 29 05:06:22.879853 2026] [core:error] [pid 1017536:tid 1017545] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.879868 2026] [core:error] [pid 1017536:tid 1017545] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.882876 2026] [security2:error] [pid 1017536:tid 1017570] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_0gACYyE"] [Sat Aug 29 05:06:22.888585 2026] [security2:error] [pid 1017536:tid 1017790] [client 209.50.169.117:12427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.169.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9LiJcY4fy7tP-rU3_wwAAApA"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:22.890178 2026] [core:error] [pid 1018003:tid 1018199] [client 20.197.61.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.890196 2026] [core:error] [pid 1018003:tid 1018199] [client 20.197.61.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.899877 2026] [security2:error] [pid 1017536:tid 1017680] [client 158.23.184.117:21524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "apK9LiJcY4fy7tP-rU3_0wAAAiI"] [Sat Aug 29 05:06:22.907707 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.907729 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.909416 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.184.117:4818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.justinfenniman.com"] [uri "/wp-admin/css/fff.php"] [unique_id "apK9LiJcY4fy7tP-rU3_1AAAAnc"] [Sat Aug 29 05:06:22.913963 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.913983 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.917206 2026] [security2:error] [pid 1017536:tid 1017593] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_1QACYzg"] [Sat Aug 29 05:06:22.917422 2026] [security2:error] [pid 1017536:tid 1017610] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_1wACY0k"] [Sat Aug 29 05:06:22.917450 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.63.81.20:44447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/222.php"] [unique_id "apK9LjAh5Y1i2tUxg4Hz1AAABdA"] [Sat Aug 29 05:06:22.917643 2026] [security2:error] [pid 1017536:tid 1017642] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9LiJcY4fy7tP-rU3_1gACY2k"] [Sat Aug 29 05:06:22.920095 2026] [core:error] [pid 1017536:tid 1017577] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.920097 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.920113 2026] [core:error] [pid 1017536:tid 1017577] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.920121 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.940183 2026] [security2:error] [pid 1017536:tid 1017683] [client 52.139.37.240:30183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/contentloader1.php"] [unique_id "apK9LiJcY4fy7tP-rU3_2QAAAiU"] [Sat Aug 29 05:06:22.946074 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.63.81.20:60445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/Q3.php"] [unique_id "apK9LjAh5Y1i2tUxg4Hz2AAABb0"] [Sat Aug 29 05:06:22.950176 2026] [security2:error] [pid 1018003:tid 1018212] [client 68.155.159.216:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9LjAh5Y1i2tUxg4Hz2QAABfU"] [Sat Aug 29 05:06:22.964135 2026] [core:error] [pid 1017536:tid 1017630] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.964154 2026] [core:error] [pid 1017536:tid 1017630] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.964621 2026] [core:error] [pid 1017536:tid 1017554] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.964639 2026] [core:error] [pid 1017536:tid 1017554] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.964846 2026] [core:error] [pid 1017536:tid 1017651] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.964854 2026] [core:error] [pid 1017536:tid 1017651] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.964856 2026] [core:error] [pid 1017536:tid 1017644] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.964867 2026] [core:error] [pid 1017536:tid 1017644] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.966933 2026] [core:error] [pid 1017536:tid 1017621] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.966948 2026] [core:error] [pid 1017536:tid 1017621] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:22.984303 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.220.204.93:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/cytyr.php"] [unique_id "apK9LjAh5Y1i2tUxg4Hz4AAABgk"] [Sat Aug 29 05:06:22.985033 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.49.130:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/load.php"] [unique_id "apK9LjAh5Y1i2tUxg4Hz4QAABbw"] [Sat Aug 29 05:06:22.988697 2026] [security2:error] [pid 1017536:tid 1017757] [client 149.34.210.141:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9LiJcY4fy7tP-rU3_3wAAAm8"] [Sat Aug 29 05:06:22.988776 2026] [security2:error] [pid 1017536:tid 1017757] [client 149.34.210.141:20301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9LiJcY4fy7tP-rU3_3wAAAm8"] [Sat Aug 29 05:06:22.994940 2026] [security2:error] [pid 1018003:tid 1018163] [client 52.139.37.240:15276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/breads1.php"] [unique_id "apK9LjAh5Y1i2tUxg4Hz4gAABcQ"] [Sat Aug 29 05:06:22.998808 2026] [security2:error] [pid 1018003:tid 1018162] [client 52.139.37.240:12866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/ac.php"] [unique_id "apK9LjAh5Y1i2tUxg4Hz5AAABcM"] [Sat Aug 29 05:06:23.007833 2026] [security2:error] [pid 1017536:tid 1017719] [client 68.155.159.216:52746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/themes/too.php"] [unique_id "apK9LyJcY4fy7tP-rU3_4AAAAkk"] [Sat Aug 29 05:06:23.010081 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.147.79:61618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9LzAh5Y1i2tUxg4Hz5gAABeM"] [Sat Aug 29 05:06:23.027492 2026] [security2:error] [pid 1018003:tid 1018160] [client 158.158.54.35:2912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/.trash7206/index.php"] [unique_id "apK9LzAh5Y1i2tUxg4Hz6wAABcE"] [Sat Aug 29 05:06:23.044552 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.151.200.44:64946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/f-401.php"] [unique_id "apK9LyJcY4fy7tP-rU3_4QAAAk0"] [Sat Aug 29 05:06:23.054312 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.196.209.81:11525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/go.php"] [unique_id "apK9LyJcY4fy7tP-rU3_4gAAAkE"] [Sat Aug 29 05:06:23.062671 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.63.81.20:46860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/key.php"] [unique_id "apK9LyJcY4fy7tP-rU3_4wAAAjo"] [Sat Aug 29 05:06:23.079961 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.48.251.3:14098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/file59.php"] [unique_id "apK9LyJcY4fy7tP-rU3_5AAAAkc"] [Sat Aug 29 05:06:23.080774 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.63.81.20:56935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/Q1.php"] [unique_id "apK9LzAh5Y1i2tUxg4Hz7wAABhQ"] [Sat Aug 29 05:06:23.088477 2026] [security2:error] [pid 1017536:tid 1017769] [client 168.107.94.195:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9LyJcY4fy7tP-rU3_5gAAAns"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:23.097671 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.220.204.93:52327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ak.php"] [unique_id "apK9LyJcY4fy7tP-rU3_6gAAAoc"] [Sat Aug 29 05:06:23.098388 2026] [security2:error] [pid 1017536:tid 1017605] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9LyJcY4fy7tP-rU3_6AACGkQ"] [Sat Aug 29 05:06:23.098453 2026] [security2:error] [pid 1017536:tid 1017565] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9LyJcY4fy7tP-rU3_5wACGhw"] [Sat Aug 29 05:06:23.101091 2026] [security2:error] [pid 1017536:tid 1017568] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9LyJcY4fy7tP-rU3_7QACGh8"] [Sat Aug 29 05:06:23.101810 2026] [core:error] [pid 1017536:tid 1017628] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.101827 2026] [core:error] [pid 1017536:tid 1017628] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.110094 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.251.3:61060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/nw.php"] [unique_id "apK9LyJcY4fy7tP-rU3_8QAAAis"] [Sat Aug 29 05:06:23.113406 2026] [core:error] [pid 1017536:tid 1017645] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.113429 2026] [core:error] [pid 1017536:tid 1017645] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.113908 2026] [core:error] [pid 1017536:tid 1017623] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.113930 2026] [core:error] [pid 1017536:tid 1017623] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.116201 2026] [core:error] [pid 1017536:tid 1017637] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.116215 2026] [core:error] [pid 1017536:tid 1017637] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.116649 2026] [core:error] [pid 1017536:tid 1017656] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.116661 2026] [core:error] [pid 1017536:tid 1017656] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.117057 2026] [cgid:error] [pid 1017536:tid 1017793] [client 20.52.41.200:1216] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:23.123008 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.123027 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.131445 2026] [core:error] [pid 1018003:tid 1018259] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.131462 2026] [core:error] [pid 1018003:tid 1018259] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.134578 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:29993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/upfile.php"] [unique_id "apK9LyJcY4fy7tP-rU0AAwAAAiA"] [Sat Aug 29 05:06:23.138994 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.139013 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.142385 2026] [security2:error] [pid 1017536:tid 1017686] [client 61.9.8.172:12029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9LyJcY4fy7tP-rU0AAAAAAig"] [Sat Aug 29 05:06:23.142506 2026] [security2:error] [pid 1017536:tid 1017686] [client 61.9.8.172:12029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9LyJcY4fy7tP-rU0AAAAAAig"] [Sat Aug 29 05:06:23.157590 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.157610 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.162853 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.162870 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.162890 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.162898 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.162932 2026] [core:error] [pid 1017536:tid 1017694] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.162941 2026] [core:error] [pid 1017536:tid 1017694] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.169330 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.169341 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.193842 2026] [security2:error] [pid 1018003:tid 1018276] [client 52.139.37.240:12525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/ctex1.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0AQAABjQ"] [Sat Aug 29 05:06:23.207290 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.220.204.93:65004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/galer.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0AwAABf4"] [Sat Aug 29 05:06:23.210405 2026] [security2:error] [pid 1017536:tid 1017713] [client 52.139.37.240:14926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/must.php"] [unique_id "apK9LyJcY4fy7tP-rU0ADQAAAkM"] [Sat Aug 29 05:06:23.214452 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.197.61.180:16282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0BAAABdw"] [Sat Aug 29 05:06:23.224731 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.63.81.20:56934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/nz.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0BgAABd4"] [Sat Aug 29 05:06:23.245459 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.251.3:61113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/product.php"] [unique_id "apK9LyJcY4fy7tP-rU0ADgAAAkA"] [Sat Aug 29 05:06:23.251571 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.63.81.20:46883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/chosen.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0DgAABfs"] [Sat Aug 29 05:06:23.251814 2026] [security2:error] [pid 1017536:tid 1017641] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AEgACP2g"] [Sat Aug 29 05:06:23.252090 2026] [security2:error] [pid 1018003:tid 1018188] [client 114.119.154.87:55539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thesldiet.com"] [uri "/product-category/dinner"] [unique_id "apK9LzAh5Y1i2tUxg4H0DwAABd0"], referer: http://www.thesldiet.com/product-category/dinner [Sat Aug 29 05:06:23.252566 2026] [core:error] [pid 1017536:tid 1017649] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.252579 2026] [core:error] [pid 1017536:tid 1017649] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.262291 2026] [security2:error] [pid 1017536:tid 1017689] [client 68.155.159.216:51455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK9LyJcY4fy7tP-rU0AFQAAAis"] [Sat Aug 29 05:06:23.267546 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.52.41.200:1216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/cv.php"] [unique_id "apK9LyJcY4fy7tP-rU0AFwAAAjw"] [Sat Aug 29 05:06:23.271114 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.251.3:13981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/cli_bootstrap.php"] [unique_id "apK9LyJcY4fy7tP-rU0AGAAAAlY"] [Sat Aug 29 05:06:23.273721 2026] [security2:error] [pid 1017536:tid 1017724] [client 68.155.159.216:16173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-admin/admin.php"] [unique_id "apK9LyJcY4fy7tP-rU0AGgAAAk4"] [Sat Aug 29 05:06:23.277750 2026] [security2:error] [pid 1017536:tid 1017609] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AHAACG0g"] [Sat Aug 29 05:06:23.279168 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.196.209.81:5969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/languages/index.php"] [unique_id "apK9LyJcY4fy7tP-rU0AJAAAAos"] [Sat Aug 29 05:06:23.280616 2026] [core:error] [pid 1017536:tid 1017576] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.280633 2026] [core:error] [pid 1017536:tid 1017576] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.281073 2026] [core:error] [pid 1017536:tid 1017609] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.281083 2026] [core:error] [pid 1017536:tid 1017609] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.282587 2026] [core:error] [pid 1018003:tid 1018186] [client 35.234.155.175:54112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.282609 2026] [core:error] [pid 1018003:tid 1018186] [client 35.234.155.175:54112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.282858 2026] [core:error] [pid 1017536:tid 1017705] [client 35.234.155.175:54046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.282875 2026] [core:error] [pid 1017536:tid 1017705] [client 35.234.155.175:54046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.285304 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.104.49.130:60788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/sxxb.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0GwAABdU"] [Sat Aug 29 05:06:23.285649 2026] [core:error] [pid 1017536:tid 1017744] [client 35.234.155.175:54158] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.285675 2026] [core:error] [pid 1017536:tid 1017744] [client 35.234.155.175:54158] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.285919 2026] [core:error] [pid 1018003:tid 1018207] [client 35.234.155.175:54048] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.285930 2026] [core:error] [pid 1018003:tid 1018207] [client 35.234.155.175:54048] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.286186 2026] [core:error] [pid 1017536:tid 1017773] [client 35.234.155.175:54140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.286195 2026] [core:error] [pid 1017536:tid 1017773] [client 35.234.155.175:54140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.286388 2026] [core:error] [pid 1018003:tid 1018245] [client 35.234.155.175:54068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.286405 2026] [core:error] [pid 1018003:tid 1018245] [client 35.234.155.175:54068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.286677 2026] [core:error] [pid 1017536:tid 1017790] [client 35.234.155.175:54080] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.286690 2026] [core:error] [pid 1017536:tid 1017790] [client 35.234.155.175:54080] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.286706 2026] [core:error] [pid 1018003:tid 1018179] [client 35.234.155.175:54150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.286715 2026] [core:error] [pid 1018003:tid 1018179] [client 35.234.155.175:54150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.287773 2026] [core:error] [pid 1018003:tid 1018206] [client 35.234.155.175:54054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.287787 2026] [core:error] [pid 1018003:tid 1018206] [client 35.234.155.175:54054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.288205 2026] [security2:error] [pid 1017536:tid 1017652] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config.php"] [unique_id "apK9LyJcY4fy7tP-rU0AKQACG3M"] [Sat Aug 29 05:06:23.288881 2026] [core:error] [pid 1018003:tid 1018270] [client 35.234.155.175:54126] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.288902 2026] [core:error] [pid 1018003:tid 1018270] [client 35.234.155.175:54126] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.289229 2026] [core:error] [pid 1018003:tid 1018216] [client 35.234.155.175:54096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.289241 2026] [core:error] [pid 1018003:tid 1018216] [client 35.234.155.175:54096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.289468 2026] [core:error] [pid 1017536:tid 1017747] [client 35.234.155.175:54098] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.289481 2026] [core:error] [pid 1017536:tid 1017747] [client 35.234.155.175:54098] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.299848 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.151.200.44:62001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/hq.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0IAAABcs"] [Sat Aug 29 05:06:23.315023 2026] [core:error] [pid 1017536:tid 1017695] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.315042 2026] [core:error] [pid 1017536:tid 1017695] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.315320 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.315332 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.317288 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.317302 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.318442 2026] [core:error] [pid 1017536:tid 1017788] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.318459 2026] [core:error] [pid 1017536:tid 1017788] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.326972 2026] [security2:error] [pid 1018003:tid 1018215] [client 68.155.159.216:50197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0JQAABfg"] [Sat Aug 29 05:06:23.328632 2026] [security2:error] [pid 1018003:tid 1018268] [client 52.139.37.240:30202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/form.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0JwAABiw"] [Sat Aug 29 05:06:23.345257 2026] [security2:error] [pid 1018003:tid 1018212] [client 68.155.159.216:33685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/asd.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0KwAABfU"] [Sat Aug 29 05:06:23.347288 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.220.204.93:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/lib.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0LAAABdk"] [Sat Aug 29 05:06:23.357685 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.220.204.93:64283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/baixy.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0LgAABfo"] [Sat Aug 29 05:06:23.357704 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.63.81.20:60455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/sg.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0LwAABew"] [Sat Aug 29 05:06:23.360423 2026] [security2:error] [pid 1017536:tid 1017752] [client 68.155.159.216:24456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9LyJcY4fy7tP-rU0AMgAAAmo"] [Sat Aug 29 05:06:23.372813 2026] [security2:error] [pid 1017536:tid 1017591] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AOAACGzY"] [Sat Aug 29 05:06:23.384722 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.384742 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.384943 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.384955 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.387626 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.48.251.3:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/fun.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0NAAABio"] [Sat Aug 29 05:06:23.387686 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.63.81.20:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/file1221.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0NQAABcQ"] [Sat Aug 29 05:06:23.388791 2026] [security2:error] [pid 1018003:tid 1018167] [client 52.139.37.240:12886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/defaults.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0NgAABcg"] [Sat Aug 29 05:06:23.395760 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.395776 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.407313 2026] [security2:error] [pid 1018003:tid 1018156] [client 52.139.37.240:14480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/up.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0OgAABb0"] [Sat Aug 29 05:06:23.410525 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.410546 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.417446 2026] [core:error] [pid 1017536:tid 1017632] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.417466 2026] [core:error] [pid 1017536:tid 1017632] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.417664 2026] [core:error] [pid 1017536:tid 1017786] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.417675 2026] [core:error] [pid 1017536:tid 1017786] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.435041 2026] [security2:error] [pid 1017536:tid 1017599] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/aws.php"] [unique_id "apK9LyJcY4fy7tP-rU0AQQACGz4"] [Sat Aug 29 05:06:23.437040 2026] [core:error] [pid 1017536:tid 1017629] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.437055 2026] [core:error] [pid 1017536:tid 1017629] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.438892 2026] [security2:error] [pid 1017536:tid 1017747] [client 158.23.147.79:32576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9LyJcY4fy7tP-rU0AQwAAAmU"] [Sat Aug 29 05:06:23.444277 2026] [security2:error] [pid 1017536:tid 1017751] [client 68.155.159.216:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK9LyJcY4fy7tP-rU0ARAAAAmk"] [Sat Aug 29 05:06:23.445494 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.251.3:14010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/dd.php"] [unique_id "apK9LyJcY4fy7tP-rU0ARQAAAiM"] [Sat Aug 29 05:06:23.448347 2026] [security2:error] [pid 1017536:tid 1017694] [client 68.155.159.216:49234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/goods.php"] [unique_id "apK9LyJcY4fy7tP-rU0ASAAAAjA"] [Sat Aug 29 05:06:23.449618 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.147.79:26495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9LyJcY4fy7tP-rU0ASQAAAoI"] [Sat Aug 29 05:06:23.450722 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.452402 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.455888 2026] [core:error] [pid 1017536:tid 1017694] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.455903 2026] [core:error] [pid 1017536:tid 1017694] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.468227 2026] [security2:error] [pid 1018003:tid 1018242] [client 168.107.94.195:52251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0PgAABhI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:23.469603 2026] [core:error] [pid 1017536:tid 1017546] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.469618 2026] [core:error] [pid 1017536:tid 1017546] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.472019 2026] [security2:error] [pid 1018003:tid 1018243] [client 4.205.62.107:22355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/u88.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0PwAABhM"] [Sat Aug 29 05:06:23.472799 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.23.147.79:63002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-blog-header.php"] [unique_id "apK9LyJcY4fy7tP-rU0ATgAAAms"] [Sat Aug 29 05:06:23.475578 2026] [security2:error] [pid 1017536:tid 1017537] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/config.inc.php"] [unique_id "apK9LyJcY4fy7tP-rU0AUAACFgA"] [Sat Aug 29 05:06:23.477850 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.220.204.93:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wp-style.php"] [unique_id "apK9LyJcY4fy7tP-rU0AUgAAAoY"] [Sat Aug 29 05:06:23.478321 2026] [core:error] [pid 1017536:tid 1017620] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.478331 2026] [core:error] [pid 1017536:tid 1017620] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.478832 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.151.200.44:64866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/mcd.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0QQAABdw"] [Sat Aug 29 05:06:23.485345 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.196.209.81:11577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/gecko-new.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0QgAABdI"] [Sat Aug 29 05:06:23.494947 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.63.81.20:60418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/hypo.php"] [unique_id "apK9LyJcY4fy7tP-rU0AVAAAAnw"] [Sat Aug 29 05:06:23.501403 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.147.79:30673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/hehehehe.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0RQAABd0"] [Sat Aug 29 05:06:23.505616 2026] [security2:error] [pid 1017536:tid 1017731] [client 4.205.62.107:22434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/luJMF.php"] [unique_id "apK9LyJcY4fy7tP-rU0AVQAAAlU"] [Sat Aug 29 05:06:23.506003 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.506014 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.517825 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.48.251.3:61656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/kedi.php"] [unique_id "apK9LyJcY4fy7tP-rU0AVgAAAkw"] [Sat Aug 29 05:06:23.524592 2026] [security2:error] [pid 1017536:tid 1017788] [client 52.139.37.240:30206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/wp-sigunq.php"] [unique_id "apK9LyJcY4fy7tP-rU0AWAAAAo4"] [Sat Aug 29 05:06:23.524620 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.220.204.93:64266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ava.php"] [unique_id "apK9LyJcY4fy7tP-rU0AVwAAAkc"] [Sat Aug 29 05:06:23.529755 2026] [core:error] [pid 1017536:tid 1017658] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.529769 2026] [core:error] [pid 1017536:tid 1017658] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.529896 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.158.54.35:2897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wk/index.php"] [unique_id "apK9LyJcY4fy7tP-rU0AWgAAAmc"] [Sat Aug 29 05:06:23.532037 2026] [security2:error] [pid 1017536:tid 1017713] [client 4.205.62.107:65426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/koiy.php"] [unique_id "apK9LyJcY4fy7tP-rU0AWwAAAkM"] [Sat Aug 29 05:06:23.537760 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.63.81.20:46969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/nox.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0TAAABi4"] [Sat Aug 29 05:06:23.562449 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.151.200.44:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/mh.php"] [unique_id "apK9LyJcY4fy7tP-rU0AaAAAAjs"] [Sat Aug 29 05:06:23.573058 2026] [security2:error] [pid 1017536:tid 1017542] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/config.php"] [unique_id "apK9LyJcY4fy7tP-rU0AagACKAU"] [Sat Aug 29 05:06:23.578030 2026] [core:error] [pid 1017536:tid 1017586] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.578047 2026] [core:error] [pid 1017536:tid 1017586] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.579661 2026] [core:error] [pid 1017536:tid 1017597] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.579678 2026] [core:error] [pid 1017536:tid 1017597] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.582738 2026] [core:error] [pid 1017536:tid 1017607] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.582752 2026] [core:error] [pid 1017536:tid 1017607] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.583194 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.147.79:50015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/x.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0VQAABf8"] [Sat Aug 29 05:06:23.585568 2026] [security2:error] [pid 1017536:tid 1017650] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/env.php"] [unique_id "apK9LyJcY4fy7tP-rU0AbwACKHE"] [Sat Aug 29 05:06:23.586474 2026] [core:error] [pid 1017536:tid 1017544] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.586500 2026] [core:error] [pid 1017536:tid 1017544] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.588226 2026] [core:error] [pid 1017536:tid 1017581] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.588238 2026] [core:error] [pid 1017536:tid 1017581] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.595601 2026] [security2:error] [pid 1017536:tid 1017746] [client 52.139.37.240:12919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/domains.php"] [unique_id "apK9LyJcY4fy7tP-rU0AcQAAAmQ"] [Sat Aug 29 05:06:23.609397 2026] [security2:error] [pid 1017536:tid 1017662] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/module.config.php"] [unique_id "apK9LyJcY4fy7tP-rU0AcgACMH0"] [Sat Aug 29 05:06:23.610901 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.151.200.44:47422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/uuu.php"] [unique_id "apK9LyJcY4fy7tP-rU0AdAAAAnk"] [Sat Aug 29 05:06:23.621339 2026] [security2:error] [pid 1017536:tid 1017598] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/nexmo.php"] [unique_id "apK9LyJcY4fy7tP-rU0AdwACMD0"] [Sat Aug 29 05:06:23.624892 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.48.251.3:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/wp-tem.php"] [unique_id "apK9LyJcY4fy7tP-rU0AeAAAAkI"] [Sat Aug 29 05:06:23.629491 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.147.79:30620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0WQAABfU"] [Sat Aug 29 05:06:23.631108 2026] [core:error] [pid 1017536:tid 1017655] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.631129 2026] [core:error] [pid 1017536:tid 1017655] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.634058 2026] [core:error] [pid 1017536:tid 1017613] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.634075 2026] [core:error] [pid 1017536:tid 1017613] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.635324 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.63.81.20:43591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/Hd.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0WwAABdk"] [Sat Aug 29 05:06:23.638509 2026] [core:error] [pid 1017536:tid 1017733] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.638523 2026] [core:error] [pid 1017536:tid 1017733] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.650702 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.48.251.3:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/oc460l3x.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0XAAABiA"] [Sat Aug 29 05:06:23.657689 2026] [core:error] [pid 1017536:tid 1017752] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.657707 2026] [core:error] [pid 1017536:tid 1017752] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.659514 2026] [core:error] [pid 1017536:tid 1017678] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.659529 2026] [core:error] [pid 1017536:tid 1017678] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.668479 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.220.204.93:59084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/browse.php"] [unique_id "apK9LyJcY4fy7tP-rU0AgQAAAlU"] [Sat Aug 29 05:06:23.670402 2026] [security2:error] [pid 1018003:tid 1018167] [client 52.139.37.240:15233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-content/155.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0XQAABcg"] [Sat Aug 29 05:06:23.674263 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.147.79:24574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0XwAABcQ"] [Sat Aug 29 05:06:23.676115 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.63.81.20:44486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/akismet.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0YAAABeA"] [Sat Aug 29 05:06:23.678936 2026] [security2:error] [pid 1017536:tid 1017616] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/stripe.php"] [unique_id "apK9LyJcY4fy7tP-rU0AgwACTE8"] [Sat Aug 29 05:06:23.684109 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.196.209.81:5977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/languages/min.php"] [unique_id "apK9LyJcY4fy7tP-rU0AhQAAAk0"] [Sat Aug 29 05:06:23.684256 2026] [security2:error] [pid 1018003:tid 1018244] [client 158.23.147.79:35725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0YgAABhQ"] [Sat Aug 29 05:06:23.701990 2026] [security2:error] [pid 1018003:tid 1018048] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0aAAF4xs"] [Sat Aug 29 05:06:23.713768 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.713789 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.721390 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.52.41.200:1791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/packed.php"] [unique_id "apK9LyJcY4fy7tP-rU0AiQAAAn8"] [Sat Aug 29 05:06:23.724725 2026] [security2:error] [pid 1018003:tid 1018155] [client 136.107.231.130:52558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/.env"] [unique_id "apK9LzAh5Y1i2tUxg4H0bQAABbw"] [Sat Aug 29 05:06:23.726469 2026] [security2:error] [pid 1017536:tid 1017761] [client 136.107.231.130:52588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/app/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AiwAAAnM"] [Sat Aug 29 05:06:23.726891 2026] [security2:error] [pid 1018003:tid 1018233] [client 136.107.231.130:52590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/src/.env"] [unique_id "apK9LzAh5Y1i2tUxg4H0bgAABgk"] [Sat Aug 29 05:06:23.729737 2026] [security2:error] [pid 1017536:tid 1017731] [client 136.107.231.130:52572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/root/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AjAAAAlU"] [Sat Aug 29 05:06:23.729771 2026] [security2:error] [pid 1018003:tid 1018162] [client 136.107.231.130:52606] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9LzAh5Y1i2tUxg4H0bwAABcM"] [Sat Aug 29 05:06:23.729884 2026] [security2:error] [pid 1017536:tid 1017687] [client 52.139.37.240:29982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.thesldiet.com"] [uri "/07.php"] [unique_id "apK9LyJcY4fy7tP-rU0AjQAAAik"] [Sat Aug 29 05:06:23.731593 2026] [security2:error] [pid 1018003:tid 1018238] [client 136.107.231.130:52628] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK9LzAh5Y1i2tUxg4H0cwAABg4"] [Sat Aug 29 05:06:23.731688 2026] [security2:error] [pid 1018003:tid 1018174] [client 136.107.231.130:52592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apK9LzAh5Y1i2tUxg4H0cgAABc8"] [Sat Aug 29 05:06:23.732279 2026] [security2:error] [pid 1018003:tid 1018160] [client 136.107.231.130:52614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apK9LzAh5Y1i2tUxg4H0cQAABcE"] [Sat Aug 29 05:06:23.735948 2026] [core:error] [pid 1018003:tid 1018190] [client 136.107.231.130:52646] AH10244: invalid URI path (/@fs/../../.env?raw??) [Sat Aug 29 05:06:23.736433 2026] [security2:error] [pid 1018003:tid 1018190] [client 136.107.231.130:52646] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/400.shtml"] [unique_id "apK9LzAh5Y1i2tUxg4H0dAAABd8"] [Sat Aug 29 05:06:23.737398 2026] [security2:error] [pid 1018003:tid 1018261] [client 136.107.231.130:52640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.env"] [unique_id "apK9LzAh5Y1i2tUxg4H0dQAABiU"] [Sat Aug 29 05:06:23.737510 2026] [security2:error] [pid 1018003:tid 1018261] [client 136.107.231.130:52640] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.env"] [unique_id "apK9LzAh5Y1i2tUxg4H0dQAABiU"] [Sat Aug 29 05:06:23.745445 2026] [security2:error] [pid 1018003:tid 1018234] [client 136.107.231.130:52672] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9LzAh5Y1i2tUxg4H0egAABgo"] [Sat Aug 29 05:06:23.746184 2026] [security2:error] [pid 1018003:tid 1018200] [client 136.107.231.130:52686] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/root/.aws/credentials.bak"] [unique_id "apK9LzAh5Y1i2tUxg4H0fQAABek"] [Sat Aug 29 05:06:23.746603 2026] [core:error] [pid 1017536:tid 1017601] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.746618 2026] [core:error] [pid 1017536:tid 1017601] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.746702 2026] [security2:error] [pid 1017536:tid 1017668] [client 136.107.231.130:52696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/root/.aws/credentials.backup"] [unique_id "apK9LyJcY4fy7tP-rU0AjwAAAhY"] [Sat Aug 29 05:06:23.763902 2026] [core:error] [pid 1017536:tid 1017590] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.763919 2026] [core:error] [pid 1017536:tid 1017590] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.766052 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.63.81.20:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/im.php"] [unique_id "apK9LyJcY4fy7tP-rU0AmgAAAmU"] [Sat Aug 29 05:06:23.774197 2026] [core:error] [pid 1017536:tid 1017589] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.774216 2026] [core:error] [pid 1017536:tid 1017589] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.782104 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.251.3:3352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/drykl.php"] [unique_id "apK9LyJcY4fy7tP-rU0AnwAAAmQ"] [Sat Aug 29 05:06:23.785028 2026] [core:error] [pid 1017536:tid 1017561] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.785047 2026] [core:error] [pid 1017536:tid 1017561] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.785109 2026] [core:error] [pid 1017536:tid 1017596] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.785120 2026] [core:error] [pid 1017536:tid 1017596] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.793798 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.793815 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.796436 2026] [security2:error] [pid 1018003:tid 1018225] [client 52.139.37.240:12906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/dropdown.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0jQAABgI"] [Sat Aug 29 05:06:23.797634 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.797649 2026] [core:error] [pid 1017536:tid 1017712] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.804671 2026] [core:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.804690 2026] [core:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.805833 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.220.204.93:59117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/zoo.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0jgAABd0"] [Sat Aug 29 05:06:23.813128 2026] [core:error] [pid 1018003:tid 1018171] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.813151 2026] [core:error] [pid 1018003:tid 1018171] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.816481 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.816500 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.816505 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.816516 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.817544 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.817553 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.824377 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.63.81.20:46943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ajax.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0lAAABdQ"] [Sat Aug 29 05:06:23.844840 2026] [security2:error] [pid 1017536:tid 1017770] [client 4.205.62.107:8988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wp-tem.php"] [unique_id "apK9LyJcY4fy7tP-rU0ArwAAAnw"] [Sat Aug 29 05:06:23.845135 2026] [security2:error] [pid 1018003:tid 1018270] [client 4.205.62.107:21603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/guk.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0lwAABi4"] [Sat Aug 29 05:06:23.848200 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.151.200.44:64852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/f2r4.php"] [unique_id "apK9LyJcY4fy7tP-rU0AswAAApI"] [Sat Aug 29 05:06:23.848898 2026] [security2:error] [pid 1017536:tid 1017734] [client 168.107.94.195:52573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9LyJcY4fy7tP-rU0AtAAAAlg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:23.851434 2026] [security2:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/aws.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0mAAF4z8"] [Sat Aug 29 05:06:23.854039 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.48.251.3:33318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/txets.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0nAAABeE"] [Sat Aug 29 05:06:23.863821 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.147.79:48272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9LyJcY4fy7tP-rU0AtgAAAoQ"] [Sat Aug 29 05:06:23.867211 2026] [security2:error] [pid 1017536:tid 1017698] [client 52.139.37.240:14499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-update.php"] [unique_id "apK9LyJcY4fy7tP-rU0AtwAAAjQ"] [Sat Aug 29 05:06:23.878054 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.878347 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.878541 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.878559 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.881489 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.881506 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.882381 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.196.209.81:16759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/wp-admin.php"] [unique_id "apK9LyJcY4fy7tP-rU0AuwAAAmI"] [Sat Aug 29 05:06:23.904469 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.63.81.20:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/fc.php"] [unique_id "apK9LyJcY4fy7tP-rU0AvQAAAlo"] [Sat Aug 29 05:06:23.905806 2026] [core:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.905824 2026] [core:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.911943 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.911960 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.916330 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.48.251.3:3183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/rpk.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0oAAABcA"] [Sat Aug 29 05:06:23.924446 2026] [security2:error] [pid 1018003:tid 1018195] [client 52.139.37.240:30162] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.thesldiet.com"] [uri "/c99.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0oQAABeQ"] [Sat Aug 29 05:06:23.934001 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.220.204.93:64986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/gdn.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0ogAABdk"] [Sat Aug 29 05:06:23.935279 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.197.61.180:16980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0owAABiM"] [Sat Aug 29 05:06:23.935945 2026] [core:error] [pid 1017536:tid 1017625] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.935972 2026] [core:error] [pid 1017536:tid 1017625] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.941851 2026] [security2:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/config.inc.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0pQAGNTE"] [Sat Aug 29 05:06:23.947817 2026] [security2:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/config.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0qQAGNX0"] [Sat Aug 29 05:06:23.949032 2026] [security2:error] [pid 1017536:tid 1017595] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AwgACKDo"] [Sat Aug 29 05:06:23.950018 2026] [security2:error] [pid 1017536:tid 1017562] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AwwACKBk"] [Sat Aug 29 05:06:23.950915 2026] [security2:error] [pid 1017536:tid 1017643] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AxAACKGo"] [Sat Aug 29 05:06:23.955611 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.220.204.93:59027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/elp.php"] [unique_id "apK9LyJcY4fy7tP-rU0AxgAAAoI"] [Sat Aug 29 05:06:23.959567 2026] [security2:error] [pid 1017536:tid 1017572] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AxwACKCM"] [Sat Aug 29 05:06:23.960272 2026] [security2:error] [pid 1017536:tid 1017673] [client 4.205.62.107:56032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/a1vx.php"] [unique_id "apK9LyJcY4fy7tP-rU0AyAAAAhs"] [Sat Aug 29 05:06:23.972552 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.63.81.20:41929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/atomlib.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0qwAABiA"] [Sat Aug 29 05:06:23.979819 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.158.54.35:14122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/admin.php"] [unique_id "apK9LzAh5Y1i2tUxg4H0rAAABcI"] [Sat Aug 29 05:06:23.984108 2026] [security2:error] [pid 1017536:tid 1017712] [client 68.155.159.216:12103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/content.php"] [unique_id "apK9LyJcY4fy7tP-rU0AywAAAkI"] [Sat Aug 29 05:06:23.990944 2026] [security2:error] [pid 1017536:tid 1017571] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9LyJcY4fy7tP-rU0AzQACKCI"] [Sat Aug 29 05:06:23.993392 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.993418 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.993624 2026] [core:error] [pid 1017536:tid 1017551] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.993639 2026] [core:error] [pid 1017536:tid 1017551] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.994123 2026] [core:error] [pid 1017536:tid 1017743] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.994135 2026] [core:error] [pid 1017536:tid 1017743] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:23.994135 2026] [security2:error] [pid 1017536:tid 1017564] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9LyJcY4fy7tP-rU0A0AACKBs"] [Sat Aug 29 05:06:23.999143 2026] [security2:error] [pid 1017536:tid 1017619] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9LyJcY4fy7tP-rU0A0QACKFI"] [Sat Aug 29 05:06:24.005465 2026] [security2:error] [pid 1017536:tid 1017668] [client 52.139.37.240:12891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/files/index.php"] [unique_id "apK9MCJcY4fy7tP-rU0A0gAAAhY"] [Sat Aug 29 05:06:24.021073 2026] [security2:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/env.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0sQAGNUU"] [Sat Aug 29 05:06:24.021086 2026] [security2:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/module.config.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0swAGNUc"] [Sat Aug 29 05:06:24.029271 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.23.147.79:25595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/dropdown.php"] [unique_id "apK9MCJcY4fy7tP-rU0A0wAAAmY"] [Sat Aug 29 05:06:24.031227 2026] [security2:error] [pid 1017536:tid 1017552] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9MCJcY4fy7tP-rU0A1AACUw8"] [Sat Aug 29 05:06:24.035072 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.63.81.20:60529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/ke.php"] [unique_id "apK9MCJcY4fy7tP-rU0A1gAAAkw"] [Sat Aug 29 05:06:24.041483 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.151.200.44:65507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/sadis.php"] [unique_id "apK9MCJcY4fy7tP-rU0A2AAAAk0"] [Sat Aug 29 05:06:24.044901 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.48.251.3:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/saml.php"] [unique_id "apK9MCJcY4fy7tP-rU0A2gAAAoQ"] [Sat Aug 29 05:06:24.057128 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.49.130:63437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/menu.php"] [unique_id "apK9MCJcY4fy7tP-rU0A3AAAAnc"] [Sat Aug 29 05:06:24.079848 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.196.209.81:5619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/languages/pk.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0tgAABew"] [Sat Aug 29 05:06:24.079898 2026] [security2:error] [pid 1018003:tid 1018153] [client 52.139.37.240:14500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/xmrlpc.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0twAABbo"] [Sat Aug 29 05:06:24.080016 2026] [core:error] [pid 1017536:tid 1017618] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.080033 2026] [core:error] [pid 1017536:tid 1017618] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.093604 2026] [security2:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/nexmo.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0ugAFxks"] [Sat Aug 29 05:06:24.104514 2026] [security2:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/stripe.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0vwAFxkE"] [Sat Aug 29 05:06:24.108455 2026] [security2:error] [pid 1017536:tid 1017687] [client 68.155.159.216:52801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/radio.php"] [unique_id "apK9MCJcY4fy7tP-rU0A5gAAAik"] [Sat Aug 29 05:06:24.112262 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.112278 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.112397 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.112419 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.114466 2026] [core:error] [pid 1017536:tid 1017694] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.114482 2026] [core:error] [pid 1017536:tid 1017694] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.123613 2026] [security2:error] [pid 1017536:tid 1017709] [client 52.139.37.240:30152] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.thesldiet.com"] [uri "/c99.php"] [unique_id "apK9MCJcY4fy7tP-rU0A6QAAAj8"] [Sat Aug 29 05:06:24.125933 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.125953 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.126900 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.63.81.20:46968] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/1.php"] [unique_id "apK9MCJcY4fy7tP-rU0A6gAAAhs"] [Sat Aug 29 05:06:24.126990 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.63.81.20:46968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/1.php"] [unique_id "apK9MCJcY4fy7tP-rU0A6gAAAhs"] [Sat Aug 29 05:06:24.131258 2026] [core:error] [pid 1017536:tid 1017769] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.131272 2026] [core:error] [pid 1017536:tid 1017769] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.133604 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.133619 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.139521 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.139534 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.144531 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.220.204.93:59135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/666.php"] [unique_id "apK9MCJcY4fy7tP-rU0A9AAAAlc"] [Sat Aug 29 05:06:24.150689 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.147.79:37773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/file.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0xQAABb0"] [Sat Aug 29 05:06:24.153122 2026] [core:error] [pid 1017536:tid 1017538] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.153136 2026] [core:error] [pid 1017536:tid 1017538] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.153184 2026] [core:error] [pid 1017536:tid 1017569] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.153192 2026] [core:error] [pid 1017536:tid 1017569] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.167867 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.63.81.20:60468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/tf.php"] [unique_id "apK9MCJcY4fy7tP-rU0A_QAAAh0"] [Sat Aug 29 05:06:24.176778 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.52.41.200:1771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/js/index.php"] [unique_id "apK9MCJcY4fy7tP-rU0A_wAAAiA"] [Sat Aug 29 05:06:24.180735 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.151.200.44:64912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/waw.php"] [unique_id "apK9MCJcY4fy7tP-rU0BAgAAAjE"] [Sat Aug 29 05:06:24.191877 2026] [core:error] [pid 1017536:tid 1017748] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.191896 2026] [core:error] [pid 1017536:tid 1017748] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.192075 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.151.200.44:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9MCJcY4fy7tP-rU0BBgAAAk0"] [Sat Aug 29 05:06:24.198030 2026] [core:error] [pid 1017536:tid 1017778] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.198050 2026] [core:error] [pid 1017536:tid 1017778] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.202770 2026] [core:error] [pid 1017536:tid 1017704] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.202785 2026] [core:error] [pid 1017536:tid 1017704] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.203202 2026] [core:error] [pid 1017536:tid 1017749] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.203214 2026] [core:error] [pid 1017536:tid 1017749] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.220127 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.220.204.93:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/f2.php"] [unique_id "apK9MCJcY4fy7tP-rU0BDAAAAlo"] [Sat Aug 29 05:06:24.225885 2026] [security2:error] [pid 1017536:tid 1017780] [client 52.139.37.240:12435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ihtpa.tntrental.com"] [uri "/flower.php"] [unique_id "apK9MCJcY4fy7tP-rU0BDQAAAoY"] [Sat Aug 29 05:06:24.229274 2026] [security2:error] [pid 1018003:tid 1018248] [client 168.107.94.195:52947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0zgAABhg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:24.230943 2026] [security2:error] [pid 1017536:tid 1017570] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BDgACfCE"] [Sat Aug 29 05:06:24.274596 2026] [security2:error] [pid 1017536:tid 1017610] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9MCJcY4fy7tP-rU0BFgACfEk"] [Sat Aug 29 05:06:24.274957 2026] [security2:error] [pid 1018003:tid 1018213] [client 52.139.37.240:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/about/function.php"] [unique_id "apK9MDAh5Y1i2tUxg4H00wAABfY"] [Sat Aug 29 05:06:24.275394 2026] [security2:error] [pid 1017536:tid 1017577] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9MCJcY4fy7tP-rU0BFwACfCg"] [Sat Aug 29 05:06:24.276308 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.220.204.93:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/knmt.php"] [unique_id "apK9MDAh5Y1i2tUxg4H01QAABh8"] [Sat Aug 29 05:06:24.278938 2026] [security2:error] [pid 1017536:tid 1017580] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BGAACfCs"] [Sat Aug 29 05:06:24.284907 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.151.200.44:64243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/xcre1.php"] [unique_id "apK9MDAh5Y1i2tUxg4H01gAABgc"] [Sat Aug 29 05:06:24.290009 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.63.81.20:46949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/samll.php"] [unique_id "apK9MDAh5Y1i2tUxg4H01wAABhM"] [Sat Aug 29 05:06:24.301268 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.81.20:60423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/px.php"] [unique_id "apK9MCJcY4fy7tP-rU0BHgAAAlY"] [Sat Aug 29 05:06:24.304575 2026] [security2:error] [pid 1017536:tid 1017644] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BHwACfGs"] [Sat Aug 29 05:06:24.317630 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.317647 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.319047 2026] [security2:error] [pid 1017536:tid 1017781] [client 52.139.37.240:30180] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.thesldiet.com"] [uri "/c99.php"] [unique_id "apK9MCJcY4fy7tP-rU0BIQAAAoc"] [Sat Aug 29 05:06:24.320436 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.322826 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.323957 2026] [security2:error] [pid 1017536:tid 1017673] [client 66.248.203.2:3438] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2017/12/28/theyre-on-their-way-2/"] [unique_id "apK9MCJcY4fy7tP-rU0BIgAAAhs"] [Sat Aug 29 05:06:24.340178 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.340196 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.356776 2026] [security2:error] [pid 1017536:tid 1017621] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BIwACfFQ"] [Sat Aug 29 05:06:24.356993 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.357008 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.365958 2026] [core:error] [pid 1017536:tid 1017767] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.365973 2026] [core:error] [pid 1017536:tid 1017767] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.374117 2026] [security2:error] [pid 1018003:tid 1018202] [client 68.155.159.216:51262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9MDAh5Y1i2tUxg4H06AAABes"] [Sat Aug 29 05:06:24.377172 2026] [security2:error] [pid 1017536:tid 1017705] [client 35.198.240.194:15106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.omni-staffing.com"] [uri "/secret.json"] [unique_id "apK9MCJcY4fy7tP-rU0BKAAAAjs"] [Sat Aug 29 05:06:24.379626 2026] [security2:error] [pid 1017536:tid 1017680] [client 68.155.159.216:16130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9MCJcY4fy7tP-rU0BKwAAAiI"] [Sat Aug 29 05:06:24.380206 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.151.200.44:65035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9MDAh5Y1i2tUxg4H06gAABfo"] [Sat Aug 29 05:06:24.387840 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.196.209.81:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/wp-configs.php"] [unique_id "apK9MCJcY4fy7tP-rU0BLgAAAjQ"] [Sat Aug 29 05:06:24.423967 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.220.204.93:64302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/grsiuk.php"] [unique_id "apK9MCJcY4fy7tP-rU0BMwAAAlc"] [Sat Aug 29 05:06:24.424810 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.220.204.93:59109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/sbhu.php"] [unique_id "apK9MCJcY4fy7tP-rU0BNAAAAhs"] [Sat Aug 29 05:06:24.425475 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.158.54.35:7419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/php8.php"] [unique_id "apK9MCJcY4fy7tP-rU0BNgAAAiU"] [Sat Aug 29 05:06:24.426094 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.63.81.20:46953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/she11.php"] [unique_id "apK9MCJcY4fy7tP-rU0BNwAAAi0"] [Sat Aug 29 05:06:24.443034 2026] [security2:error] [pid 1017536:tid 1017675] [client 68.155.159.216:50237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9MCJcY4fy7tP-rU0BPwAAAh0"] [Sat Aug 29 05:06:24.443907 2026] [security2:error] [pid 1017536:tid 1017722] [client 20.151.200.44:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/motu.php"] [unique_id "apK9MCJcY4fy7tP-rU0BQAAAAkw"] [Sat Aug 29 05:06:24.444813 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.63.81.20:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/jg.php"] [unique_id "apK9MDAh5Y1i2tUxg4H08QAABhQ"] [Sat Aug 29 05:06:24.451439 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.451456 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.456047 2026] [security2:error] [pid 1018003:tid 1018236] [client 35.198.240.194:15116] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9MDAh5Y1i2tUxg4H09QAABgw"] [Sat Aug 29 05:06:24.462490 2026] [security2:error] [pid 1017536:tid 1017793] [client 52.139.37.240:14494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/an.php"] [unique_id "apK9MCJcY4fy7tP-rU0BSAAAApM"] [Sat Aug 29 05:06:24.465706 2026] [security2:error] [pid 1017536:tid 1017711] [client 68.155.159.216:24470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9MCJcY4fy7tP-rU0BSwAAAkE"] [Sat Aug 29 05:06:24.467402 2026] [security2:error] [pid 1017536:tid 1017661] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/info.php"] [unique_id "apK9MCJcY4fy7tP-rU0BTwACfHw"] [Sat Aug 29 05:06:24.468908 2026] [core:error] [pid 1017536:tid 1017614] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.468925 2026] [core:error] [pid 1017536:tid 1017614] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.471440 2026] [security2:error] [pid 1017536:tid 1017743] [client 35.198.240.194:15210] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9MCJcY4fy7tP-rU0BUQAAAmE"] [Sat Aug 29 05:06:24.473075 2026] [core:error] [pid 1017536:tid 1017695] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.473090 2026] [core:error] [pid 1017536:tid 1017695] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.473453 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.196.209.81:5778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.voicexnet.com"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK9MCJcY4fy7tP-rU0BUwAAAiA"] [Sat Aug 29 05:06:24.479613 2026] [core:error] [pid 1017536:tid 1017736] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.479629 2026] [core:error] [pid 1017536:tid 1017736] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.480264 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.49.130:47832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/red.php"] [unique_id "apK9MDAh5Y1i2tUxg4H0-wAABhI"] [Sat Aug 29 05:06:24.480825 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.480844 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.481659 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.481676 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.482592 2026] [security2:error] [pid 1017536:tid 1017624] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/infophp.php"] [unique_id "apK9MCJcY4fy7tP-rU0BVwACfFc"] [Sat Aug 29 05:06:24.486428 2026] [core:error] [pid 1017536:tid 1017777] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.486448 2026] [core:error] [pid 1017536:tid 1017777] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.487795 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.487811 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.514677 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.514697 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.515882 2026] [security2:error] [pid 1017536:tid 1017638] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/infos.php"] [unique_id "apK9MCJcY4fy7tP-rU0BWwACfGU"] [Sat Aug 29 05:06:24.520236 2026] [security2:error] [pid 1017536:tid 1017689] [client 52.139.37.240:30015] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.thesldiet.com"] [uri "/c99.php"] [unique_id "apK9MCJcY4fy7tP-rU0BXAAAAis"] [Sat Aug 29 05:06:24.542939 2026] [security2:error] [pid 1017536:tid 1017680] [client 158.23.147.79:32580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9MCJcY4fy7tP-rU0BYgAAAiI"] [Sat Aug 29 05:06:24.547549 2026] [security2:error] [pid 1017536:tid 1017556] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BZAACKRM"] [Sat Aug 29 05:06:24.560516 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.104.18.15:36816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1BAAABfY"] [Sat Aug 29 05:06:24.563117 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.81.20:46850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/kerang.php"] [unique_id "apK9MCJcY4fy7tP-rU0BZwAAAlY"] [Sat Aug 29 05:06:24.563152 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.23.147.79:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/chosen.php"] [unique_id "apK9MCJcY4fy7tP-rU0BZgAAAms"] [Sat Aug 29 05:06:24.568244 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.568264 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.574641 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.574655 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.593457 2026] [security2:error] [pid 1017536:tid 1017788] [client 111.235.68.106:60537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9MCJcY4fy7tP-rU0BaQAAAo4"] [Sat Aug 29 05:06:24.593565 2026] [security2:error] [pid 1017536:tid 1017788] [client 111.235.68.106:60537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9MCJcY4fy7tP-rU0BaQAAAo4"] [Sat Aug 29 05:06:24.597304 2026] [security2:error] [pid 1017536:tid 1017622] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BagACb1U"] [Sat Aug 29 05:06:24.597885 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.81.20:60456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/yj.php"] [unique_id "apK9MCJcY4fy7tP-rU0BawAAAkc"] [Sat Aug 29 05:06:24.608072 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.23.147.79:30571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/admin.php"] [unique_id "apK9MCJcY4fy7tP-rU0BbAAAAnM"] [Sat Aug 29 05:06:24.610555 2026] [security2:error] [pid 1018003:tid 1018219] [client 4.205.62.107:22364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/mcebraed.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1DQAABfw"] [Sat Aug 29 05:06:24.610567 2026] [security2:error] [pid 1018003:tid 1018207] [client 168.107.94.195:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1DAAABfA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:24.623594 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.147.79:63852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9MCJcY4fy7tP-rU0BcAAAAmc"] [Sat Aug 29 05:06:24.625223 2026] [security2:error] [pid 1017536:tid 1017649] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BbwACY3A"] [Sat Aug 29 05:06:24.637253 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.52.41.200:1258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/core.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1DwAABiU"] [Sat Aug 29 05:06:24.643500 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.197.61.180:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/languages/index.php"] [unique_id "apK9MCJcY4fy7tP-rU0BdQAAAj8"] [Sat Aug 29 05:06:24.644461 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.220.204.93:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/a332.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1EwAABd4"] [Sat Aug 29 05:06:24.644735 2026] [security2:error] [pid 1017536:tid 1017678] [client 4.205.62.107:22492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/drykl.php"] [unique_id "apK9MCJcY4fy7tP-rU0BdgAAAiA"] [Sat Aug 29 05:06:24.644982 2026] [security2:error] [pid 1017536:tid 1017785] [client 103.162.125.59:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9MCJcY4fy7tP-rU0BdwAAAos"] [Sat Aug 29 05:06:24.645069 2026] [security2:error] [pid 1017536:tid 1017785] [client 103.162.125.59:53572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9MCJcY4fy7tP-rU0BdwAAAos"] [Sat Aug 29 05:06:24.647382 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.151.200.44:64275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/wefile.php"] [unique_id "apK9MCJcY4fy7tP-rU0BeQAAAlg"] [Sat Aug 29 05:06:24.657453 2026] [security2:error] [pid 1017536:tid 1017698] [client 52.139.37.240:14931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/asw.php"] [unique_id "apK9MCJcY4fy7tP-rU0BfAAAAjQ"] [Sat Aug 29 05:06:24.657890 2026] [core:error] [pid 1018003:tid 1018245] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.657905 2026] [core:error] [pid 1018003:tid 1018245] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.659995 2026] [core:error] [pid 1017536:tid 1017705] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.660009 2026] [core:error] [pid 1017536:tid 1017705] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.660752 2026] [security2:error] [pid 1017536:tid 1017652] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BfwACY3M"] [Sat Aug 29 05:06:24.660798 2026] [security2:error] [pid 1017536:tid 1017663] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BgAACY34"] [Sat Aug 29 05:06:24.664303 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.151.200.44:64995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/baee.php"] [unique_id "apK9MCJcY4fy7tP-rU0BgQAAAiI"] [Sat Aug 29 05:06:24.681656 2026] [security2:error] [pid 1018003:tid 1018164] [client 34.21.253.104:1054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.253.21.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.replenishink.com"] [uri "/pi.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1FgAABcU"] [Sat Aug 29 05:06:24.682440 2026] [security2:error] [pid 1017536:tid 1017673] [client 34.21.253.104:1038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.253.21.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.replenishink.com"] [uri "/i.php"] [unique_id "apK9MCJcY4fy7tP-rU0BhQAAAhs"] [Sat Aug 29 05:06:24.683620 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.220.204.93:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wp-scr1pts.php"] [unique_id "apK9MCJcY4fy7tP-rU0BhgAAAmU"] [Sat Aug 29 05:06:24.686541 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.686556 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.687285 2026] [security2:error] [pid 1017536:tid 1017654] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BgwACY3U"] [Sat Aug 29 05:06:24.688748 2026] [security2:error] [pid 1018003:tid 1018192] [client 4.205.62.107:65489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/w.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1HQAABeE"] [Sat Aug 29 05:06:24.696210 2026] [security2:error] [pid 1017536:tid 1017733] [client 158.23.147.79:49792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/x.php"] [unique_id "apK9MCJcY4fy7tP-rU0BkgAAAlc"] [Sat Aug 29 05:06:24.697631 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.697653 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.699233 2026] [security2:error] [pid 1017536:tid 1017659] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BlQACY3o"] [Sat Aug 29 05:06:24.699844 2026] [proxy_http:error] [pid 1018003:tid 1018165] (20014)Internal error (specific information not available): [client 34.21.253.104:1108] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:24.699856 2026] [proxy:error] [pid 1018003:tid 1018165] [client 34.21.253.104:1108] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env~ [Sat Aug 29 05:06:24.705251 2026] [proxy_http:error] [pid 1017536:tid 1017769] (20014)Internal error (specific information not available): [client 34.21.253.104:1088] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:24.705274 2026] [proxy:error] [pid 1017536:tid 1017769] [client 34.21.253.104:1088] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/gradle.properties [Sat Aug 29 05:06:24.710226 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.710245 2026] [core:error] [pid 1017536:tid 1017722] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.712758 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.713630 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.715082 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.18.15:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9MCJcY4fy7tP-rU0BmQAAAnk"] [Sat Aug 29 05:06:24.715396 2026] [proxy_http:error] [pid 1017536:tid 1017707] (20014)Internal error (specific information not available): [client 34.21.253.104:1106] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:24.715418 2026] [proxy:error] [pid 1017536:tid 1017707] [client 34.21.253.104:1106] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.prod [Sat Aug 29 05:06:24.716378 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.81.20:46920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/m.php"] [unique_id "apK9MCJcY4fy7tP-rU0BmgAAAkc"] [Sat Aug 29 05:06:24.719721 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.719738 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.724806 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.63.81.20:56959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/zi.php"] [unique_id "apK9MCJcY4fy7tP-rU0BmwAAAmc"] [Sat Aug 29 05:06:24.728567 2026] [proxy_http:error] [pid 1017536:tid 1017778] (20014)Internal error (specific information not available): [client 34.21.253.104:1130] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:24.728583 2026] [proxy:error] [pid 1017536:tid 1017778] [client 34.21.253.104:1130] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/_next/.env [Sat Aug 29 05:06:24.730678 2026] [core:error] [pid 1017536:tid 1017711] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.730692 2026] [core:error] [pid 1017536:tid 1017711] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.735404 2026] [security2:error] [pid 1017536:tid 1017539] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BnQACYwI"] [Sat Aug 29 05:06:24.735406 2026] [security2:error] [pid 1017536:tid 1017592] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BngACYzc"] [Sat Aug 29 05:06:24.744140 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.147.79:30715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/xmlrpc.php"] [unique_id "apK9MCJcY4fy7tP-rU0BnwAAAiA"] [Sat Aug 29 05:06:24.747372 2026] [security2:error] [pid 1017536:tid 1017632] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BoAACTl8"] [Sat Aug 29 05:06:24.779512 2026] [security2:error] [pid 1017536:tid 1017574] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BoQACMSU"] [Sat Aug 29 05:06:24.780908 2026] [security2:error] [pid 1017536:tid 1017689] [client 158.23.147.79:24401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9MCJcY4fy7tP-rU0BogAAAis"] [Sat Aug 29 05:06:24.791001 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.147.79:35765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/radio.php"] [unique_id "apK9MCJcY4fy7tP-rU0BowAAAhs"] [Sat Aug 29 05:06:24.795341 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.196.209.81:19396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/essexec.php"] [unique_id "apK9MCJcY4fy7tP-rU0BpAAAAjA"] [Sat Aug 29 05:06:24.799822 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.151.200.44:64290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/EM.php"] [unique_id "apK9MCJcY4fy7tP-rU0BpQAAAmk"] [Sat Aug 29 05:06:24.807588 2026] [security2:error] [pid 1017536:tid 1017732] [client 68.155.159.216:14084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/ans.php"] [unique_id "apK9MCJcY4fy7tP-rU0BpwAAAlY"] [Sat Aug 29 05:06:24.821680 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.220.204.93:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ws66.php"] [unique_id "apK9MCJcY4fy7tP-rU0BqAAAAlc"] [Sat Aug 29 05:06:24.837299 2026] [security2:error] [pid 1017536:tid 1017640] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BqwACU2c"] [Sat Aug 29 05:06:24.846377 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.63.81.20:46934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/fling.php"] [unique_id "apK9MCJcY4fy7tP-rU0BrgAAAo4"] [Sat Aug 29 05:06:24.848672 2026] [security2:error] [pid 1017536:tid 1017594] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BrQACUzk"] [Sat Aug 29 05:06:24.848685 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.18.15:36853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ap.php"] [unique_id "apK9MCJcY4fy7tP-rU0BrwAAApM"] [Sat Aug 29 05:06:24.858197 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.63.81.20:56912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/ue.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1MgAABdk"] [Sat Aug 29 05:06:24.862545 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.49.130:34506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/82.php"] [unique_id "apK9MCJcY4fy7tP-rU0BsAAAAnk"] [Sat Aug 29 05:06:24.870261 2026] [security2:error] [pid 1017536:tid 1017713] [client 52.139.37.240:14912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/item.php"] [unique_id "apK9MCJcY4fy7tP-rU0BtAAAAkM"] [Sat Aug 29 05:06:24.871097 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.871114 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.871851 2026] [core:error] [pid 1017536:tid 1017717] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.871863 2026] [core:error] [pid 1017536:tid 1017717] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.878187 2026] [security2:error] [pid 1017536:tid 1017546] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BtgACZwk"] [Sat Aug 29 05:06:24.880551 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.151.200.44:65053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/d12.php"] [unique_id "apK9MCJcY4fy7tP-rU0BtwAAAmY"] [Sat Aug 29 05:06:24.882998 2026] [security2:error] [pid 1017536:tid 1017620] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9MCJcY4fy7tP-rU0BuQACZ1M"] [Sat Aug 29 05:06:24.918185 2026] [security2:error] [pid 1018003:tid 1018166] [client 40.83.93.50:1637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK9MDAh5Y1i2tUxg4H1OgAABcc"] [Sat Aug 29 05:06:24.928959 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.928984 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.943557 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.943581 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.948257 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.220.204.93:64278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/num.php"] [unique_id "apK9MCJcY4fy7tP-rU0BygAAAoQ"] [Sat Aug 29 05:06:24.948560 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.948573 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.952618 2026] [core:error] [pid 1017536:tid 1017736] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.952635 2026] [core:error] [pid 1017536:tid 1017736] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.956446 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.956466 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.962095 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.151.200.44:64218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/ca4.php"] [unique_id "apK9MCJcY4fy7tP-rU0B1AAAApA"] [Sat Aug 29 05:06:24.979672 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.147.79:48205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9MCJcY4fy7tP-rU0B2AAAAnc"] [Sat Aug 29 05:06:24.985047 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.985073 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.985348 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.985364 2026] [core:error] [pid 1017536:tid 1017788] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.985375 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.985377 2026] [core:error] [pid 1017536:tid 1017788] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.986115 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.986685 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:24.988010 2026] [security2:error] [pid 1017536:tid 1017722] [client 4.205.62.107:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/config_dev.php"] [unique_id "apK9MCJcY4fy7tP-rU0B3AAAAkw"] [Sat Aug 29 05:06:24.991287 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.63.81.20:46917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/btyuio.php"] [unique_id "apK9MCJcY4fy7tP-rU0B3gAAAk0"] [Sat Aug 29 05:06:24.996765 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.220.204.93:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ws68.php"] [unique_id "apK9MCJcY4fy7tP-rU0B3wAAAoM"] [Sat Aug 29 05:06:24.999641 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.63.81.20:56913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/nv.php"] [unique_id "apK9MCJcY4fy7tP-rU0B4gAAAlM"] [Sat Aug 29 05:06:25.002025 2026] [core:error] [pid 1017536:tid 1017752] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.002045 2026] [core:error] [pid 1017536:tid 1017752] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.004736 2026] [security2:error] [pid 1018003:tid 1018236] [client 4.205.62.107:9001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/bootstrap.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1RAAABgw"] [Sat Aug 29 05:06:25.013760 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:36789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/media.php"] [unique_id "apK9MSJcY4fy7tP-rU0B5QAAAkA"] [Sat Aug 29 05:06:25.015662 2026] [security2:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/info.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1SAAF6AI"] [Sat Aug 29 05:06:25.015699 2026] [security2:error] [pid 1017536:tid 1017724] [client 168.107.94.195:53978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9MSJcY4fy7tP-rU0B5gAAAk4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:25.031776 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.151.200.44:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/x23.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1SQAABd0"] [Sat Aug 29 05:06:25.037769 2026] [security2:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/infophp.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1TAAF6HM"] [Sat Aug 29 05:06:25.038721 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.038739 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.038896 2026] [security2:error] [pid 1018003:tid 1018131] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/infos.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1TQAF6G4"] [Sat Aug 29 05:06:25.050438 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.151.200.44:65012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/yyy.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1TwAABg4"] [Sat Aug 29 05:06:25.074876 2026] [security2:error] [pid 1017536:tid 1017709] [client 52.139.37.240:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/jga.php"] [unique_id "apK9MSJcY4fy7tP-rU0B8wAAAj8"] [Sat Aug 29 05:06:25.091494 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.091511 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.091904 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.220.204.93:64337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/a4.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1VAAABc8"] [Sat Aug 29 05:06:25.096463 2026] [core:error] [pid 1017536:tid 1017790] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.096477 2026] [core:error] [pid 1017536:tid 1017790] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.103731 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.52.41.200:1786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/admin/function.php"] [unique_id "apK9MSJcY4fy7tP-rU0B-AAAAkk"] [Sat Aug 29 05:06:25.105395 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.105421 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.105703 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.105712 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.105915 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.105929 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.112577 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.112595 2026] [core:error] [pid 1017536:tid 1017683] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.118338 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.151.200.44:64950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/x0x.php"] [unique_id "apK9MSJcY4fy7tP-rU0B_AAAAh0"] [Sat Aug 29 05:06:25.119321 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.158.54.35:35235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/install.php"] [unique_id "apK9MSJcY4fy7tP-rU0B_QAAAkM"] [Sat Aug 29 05:06:25.119955 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.251.3:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/time.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1WAAABgY"] [Sat Aug 29 05:06:25.121230 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.63.81.20:44496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/dehnl.php"] [unique_id "apK9MSJcY4fy7tP-rU0B_gAAAnk"] [Sat Aug 29 05:06:25.121949 2026] [security2:error] [pid 1017536:tid 1017712] [client 4.205.62.107:56058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/public/vx.php"] [unique_id "apK9MSJcY4fy7tP-rU0B_wAAAkI"] [Sat Aug 29 05:06:25.127457 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.147.79:25437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/sad/about.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1WQAABec"] [Sat Aug 29 05:06:25.132566 2026] [core:error] [pid 1018003:tid 1018248] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.132589 2026] [core:error] [pid 1018003:tid 1018248] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.133994 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.81.20:60446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/jw.php"] [unique_id "apK9MSJcY4fy7tP-rU0CAgAAAkc"] [Sat Aug 29 05:06:25.136012 2026] [core:error] [pid 1017536:tid 1017786] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.136030 2026] [core:error] [pid 1017536:tid 1017786] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.152256 2026] [security2:error] [pid 1017536:tid 1017590] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/php-info.php"] [unique_id "apK9MSJcY4fy7tP-rU0CBQACMjU"] [Sat Aug 29 05:06:25.152455 2026] [core:error] [pid 1017536:tid 1017749] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.152473 2026] [core:error] [pid 1017536:tid 1017749] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.152949 2026] [security2:error] [pid 1017536:tid 1017589] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/php.php"] [unique_id "apK9MSJcY4fy7tP-rU0CBgACMjQ"] [Sat Aug 29 05:06:25.155043 2026] [security2:error] [pid 1017536:tid 1017561] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/php_info.php"] [unique_id "apK9MSJcY4fy7tP-rU0CBwACMhg"] [Sat Aug 29 05:06:25.155224 2026] [security2:error] [pid 1017536:tid 1017653] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/phpinfo.php"] [unique_id "apK9MSJcY4fy7tP-rU0CCAACMnQ"] [Sat Aug 29 05:06:25.177450 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.220.204.93:59083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/users.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1ZAAABdw"] [Sat Aug 29 05:06:25.184208 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.48.251.3:3344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws_settings.php"] [unique_id "apK9MSJcY4fy7tP-rU0CDQAAAlg"] [Sat Aug 29 05:06:25.188446 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.18.15:36677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/adminfuns.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1ZgAABfA"] [Sat Aug 29 05:06:25.190911 2026] [security2:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CDwACMgM"] [Sat Aug 29 05:06:25.192213 2026] [core:error] [pid 1017536:tid 1017588] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.192229 2026] [core:error] [pid 1017536:tid 1017588] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.194555 2026] [core:error] [pid 1018003:tid 1018219] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.194568 2026] [core:error] [pid 1018003:tid 1018219] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.194606 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.196.209.81:11522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/hello.php"] [unique_id "apK9MSJcY4fy7tP-rU0CEAAAAos"] [Sat Aug 29 05:06:25.204381 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.151.200.44:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/bgymj.php"] [unique_id "apK9MSJcY4fy7tP-rU0CEQAAAhc"] [Sat Aug 29 05:06:25.229122 2026] [security2:error] [pid 1017536:tid 1017732] [client 68.155.159.216:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9MSJcY4fy7tP-rU0CEgAAAlY"] [Sat Aug 29 05:06:25.243522 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.151.200.44:47419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/private.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1bAAABhU"] [Sat Aug 29 05:06:25.254791 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.251.3:13972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/doc.php"] [unique_id "apK9MSJcY4fy7tP-rU0CEwAAAo4"] [Sat Aug 29 05:06:25.256156 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.63.81.20:44493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/zoo2.php"] [unique_id "apK9MSJcY4fy7tP-rU0CFAAAAiU"] [Sat Aug 29 05:06:25.261352 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.151.200.44:64264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.familytrade.ca"] [uri "/fesa.php"] [unique_id "apK9MSJcY4fy7tP-rU0CFQAAAkM"] [Sat Aug 29 05:06:25.270164 2026] [security2:error] [pid 1017536:tid 1017694] [client 52.139.37.240:15244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/mac.php"] [unique_id "apK9MSJcY4fy7tP-rU0CFgAAAjA"] [Sat Aug 29 05:06:25.275892 2026] [security2:error] [pid 1017536:tid 1017548] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CGQACVQs"] [Sat Aug 29 05:06:25.277625 2026] [security2:error] [pid 1017536:tid 1017582] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CGwACVS0"] [Sat Aug 29 05:06:25.279888 2026] [core:error] [pid 1017536:tid 1017603] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.279906 2026] [core:error] [pid 1017536:tid 1017603] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.300730 2026] [security2:error] [pid 1017536:tid 1017541] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CIAACVQQ"] [Sat Aug 29 05:06:25.304139 2026] [security2:error] [pid 1017536:tid 1017567] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CIgACVR4"] [Sat Aug 29 05:06:25.308407 2026] [security2:error] [pid 1017536:tid 1017562] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CJwACVRk"] [Sat Aug 29 05:06:25.308420 2026] [security2:error] [pid 1017536:tid 1017595] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CJgACVTo"] [Sat Aug 29 05:06:25.313111 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.251.3:61202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-konfig.backup.php"] [unique_id "apK9MSJcY4fy7tP-rU0CKgAAAk0"] [Sat Aug 29 05:06:25.314223 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.314240 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.321567 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.220.204.93:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/bzjdlofz.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1dAAABi8"] [Sat Aug 29 05:06:25.323146 2026] [core:error] [pid 1017536:tid 1017691] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.323162 2026] [core:error] [pid 1017536:tid 1017691] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.342862 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:36686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/classwithtostring.php"] [unique_id "apK9MSJcY4fy7tP-rU0CMQAAAkA"] [Sat Aug 29 05:06:25.344497 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.344512 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.347215 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.347232 2026] [core:error] [pid 1017536:tid 1017770] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.347832 2026] [security2:error] [pid 1017536:tid 1017698] [client 103.168.67.159:57718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9MSJcY4fy7tP-rU0CNQAAAjQ"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:06:25.347965 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.347977 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.367334 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.197.61.180:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/languages/min.php"] [unique_id "apK9MSJcY4fy7tP-rU0COAAAAmQ"] [Sat Aug 29 05:06:25.384708 2026] [security2:error] [pid 1017536:tid 1017551] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CPAACMg4"] [Sat Aug 29 05:06:25.385853 2026] [security2:error] [pid 1017536:tid 1017587] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/public/phpinfo.php"] [unique_id "apK9MSJcY4fy7tP-rU0CPgACMjI"] [Sat Aug 29 05:06:25.386616 2026] [core:error] [pid 1017536:tid 1017571] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.386634 2026] [core:error] [pid 1017536:tid 1017571] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.395245 2026] [security2:error] [pid 1018003:tid 1018216] [client 168.107.94.195:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1fwAABfk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:25.400644 2026] [security2:error] [pid 1017536:tid 1017719] [client 40.83.93.50:1624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/options-general.php"] [unique_id "apK9MSJcY4fy7tP-rU0CQQAAAkk"] [Sat Aug 29 05:06:25.401689 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.251.3:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/classsmtps.php"] [unique_id "apK9MSJcY4fy7tP-rU0CQgAAAig"] [Sat Aug 29 05:06:25.417248 2026] [core:error] [pid 1018003:tid 1018193] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.417270 2026] [core:error] [pid 1018003:tid 1018193] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.446001 2026] [security2:error] [pid 1017536:tid 1017765] [client 68.155.159.216:33682] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/1.php"] [unique_id "apK9MSJcY4fy7tP-rU0CRgAAAnc"] [Sat Aug 29 05:06:25.446115 2026] [security2:error] [pid 1017536:tid 1017765] [client 68.155.159.216:33682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/1.php"] [unique_id "apK9MSJcY4fy7tP-rU0CRgAAAnc"] [Sat Aug 29 05:06:25.449160 2026] [security2:error] [pid 1017536:tid 1017552] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CRwACTQ8"] [Sat Aug 29 05:06:25.453666 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.251.3:61211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/packed.php"] [unique_id "apK9MSJcY4fy7tP-rU0CSgAAAis"] [Sat Aug 29 05:06:25.456203 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.151.200.44:64970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/fh26.php"] [unique_id "apK9MSJcY4fy7tP-rU0CSwAAAoM"] [Sat Aug 29 05:06:25.471365 2026] [security2:error] [pid 1017536:tid 1017753] [client 52.139.37.240:14933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9MSJcY4fy7tP-rU0CTwAAAms"] [Sat Aug 29 05:06:25.486181 2026] [security2:error] [pid 1017536:tid 1017769] [client 68.155.159.216:16312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/classwithtostring.php"] [unique_id "apK9MSJcY4fy7tP-rU0CVwAAAns"] [Sat Aug 29 05:06:25.491836 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.491858 2026] [core:error] [pid 1017536:tid 1017724] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.493835 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.104.18.15:36764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK9MSJcY4fy7tP-rU0CWgAAAnw"] [Sat Aug 29 05:06:25.496046 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.496062 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.501877 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.151.200.44:64923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/ws66.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1igAABcw"] [Sat Aug 29 05:06:25.514103 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.220.204.93:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/selesai.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1jgAABdU"] [Sat Aug 29 05:06:25.516477 2026] [core:error] [pid 1017536:tid 1017785] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.516498 2026] [core:error] [pid 1017536:tid 1017785] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.519213 2026] [core:error] [pid 1017536:tid 1017673] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.519234 2026] [core:error] [pid 1017536:tid 1017673] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.519236 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.519248 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.519537 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.519547 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.522218 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.522232 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.529722 2026] [core:error] [pid 1017536:tid 1017749] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.529737 2026] [core:error] [pid 1017536:tid 1017749] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.531813 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.220.204.93:63822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/tfm.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1kwAABcQ"] [Sat Aug 29 05:06:25.534846 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.251.3:13963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/cache-compat.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1lAAABds"] [Sat Aug 29 05:06:25.535966 2026] [core:error] [pid 1017536:tid 1017705] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.535978 2026] [core:error] [pid 1017536:tid 1017705] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.548494 2026] [core:error] [pid 1017536:tid 1017792] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.548514 2026] [core:error] [pid 1017536:tid 1017792] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.551421 2026] [core:error] [pid 1017536:tid 1017698] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.551436 2026] [core:error] [pid 1017536:tid 1017698] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.564656 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.52.41.200:1227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/admin/index.php"] [unique_id "apK9MSJcY4fy7tP-rU0CcAAAAjw"] [Sat Aug 29 05:06:25.567641 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.158.54.35:11340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/ioxi-o.php"] [unique_id "apK9MSJcY4fy7tP-rU0CcQAAAoY"] [Sat Aug 29 05:06:25.569750 2026] [security2:error] [pid 1018003:tid 1018153] [client 68.155.159.216:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1mQAABbo"] [Sat Aug 29 05:06:25.577293 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.577310 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.582347 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.48.251.3:3345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-info.php"] [unique_id "apK9MSJcY4fy7tP-rU0CdAAAAkE"] [Sat Aug 29 05:06:25.594938 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.594959 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.595263 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.595274 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.603375 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.196.209.81:19443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/fi2.php"] [unique_id "apK9MSJcY4fy7tP-rU0CdQAAAoc"] [Sat Aug 29 05:06:25.617698 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.617717 2026] [core:error] [pid 1017536:tid 1017687] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.649595 2026] [security2:error] [pid 1017536:tid 1017737] [client 158.23.147.79:32661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9MSJcY4fy7tP-rU0CegAAAls"] [Sat Aug 29 05:06:25.652617 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.18.15:36792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK9MSJcY4fy7tP-rU0CfAAAAiU"] [Sat Aug 29 05:06:25.669900 2026] [security2:error] [pid 1017536:tid 1017686] [client 52.139.37.240:14918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9MSJcY4fy7tP-rU0CfwAAAig"] [Sat Aug 29 05:06:25.676727 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.251.3:14064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/aws_keys.php"] [unique_id "apK9MSJcY4fy7tP-rU0ChgAAAnc"] [Sat Aug 29 05:06:25.682518 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.220.204.93:59123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/shlo.php"] [unique_id "apK9MSJcY4fy7tP-rU0CigAAAoI"] [Sat Aug 29 05:06:25.683388 2026] [security2:error] [pid 1018003:tid 1018198] [client 68.155.159.216:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/index.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1owAABec"] [Sat Aug 29 05:06:25.690926 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.151.200.44:64401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/fgd.php"] [unique_id "apK9MSJcY4fy7tP-rU0CjwAAAmo"] [Sat Aug 29 05:06:25.710012 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.710030 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.712396 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.48.251.3:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/fns.php"] [unique_id "apK9MSJcY4fy7tP-rU0ClQAAAkk"] [Sat Aug 29 05:06:25.724130 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.724335 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.726234 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.726246 2026] [core:error] [pid 1017536:tid 1017672] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.731999 2026] [core:error] [pid 1017536:tid 1017706] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.732031 2026] [core:error] [pid 1017536:tid 1017706] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.738471 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.147.79:30468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/atomlib.php"] [unique_id "apK9MSJcY4fy7tP-rU0CnAAAAow"] [Sat Aug 29 05:06:25.742570 2026] [core:error] [pid 1018003:tid 1018152] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.742590 2026] [core:error] [pid 1018003:tid 1018152] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.742772 2026] [core:error] [pid 1017536:tid 1017778] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.742785 2026] [core:error] [pid 1017536:tid 1017778] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.743632 2026] [core:error] [pid 1017536:tid 1017733] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.743644 2026] [core:error] [pid 1017536:tid 1017733] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.743795 2026] [core:error] [pid 1017536:tid 1017674] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.743806 2026] [core:error] [pid 1017536:tid 1017674] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.749553 2026] [security2:error] [pid 1017536:tid 1017793] [client 4.205.62.107:22249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/verox.php"] [unique_id "apK9MSJcY4fy7tP-rU0CoQAAApM"] [Sat Aug 29 05:06:25.757361 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.23.147.79:26565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/goods.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1rgAABdw"] [Sat Aug 29 05:06:25.764993 2026] [core:error] [pid 1018003:tid 1018261] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.765011 2026] [core:error] [pid 1018003:tid 1018261] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.765712 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.765723 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.766038 2026] [security2:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/php-info.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1tAAGHHE"] [Sat Aug 29 05:06:25.766072 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.766080 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.768252 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.768264 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.773840 2026] [security2:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/php.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1tQAGHDg"] [Sat Aug 29 05:06:25.776346 2026] [security2:error] [pid 1018003:tid 1018266] [client 168.107.94.195:54560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1tgAABio"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:25.787522 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.147.79:63854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1twAABgo"] [Sat Aug 29 05:06:25.792144 2026] [core:error] [pid 1018003:tid 1018249] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.792161 2026] [core:error] [pid 1018003:tid 1018249] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.792282 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.792291 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.792420 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.792433 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.792739 2026] [security2:error] [pid 1018003:tid 1018081] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/php_info.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1uwAGHDw"] [Sat Aug 29 05:06:25.796134 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.151.200.44:64205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/Cok.php"] [unique_id "apK9MSJcY4fy7tP-rU0CpwAAApI"] [Sat Aug 29 05:06:25.799047 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.799062 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.801659 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.151.200.44:46605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/lfi.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1vgAABc0"] [Sat Aug 29 05:06:25.808487 2026] [security2:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/phpinfo.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1wAAGHCo"] [Sat Aug 29 05:06:25.812042 2026] [security2:error] [pid 1018003:tid 1018212] [client 4.205.62.107:22215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/aws.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1wQAABfU"] [Sat Aug 29 05:06:25.820242 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.48.251.3:14304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/umgebung.php"] [unique_id "apK9MSJcY4fy7tP-rU0CqgAAAn8"] [Sat Aug 29 05:06:25.821540 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.104.18.15:36850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK9MSJcY4fy7tP-rU0CqwAAAho"] [Sat Aug 29 05:06:25.835643 2026] [security2:error] [pid 1018003:tid 1018171] [client 158.23.147.79:37764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/file17.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1xwAABcw"] [Sat Aug 29 05:06:25.841868 2026] [security2:error] [pid 1018003:tid 1018271] [client 4.205.62.107:65438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/btx25.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1yAAABi8"] [Sat Aug 29 05:06:25.850460 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.48.251.3:61246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/params.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1ygAABdU"] [Sat Aug 29 05:06:25.871995 2026] [security2:error] [pid 1017536:tid 1017724] [client 40.83.93.50:1612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/options.php"] [unique_id "apK9MSJcY4fy7tP-rU0CrQAAAk4"] [Sat Aug 29 05:06:25.875043 2026] [security2:error] [pid 1017536:tid 1017628] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9MSJcY4fy7tP-rU0CrgACXls"] [Sat Aug 29 05:06:25.876714 2026] [security2:error] [pid 1018003:tid 1018275] [client 52.139.37.240:14945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/zafir1.php"] [unique_id "apK9MTAh5Y1i2tUxg4H1zgAABjM"] [Sat Aug 29 05:06:25.892799 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.147.79:35819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9MSJcY4fy7tP-rU0CsAAAAh0"] [Sat Aug 29 05:06:25.917780 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.23.147.79:50140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9MSJcY4fy7tP-rU0CtgAAApM"] [Sat Aug 29 05:06:25.923674 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.220.204.93:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/asax.php"] [unique_id "apK9MSJcY4fy7tP-rU0CtwAAAik"] [Sat Aug 29 05:06:25.942562 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.220.204.93:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/Geforce.php"] [unique_id "apK9MSJcY4fy7tP-rU0CvQAAAkI"] [Sat Aug 29 05:06:25.944175 2026] [security2:error] [pid 1017536:tid 1017673] [client 68.155.159.216:14144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/worksec.php"] [unique_id "apK9MSJcY4fy7tP-rU0CvAAAAhs"] [Sat Aug 29 05:06:25.953610 2026] [security2:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/public/phpinfo.php"] [unique_id "apK9MTAh5Y1i2tUxg4H13gAF-ls"] [Sat Aug 29 05:06:25.955191 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.250.41:25573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9MSJcY4fy7tP-rU0CwwAAAkM"] [Sat Aug 29 05:06:25.956284 2026] [core:error] [pid 1017536:tid 1017547] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.956300 2026] [core:error] [pid 1017536:tid 1017547] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.958185 2026] [security2:error] [pid 1017536:tid 1017584] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CxQACVy8"] [Sat Aug 29 05:06:25.969876 2026] [core:error] [pid 1017536:tid 1017622] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.969890 2026] [core:error] [pid 1017536:tid 1017622] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.973128 2026] [security2:error] [pid 1017536:tid 1017649] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CxwACV3A"] [Sat Aug 29 05:06:25.973141 2026] [security2:error] [pid 1017536:tid 1017663] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9MSJcY4fy7tP-rU0CyAACV34"] [Sat Aug 29 05:06:25.975855 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.23.147.79:30538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/lv.php"] [unique_id "apK9MTAh5Y1i2tUxg4H14AAABcM"] [Sat Aug 29 05:06:25.978176 2026] [core:error] [pid 1017536:tid 1017652] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.978193 2026] [core:error] [pid 1017536:tid 1017652] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.978810 2026] [core:error] [pid 1017536:tid 1017757] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.978824 2026] [core:error] [pid 1017536:tid 1017757] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.979118 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.979129 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.980697 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.48.251.3:61240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/gjm.php"] [unique_id "apK9MTAh5Y1i2tUxg4H15AAABhA"] [Sat Aug 29 05:06:25.980719 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.980730 2026] [core:error] [pid 1017536:tid 1017689] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.980934 2026] [core:error] [pid 1017536:tid 1017747] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.980945 2026] [core:error] [pid 1017536:tid 1017747] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.981753 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.981766 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.982371 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.982385 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.983506 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.983521 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.983591 2026] [core:error] [pid 1017536:tid 1017737] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.983600 2026] [core:error] [pid 1017536:tid 1017737] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.984937 2026] [core:error] [pid 1017536:tid 1017553] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.984946 2026] [core:error] [pid 1017536:tid 1017553] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:25.986947 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.18.15:36684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wsd.php"] [unique_id "apK9MTAh5Y1i2tUxg4H15QAABhY"] [Sat Aug 29 05:06:26.008141 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.52.41.200:1226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/storage/rip.php"] [unique_id "apK9MiJcY4fy7tP-rU0C0AAAApA"] [Sat Aug 29 05:06:26.017424 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.158.54.35:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/xmlrpc.php"] [unique_id "apK9MiJcY4fy7tP-rU0C0QAAAow"] [Sat Aug 29 05:06:26.036289 2026] [core:error] [pid 1017536:tid 1017641] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.036313 2026] [core:error] [pid 1017536:tid 1017641] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.037169 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.196.209.81:11537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/1p.php"] [unique_id "apK9MiJcY4fy7tP-rU0C0wAAAoQ"] [Sat Aug 29 05:06:26.055552 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.18.15:36847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apK9MiJcY4fy7tP-rU0C1AAAAlo"] [Sat Aug 29 05:06:26.065704 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.151.200.44:64400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/inject.php"] [unique_id "apK9MjAh5Y1i2tUxg4H16gAABgM"] [Sat Aug 29 05:06:26.070378 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.104.18.15:23397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-admin/w.php"] [unique_id "apK9MiJcY4fy7tP-rU0C1QAAAnw"] [Sat Aug 29 05:06:26.079304 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.147.79:48342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/dropdown.php"] [unique_id "apK9MiJcY4fy7tP-rU0C1gAAAmE"] [Sat Aug 29 05:06:26.080230 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.197.61.180:5702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/languages/pk.php"] [unique_id "apK9MjAh5Y1i2tUxg4H16wAABeM"] [Sat Aug 29 05:06:26.080325 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.49.130:55133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9MiJcY4fy7tP-rU0C1wAAAnM"] [Sat Aug 29 05:06:26.087174 2026] [security2:error] [pid 1017536:tid 1017752] [client 52.139.37.240:15285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/abc.php"] [unique_id "apK9MiJcY4fy7tP-rU0C2AAAAmo"] [Sat Aug 29 05:06:26.090233 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.18.15:13213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/gos.php"] [unique_id "apK9MiJcY4fy7tP-rU0C2gAAAn8"] [Sat Aug 29 05:06:26.106582 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.104.18.15:7098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/ta.php"] [unique_id "apK9MjAh5Y1i2tUxg4H18AAABgY"] [Sat Aug 29 05:06:26.112955 2026] [core:error] [pid 1017536:tid 1017654] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.112972 2026] [core:error] [pid 1017536:tid 1017654] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.118778 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.220.204.93:64939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/click.php"] [unique_id "apK9MjAh5Y1i2tUxg4H18QAABfY"] [Sat Aug 29 05:06:26.122585 2026] [core:error] [pid 1017536:tid 1017636] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.122604 2026] [core:error] [pid 1017536:tid 1017636] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.129970 2026] [security2:error] [pid 1017536:tid 1017734] [client 4.205.62.107:22346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/aws_credentials.php"] [unique_id "apK9MiJcY4fy7tP-rU0C4AAAAlg"] [Sat Aug 29 05:06:26.136970 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.18.15:36610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/bulet.php"] [unique_id "apK9MiJcY4fy7tP-rU0C5wAAAhs"] [Sat Aug 29 05:06:26.137002 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.48.250.41:25418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9MiJcY4fy7tP-rU0C5gAAAnk"] [Sat Aug 29 05:06:26.138998 2026] [core:error] [pid 1017536:tid 1017576] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.139014 2026] [core:error] [pid 1017536:tid 1017576] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.141269 2026] [security2:error] [pid 1017536:tid 1017617] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9MiJcY4fy7tP-rU0C6AACQlA"] [Sat Aug 29 05:06:26.142864 2026] [security2:error] [pid 1017536:tid 1017749] [client 68.155.159.216:12216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/css/index.php"] [unique_id "apK9MiJcY4fy7tP-rU0C7AAAAmc"] [Sat Aug 29 05:06:26.144708 2026] [security2:error] [pid 1017536:tid 1017539] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9MiJcY4fy7tP-rU0C6gACQgI"] [Sat Aug 29 05:06:26.148082 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.220.204.93:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/fetch.php"] [unique_id "apK9MjAh5Y1i2tUxg4H19QAABdI"] [Sat Aug 29 05:06:26.148858 2026] [core:error] [pid 1017536:tid 1017632] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.148873 2026] [core:error] [pid 1017536:tid 1017632] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.151844 2026] [security2:error] [pid 1018003:tid 1018187] [client 4.205.62.107:53359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wo.php"] [unique_id "apK9MjAh5Y1i2tUxg4H19gAABdw"] [Sat Aug 29 05:06:26.156647 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:8012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wnnjpsby.php"] [unique_id "apK9MiJcY4fy7tP-rU0C9wAAAkA"] [Sat Aug 29 05:06:26.157231 2026] [security2:error] [pid 1018003:tid 1018200] [client 168.107.94.195:54898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9MjAh5Y1i2tUxg4H1-AAABek"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:26.177432 2026] [core:error] [pid 1017536:tid 1017691] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.177448 2026] [core:error] [pid 1017536:tid 1017691] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.181795 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.181811 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.188283 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.188304 2026] [core:error] [pid 1017536:tid 1017686] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.188964 2026] [security2:error] [pid 1017536:tid 1017594] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9MiJcY4fy7tP-rU0C-gACQjk"] [Sat Aug 29 05:06:26.189642 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.49.130:43603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/1xmomo.php"] [unique_id "apK9MiJcY4fy7tP-rU0C-wAAAmk"] [Sat Aug 29 05:06:26.206677 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.206699 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.207898 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.207918 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.208556 2026] [core:error] [pid 1017536:tid 1017733] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.208573 2026] [core:error] [pid 1017536:tid 1017733] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.209693 2026] [core:error] [pid 1017536:tid 1017709] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.209709 2026] [core:error] [pid 1017536:tid 1017709] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.210474 2026] [core:error] [pid 1017536:tid 1017705] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.210489 2026] [core:error] [pid 1017536:tid 1017705] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.211057 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.18.15:23445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-content/k.php"] [unique_id "apK9MjAh5Y1i2tUxg4H1_wAABio"] [Sat Aug 29 05:06:26.212193 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.212205 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.228920 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.151.200.44:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/X7T6.php"] [unique_id "apK9MiJcY4fy7tP-rU0DAAAAAmY"] [Sat Aug 29 05:06:26.233305 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.104.18.15:13146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/132.php"] [unique_id "apK9MiJcY4fy7tP-rU0DAQAAAmE"] [Sat Aug 29 05:06:26.235058 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:25481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/admin.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2BQAABb4"] [Sat Aug 29 05:06:26.235494 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:36745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/sao.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2BgAABeE"] [Sat Aug 29 05:06:26.235953 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:7149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/bo.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2BwAABi4"] [Sat Aug 29 05:06:26.264314 2026] [security2:error] [pid 1017536:tid 1017629] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DAgACf1w"] [Sat Aug 29 05:06:26.276509 2026] [security2:error] [pid 1018003:tid 1018231] [client 4.205.62.107:56063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/log.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2CQAABgc"] [Sat Aug 29 05:06:26.277523 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.63.81.20:60428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/or.php"] [unique_id "apK9MiJcY4fy7tP-rU0DBgAAAoc"] [Sat Aug 29 05:06:26.282576 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.220.204.93:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/vx.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2CwAABfk"] [Sat Aug 29 05:06:26.284245 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.18.15:8172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/gigi.php"] [unique_id "apK9MiJcY4fy7tP-rU0DCAAAAlg"] [Sat Aug 29 05:06:26.284276 2026] [security2:error] [pid 1017536:tid 1017778] [client 52.139.37.240:14932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/c1.php"] [unique_id "apK9MiJcY4fy7tP-rU0DBwAAAoQ"] [Sat Aug 29 05:06:26.284974 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.151.200.44:47319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/quoys.php"] [unique_id "apK9MiJcY4fy7tP-rU0DCQAAApM"] [Sat Aug 29 05:06:26.306962 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.306984 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.309088 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.18.15:36768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/av.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2EAAABi8"] [Sat Aug 29 05:06:26.318273 2026] [core:error] [pid 1018003:tid 1018222] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.318290 2026] [core:error] [pid 1018003:tid 1018222] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.320590 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.320607 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.324881 2026] [core:error] [pid 1017536:tid 1017717] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.324897 2026] [core:error] [pid 1017536:tid 1017717] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.343924 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.250.41:25346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ff1.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2FgAABcM"] [Sat Aug 29 05:06:26.347567 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.18.15:23519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/os.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2FwAABe8"] [Sat Aug 29 05:06:26.361274 2026] [security2:error] [pid 1018003:tid 1018218] [client 40.83.93.50:1605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/panel.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2GgAABfs"] [Sat Aug 29 05:06:26.366063 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.366084 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.367827 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.18.15:6999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/44.php"] [unique_id "apK9MiJcY4fy7tP-rU0DGAAAAoY"] [Sat Aug 29 05:06:26.375879 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:9243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/makeasmtp.php"] [unique_id "apK9MiJcY4fy7tP-rU0DGQAAAjo"] [Sat Aug 29 05:06:26.377328 2026] [security2:error] [pid 1017536:tid 1017674] [client 136.107.231.130:5866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/home/ubuntu/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DGgAAAhw"] [Sat Aug 29 05:06:26.380718 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.18.15:13256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/v22.php"] [unique_id "apK9MiJcY4fy7tP-rU0DGwAAAjI"] [Sat Aug 29 05:06:26.384005 2026] [security2:error] [pid 1017536:tid 1017542] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DHAACHQU"] [Sat Aug 29 05:06:26.384694 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.49.130:52513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/worksec.php"] [unique_id "apK9MiJcY4fy7tP-rU0DHgAAAj8"] [Sat Aug 29 05:06:26.385544 2026] [core:error] [pid 1017536:tid 1017544] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.385554 2026] [core:error] [pid 1017536:tid 1017544] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.388950 2026] [core:error] [pid 1017536:tid 1017607] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.388963 2026] [core:error] [pid 1017536:tid 1017607] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.394536 2026] [core:error] [pid 1017536:tid 1017579] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.394550 2026] [core:error] [pid 1017536:tid 1017579] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.396287 2026] [core:error] [pid 1017536:tid 1017662] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.396298 2026] [core:error] [pid 1017536:tid 1017662] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.396465 2026] [core:error] [pid 1017536:tid 1017650] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.396479 2026] [core:error] [pid 1017536:tid 1017650] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.397125 2026] [core:error] [pid 1017536:tid 1017581] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.397135 2026] [core:error] [pid 1017536:tid 1017581] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.406312 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.18.15:36748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/dapa.php"] [unique_id "apK9MiJcY4fy7tP-rU0DJQAAAjs"] [Sat Aug 29 05:06:26.408258 2026] [security2:error] [pid 1017536:tid 1017719] [client 136.107.231.130:5808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/var/www/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DJgAAAkk"] [Sat Aug 29 05:06:26.410178 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.63.81.20:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/ile56.php"] [unique_id "apK9MiJcY4fy7tP-rU0DKQAAAiM"] [Sat Aug 29 05:06:26.410818 2026] [security2:error] [pid 1018003:tid 1018277] [client 136.107.231.130:5910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/var/www/html/.env"] [unique_id "apK9MjAh5Y1i2tUxg4H2JwAABjU"] [Sat Aug 29 05:06:26.413967 2026] [security2:error] [pid 1018003:tid 1018238] [client 136.107.231.130:5918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/usr/src/app/.env"] [unique_id "apK9MjAh5Y1i2tUxg4H2KgAABg4"] [Sat Aug 29 05:06:26.414595 2026] [core:error] [pid 1017536:tid 1017635] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.414610 2026] [core:error] [pid 1017536:tid 1017635] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.418672 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.63.81.20:46853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/zoo1.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2LQAABiI"] [Sat Aug 29 05:06:26.421118 2026] [core:error] [pid 1017536:tid 1017655] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.421132 2026] [core:error] [pid 1017536:tid 1017655] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.422145 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.422158 2026] [core:error] [pid 1017536:tid 1017606] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.422937 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.151.200.44:65043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/mga.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2LwAABcg"] [Sat Aug 29 05:06:26.432104 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.151.200.44:47337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/vbbn.php"] [unique_id "apK9MiJcY4fy7tP-rU0DLgAAAjE"] [Sat Aug 29 05:06:26.446778 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.18.15:8120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/info.php/new.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2MwAABco"] [Sat Aug 29 05:06:26.456925 2026] [core:error] [pid 1017536:tid 1017707] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.456943 2026] [core:error] [pid 1017536:tid 1017707] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.458434 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.52.41.200:1201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/zoom1.php"] [unique_id "apK9MiJcY4fy7tP-rU0DMwAAAhs"] [Sat Aug 29 05:06:26.463077 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.151.200.44:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/see.php"] [unique_id "apK9MiJcY4fy7tP-rU0DNQAAAn8"] [Sat Aug 29 05:06:26.468185 2026] [core:error] [pid 1017536:tid 1017602] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.468204 2026] [core:error] [pid 1017536:tid 1017602] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.469665 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.196.209.81:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/Njima.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2NQAABdU"] [Sat Aug 29 05:06:26.472347 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.104.18.15:36779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/images.php"] [unique_id "apK9MiJcY4fy7tP-rU0DNwAAAmc"] [Sat Aug 29 05:06:26.472918 2026] [security2:error] [pid 1018003:tid 1018166] [client 158.158.54.35:2822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/filemanager.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2NgAABcc"] [Sat Aug 29 05:06:26.480632 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.49.130:29995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/x1da.php"] [unique_id "apK9MiJcY4fy7tP-rU0DOAAAAis"] [Sat Aug 29 05:06:26.480645 2026] [security2:error] [pid 1017536:tid 1017747] [client 20.104.18.15:23520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/htio.php"] [unique_id "apK9MiJcY4fy7tP-rU0DOQAAAmU"] [Sat Aug 29 05:06:26.484301 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.220.204.93:59066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/global.php"] [unique_id "apK9MiJcY4fy7tP-rU0DOgAAAkc"] [Sat Aug 29 05:06:26.490669 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.250.41:25443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/t.php"] [unique_id "apK9MiJcY4fy7tP-rU0DOwAAAmQ"] [Sat Aug 29 05:06:26.507944 2026] [security2:error] [pid 1017536:tid 1017712] [client 52.139.37.240:15258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/index.php/feed/atom/"] [unique_id "apK9MiJcY4fy7tP-rU0DPAAAAkI"] [Sat Aug 29 05:06:26.522520 2026] [security2:error] [pid 1017536:tid 1017616] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DPgACXk8"] [Sat Aug 29 05:06:26.522634 2026] [security2:error] [pid 1017536:tid 1017639] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DPQACXmY"] [Sat Aug 29 05:06:26.527206 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.104.18.15:6939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/h2.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2OgAABeM"] [Sat Aug 29 05:06:26.539746 2026] [security2:error] [pid 1017536:tid 1017724] [client 168.107.94.195:55265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9MiJcY4fy7tP-rU0DPwAAAk4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:26.541667 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.220.204.93:64979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ms.php"] [unique_id "apK9MiJcY4fy7tP-rU0DQAAAAoI"] [Sat Aug 29 05:06:26.542631 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.63.81.20:60541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/emmh.php"] [unique_id "apK9MiJcY4fy7tP-rU0DQQAAAlc"] [Sat Aug 29 05:06:26.554556 2026] [security2:error] [pid 1017536:tid 1017709] [client 68.155.159.216:50273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/index.php"] [unique_id "apK9MiJcY4fy7tP-rU0DQgAAAj8"] [Sat Aug 29 05:06:26.561998 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:36778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-content/l.php"] [unique_id "apK9MiJcY4fy7tP-rU0DQwAAAh0"] [Sat Aug 29 05:06:26.572284 2026] [security2:error] [pid 1017536:tid 1017573] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DRQACGiQ"] [Sat Aug 29 05:06:26.579304 2026] [security2:error] [pid 1018003:tid 1018226] [client 5.161.117.52:56050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ridetime.com"] [uri "/"] [unique_id "apK9MjAh5Y1i2tUxg4H2QAAABgM"], referer: https://ridetime.com [Sat Aug 29 05:06:26.590475 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.18.15:13121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-activate.php"] [unique_id "apK9MiJcY4fy7tP-rU0DSwAAAiM"] [Sat Aug 29 05:06:26.592335 2026] [core:error] [pid 1017536:tid 1017561] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.592350 2026] [core:error] [pid 1017536:tid 1017561] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.593442 2026] [core:error] [pid 1017536:tid 1017590] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.593461 2026] [core:error] [pid 1017536:tid 1017590] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.594620 2026] [security2:error] [pid 1017536:tid 1017582] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DUwACiy0"] [Sat Aug 29 05:06:26.595105 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.63.81.20:44484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/radio.php"] [unique_id "apK9MiJcY4fy7tP-rU0DVAAAAls"] [Sat Aug 29 05:06:26.597150 2026] [core:error] [pid 1017536:tid 1017589] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.597165 2026] [core:error] [pid 1017536:tid 1017589] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.597650 2026] [core:error] [pid 1017536:tid 1017561] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.597661 2026] [core:error] [pid 1017536:tid 1017561] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.598320 2026] [core:error] [pid 1017536:tid 1017588] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.598331 2026] [core:error] [pid 1017536:tid 1017588] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.598631 2026] [core:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.598645 2026] [core:error] [pid 1017536:tid 1017540] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.599076 2026] [core:error] [pid 1017536:tid 1017653] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.599085 2026] [core:error] [pid 1017536:tid 1017653] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.599807 2026] [core:error] [pid 1017536:tid 1017601] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.599818 2026] [core:error] [pid 1017536:tid 1017601] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.612939 2026] [security2:error] [pid 1018003:tid 1018213] [client 68.155.159.216:49185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2RAAABfY"] [Sat Aug 29 05:06:26.613461 2026] [autoindex:error] [pid 1017536:tid 1017719] [client 20.104.18.15:0] AH01276: Cannot serve directory /home1/abmaccom/public_html/website_6571184f/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:26.617032 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.104.18.15:36710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ops.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2RgAABjQ"] [Sat Aug 29 05:06:26.627958 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.627976 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.628438 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.151.200.44:65032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/inwp.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2SgAABes"] [Sat Aug 29 05:06:26.629492 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.629510 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.642899 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.220.204.93:59029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/fs.php"] [unique_id "apK9MiJcY4fy7tP-rU0DWQAAAlY"] [Sat Aug 29 05:06:26.651815 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.18.15:23457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/dev.php"] [unique_id "apK9MiJcY4fy7tP-rU0DWwAAAiI"] [Sat Aug 29 05:06:26.652602 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.151.200.44:64886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/horeg.php"] [unique_id "apK9MiJcY4fy7tP-rU0DXAAAAoc"] [Sat Aug 29 05:06:26.667999 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.18.15:6978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apK9MiJcY4fy7tP-rU0DXQAAApM"] [Sat Aug 29 05:06:26.669967 2026] [security2:error] [pid 1018003:tid 1018249] [client 20.48.250.41:25519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/erty.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2UAAABhk"] [Sat Aug 29 05:06:26.677268 2026] [security2:error] [pid 1018003:tid 1018152] [client 68.155.159.216:24476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/radio.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2VQAABbk"] [Sat Aug 29 05:06:26.678142 2026] [security2:error] [pid 1018003:tid 1018234] [client 57.141.14.105:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK9MjAh5Y1i2tUxg4H2UwAABgo"] [Sat Aug 29 05:06:26.683714 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.220.204.93:64315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/zxekqlxb.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2VgAABiM"] [Sat Aug 29 05:06:26.685115 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.63.81.20:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/em.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2VwAABfw"] [Sat Aug 29 05:06:26.697407 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:8156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/w.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2WgAABi4"] [Sat Aug 29 05:06:26.698282 2026] [security2:error] [pid 1017536:tid 1017603] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DXgACfEI"] [Sat Aug 29 05:06:26.707456 2026] [core:error] [pid 1017536:tid 1017541] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.707474 2026] [core:error] [pid 1017536:tid 1017541] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.712031 2026] [security2:error] [pid 1017536:tid 1017734] [client 52.139.37.240:14493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/root.php"] [unique_id "apK9MiJcY4fy7tP-rU0DYgAAAlg"] [Sat Aug 29 05:06:26.718076 2026] [security2:error] [pid 1017536:tid 1017712] [client 68.155.159.216:30602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9MiJcY4fy7tP-rU0DZgAAAkI"] [Sat Aug 29 05:06:26.718109 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.104.18.15:36765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-admin/w.php"] [unique_id "apK9MiJcY4fy7tP-rU0DZQAAAi0"] [Sat Aug 29 05:06:26.741291 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.63.81.20:46865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/one.php"] [unique_id "apK9MiJcY4fy7tP-rU0DaQAAAkA"] [Sat Aug 29 05:06:26.744038 2026] [core:error] [pid 1017536:tid 1017761] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.744060 2026] [core:error] [pid 1017536:tid 1017761] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.745677 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.745694 2026] [core:error] [pid 1017536:tid 1017751] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.748516 2026] [security2:error] [pid 1017536:tid 1017550] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9MiJcY4fy7tP-rU0DbAACKw0"] [Sat Aug 29 05:06:26.753137 2026] [security2:error] [pid 1017536:tid 1017551] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/test.php"] [unique_id "apK9MiJcY4fy7tP-rU0DcgACKw4"] [Sat Aug 29 05:06:26.753946 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.18.15:13073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-trackback.php"] [unique_id "apK9MiJcY4fy7tP-rU0DdQAAAlc"] [Sat Aug 29 05:06:26.755914 2026] [core:error] [pid 1017536:tid 1017563] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.755929 2026] [core:error] [pid 1017536:tid 1017563] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.759930 2026] [security2:error] [pid 1017536:tid 1017571] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DeQACKyI"] [Sat Aug 29 05:06:26.774311 2026] [security2:error] [pid 1017536:tid 1017790] [client 68.155.159.216:65063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9MiJcY4fy7tP-rU0DfAAAApA"] [Sat Aug 29 05:06:26.776432 2026] [security2:error] [pid 1017536:tid 1017747] [client 5.161.117.52:56066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ridetime.com"] [uri "/index.html"] [unique_id "apK9MiJcY4fy7tP-rU0DewAAAmU"], referer: https://ridetime.com [Sat Aug 29 05:06:26.776799 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.18.15:36673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/coffexium.php"] [unique_id "apK9MiJcY4fy7tP-rU0DfQAAAiA"] [Sat Aug 29 05:06:26.777597 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.777614 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.779175 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.197.61.180:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bestcharlottecosmeticdentists.com"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK9MiJcY4fy7tP-rU0DgAAAAjo"] [Sat Aug 29 05:06:26.780417 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.780434 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.782107 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.782124 2026] [core:error] [pid 1017536:tid 1017753] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.782501 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.782515 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.782524 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.782532 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.787790 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.220.204.93:59126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ioxi.php"] [unique_id "apK9MiJcY4fy7tP-rU0DhAAAAj0"] [Sat Aug 29 05:06:26.790850 2026] [core:error] [pid 1017536:tid 1017736] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.790866 2026] [core:error] [pid 1017536:tid 1017736] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.793883 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.18.15:23494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/gos.php"] [unique_id "apK9MiJcY4fy7tP-rU0DhgAAAjE"] [Sat Aug 29 05:06:26.800895 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.18.15:6935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/sao.php"] [unique_id "apK9MiJcY4fy7tP-rU0DhwAAAlY"] [Sat Aug 29 05:06:26.802777 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.151.200.44:64964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/ad1.php"] [unique_id "apK9MiJcY4fy7tP-rU0DiAAAAiI"] [Sat Aug 29 05:06:26.812888 2026] [security2:error] [pid 1017536:tid 1017687] [client 68.155.159.216:51411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/mah.php"] [unique_id "apK9MiJcY4fy7tP-rU0DigAAAik"] [Sat Aug 29 05:06:26.816258 2026] [core:error] [pid 1017536:tid 1017752] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.816281 2026] [core:error] [pid 1017536:tid 1017752] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.816309 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.151.200.44:47415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/rfi.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2agAABcM"] [Sat Aug 29 05:06:26.818472 2026] [core:error] [pid 1017536:tid 1017793] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.818487 2026] [core:error] [pid 1017536:tid 1017793] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.821526 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.63.81.20:56861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/dvve.php"] [unique_id "apK9MiJcY4fy7tP-rU0DjQAAAjw"] [Sat Aug 29 05:06:26.821782 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/0x.php"] [unique_id "apK9MiJcY4fy7tP-rU0DjgAAAnw"] [Sat Aug 29 05:06:26.832313 2026] [security2:error] [pid 1017536:tid 1017769] [client 40.83.93.50:1740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/pk.php"] [unique_id "apK9MiJcY4fy7tP-rU0DkAAAAns"] [Sat Aug 29 05:06:26.850562 2026] [security2:error] [pid 1018003:tid 1018183] [client 87.219.197.128:53709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2bQAABdg"] [Sat Aug 29 05:06:26.850648 2026] [security2:error] [pid 1018003:tid 1018183] [client 87.219.197.128:53709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2bQAABdg"] [Sat Aug 29 05:06:26.860039 2026] [security2:error] [pid 1017536:tid 1017557] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DkQACaRQ"] [Sat Aug 29 05:06:26.871027 2026] [security2:error] [pid 1017536:tid 1017733] [client 158.23.147.79:30653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9MiJcY4fy7tP-rU0DlAAAAlc"] [Sat Aug 29 05:06:26.873560 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.147.79:26503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9MiJcY4fy7tP-rU0DlgAAAho"] [Sat Aug 29 05:06:26.881246 2026] [security2:error] [pid 1017536:tid 1017675] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9MiJcY4fy7tP-rU0DZwACHTo"] [Sat Aug 29 05:06:26.886683 2026] [security2:error] [pid 1018003:tid 1018240] [client 4.205.62.107:21570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/localconf.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2cgAABhA"] [Sat Aug 29 05:06:26.895818 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.104.18.15:36774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-content/k.php"] [unique_id "apK9MiJcY4fy7tP-rU0DlwAAAmc"] [Sat Aug 29 05:06:26.901037 2026] [security2:error] [pid 1017536:tid 1017549] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DmQACjgw"] [Sat Aug 29 05:06:26.901038 2026] [security2:error] [pid 1017536:tid 1017600] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DmwACjj8"] [Sat Aug 29 05:06:26.901880 2026] [core:error] [pid 1017536:tid 1017781] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.901901 2026] [core:error] [pid 1017536:tid 1017781] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.902945 2026] [security2:error] [pid 1017536:tid 1017578] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9MiJcY4fy7tP-rU0DnAACjik"] [Sat Aug 29 05:06:26.904649 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.52.41.200:1747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/txets.php"] [unique_id "apK9MiJcY4fy7tP-rU0DnQAAAhw"] [Sat Aug 29 05:06:26.908689 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.220.204.93:64945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/init.php"] [unique_id "apK9MiJcY4fy7tP-rU0DoQAAAlg"] [Sat Aug 29 05:06:26.911121 2026] [security2:error] [pid 1018003:tid 1018207] [client 52.139.37.240:14917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/shell.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2dAAABfA"] [Sat Aug 29 05:06:26.912462 2026] [security2:error] [pid 1018003:tid 1018180] [client 158.23.147.79:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2dQAABdU"] [Sat Aug 29 05:06:26.919201 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.151.200.44:64227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/basic.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2dgAABcc"] [Sat Aug 29 05:06:26.921183 2026] [security2:error] [pid 1017536:tid 1017683] [client 213.202.253.4:61512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/wp-content/schallfuns.php"] [unique_id "apK9MiJcY4fy7tP-rU0DogAAAiU"], referer: www.google.com [Sat Aug 29 05:06:26.921818 2026] [security2:error] [pid 1017536:tid 1017770] [client 168.107.94.195:55729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9MiJcY4fy7tP-rU0DowAAAnw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:26.925757 2026] [security2:error] [pid 1017536:tid 1017689] [client 158.23.147.79:24389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/images/index.php"] [unique_id "apK9MiJcY4fy7tP-rU0DpQAAAis"] [Sat Aug 29 05:06:26.926870 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.104.18.15:13125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/pri.php"] [unique_id "apK9MiJcY4fy7tP-rU0DpgAAAig"] [Sat Aug 29 05:06:26.930757 2026] [security2:error] [pid 1018003:tid 1018221] [client 158.158.54.35:2854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2dwAABf4"] [Sat Aug 29 05:06:26.933268 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.18.15:6979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/dapa.php"] [unique_id "apK9MiJcY4fy7tP-rU0DpwAAAkI"] [Sat Aug 29 05:06:26.947679 2026] [core:error] [pid 1017536:tid 1017777] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.947698 2026] [core:error] [pid 1017536:tid 1017777] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.947798 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.18.15:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/BDKR28WP.php"] [unique_id "apK9MiJcY4fy7tP-rU0DsAAAAmk"] [Sat Aug 29 05:06:26.948603 2026] [security2:error] [pid 1017536:tid 1017790] [client 4.205.62.107:22414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/05.php"] [unique_id "apK9MiJcY4fy7tP-rU0DsQAAApA"] [Sat Aug 29 05:06:26.948802 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.104.18.15:23542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/132.php"] [unique_id "apK9MiJcY4fy7tP-rU0DsgAAAoQ"] [Sat Aug 29 05:06:26.949697 2026] [core:error] [pid 1017536:tid 1017570] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.949711 2026] [core:error] [pid 1017536:tid 1017570] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.949767 2026] [core:error] [pid 1017536:tid 1017627] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.949775 2026] [core:error] [pid 1017536:tid 1017627] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.962594 2026] [core:error] [pid 1017536:tid 1017776] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.962613 2026] [core:error] [pid 1017536:tid 1017776] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.962762 2026] [security2:error] [pid 1018003:tid 1018199] [client 158.23.147.79:61588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/file5.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2eQAABeg"] [Sat Aug 29 05:06:26.968618 2026] [core:error] [pid 1017536:tid 1017729] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.968636 2026] [core:error] [pid 1017536:tid 1017729] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.977712 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.18.15:8139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/x.php"] [unique_id "apK9MiJcY4fy7tP-rU0DuwAAAjA"] [Sat Aug 29 05:06:26.979033 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.979063 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.979842 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.979856 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.982036 2026] [core:error] [pid 1017536:tid 1017585] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.982050 2026] [core:error] [pid 1017536:tid 1017585] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.983154 2026] [core:error] [pid 1017536:tid 1017781] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.983169 2026] [core:error] [pid 1017536:tid 1017781] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:26.985231 2026] [security2:error] [pid 1017536:tid 1017723] [client 4.205.62.107:65456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/app_dev.php"] [unique_id "apK9MiJcY4fy7tP-rU0DvgAAAk0"] [Sat Aug 29 05:06:26.985980 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.48.250.41:25441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/66.php"] [unique_id "apK9MjAh5Y1i2tUxg4H2fgAABjQ"] [Sat Aug 29 05:06:27.014128 2026] [cgid:error] [pid 1017536:tid 1017780] [client 34.7.40.70:62760] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.014401 2026] [cgid:error] [pid 1017536:tid 1017765] [client 34.7.40.70:62750] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.014465 2026] [cgid:error] [pid 1017536:tid 1017767] [client 34.7.40.70:62766] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.018115 2026] [security2:error] [pid 1017536:tid 1017737] [client 34.7.40.70:62790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/api/graphql"] [unique_id "apK9MyJcY4fy7tP-rU0DxAAAAls"] [Sat Aug 29 05:06:27.018619 2026] [cgid:error] [pid 1017536:tid 1017678] [client 34.7.40.70:62786] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.019408 2026] [cgid:error] [pid 1017536:tid 1017747] [client 34.7.40.70:62752] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.022060 2026] [cgid:error] [pid 1017536:tid 1017681] [client 34.7.40.70:62776] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.023734 2026] [cgid:error] [pid 1018003:tid 1018195] [client 34.7.40.70:62896] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.023791 2026] [cgid:error] [pid 1017536:tid 1017748] [client 34.7.40.70:62876] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.023817 2026] [cgid:error] [pid 1018003:tid 1018175] [client 34.7.40.70:62796] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.024172 2026] [cgid:error] [pid 1017536:tid 1017713] [client 34.7.40.70:62826] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.025352 2026] [security2:error] [pid 1017536:tid 1017748] [client 34.7.40.70:62876] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9MyJcY4fy7tP-rU0DyQAAAmY"] [Sat Aug 29 05:06:27.025363 2026] [security2:error] [pid 1018003:tid 1018195] [client 34.7.40.70:62896] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9MzAh5Y1i2tUxg4H2gQAABeQ"] [Sat Aug 29 05:06:27.025453 2026] [security2:error] [pid 1018003:tid 1018175] [client 34.7.40.70:62796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9MzAh5Y1i2tUxg4H2ggAABdA"] [Sat Aug 29 05:06:27.025745 2026] [cgid:error] [pid 1017536:tid 1017717] [client 34.7.40.70:62794] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.027437 2026] [cgid:error] [pid 1017536:tid 1017696] [client 34.7.40.70:62880] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.027517 2026] [cgid:error] [pid 1017536:tid 1017698] [client 34.7.40.70:62860] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.027608 2026] [cgid:error] [pid 1018003:tid 1018212] [client 34.7.40.70:62858] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.028050 2026] [cgid:error] [pid 1017536:tid 1017711] [client 34.7.40.70:62922] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.028587 2026] [cgid:error] [pid 1018003:tid 1018150] [client 34.7.40.70:62836] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.029192 2026] [security2:error] [pid 1017536:tid 1017743] [client 34.7.40.70:62900] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.claude.json"] [unique_id "apK9MyJcY4fy7tP-rU0DzwAAAmE"] [Sat Aug 29 05:06:27.029652 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.151.200.44:65079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/1vbqo.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2hgAABhU"] [Sat Aug 29 05:06:27.030264 2026] [cgid:error] [pid 1018003:tid 1018246] [client 34.7.40.70:62810] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.030500 2026] [cgid:error] [pid 1017536:tid 1017753] [client 34.7.40.70:62994] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.030663 2026] [security2:error] [pid 1017536:tid 1017705] [client 34.7.40.70:62862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.openclaw/.env"] [unique_id "apK9MyJcY4fy7tP-rU0D0AAAAjs"] [Sat Aug 29 05:06:27.030887 2026] [security2:error] [pid 1018003:tid 1018150] [client 158.23.147.79:35209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/makeasmtp.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2iAAABbc"] [Sat Aug 29 05:06:27.031760 2026] [security2:error] [pid 1018003:tid 1018188] [client 34.7.40.70:62850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.hermes/.env"] [unique_id "apK9MzAh5Y1i2tUxg4H2hwAABd0"] [Sat Aug 29 05:06:27.032978 2026] [cgid:error] [pid 1017536:tid 1017673] [client 34.7.40.70:62944] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.033347 2026] [cgid:error] [pid 1017536:tid 1017724] [client 34.7.40.70:62928] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.034347 2026] [cgid:error] [pid 1017536:tid 1017707] [client 34.7.40.70:62978] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.034805 2026] [cgid:error] [pid 1017536:tid 1017669] [client 34.7.40.70:62968] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.034904 2026] [security2:error] [pid 1017536:tid 1017669] [client 34.7.40.70:62968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9MyJcY4fy7tP-rU0D1AAAAhc"] [Sat Aug 29 05:06:27.035804 2026] [cgid:error] [pid 1017536:tid 1017785] [client 34.7.40.70:62986] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.036173 2026] [cgid:error] [pid 1017536:tid 1017736] [client 34.7.40.70:62940] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.036234 2026] [cgid:error] [pid 1018003:tid 1018238] [client 34.7.40.70:62952] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.037465 2026] [cgid:error] [pid 1017536:tid 1017695] [client 34.7.40.70:62988] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.037713 2026] [cgid:error] [pid 1017536:tid 1017745] [client 34.7.40.70:62912] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.039588 2026] [cgid:error] [pid 1017536:tid 1017732] [client 34.7.40.70:62980] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:27.041447 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.220.204.93:52289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/bootstrap.php"] [unique_id "apK9MyJcY4fy7tP-rU0D2wAAAoM"] [Sat Aug 29 05:06:27.043092 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.151.200.44:47307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/tajj.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2igAABio"] [Sat Aug 29 05:06:27.043907 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.043923 2026] [core:error] [pid 1017536:tid 1017731] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.047215 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.147.79:50055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/log-mama/function.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2iwAABiU"] [Sat Aug 29 05:06:27.053817 2026] [core:error] [pid 1017536:tid 1017621] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.053840 2026] [core:error] [pid 1017536:tid 1017621] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.055333 2026] [core:error] [pid 1017536:tid 1017626] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.055349 2026] [core:error] [pid 1017536:tid 1017626] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.057569 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.104.18.15:13175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp_blog_footer.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2jwAABiM"] [Sat Aug 29 05:06:27.064327 2026] [security2:error] [pid 1018003:tid 1018219] [client 68.155.159.216:33768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/ws.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2kwAABfw"] [Sat Aug 29 05:06:27.074761 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.18.15:36766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/os.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2lgAABiY"] [Sat Aug 29 05:06:27.080218 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:30622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/content.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2lwAABgc"] [Sat Aug 29 05:06:27.083184 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.48.251.3:14298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.capturephoto.net"] [uri "/old_phpinfo.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2mAAABfk"] [Sat Aug 29 05:06:27.091335 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.091352 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.095384 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:36615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/sf.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2nQAABcA"] [Sat Aug 29 05:06:27.099735 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.196.209.81:11574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/configs.php"] [unique_id "apK9MyJcY4fy7tP-rU0D4QAAAoQ"] [Sat Aug 29 05:06:27.108406 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.49.130:57606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/read.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2ngAABf8"] [Sat Aug 29 05:06:27.108918 2026] [security2:error] [pid 1017536:tid 1017545] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9MyJcY4fy7tP-rU0D4gACjgg"] [Sat Aug 29 05:06:27.108956 2026] [security2:error] [pid 1017536:tid 1017564] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9MyJcY4fy7tP-rU0D5AACjhs"] [Sat Aug 29 05:06:27.110365 2026] [security2:error] [pid 1017536:tid 1017776] [client 52.139.37.240:14935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9MyJcY4fy7tP-rU0D5QAAAoI"] [Sat Aug 29 05:06:27.111300 2026] [core:error] [pid 1017536:tid 1017610] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.111313 2026] [core:error] [pid 1017536:tid 1017610] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.114208 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.48.251.3:3347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/configuration.php"] [unique_id "apK9MyJcY4fy7tP-rU0D5gAAAhw"] [Sat Aug 29 05:06:27.117461 2026] [core:error] [pid 1017536:tid 1017580] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.117473 2026] [core:error] [pid 1017536:tid 1017580] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.132184 2026] [security2:error] [pid 1017536:tid 1017646] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9MyJcY4fy7tP-rU0D6QACjm0"] [Sat Aug 29 05:06:27.135868 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.18.15:23455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/v22.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2ogAABgw"] [Sat Aug 29 05:06:27.136664 2026] [core:error] [pid 1017536:tid 1017634] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.136679 2026] [core:error] [pid 1017536:tid 1017634] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.136843 2026] [core:error] [pid 1018003:tid 1018171] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.136851 2026] [core:error] [pid 1018003:tid 1018171] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.138677 2026] [core:error] [pid 1017536:tid 1017648] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.138694 2026] [core:error] [pid 1017536:tid 1017648] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.138801 2026] [core:error] [pid 1017536:tid 1017577] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.138816 2026] [core:error] [pid 1017536:tid 1017577] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.147305 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.147320 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.151397 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:7077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-content/l.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2pAAABeE"] [Sat Aug 29 05:06:27.163407 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.220.204.93:64984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/term.php"] [unique_id "apK9MyJcY4fy7tP-rU0D7wAAAlc"] [Sat Aug 29 05:06:27.163682 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.18.15:8178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ssla.php"] [unique_id "apK9MyJcY4fy7tP-rU0D8AAAAkk"] [Sat Aug 29 05:06:27.173425 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.220.204.93:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/export.php"] [unique_id "apK9MyJcY4fy7tP-rU0D8QAAAk0"] [Sat Aug 29 05:06:27.175427 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.48.250.41:25542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/f35.php"] [unique_id "apK9MyJcY4fy7tP-rU0D8gAAAiU"] [Sat Aug 29 05:06:27.196528 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.18.15:13062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/sushi.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2qgAABc8"] [Sat Aug 29 05:06:27.208811 2026] [core:error] [pid 1017536:tid 1017651] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.208824 2026] [core:error] [pid 1017536:tid 1017661] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.208838 2026] [core:error] [pid 1017536:tid 1017651] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.208842 2026] [core:error] [pid 1017536:tid 1017661] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.221153 2026] [core:error] [pid 1017536:tid 1017761] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.221169 2026] [core:error] [pid 1017536:tid 1017761] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.229231 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.229246 2026] [core:error] [pid 1017536:tid 1017780] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.245627 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.48.251.3:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/server_info.php"] [unique_id "apK9MyJcY4fy7tP-rU0D9wAAAkM"] [Sat Aug 29 05:06:27.253781 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.18.15:36746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/htio.php"] [unique_id "apK9MyJcY4fy7tP-rU0D-QAAAjI"] [Sat Aug 29 05:06:27.256131 2026] [core:error] [pid 1017536:tid 1017614] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.256146 2026] [core:error] [pid 1017536:tid 1017614] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.256466 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.18.15:36760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/k.php"] [unique_id "apK9MyJcY4fy7tP-rU0D-gAAAkE"] [Sat Aug 29 05:06:27.265353 2026] [security2:error] [pid 1018003:tid 1018240] [client 4.205.62.107:22440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/aws-credentials.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2rQAABhA"] [Sat Aug 29 05:06:27.285795 2026] [core:error] [pid 1017536:tid 1017622] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.285812 2026] [core:error] [pid 1017536:tid 1017622] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.287388 2026] [core:error] [pid 1017536:tid 1017777] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.287403 2026] [core:error] [pid 1017536:tid 1017777] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.288620 2026] [core:error] [pid 1018003:tid 1018156] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.288638 2026] [core:error] [pid 1018003:tid 1018156] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.289565 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.151.200.44:64878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/monso.php"] [unique_id "apK9MyJcY4fy7tP-rU0ECAAAApM"] [Sat Aug 29 05:06:27.291066 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.291079 2026] [core:error] [pid 1017536:tid 1017732] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.291628 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.291643 2026] [core:error] [pid 1017536:tid 1017745] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.292952 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.104.18.15:6984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-admin/w.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2sQAABdU"] [Sat Aug 29 05:06:27.293516 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.18.15:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2sgAABcc"] [Sat Aug 29 05:06:27.293985 2026] [security2:error] [pid 1017536:tid 1017565] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/wp-config.php"] [unique_id "apK9MyJcY4fy7tP-rU0EDAACYRw"] [Sat Aug 29 05:06:27.294033 2026] [security2:error] [pid 1017536:tid 1017663] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9MyJcY4fy7tP-rU0ECgACYX4"] [Sat Aug 29 05:06:27.298081 2026] [security2:error] [pid 1017536:tid 1017638] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.evecreative.co"] [uri "/wp-config.php.bak"] [unique_id "apK9MyJcY4fy7tP-rU0EDgACYWU"] [Sat Aug 29 05:06:27.298552 2026] [security2:error] [pid 1018003:tid 1018162] [client 40.83.93.50:1777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2tAAABcM"] [Sat Aug 29 05:06:27.304836 2026] [security2:error] [pid 1017536:tid 1017752] [client 168.107.94.195:56083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9MyJcY4fy7tP-rU0EEAAAAmo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:27.305033 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.18.15:23404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-activate.php"] [unique_id "apK9MyJcY4fy7tP-rU0EEQAAAhw"] [Sat Aug 29 05:06:27.306500 2026] [security2:error] [pid 1018003:tid 1018265] [client 4.205.62.107:53434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/xza.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2tQAABik"] [Sat Aug 29 05:06:27.309021 2026] [security2:error] [pid 1018003:tid 1018277] [client 52.139.37.240:14518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2tgAABjU"] [Sat Aug 29 05:06:27.317222 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.317242 2026] [core:error] [pid 1017536:tid 1017746] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.339571 2026] [security2:error] [pid 1017536:tid 1017623] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.evecreative.co"] [uri "/wp-config.php.new"] [unique_id "apK9MyJcY4fy7tP-rU0EEwACYVY"] [Sat Aug 29 05:06:27.340317 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.49.130:29957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/1xmomo.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2uwAABf4"] [Sat Aug 29 05:06:27.342670 2026] [security2:error] [pid 1017536:tid 1017719] [client 158.23.147.79:25588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9MyJcY4fy7tP-rU0EFAAAAkk"] [Sat Aug 29 05:06:27.345796 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.48.250.41:25434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wen.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2vAAABgQ"] [Sat Aug 29 05:06:27.360172 2026] [cgid:error] [pid 1018003:tid 1018183] [client 20.52.41.200:1785] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:27.361192 2026] [security2:error] [pid 1017536:tid 1017553] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.evecreative.co"] [uri "/wp-config.php.old"] [unique_id "apK9MyJcY4fy7tP-rU0EFgACYRA"] [Sat Aug 29 05:06:27.365282 2026] [core:error] [pid 1017536:tid 1017553] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.365301 2026] [core:error] [pid 1017536:tid 1017553] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.367290 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.151.200.44:45917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/grsiuk.php"] [unique_id "apK9MyJcY4fy7tP-rU0EGAAAAiU"] [Sat Aug 29 05:06:27.368762 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.220.204.93:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/gk.php"] [unique_id "apK9MyJcY4fy7tP-rU0EGQAAAis"] [Sat Aug 29 05:06:27.372613 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.48.251.3:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/hosty.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2wgAABdI"] [Sat Aug 29 05:06:27.379248 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.104.18.15:13223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/manga.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2wwAABgY"] [Sat Aug 29 05:06:27.388176 2026] [security2:error] [pid 1017536:tid 1017691] [client 103.185.242.143:62443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9MyJcY4fy7tP-rU0EGwAAAi0"] [Sat Aug 29 05:06:27.388269 2026] [security2:error] [pid 1017536:tid 1017691] [client 103.185.242.143:62443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9MyJcY4fy7tP-rU0EGwAAAi0"] [Sat Aug 29 05:06:27.390185 2026] [security2:error] [pid 1017536:tid 1017568] [remote 93.123.109.228:34856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9MyJcY4fy7tP-rU0EGgACYR8"] [Sat Aug 29 05:06:27.393960 2026] [core:error] [pid 1017536:tid 1017593] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.393984 2026] [core:error] [pid 1017536:tid 1017593] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.396098 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.396111 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.397249 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.158.54.35:14094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-admin/css/admin.php"] [unique_id "apK9MyJcY4fy7tP-rU0EHQAAAkc"] [Sat Aug 29 05:06:27.403029 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.18.15:36711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/82.php"] [unique_id "apK9MyJcY4fy7tP-rU0EHgAAAmk"] [Sat Aug 29 05:06:27.408345 2026] [core:error] [pid 1017536:tid 1017656] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.408368 2026] [core:error] [pid 1017536:tid 1017656] [remote 93.123.109.228:34856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.419567 2026] [security2:error] [pid 1017536:tid 1017761] [client 4.205.62.107:56042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ebahvhhh.php"] [unique_id "apK9MyJcY4fy7tP-rU0EIQAAAnM"] [Sat Aug 29 05:06:27.425739 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.18.15:36691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/dev.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2ywAABcI"] [Sat Aug 29 05:06:27.428977 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.18.15:8151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-aothait.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2zAAABek"] [Sat Aug 29 05:06:27.432582 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.18.15:7007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-content/k.php"] [unique_id "apK9MyJcY4fy7tP-rU0EIgAAAik"] [Sat Aug 29 05:06:27.444956 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.18.15:23459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-trackback.php"] [unique_id "apK9MyJcY4fy7tP-rU0EIwAAAls"] [Sat Aug 29 05:06:27.475396 2026] [security2:error] [pid 1017536:tid 1017788] [client 68.155.159.216:52763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9MyJcY4fy7tP-rU0EKAAAAo4"] [Sat Aug 29 05:06:27.477746 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.220.204.93:64290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/aaa.php"] [unique_id "apK9MyJcY4fy7tP-rU0EKQAAAkM"] [Sat Aug 29 05:06:27.484875 2026] [core:error] [pid 1017536:tid 1017698] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.484896 2026] [core:error] [pid 1017536:tid 1017698] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:27.496572 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.196.209.81:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/disagraeed.php"] [unique_id "apK9MyJcY4fy7tP-rU0EKwAAAh0"] [Sat Aug 29 05:06:27.497059 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.48.251.3:61242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/pass4.php"] [unique_id "apK9MyJcY4fy7tP-rU0ELAAAAhs"] [Sat Aug 29 05:06:27.499183 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.104.62:60417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/7logs.php"] [unique_id "apK9MyJcY4fy7tP-rU0ELQAAAow"] [Sat Aug 29 05:06:27.503759 2026] [security2:error] [pid 1017536:tid 1017767] [client 52.139.37.240:15237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-header-json.php"] [unique_id "apK9MyJcY4fy7tP-rU0ELgAAAnk"] [Sat Aug 29 05:06:27.514600 2026] [cgid:error] [pid 1018003:tid 1018188] [client 20.52.41.200:1785] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:27.517924 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.104.104.62:64643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/mcd.php"] [unique_id "apK9MzAh5Y1i2tUxg4H20wAABg4"] [Sat Aug 29 05:06:27.520797 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:13131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/asdfghj.php"] [unique_id "apK9MzAh5Y1i2tUxg4H21QAABes"] [Sat Aug 29 05:06:27.536591 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.250.41:25345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/inc.php"] [unique_id "apK9MyJcY4fy7tP-rU0EMAAAAlU"] [Sat Aug 29 05:06:27.544728 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.18.15:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/dex.php"] [unique_id "apK9MzAh5Y1i2tUxg4H21wAABio"] [Sat Aug 29 05:06:27.549745 2026] [security2:error] [pid 1017536:tid 1017704] [client 68.155.159.216:14085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/x.php"] [unique_id "apK9MyJcY4fy7tP-rU0EMQAAAjo"] [Sat Aug 29 05:06:27.569913 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.18.15:36721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/gos.php"] [unique_id "apK9MzAh5Y1i2tUxg4H22gAABb4"] [Sat Aug 29 05:06:27.574167 2026] [security2:error] [pid 1017536:tid 1017719] [client 20.104.18.15:8149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-includes/index.php"] [unique_id "apK9MyJcY4fy7tP-rU0EMwAAAkk"] [Sat Aug 29 05:06:27.574553 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.18.15:7083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/os.php"] [unique_id "apK9MyJcY4fy7tP-rU0ENAAAAiU"] [Sat Aug 29 05:06:27.577325 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.220.204.93:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/logs1.php"] [unique_id "apK9MzAh5Y1i2tUxg4H22wAABgc"] [Sat Aug 29 05:06:27.590260 2026] [security2:error] [pid 1017536:tid 1017761] [client 93.123.109.228:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9MyJcY4fy7tP-rU0ENQAAAnM"] [Sat Aug 29 05:06:27.593437 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.18.15:23408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/pri.php"] [unique_id "apK9MyJcY4fy7tP-rU0ENgAAAik"] [Sat Aug 29 05:06:27.603293 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.151.200.44:64975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/h02ugyh.php"] [unique_id "apK9MyJcY4fy7tP-rU0EOAAAAiA"] [Sat Aug 29 05:06:27.606400 2026] [security2:error] [pid 1017536:tid 1017748] [client 93.123.109.228:49546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9MyJcY4fy7tP-rU0EOQAAAmY"] [Sat Aug 29 05:06:27.606788 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.104.62:48494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/quoys.php"] [unique_id "apK9MzAh5Y1i2tUxg4H23wAABcA"] [Sat Aug 29 05:06:27.607024 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.151.200.44:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/rce.php"] [unique_id "apK9MyJcY4fy7tP-rU0EOgAAApI"] [Sat Aug 29 05:06:27.611573 2026] [security2:error] [pid 1018003:tid 1018066] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/test.php"] [unique_id "apK9MzAh5Y1i2tUxg4H24QAGCi0"] [Sat Aug 29 05:06:27.624656 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.251.3:61094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/cu.php"] [unique_id "apK9MyJcY4fy7tP-rU0EPgAAAjQ"] [Sat Aug 29 05:06:27.660104 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.104.62:36969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/sf.php"] [unique_id "apK9MyJcY4fy7tP-rU0EQgAAAhs"] [Sat Aug 29 05:06:27.664009 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.52.41.200:1785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/themes/about.php"] [unique_id "apK9MzAh5Y1i2tUxg4H25wAABhw"] [Sat Aug 29 05:06:27.665793 2026] [security2:error] [pid 1017536:tid 1017695] [client 68.155.159.216:50258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/mah.php"] [unique_id "apK9MyJcY4fy7tP-rU0ERAAAAjE"] [Sat Aug 29 05:06:27.668107 2026] [security2:error] [pid 1017536:tid 1017767] [client 93.123.109.228:49580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9MyJcY4fy7tP-rU0ERQAAAnk"] [Sat Aug 29 05:06:27.681831 2026] [security2:error] [pid 1017536:tid 1017696] [client 52.139.37.240:31504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/ahax.php"] [unique_id "apK9MyJcY4fy7tP-rU0ERgAAAjI"] [Sat Aug 29 05:06:27.687457 2026] [security2:error] [pid 1017536:tid 1017731] [client 168.107.94.195:56487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9MyJcY4fy7tP-rU0ESAAAAlU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:27.688619 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.18.15:13071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/dragonshell.php"] [unique_id "apK9MzAh5Y1i2tUxg4H26QAABfo"] [Sat Aug 29 05:06:27.688778 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.104.104.62:64689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/waw.php"] [unique_id "apK9MzAh5Y1i2tUxg4H26wAABg8"] [Sat Aug 29 05:06:27.700117 2026] [security2:error] [pid 1017536:tid 1017681] [client 52.139.37.240:15257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/zup.php"] [unique_id "apK9MyJcY4fy7tP-rU0ESgAAAiM"] [Sat Aug 29 05:06:27.701567 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.104.62:20879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/.well-known/fox.php"] [unique_id "apK9MyJcY4fy7tP-rU0ESwAAAhc"] [Sat Aug 29 05:06:27.704554 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.250.41:25501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/6bcwiqwj.php"] [unique_id "apK9MyJcY4fy7tP-rU0ETAAAAjw"] [Sat Aug 29 05:06:27.731856 2026] [security2:error] [pid 1018003:tid 1018179] [client 68.155.159.216:49215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9MzAh5Y1i2tUxg4H27wAABdQ"] [Sat Aug 29 05:06:27.736399 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.104.18.15:36617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/132.php"] [unique_id "apK9MyJcY4fy7tP-rU0ETwAAAj0"] [Sat Aug 29 05:06:27.741192 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.18.15:23405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp_blog_footer.php"] [unique_id "apK9MzAh5Y1i2tUxg4H28AAABe8"] [Sat Aug 29 05:06:27.744822 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.104.18.15:8123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/file31.php"] [unique_id "apK9MyJcY4fy7tP-rU0EUAAAAmc"] [Sat Aug 29 05:06:27.749077 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.151.200.44:47350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/ahy66.php"] [unique_id "apK9MyJcY4fy7tP-rU0EUQAAApA"] [Sat Aug 29 05:06:27.755230 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.104.62:48667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/vbbn.php"] [unique_id "apK9MyJcY4fy7tP-rU0EUgAAAhw"] [Sat Aug 29 05:06:27.755727 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.251.3:3176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/services.php"] [unique_id "apK9MyJcY4fy7tP-rU0EUwAAAmQ"] [Sat Aug 29 05:06:27.758148 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.18.15:36694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/inso.php"] [unique_id "apK9MyJcY4fy7tP-rU0EVAAAAlg"] [Sat Aug 29 05:06:27.763263 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.18.15:7142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/htio.php"] [unique_id "apK9MzAh5Y1i2tUxg4H28QAABew"] [Sat Aug 29 05:06:27.767757 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.104.49.130:43807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/browse.php"] [unique_id "apK9MyJcY4fy7tP-rU0EVQAAAns"] [Sat Aug 29 05:06:27.786438 2026] [security2:error] [pid 1017536:tid 1017711] [client 40.83.93.50:1734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK9MyJcY4fy7tP-rU0EVgAAAkE"] [Sat Aug 29 05:06:27.792885 2026] [security2:error] [pid 1017536:tid 1017686] [client 93.123.109.228:49546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9MyJcY4fy7tP-rU0EVwAAAig"] [Sat Aug 29 05:06:27.808816 2026] [security2:error] [pid 1017536:tid 1017683] [client 93.123.109.228:49528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9MyJcY4fy7tP-rU0EWgAAAiU"] [Sat Aug 29 05:06:27.813543 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.104.104.62:42699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/super.php"] [unique_id "apK9MyJcY4fy7tP-rU0EWwAAAho"] [Sat Aug 29 05:06:27.817454 2026] [security2:error] [pid 1018003:tid 1018218] [client 74.7.244.26:55688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pnh.vev.mybluehost.me"] [uri "/robots.txt"] [unique_id "apK9MzAh5Y1i2tUxg4H2-gAF-1g"] [Sat Aug 29 05:06:27.820416 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.104.18.15:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-safe.php"] [unique_id "apK9MyJcY4fy7tP-rU0EXAAAAjA"] [Sat Aug 29 05:06:27.832480 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.158.54.35:7394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/adminfuns.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2_AAABiw"] [Sat Aug 29 05:06:27.835570 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.250.41:25491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/easy.php"] [unique_id "apK9MzAh5Y1i2tUxg4H2_gAABbo"] [Sat Aug 29 05:06:27.838484 2026] [security2:error] [pid 1017536:tid 1017792] [client 93.123.109.228:49548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9MyJcY4fy7tP-rU0EXgAAApI"] [Sat Aug 29 05:06:27.842564 2026] [security2:error] [pid 1018003:tid 1018160] [client 68.155.159.216:30608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3AQAABcE"] [Sat Aug 29 05:06:27.873614 2026] [security2:error] [pid 1017536:tid 1017713] [client 93.123.109.228:49600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9MyJcY4fy7tP-rU0EZAAAAkM"] [Sat Aug 29 05:06:27.875021 2026] [security2:error] [pid 1017536:tid 1017757] [client 93.123.109.228:49500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9MyJcY4fy7tP-rU0EZgAAAm8"] [Sat Aug 29 05:06:27.881103 2026] [security2:error] [pid 1018003:tid 1018225] [client 68.155.159.216:65077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3BwAABgI"] [Sat Aug 29 05:06:27.881146 2026] [security2:error] [pid 1017536:tid 1017710] [client 52.139.37.240:31511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/breads1.php"] [unique_id "apK9MyJcY4fy7tP-rU0EZwAAAkA"] [Sat Aug 29 05:06:27.883969 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.18.15:23422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/sushi.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3CAAABhA"] [Sat Aug 29 05:06:27.884926 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.18.15:36695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/v22.php"] [unique_id "apK9MyJcY4fy7tP-rU0EaAAAAl4"] [Sat Aug 29 05:06:27.885815 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.220.204.93:64301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/xsox.php"] [unique_id "apK9MyJcY4fy7tP-rU0EaQAAAnk"] [Sat Aug 29 05:06:27.890374 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.18.15:36742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/aa.php"] [unique_id "apK9MyJcY4fy7tP-rU0EawAAAjI"] [Sat Aug 29 05:06:27.895248 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.220.204.93:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/inege.php"] [unique_id "apK9MyJcY4fy7tP-rU0EbAAAAlU"] [Sat Aug 29 05:06:27.897737 2026] [security2:error] [pid 1017536:tid 1017737] [client 52.139.37.240:14939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/a9.php"] [unique_id "apK9MyJcY4fy7tP-rU0EbQAAAls"] [Sat Aug 29 05:06:27.899126 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.18.15:7067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/dev.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3CgAABcg"] [Sat Aug 29 05:06:27.900623 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.104.62:56349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/x23.php"] [unique_id "apK9MyJcY4fy7tP-rU0EbwAAAow"] [Sat Aug 29 05:06:27.901962 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.63.81.20:44530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/503.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3CwAABb0"] [Sat Aug 29 05:06:27.903396 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.48.251.3:3330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/filesystems.php"] [unique_id "apK9MyJcY4fy7tP-rU0EcAAAAiM"] [Sat Aug 29 05:06:27.921614 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:51492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-blog-header.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3DAAABbw"] [Sat Aug 29 05:06:27.930433 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.104.62:48748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/rfi.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3DgAABfA"] [Sat Aug 29 05:06:27.930697 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.18.15:8061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/dk.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3DQAABhQ"] [Sat Aug 29 05:06:27.947878 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.196.209.81:19412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/add_actualites.php"] [unique_id "apK9MyJcY4fy7tP-rU0EdAAAAlc"] [Sat Aug 29 05:06:27.955691 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.63.81.20:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/doo.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3EAAABik"] [Sat Aug 29 05:06:27.958299 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.104.62:36988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/lufix1.php"] [unique_id "apK9MyJcY4fy7tP-rU0EdwAAAn8"] [Sat Aug 29 05:06:27.976939 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.147.79:26623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9MyJcY4fy7tP-rU0EeQAAApA"] [Sat Aug 29 05:06:27.984262 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.147.79:30535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9MyJcY4fy7tP-rU0EegAAAhw"] [Sat Aug 29 05:06:27.993459 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:13131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/gjewuagf.php"] [unique_id "apK9MzAh5Y1i2tUxg4H3FQAABec"] [Sat Aug 29 05:06:28.014276 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.151.200.44:64297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/exec.php"] [unique_id "apK9NCJcY4fy7tP-rU0EfQAAAkE"] [Sat Aug 29 05:06:28.018620 2026] [security2:error] [pid 1017536:tid 1017686] [client 93.123.109.228:49592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9NCJcY4fy7tP-rU0EfgAAAig"] [Sat Aug 29 05:06:28.026929 2026] [security2:error] [pid 1018003:tid 1018175] [client 4.205.62.107:22441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/xa.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3HAAABdA"] [Sat Aug 29 05:06:28.030494 2026] [security2:error] [pid 1017536:tid 1017694] [client 93.123.109.228:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/.env.php"] [unique_id "apK9NCJcY4fy7tP-rU0EggAAAjA"] [Sat Aug 29 05:06:28.030780 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.220.204.93:59058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wp-link10.php"] [unique_id "apK9NCJcY4fy7tP-rU0EgwAAAmk"] [Sat Aug 29 05:06:28.032267 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.18.15:23548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/manga.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3HwAABfU"] [Sat Aug 29 05:06:28.036728 2026] [autoindex:error] [pid 1018003:tid 1018140] [remote 74.7.227.185:37412] AH01276: Cannot serve directory /home3/pnhvevmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:28.036960 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.49.130:57608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/gecko-new.php"] [unique_id "apK9NCJcY4fy7tP-rU0EhQAAAmY"] [Sat Aug 29 05:06:28.037474 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.63.81.20:46857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/504.php"] [unique_id "apK9NCJcY4fy7tP-rU0EhgAAAnc"] [Sat Aug 29 05:06:28.037979 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:24539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9NCJcY4fy7tP-rU0EhwAAApI"] [Sat Aug 29 05:06:28.040569 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.18.15:6921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/gos.php"] [unique_id "apK9NCJcY4fy7tP-rU0EiQAAAjQ"] [Sat Aug 29 05:06:28.053663 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.23.147.79:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9NCJcY4fy7tP-rU0EigAAAms"] [Sat Aug 29 05:06:28.057916 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.18.15:36701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-activate.php"] [unique_id "apK9NCJcY4fy7tP-rU0EiwAAAhs"] [Sat Aug 29 05:06:28.062011 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.48.250.41:25449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/fresh3.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3IgAABhU"] [Sat Aug 29 05:06:28.064307 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.104.104.62:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/ws66.php"] [unique_id "apK9NCJcY4fy7tP-rU0EjAAAAkM"] [Sat Aug 29 05:06:28.067430 2026] [security2:error] [pid 1017536:tid 1017757] [client 168.107.94.195:56773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9NCJcY4fy7tP-rU0EjQAAAm8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:28.069049 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:37785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/file88.php"] [unique_id "apK9NCJcY4fy7tP-rU0EjgAAAjE"] [Sat Aug 29 05:06:28.070790 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:8004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/ta.php"] [unique_id "apK9NCJcY4fy7tP-rU0EkAAAAkA"] [Sat Aug 29 05:06:28.078563 2026] [security2:error] [pid 1017536:tid 1017740] [client 4.205.62.107:22251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/xmy.php"] [unique_id "apK9NCJcY4fy7tP-rU0EkgAAAl4"] [Sat Aug 29 05:06:28.079447 2026] [security2:error] [pid 1018003:tid 1018161] [client 52.139.37.240:31058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/must.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3JAAABcI"] [Sat Aug 29 05:06:28.081681 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.49.130:60743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/3.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3JQAABd0"] [Sat Aug 29 05:06:28.088424 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.63.81.20:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/adminer-4.6.6.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3JgAABg4"] [Sat Aug 29 05:06:28.093616 2026] [security2:error] [pid 1017536:tid 1017717] [client 52.139.37.240:15283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/admin/index.php"] [unique_id "apK9NCJcY4fy7tP-rU0ElAAAAkc"] [Sat Aug 29 05:06:28.099133 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.18.15:36709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/img.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3KAAABio"] [Sat Aug 29 05:06:28.117684 2026] [security2:error] [pid 1017536:tid 1017745] [client 93.123.109.228:49652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9NCJcY4fy7tP-rU0ElQAAAmM"] [Sat Aug 29 05:06:28.119193 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.52.41.200:1748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3KwAABh8"] [Sat Aug 29 05:06:28.133626 2026] [security2:error] [pid 1018003:tid 1018157] [client 4.205.62.107:26647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/php-info.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3LQAABb4"] [Sat Aug 29 05:06:28.135503 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.104.62:41802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/hack.php"] [unique_id "apK9NCJcY4fy7tP-rU0ElgAAAhc"] [Sat Aug 29 05:06:28.135966 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.104.62:48449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/tajj.php"] [unique_id "apK9NCJcY4fy7tP-rU0ElwAAAk0"] [Sat Aug 29 05:06:28.153316 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:35816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3MQAABgc"] [Sat Aug 29 05:06:28.157758 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.151.200.44:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/gaje.php"] [unique_id "apK9NCJcY4fy7tP-rU0EmwAAAmc"] [Sat Aug 29 05:06:28.167416 2026] [security2:error] [pid 1018003:tid 1018172] [client 68.155.159.216:33761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3MgAABc0"] [Sat Aug 29 05:06:28.170869 2026] [security2:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-config.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3NAAGKwM"] [Sat Aug 29 05:06:28.175401 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.81.20:46907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/admin.php"] [unique_id "apK9NCJcY4fy7tP-rU0EnAAAAlY"] [Sat Aug 29 05:06:28.176821 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.18.15:7093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/132.php"] [unique_id "apK9NCJcY4fy7tP-rU0EngAAAhw"] [Sat Aug 29 05:06:28.177164 2026] [security2:error] [pid 1017536:tid 1017746] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9NCJcY4fy7tP-rU0EnQAAAmQ"] [Sat Aug 29 05:06:28.186473 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.104.62:40204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/.well-known/alfa.php"] [unique_id "apK9NCJcY4fy7tP-rU0EnwAAAlg"] [Sat Aug 29 05:06:28.189440 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.147.79:30531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/goat.php"] [unique_id "apK9NCJcY4fy7tP-rU0EoAAAAoI"] [Sat Aug 29 05:06:28.191028 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.104.18.15:13185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/tnglzqmv.php"] [unique_id "apK9NCJcY4fy7tP-rU0EoQAAAj0"] [Sat Aug 29 05:06:28.200997 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.151.200.44:65077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/shelp.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3NwAABfo"] [Sat Aug 29 05:06:28.203754 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.18.15:7946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/bo.php"] [unique_id "apK9NCJcY4fy7tP-rU0EpwAAAis"] [Sat Aug 29 05:06:28.205731 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.18.15:36743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-trackback.php"] [unique_id "apK9NCJcY4fy7tP-rU0EqAAAAik"] [Sat Aug 29 05:06:28.206166 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.250.41:25575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/bgymj.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3OAAABeU"] [Sat Aug 29 05:06:28.208787 2026] [security2:error] [pid 1018003:tid 1018026] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-config.php.new"] [unique_id "apK9NDAh5Y1i2tUxg4H3OQAGKwU"] [Sat Aug 29 05:06:28.210556 2026] [security2:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-config.php.old"] [unique_id "apK9NDAh5Y1i2tUxg4H3OwAGKwk"] [Sat Aug 29 05:06:28.210740 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.18.15:23300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/asdfghj.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3OgAABi8"] [Sat Aug 29 05:06:28.213247 2026] [security2:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:34972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-config.php.bak"] [unique_id "apK9NDAh5Y1i2tUxg4H3PAAGDHo"] [Sat Aug 29 05:06:28.224170 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.63.81.20:60480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/gelap1.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3PQAABeE"] [Sat Aug 29 05:06:28.247660 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.220.204.93:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ww.php"] [unique_id "apK9NCJcY4fy7tP-rU0ErQAAAkA"] [Sat Aug 29 05:06:28.257618 2026] [security2:error] [pid 1017536:tid 1017767] [client 93.123.109.228:49502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9NCJcY4fy7tP-rU0ErwAAAnk"] [Sat Aug 29 05:06:28.259961 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/sad/about.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3QAAABc8"] [Sat Aug 29 05:06:28.267727 2026] [security2:error] [pid 1017536:tid 1017696] [client 93.123.109.228:49518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9NCJcY4fy7tP-rU0EsAAAAjI"] [Sat Aug 29 05:06:28.270073 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.18.15:36737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/222.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3QQAABbk"] [Sat Aug 29 05:06:28.273245 2026] [security2:error] [pid 1018003:tid 1018171] [client 52.139.37.240:31136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/up.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3QgAABcw"] [Sat Aug 29 05:06:28.273694 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.158.54.35:14082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/goods.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3QwAABfw"] [Sat Aug 29 05:06:28.275774 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.104.62:36971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/155.php"] [unique_id "apK9NCJcY4fy7tP-rU0EsgAAAls"] [Sat Aug 29 05:06:28.277437 2026] [security2:error] [pid 1017536:tid 1017786] [client 93.123.109.228:49652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9NCJcY4fy7tP-rU0EswAAAow"] [Sat Aug 29 05:06:28.278388 2026] [security2:error] [pid 1018003:tid 1018259] [client 40.83.93.50:1653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/security.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3RwAABiM"] [Sat Aug 29 05:06:28.285927 2026] [security2:error] [pid 1018003:tid 1018234] [client 52.139.37.240:14476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/makeasmtp.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3SAAABgo"] [Sat Aug 29 05:06:28.300775 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.251.3:3142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/tax.php"] [unique_id "apK9NCJcY4fy7tP-rU0EtQAAAjw"] [Sat Aug 29 05:06:28.304776 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.63.81.20:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ws85.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3SQAABds"] [Sat Aug 29 05:06:28.306882 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.104.62:48457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/grsiuk.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3SgAABgI"] [Sat Aug 29 05:06:28.318647 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.18.15:6992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/v22.php"] [unique_id "apK9NCJcY4fy7tP-rU0EtwAAAk0"] [Sat Aug 29 05:06:28.339822 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.104.62:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/Cok.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3TAAABb0"] [Sat Aug 29 05:06:28.340589 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.18.15:8088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/44.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3TQAABbw"] [Sat Aug 29 05:06:28.344470 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.104.18.15:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wefile.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3TgAABdU"] [Sat Aug 29 05:06:28.347494 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.104.18.15:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/dragonshell.php"] [unique_id "apK9NCJcY4fy7tP-rU0EugAAAlc"] [Sat Aug 29 05:06:28.352944 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.18.15:36727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/pri.php"] [unique_id "apK9NCJcY4fy7tP-rU0EuwAAAoc"] [Sat Aug 29 05:06:28.362127 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.63.81.20:56863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/rsjlrria.php"] [unique_id "apK9NCJcY4fy7tP-rU0EvQAAAn8"] [Sat Aug 29 05:06:28.405266 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.250.41:25452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ws69.php"] [unique_id "apK9NCJcY4fy7tP-rU0EwgAAAlo"] [Sat Aug 29 05:06:28.405298 2026] [security2:error] [pid 1017536:tid 1017743] [client 4.205.62.107:22221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/4563.php"] [unique_id "apK9NCJcY4fy7tP-rU0EwwAAAmE"] [Sat Aug 29 05:06:28.406153 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.151.200.44:65019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/13ede.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3UAAABgQ"] [Sat Aug 29 05:06:28.410512 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/key.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3UQAABec"] [Sat Aug 29 05:06:28.431027 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.48.251.3:61110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3UgAABek"] [Sat Aug 29 05:06:28.438964 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.104.62:42722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/mcd.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3UwAABeQ"] [Sat Aug 29 05:06:28.445651 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.196.209.81:11521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/alfanew.php7"] [unique_id "apK9NCJcY4fy7tP-rU0EzAAAAmM"] [Sat Aug 29 05:06:28.445954 2026] [security2:error] [pid 1017536:tid 1017686] [client 158.23.147.79:25563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9NCJcY4fy7tP-rU0EzgAAAig"] [Sat Aug 29 05:06:28.447951 2026] [security2:error] [pid 1017536:tid 1017753] [client 168.107.94.195:57118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9NCJcY4fy7tP-rU0EzwAAAms"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:28.448815 2026] [security2:error] [pid 1017536:tid 1017778] [client 4.205.62.107:53335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/var/www/wallet/index.php"] [unique_id "apK9NCJcY4fy7tP-rU0E0AAAAoQ"] [Sat Aug 29 05:06:28.453568 2026] [security2:error] [pid 1018003:tid 1018183] [client 93.123.109.228:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9NDAh5Y1i2tUxg4H3VgAABdg"] [Sat Aug 29 05:06:28.453852 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.104.104.62:48541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/ahy66.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3VwAABhU"] [Sat Aug 29 05:06:28.456116 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.18.15:7034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-activate.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3WQAABhY"] [Sat Aug 29 05:06:28.474689 2026] [security2:error] [pid 1018003:tid 1018187] [client 66.248.203.2:21504] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2016/09/23/shoe-laces/"] [unique_id "apK9NDAh5Y1i2tUxg4H3WwAABdw"] [Sat Aug 29 05:06:28.480095 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.220.204.93:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/w1px.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3XQAABiI"] [Sat Aug 29 05:06:28.482160 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.18.15:13061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/blog.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3XgAABio"] [Sat Aug 29 05:06:28.489606 2026] [security2:error] [pid 1018003:tid 1018230] [client 52.139.37.240:14656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/paku.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3XwAABgY"] [Sat Aug 29 05:06:28.491896 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.151.200.44:46640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/wp-admin/zwso.php"] [unique_id "apK9NCJcY4fy7tP-rU0E1wAAAnk"] [Sat Aug 29 05:06:28.496551 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.151.200.44:61965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/dbc.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3YAAABiU"] [Sat Aug 29 05:06:28.507264 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.18.15:23461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-safe.php"] [unique_id "apK9NCJcY4fy7tP-rU0E2AAAAmk"] [Sat Aug 29 05:06:28.508117 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.18.15:8108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/h2.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3YQAABh8"] [Sat Aug 29 05:06:28.512370 2026] [security2:error] [pid 1017536:tid 1017696] [client 93.123.109.228:49732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9NCJcY4fy7tP-rU0E2gAAAjI"] [Sat Aug 29 05:06:28.531268 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.104.104.62:43014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/X7T6.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3ZQAABdo"] [Sat Aug 29 05:06:28.539957 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.220.204.93:63169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/lkui.php"] [unique_id "apK9NCJcY4fy7tP-rU0E3gAAAiM"] [Sat Aug 29 05:06:28.546602 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.18.15:36699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp_blog_footer.php"] [unique_id "apK9NCJcY4fy7tP-rU0E4wAAApM"] [Sat Aug 29 05:06:28.547629 2026] [security2:error] [pid 1017536:tid 1017780] [client 93.123.109.228:49766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9NCJcY4fy7tP-rU0E4gAAAoY"] [Sat Aug 29 05:06:28.550786 2026] [autoindex:error] [pid 1017536:tid 1017694] [client 52.139.37.240:31166] AH01276: Cannot serve directory /home4/swumccom/public_html/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:28.552492 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.18.15:36623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/chosen.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3ZwAABeA"] [Sat Aug 29 05:06:28.557504 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.48.250.41:25433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ccs.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3aAAABfo"] [Sat Aug 29 05:06:28.559986 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.251.3:61117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apK9NCJcY4fy7tP-rU0E5gAAAmo"] [Sat Aug 29 05:06:28.563049 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.151.200.44:64994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/k8.php"] [unique_id "apK9NCJcY4fy7tP-rU0E5wAAAiI"] [Sat Aug 29 05:06:28.569574 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.104.62:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/.well-known/wso.php"] [unique_id "apK9NCJcY4fy7tP-rU0E6QAAApA"] [Sat Aug 29 05:06:28.570260 2026] [security2:error] [pid 1018003:tid 1018267] [client 4.205.62.107:56049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/asa.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3aQAABis"] [Sat Aug 29 05:06:28.580309 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.52.41.200:1197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/index.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3agAABgM"] [Sat Aug 29 05:06:28.582977 2026] [security2:error] [pid 1017536:tid 1017749] [client 68.155.159.216:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9NCJcY4fy7tP-rU0E6gAAAmc"] [Sat Aug 29 05:06:28.589680 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.104.62:60455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/waw.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3awAABdQ"] [Sat Aug 29 05:06:28.595632 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.104.62:48627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/gaje.php"] [unique_id "apK9NCJcY4fy7tP-rU0E7QAAAlg"] [Sat Aug 29 05:06:28.597186 2026] [security2:error] [pid 1017536:tid 1017736] [client 68.155.159.216:18326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/radio.php"] [unique_id "apK9NCJcY4fy7tP-rU0E7gAAAlo"] [Sat Aug 29 05:06:28.602765 2026] [security2:error] [pid 1017536:tid 1017687] [client 68.155.159.216:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/install.php"] [unique_id "apK9NCJcY4fy7tP-rU0E8AAAAik"] [Sat Aug 29 05:06:28.614350 2026] [security2:error] [pid 1017536:tid 1017753] [client 52.139.37.240:31166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-content/155.php"] [unique_id "apK9NCJcY4fy7tP-rU0E9QAAAms"] [Sat Aug 29 05:06:28.623475 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:7163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-trackback.php"] [unique_id "apK9NCJcY4fy7tP-rU0E9wAAAkA"] [Sat Aug 29 05:06:28.648197 2026] [security2:error] [pid 1017536:tid 1017696] [client 93.123.109.228:49804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9NCJcY4fy7tP-rU0E_AAAAjI"] [Sat Aug 29 05:06:28.655149 2026] [security2:error] [pid 1017536:tid 1017683] [client 93.123.109.228:49818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9NCJcY4fy7tP-rU0E_QAAAiU"] [Sat Aug 29 05:06:28.655327 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.18.15:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apK9NCJcY4fy7tP-rU0E_gAAAjw"] [Sat Aug 29 05:06:28.658013 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.147.79:50174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/bk/index.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3cgAABcQ"] [Sat Aug 29 05:06:28.659921 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.18.15:23434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/gjewuagf.php"] [unique_id "apK9NCJcY4fy7tP-rU0FAAAAAjE"] [Sat Aug 29 05:06:28.678962 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.18.15:36608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/sushi.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3cwAABhA"] [Sat Aug 29 05:06:28.680397 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.18.15:8015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3dAAABgI"] [Sat Aug 29 05:06:28.680455 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.220.204.93:52304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/to.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3dQAABds"] [Sat Aug 29 05:06:28.686720 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.48.251.3:3144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/agg.php"] [unique_id "apK9NCJcY4fy7tP-rU0FBAAAAlU"] [Sat Aug 29 05:06:28.687998 2026] [security2:error] [pid 1017536:tid 1017778] [client 52.139.37.240:14471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/rtx.php"] [unique_id "apK9NCJcY4fy7tP-rU0FBQAAAoQ"] [Sat Aug 29 05:06:28.703273 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.250.41:25281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/mar.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3dwAABcg"] [Sat Aug 29 05:06:28.724171 2026] [security2:error] [pid 1018003:tid 1018199] [client 93.123.109.228:49724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9NDAh5Y1i2tUxg4H3eAAABeg"] [Sat Aug 29 05:06:28.729482 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.104.62:64645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/see.php"] [unique_id "apK9NCJcY4fy7tP-rU0FCgAAAhw"] [Sat Aug 29 05:06:28.744289 2026] [security2:error] [pid 1018003:tid 1018206] [client 158.158.54.35:2893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/css.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3ewAABe8"] [Sat Aug 29 05:06:28.745495 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.18.15:36627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/file1221.php"] [unique_id "apK9NCJcY4fy7tP-rU0FDQAAAlg"] [Sat Aug 29 05:06:28.752113 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/wp-admin/zwso.php"] [unique_id "apK9NCJcY4fy7tP-rU0FDgAAAnM"] [Sat Aug 29 05:06:28.758382 2026] [security2:error] [pid 1017536:tid 1017669] [client 136.107.231.130:5982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NCJcY4fy7tP-rU0FDwAAAhc"] [Sat Aug 29 05:06:28.759508 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.104.62:52084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/x23.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3fAAABdA"] [Sat Aug 29 05:06:28.761141 2026] [security2:error] [pid 1017536:tid 1017707] [client 40.83.93.50:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9NCJcY4fy7tP-rU0FEAAAAj0"] [Sat Aug 29 05:06:28.767919 2026] [security2:error] [pid 1017536:tid 1017729] [client 136.107.231.130:5978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK9NCJcY4fy7tP-rU0FEgAAAlM"] [Sat Aug 29 05:06:28.768044 2026] [security2:error] [pid 1017536:tid 1017729] [client 136.107.231.130:5978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK9NCJcY4fy7tP-rU0FEgAAAlM"] [Sat Aug 29 05:06:28.774118 2026] [security2:error] [pid 1018003:tid 1018188] [client 68.155.159.216:50371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-blog-header.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3gAAABd0"] [Sat Aug 29 05:06:28.774529 2026] [security2:error] [pid 1018003:tid 1018160] [client 136.107.231.130:5976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/root/.ssh/id_rsa"] [unique_id "apK9NDAh5Y1i2tUxg4H3fgAABcE"] [Sat Aug 29 05:06:28.774599 2026] [security2:error] [pid 1018003:tid 1018169] [client 93.123.109.228:49842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9NDAh5Y1i2tUxg4H3fwAABco"] [Sat Aug 29 05:06:28.777233 2026] [security2:error] [pid 1018003:tid 1018160] [client 93.123.109.228:49858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9NDAh5Y1i2tUxg4H3ggAABcE"] [Sat Aug 29 05:06:28.784541 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.18.15:13205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/robot.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3gwAABio"] [Sat Aug 29 05:06:28.789497 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.104.49.130:36301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/init.php"] [unique_id "apK9NCJcY4fy7tP-rU0FFgAAAmY"] [Sat Aug 29 05:06:28.791394 2026] [security2:error] [pid 1017536:tid 1017712] [client 136.107.231.130:6044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NCJcY4fy7tP-rU0FFAAAAkI"] [Sat Aug 29 05:06:28.794626 2026] [core:error] [pid 1017536:tid 1017673] [client 136.107.231.130:6016] AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) [Sat Aug 29 05:06:28.803112 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.18.15:6988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/pri.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3iQAABiU"] [Sat Aug 29 05:06:28.806320 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.18.15:23488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/tnglzqmv.php"] [unique_id "apK9NCJcY4fy7tP-rU0FIgAAAnc"] [Sat Aug 29 05:06:28.807015 2026] [security2:error] [pid 1017536:tid 1017706] [client 136.107.231.130:6212] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apK9NCJcY4fy7tP-rU0FJAAAAjw"] [Sat Aug 29 05:06:28.808758 2026] [security2:error] [pid 1017536:tid 1017793] [client 136.107.231.130:6078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NCJcY4fy7tP-rU0FHQAAApM"] [Sat Aug 29 05:06:28.810765 2026] [security2:error] [pid 1017536:tid 1017713] [client 136.107.231.130:6004] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apK9NCJcY4fy7tP-rU0FJwAAAkM"] [Sat Aug 29 05:06:28.816557 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.23.147.79:32766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/asd.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3jwAABgE"] [Sat Aug 29 05:06:28.817164 2026] [core:error] [pid 1017536:tid 1017683] [client 136.107.231.130:6032] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) [Sat Aug 29 05:06:28.817661 2026] [security2:error] [pid 1017536:tid 1017778] [client 52.139.37.240:31108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-update.php"] [unique_id "apK9NCJcY4fy7tP-rU0FLAAAAoQ"] [Sat Aug 29 05:06:28.818625 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.251.3:61118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/requirements.php"] [unique_id "apK9NCJcY4fy7tP-rU0FLQAAAos"] [Sat Aug 29 05:06:28.823330 2026] [security2:error] [pid 1017536:tid 1017776] [client 136.107.231.130:6222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NCJcY4fy7tP-rU0FLgAAAoI"] [Sat Aug 29 05:06:28.829119 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.220.204.93:62590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9NCJcY4fy7tP-rU0FMQAAAig"] [Sat Aug 29 05:06:28.829216 2026] [security2:error] [pid 1017536:tid 1017707] [client 168.107.94.195:57514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9NCJcY4fy7tP-rU0FMgAAAj0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:28.835167 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.18.15:36795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/manga.php"] [unique_id "apK9NCJcY4fy7tP-rU0FMwAAAkE"] [Sat Aug 29 05:06:28.840065 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.104.18.15:8103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/sao.php"] [unique_id "apK9NCJcY4fy7tP-rU0FNAAAAlY"] [Sat Aug 29 05:06:28.842948 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.104.62:40195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/.well-known/java.php"] [unique_id "apK9NCJcY4fy7tP-rU0FNQAAAiA"] [Sat Aug 29 05:06:28.856507 2026] [security2:error] [pid 1017536:tid 1017757] [client 68.155.159.216:49195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/file.php"] [unique_id "apK9NCJcY4fy7tP-rU0FOAAAAm8"] [Sat Aug 29 05:06:28.889716 2026] [security2:error] [pid 1017536:tid 1017745] [client 52.139.37.240:14521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/update/da222.php"] [unique_id "apK9NCJcY4fy7tP-rU0FOwAAAmM"] [Sat Aug 29 05:06:28.889753 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.196.209.81:11752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/xmlrpc.php0"] [unique_id "apK9NDAh5Y1i2tUxg4H3kQAABdU"] [Sat Aug 29 05:06:28.891597 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.104.62:48496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/Contrller.php"] [unique_id "apK9NCJcY4fy7tP-rU0FPAAAAjI"] [Sat Aug 29 05:06:28.894622 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.48.250.41:25525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ccu.php"] [unique_id "apK9NCJcY4fy7tP-rU0FPgAAAjw"] [Sat Aug 29 05:06:28.947626 2026] [security2:error] [pid 1018003:tid 1018267] [client 93.123.109.228:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/.env.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3lwAABis"] [Sat Aug 29 05:06:28.949736 2026] [security2:error] [pid 1018003:tid 1018271] [client 93.123.109.228:49842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9NDAh5Y1i2tUxg4H3lgAABi8"] [Sat Aug 29 05:06:28.950182 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.48.251.3:61064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/var/www/wallet/index.php"] [unique_id "apK9NCJcY4fy7tP-rU0FRQAAAoQ"] [Sat Aug 29 05:06:28.959928 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.104.18.15:7074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp_blog_footer.php"] [unique_id "apK9NCJcY4fy7tP-rU0FRgAAAns"] [Sat Aug 29 05:06:28.961188 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.18.15:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/nox.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3mQAABgw"] [Sat Aug 29 05:06:28.963279 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.18.15:13165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/revo.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3mwAABgk"] [Sat Aug 29 05:06:28.970316 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.104.18.15:23485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wefile.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3nQAABjE"] [Sat Aug 29 05:06:28.974694 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.104.104.62:52089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/ws66.php"] [unique_id "apK9NDAh5Y1i2tUxg4H3ngAABbo"] [Sat Aug 29 05:06:28.988394 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.49.130:34547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/dehnl.php"] [unique_id "apK9NCJcY4fy7tP-rU0FRwAAAow"] [Sat Aug 29 05:06:28.991038 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.18.15:8098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/dapa.php"] [unique_id "apK9NCJcY4fy7tP-rU0FSQAAAj8"] [Sat Aug 29 05:06:29.003518 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.104.104.62:64652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/horeg.php"] [unique_id "apK9NSJcY4fy7tP-rU0FTwAAAjo"] [Sat Aug 29 05:06:29.010069 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.220.204.93:59009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/thui.php"] [unique_id "apK9NSJcY4fy7tP-rU0FUAAAAkE"] [Sat Aug 29 05:06:29.014423 2026] [security2:error] [pid 1017536:tid 1017694] [client 52.139.37.240:31042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/xmrlpc.php"] [unique_id "apK9NSJcY4fy7tP-rU0FUQAAAjA"] [Sat Aug 29 05:06:29.023957 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:30658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3ogAABdc"] [Sat Aug 29 05:06:29.031014 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.18.15:36780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/asdfghj.php"] [unique_id "apK9NSJcY4fy7tP-rU0FVAAAAhs"] [Sat Aug 29 05:06:29.034064 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.52.41.200:1790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/radio.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3pAAABdk"] [Sat Aug 29 05:06:29.037461 2026] [security2:error] [pid 1018003:tid 1018259] [client 93.123.109.228:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/.wp-config.php.swp"] [unique_id "apK9NTAh5Y1i2tUxg4H3pQAABiM"] [Sat Aug 29 05:06:29.040109 2026] [security2:error] [pid 1018003:tid 1018167] [client 93.123.109.228:49724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9NTAh5Y1i2tUxg4H3pgAABcg"] [Sat Aug 29 05:06:29.052510 2026] [security2:error] [pid 1017536:tid 1017681] [client 68.155.159.216:51900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9NSJcY4fy7tP-rU0FVQAAAiM"] [Sat Aug 29 05:06:29.064889 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.104.62:48677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/Zeiss.php"] [unique_id "apK9NSJcY4fy7tP-rU0FWAAAAjI"] [Sat Aug 29 05:06:29.074816 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.151.200.44:46653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/Contrller.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3pwAABb0"] [Sat Aug 29 05:06:29.077425 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.48.251.3:62083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/124.php"] [unique_id "apK9NSJcY4fy7tP-rU0FWgAAApM"] [Sat Aug 29 05:06:29.086025 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:30559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9NSJcY4fy7tP-rU0FWwAAAjE"] [Sat Aug 29 05:06:29.090509 2026] [security2:error] [pid 1018003:tid 1018199] [client 93.123.109.228:49744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9NTAh5Y1i2tUxg4H3qAAABeg"] [Sat Aug 29 05:06:29.094620 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:7021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/sushi.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3qQAABec"] [Sat Aug 29 05:06:29.104303 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.18.15:36642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/akismet.php"] [unique_id "apK9NSJcY4fy7tP-rU0FXgAAAkA"] [Sat Aug 29 05:06:29.110199 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.104.18.15:23413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/blog.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3rAAABjQ"] [Sat Aug 29 05:06:29.113632 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.147.79:26577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/file.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3rQAABfY"] [Sat Aug 29 05:06:29.125796 2026] [security2:error] [pid 1017536:tid 1017698] [client 93.123.109.228:49580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FYgAAAjQ"] [Sat Aug 29 05:06:29.137202 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.104.62:42735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/Cok.php"] [unique_id "apK9NSJcY4fy7tP-rU0FZAAAAow"] [Sat Aug 29 05:06:29.148150 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.18.15:13117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/birrs.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3rwAABdg"] [Sat Aug 29 05:06:29.151230 2026] [security2:error] [pid 1017536:tid 1017704] [client 158.23.147.79:24566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9NSJcY4fy7tP-rU0FZgAAAjo"] [Sat Aug 29 05:06:29.161639 2026] [security2:error] [pid 1017536:tid 1017711] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FZwAAAkE"] [Sat Aug 29 05:06:29.161839 2026] [security2:error] [pid 1018003:tid 1018175] [client 4.205.62.107:22213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/maxro.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3sgAABdA"] [Sat Aug 29 05:06:29.161841 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.48.250.41:25533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ak.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3sQAABhY"] [Sat Aug 29 05:06:29.162983 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:8100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-content/l.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3swAABes"] [Sat Aug 29 05:06:29.167726 2026] [security2:error] [pid 1017536:tid 1017694] [client 52.139.37.240:15262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-admin/min.php"] [unique_id "apK9NSJcY4fy7tP-rU0FaQAAAjA"] [Sat Aug 29 05:06:29.168956 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.220.204.93:52340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/Jcrop.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3twAABiw"] [Sat Aug 29 05:06:29.170172 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.147.79:62657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/goat1.php"] [unique_id "apK9NSJcY4fy7tP-rU0FagAAAj0"] [Sat Aug 29 05:06:29.170551 2026] [core:error] [pid 1018003:tid 1018082] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.170740 2026] [core:error] [pid 1018003:tid 1018071] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.202602 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.220.204.93:63857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/motu.php"] [unique_id "apK9NSJcY4fy7tP-rU0FbgAAAl4"] [Sat Aug 29 05:06:29.208775 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.18.15:36827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/dragonshell.php"] [unique_id "apK9NSJcY4fy7tP-rU0FbwAAAnk"] [Sat Aug 29 05:06:29.209740 2026] [security2:error] [pid 1018003:tid 1018172] [client 4.205.62.107:22350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-blog.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3vAAABc0"] [Sat Aug 29 05:06:29.210836 2026] [security2:error] [pid 1018003:tid 1018261] [client 168.107.94.195:58068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3vQAABiU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:29.212552 2026] [security2:error] [pid 1018003:tid 1018195] [client 52.139.37.240:31623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/about/function.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3vgAABeQ"] [Sat Aug 29 05:06:29.216060 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.251.3:3137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/test1.php"] [unique_id "apK9NSJcY4fy7tP-rU0FcAAAAo4"] [Sat Aug 29 05:06:29.224290 2026] [core:error] [pid 1017536:tid 1017706] [client 158.158.54.35:11367] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.224308 2026] [core:error] [pid 1017536:tid 1017706] [client 158.158.54.35:11367] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.229897 2026] [security2:error] [pid 1017536:tid 1017672] [client 40.83.93.50:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/system.php"] [unique_id "apK9NSJcY4fy7tP-rU0FcwAAAho"] [Sat Aug 29 05:06:29.236765 2026] [core:error] [pid 1018003:tid 1018031] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.236781 2026] [core:error] [pid 1018003:tid 1018031] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.237081 2026] [security2:error] [pid 1018003:tid 1018238] [client 93.123.109.228:49744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9NTAh5Y1i2tUxg4H3wgAABg4"] [Sat Aug 29 05:06:29.238245 2026] [core:error] [pid 1018003:tid 1018135] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.238261 2026] [core:error] [pid 1018003:tid 1018135] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.239109 2026] [core:error] [pid 1018003:tid 1018046] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.239375 2026] [core:error] [pid 1018003:tid 1018035] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.243137 2026] [security2:error] [pid 1017536:tid 1017752] [client 158.23.147.79:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/NewFile.php/"] [unique_id "apK9NSJcY4fy7tP-rU0FdAAAAmo"] [Sat Aug 29 05:06:29.248973 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.104.62:48499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/ww2.php"] [unique_id "apK9NSJcY4fy7tP-rU0FdwAAAjE"] [Sat Aug 29 05:06:29.255806 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.104.18.15:23469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3xQAABcs"] [Sat Aug 29 05:06:29.259888 2026] [security2:error] [pid 1017536:tid 1017734] [client 93.123.109.228:49652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FeQAAAlg"] [Sat Aug 29 05:06:29.260156 2026] [security2:error] [pid 1018003:tid 1018157] [client 93.123.109.228:49664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9NTAh5Y1i2tUxg4H3xgAABb4"] [Sat Aug 29 05:06:29.261724 2026] [security2:error] [pid 1017536:tid 1017773] [client 93.123.109.228:49782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9NSJcY4fy7tP-rU0FegAAAn8"] [Sat Aug 29 05:06:29.262757 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.104.62:56347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/basic.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3xwAABi4"] [Sat Aug 29 05:06:29.266996 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.18.15:7160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/manga.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3yAAABeA"] [Sat Aug 29 05:06:29.268635 2026] [security2:error] [pid 1018003:tid 1018180] [client 4.205.62.107:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/infos.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3yQAABdU"] [Sat Aug 29 05:06:29.276567 2026] [security2:error] [pid 1017536:tid 1017704] [client 93.123.109.228:49548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FewAAAjo"] [Sat Aug 29 05:06:29.282641 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.151.200.44:47338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/Zeiss.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3ywAABfo"] [Sat Aug 29 05:06:29.286549 2026] [security2:error] [pid 1017536:tid 1017694] [client 68.155.159.216:33764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9NSJcY4fy7tP-rU0FfQAAAjA"] [Sat Aug 29 05:06:29.290168 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.104.49.130:60767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/df.php"] [unique_id "apK9NSJcY4fy7tP-rU0FfgAAAiI"] [Sat Aug 29 05:06:29.292825 2026] [core:error] [pid 1018003:tid 1018025] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.292846 2026] [core:error] [pid 1018003:tid 1018025] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.294501 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.18.15:8122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-admin/w.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3zQAABgw"] [Sat Aug 29 05:06:29.297327 2026] [security2:error] [pid 1017536:tid 1017757] [client 93.123.109.228:49500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FgAAAAm8"] [Sat Aug 29 05:06:29.308589 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.151.200.44:65066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/alog.php"] [unique_id "apK9NTAh5Y1i2tUxg4H3zgAABfs"] [Sat Aug 29 05:06:29.309818 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.220.204.93:59039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ws58.php"] [unique_id "apK9NTAh5Y1i2tUxg4H30AAABgM"] [Sat Aug 29 05:06:29.309867 2026] [security2:error] [pid 1018003:tid 1018233] [client 158.23.147.79:30545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9NTAh5Y1i2tUxg4H30QAABgk"] [Sat Aug 29 05:06:29.313548 2026] [core:error] [pid 1018003:tid 1018038] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.313564 2026] [core:error] [pid 1018003:tid 1018038] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.324464 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.48.250.41:25455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/lib.php"] [unique_id "apK9NTAh5Y1i2tUxg4H31AAABcw"] [Sat Aug 29 05:06:29.326883 2026] [security2:error] [pid 1017536:tid 1017678] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FgQAAAiA"] [Sat Aug 29 05:06:29.330110 2026] [security2:error] [pid 1017536:tid 1017740] [client 93.123.109.228:49530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FggAAAl4"] [Sat Aug 29 05:06:29.334834 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.104.62:36930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/X7T6.php"] [unique_id "apK9NSJcY4fy7tP-rU0FhAAAAhw"] [Sat Aug 29 05:06:29.342214 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.48.251.3:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/bigdump.php"] [unique_id "apK9NTAh5Y1i2tUxg4H31gAABgI"] [Sat Aug 29 05:06:29.343803 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.196.209.81:16754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/content.php"] [unique_id "apK9NSJcY4fy7tP-rU0FhQAAAls"] [Sat Aug 29 05:06:29.344515 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.18.15:13241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/sss.php"] [unique_id "apK9NTAh5Y1i2tUxg4H31wAABds"] [Sat Aug 29 05:06:29.357473 2026] [core:error] [pid 1018003:tid 1018043] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.357490 2026] [core:error] [pid 1018003:tid 1018043] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.358084 2026] [core:error] [pid 1018003:tid 1018037] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.358098 2026] [core:error] [pid 1018003:tid 1018037] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.358430 2026] [core:error] [pid 1018003:tid 1018102] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.358828 2026] [core:error] [pid 1018003:tid 1018047] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.360041 2026] [security2:error] [pid 1017536:tid 1017672] [client 93.123.109.228:49580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FiAAAAho"] [Sat Aug 29 05:06:29.364709 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.147.79:48335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/admin.php"] [unique_id "apK9NTAh5Y1i2tUxg4H33QAABbw"] [Sat Aug 29 05:06:29.364750 2026] [security2:error] [pid 1018003:tid 1018203] [client 52.139.37.240:15259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK9NTAh5Y1i2tUxg4H33gAABew"] [Sat Aug 29 05:06:29.392078 2026] [security2:error] [pid 1017536:tid 1017781] [client 131.161.79.174:28423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.79.161.131.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michielbon.com"] [uri "/xmlrpc.php"] [unique_id "apK9NSJcY4fy7tP-rU0FjAAAAoc"] [Sat Aug 29 05:06:29.392217 2026] [security2:error] [pid 1017536:tid 1017781] [client 131.161.79.174:28423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "michielbon.com"] [uri "/xmlrpc.php"] [unique_id "apK9NSJcY4fy7tP-rU0FjAAAAoc"] [Sat Aug 29 05:06:29.398965 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.147.79:35795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9NSJcY4fy7tP-rU0FjQAAAjs"] [Sat Aug 29 05:06:29.404928 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.104.62:20645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/images/java.php"] [unique_id "apK9NSJcY4fy7tP-rU0FkQAAAkA"] [Sat Aug 29 05:06:29.412708 2026] [security2:error] [pid 1017536:tid 1017724] [client 52.139.37.240:31085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/an.php"] [unique_id "apK9NSJcY4fy7tP-rU0FlAAAAk4"] [Sat Aug 29 05:06:29.419883 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.104.104.62:43008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/monso.php"] [unique_id "apK9NSJcY4fy7tP-rU0FlQAAAoM"] [Sat Aug 29 05:06:29.420606 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.104.62:48757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/anz.php"] [unique_id "apK9NSJcY4fy7tP-rU0FlgAAAh0"] [Sat Aug 29 05:06:29.425510 2026] [security2:error] [pid 1017536:tid 1017780] [client 93.123.109.228:49652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9NSJcY4fy7tP-rU0FlwAAAoY"] [Sat Aug 29 05:06:29.439203 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.63.81.20:46965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ffs.php"] [unique_id "apK9NSJcY4fy7tP-rU0FmgAAAn8"] [Sat Aug 29 05:06:29.446103 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.220.204.93:59102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/xs.php"] [unique_id "apK9NSJcY4fy7tP-rU0FngAAAj8"] [Sat Aug 29 05:06:29.479188 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.251.3:61189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wdf.php"] [unique_id "apK9NSJcY4fy7tP-rU0FpAAAAjA"] [Sat Aug 29 05:06:29.486212 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.151.200.44:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/wp-wlx.php"] [unique_id "apK9NSJcY4fy7tP-rU0FpwAAAlY"] [Sat Aug 29 05:06:29.487256 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.52.41.200:1279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/item.php"] [unique_id "apK9NTAh5Y1i2tUxg4H35gAABfw"] [Sat Aug 29 05:06:29.503277 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.63.81.20:56927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/AxAo.php"] [unique_id "apK9NSJcY4fy7tP-rU0FrQAAAiM"] [Sat Aug 29 05:06:29.504531 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.220.204.93:64995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/Ov-Simple1.php"] [unique_id "apK9NTAh5Y1i2tUxg4H35wAABcI"] [Sat Aug 29 05:06:29.515123 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:25521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wp-style.php"] [unique_id "apK9NSJcY4fy7tP-rU0FrwAAAmM"] [Sat Aug 29 05:06:29.526786 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.104.62:42659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/see.php"] [unique_id "apK9NSJcY4fy7tP-rU0FsQAAAis"] [Sat Aug 29 05:06:29.548902 2026] [core:error] [pid 1018003:tid 1018052] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.garyandelaine.strangeworx.com [Sat Aug 29 05:06:29.548926 2026] [core:error] [pid 1018003:tid 1018052] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.garyandelaine.strangeworx.com [Sat Aug 29 05:06:29.552670 2026] [core:error] [pid 1018003:tid 1018055] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.552689 2026] [core:error] [pid 1018003:tid 1018055] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.552710 2026] [core:error] [pid 1018003:tid 1018054] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.554029 2026] [security2:error] [pid 1017536:tid 1017696] [client 4.205.62.107:22268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/cp2.php"] [unique_id "apK9NSJcY4fy7tP-rU0FtgAAAjI"] [Sat Aug 29 05:06:29.554762 2026] [core:error] [pid 1018003:tid 1018056] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.554784 2026] [core:error] [pid 1018003:tid 1018056] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.555246 2026] [core:error] [pid 1018003:tid 1018041] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.555257 2026] [core:error] [pid 1018003:tid 1018041] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.557122 2026] [core:error] [pid 1018003:tid 1018044] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.557138 2026] [core:error] [pid 1018003:tid 1018044] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.557447 2026] [core:error] [pid 1018003:tid 1018048] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.560511 2026] [security2:error] [pid 1017536:tid 1017748] [client 52.139.37.240:14524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK9NSJcY4fy7tP-rU0FtwAAAmY"] [Sat Aug 29 05:06:29.571188 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.63.81.20:46902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/nano.php"] [unique_id "apK9NSJcY4fy7tP-rU0FuQAAAkA"] [Sat Aug 29 05:06:29.586680 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.104.62:56362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/rce.php"] [unique_id "apK9NSJcY4fy7tP-rU0FvAAAAh0"] [Sat Aug 29 05:06:29.590219 2026] [security2:error] [pid 1017536:tid 1017706] [client 4.205.62.107:8961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/xp.php"] [unique_id "apK9NSJcY4fy7tP-rU0FvQAAAjw"] [Sat Aug 29 05:06:29.590931 2026] [security2:error] [pid 1017536:tid 1017773] [client 168.107.94.195:58416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9NSJcY4fy7tP-rU0FvgAAAn8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:29.604390 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.48.251.3:61204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/bb.php"] [unique_id "apK9NSJcY4fy7tP-rU0FwQAAAi0"] [Sat Aug 29 05:06:29.606524 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.104.104.62:48631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/bge.php"] [unique_id "apK9NSJcY4fy7tP-rU0FwgAAAj0"] [Sat Aug 29 05:06:29.610474 2026] [security2:error] [pid 1018003:tid 1018248] [client 52.139.37.240:31521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/asw.php"] [unique_id "apK9NTAh5Y1i2tUxg4H39wAABhg"] [Sat Aug 29 05:06:29.643217 2026] [core:error] [pid 1018003:tid 1018049] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.garyandelaine.strangeworx.com [Sat Aug 29 05:06:29.643233 2026] [core:error] [pid 1018003:tid 1018049] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.garyandelaine.strangeworx.com [Sat Aug 29 05:06:29.644970 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.63.81.20:60478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/class17.php"] [unique_id "apK9NSJcY4fy7tP-rU0FxQAAAow"] [Sat Aug 29 05:06:29.668687 2026] [core:error] [pid 1018003:tid 1018050] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.671533 2026] [core:error] [pid 1018003:tid 1018051] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.671552 2026] [core:error] [pid 1018003:tid 1018051] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.672228 2026] [core:error] [pid 1018003:tid 1018040] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.672240 2026] [core:error] [pid 1018003:tid 1018040] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.673433 2026] [core:error] [pid 1018003:tid 1018050] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.673449 2026] [core:error] [pid 1018003:tid 1018050] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.673812 2026] [core:error] [pid 1018003:tid 1018053] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.673995 2026] [core:error] [pid 1018003:tid 1018057] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.674007 2026] [core:error] [pid 1018003:tid 1018057] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.675022 2026] [core:error] [pid 1018003:tid 1018061] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.677256 2026] [core:error] [pid 1018003:tid 1018072] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.677272 2026] [core:error] [pid 1018003:tid 1018072] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.678500 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.151.200.44:47335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/ww2.php"] [unique_id "apK9NSJcY4fy7tP-rU0FyQAAAoI"] [Sat Aug 29 05:06:29.681602 2026] [core:error] [pid 1018003:tid 1018060] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.681614 2026] [core:error] [pid 1018003:tid 1018060] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.682986 2026] [core:error] [pid 1018003:tid 1018169] [client 158.158.54.35:20661] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.683001 2026] [core:error] [pid 1018003:tid 1018169] [client 158.158.54.35:20661] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.689545 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.104.104.62:42715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/horeg.php"] [unique_id "apK9NSJcY4fy7tP-rU0FygAAAlM"] [Sat Aug 29 05:06:29.690952 2026] [security2:error] [pid 1017536:tid 1017743] [client 68.155.159.216:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/languages/about.php"] [unique_id "apK9NSJcY4fy7tP-rU0FywAAAmE"] [Sat Aug 29 05:06:29.692993 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.250.41:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/browse.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4BwAABcM"] [Sat Aug 29 05:06:29.695635 2026] [core:error] [pid 1018003:tid 1018084] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.695654 2026] [core:error] [pid 1018003:tid 1018084] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.696306 2026] [core:error] [pid 1018003:tid 1018058] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.696315 2026] [core:error] [pid 1018003:tid 1018022] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.696320 2026] [core:error] [pid 1018003:tid 1018058] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.696325 2026] [core:error] [pid 1018003:tid 1018022] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.711774 2026] [security2:error] [pid 1017536:tid 1017683] [client 4.205.62.107:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/radio.php"] [unique_id "apK9NSJcY4fy7tP-rU0FzwAAAiU"] [Sat Aug 29 05:06:29.717181 2026] [core:error] [pid 1018003:tid 1018067] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.garyandelaine.strangeworx.com [Sat Aug 29 05:06:29.717207 2026] [core:error] [pid 1018003:tid 1018067] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.garyandelaine.strangeworx.com [Sat Aug 29 05:06:29.717606 2026] [security2:error] [pid 1017536:tid 1017705] [client 40.83.93.50:10119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/test.php"] [unique_id "apK9NSJcY4fy7tP-rU0F0QAAAjs"] [Sat Aug 29 05:06:29.719889 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.63.81.20:46946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ano.php"] [unique_id "apK9NSJcY4fy7tP-rU0F0gAAAnc"] [Sat Aug 29 05:06:29.731486 2026] [security2:error] [pid 1017536:tid 1017746] [client 20.48.251.3:61689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/file59.php"] [unique_id "apK9NSJcY4fy7tP-rU0F0wAAAmQ"] [Sat Aug 29 05:06:29.748033 2026] [security2:error] [pid 1017536:tid 1017686] [client 68.155.159.216:18314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9NSJcY4fy7tP-rU0F1gAAAig"] [Sat Aug 29 05:06:29.754621 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.104.62:64720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/js/java.php"] [unique_id "apK9NSJcY4fy7tP-rU0F1wAAAjE"] [Sat Aug 29 05:06:29.755224 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.104.62:48577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/wp-ana.php"] [unique_id "apK9NSJcY4fy7tP-rU0F2AAAAj8"] [Sat Aug 29 05:06:29.758746 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.104.104.62:4801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/exec.php"] [unique_id "apK9NSJcY4fy7tP-rU0F2QAAAhs"] [Sat Aug 29 05:06:29.766969 2026] [security2:error] [pid 1017536:tid 1017687] [client 158.23.147.79:50150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.spymylink.com"] [uri "/first.php"] [unique_id "apK9NSJcY4fy7tP-rU0F2gAAAik"] [Sat Aug 29 05:06:29.770957 2026] [security2:error] [pid 1017536:tid 1017704] [client 93.123.109.228:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9NSJcY4fy7tP-rU0F2wAAAjo"] [Sat Aug 29 05:06:29.773433 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.63.81.20:56927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/okxoby.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4EQAABiY"] [Sat Aug 29 05:06:29.774134 2026] [security2:error] [pid 1017536:tid 1017753] [client 52.139.37.240:14947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK9NSJcY4fy7tP-rU0F3AAAAms"] [Sat Aug 29 05:06:29.796726 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.151.200.44:64291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/attack.php"] [unique_id "apK9NSJcY4fy7tP-rU0F3wAAApM"] [Sat Aug 29 05:06:29.802522 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.197.61.180:11610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/post.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4FAAABcA"] [Sat Aug 29 05:06:29.804205 2026] [security2:error] [pid 1017536:tid 1017737] [client 68.155.159.216:24523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9NSJcY4fy7tP-rU0F4gAAAls"] [Sat Aug 29 05:06:29.807078 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.220.204.93:63827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/wp-blogs.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4FQAABjM"] [Sat Aug 29 05:06:29.807479 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.196.209.81:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/wxo.php"] [unique_id "apK9NSJcY4fy7tP-rU0F4wAAAho"] [Sat Aug 29 05:06:29.811326 2026] [security2:error] [pid 1017536:tid 1017710] [client 52.139.37.240:31078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/item.php"] [unique_id "apK9NSJcY4fy7tP-rU0F5AAAAkA"] [Sat Aug 29 05:06:29.814018 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.151.200.44:65031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/adin.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4FgAABb4"] [Sat Aug 29 05:06:29.849533 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.63.81.20:46863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/mgrr.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4GQAABfo"] [Sat Aug 29 05:06:29.860825 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.48.251.3:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/cli_bootstrap.php"] [unique_id "apK9NSJcY4fy7tP-rU0F7AAAAoM"] [Sat Aug 29 05:06:29.881068 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.250.41:25476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/zoo.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4HAAABgM"] [Sat Aug 29 05:06:29.882914 2026] [security2:error] [pid 1018003:tid 1018153] [client 68.155.159.216:50248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4HQAABbo"] [Sat Aug 29 05:06:29.885722 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.104.49.130:30075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/reviall.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4HgAABjE"] [Sat Aug 29 05:06:29.887403 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.104.104.62:42698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/basic.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4HwAABcw"] [Sat Aug 29 05:06:29.887449 2026] [security2:error] [pid 1018003:tid 1018174] [client 93.123.109.228:49724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/.wp-config.php.swp"] [unique_id "apK9NTAh5Y1i2tUxg4H4IAAABc8"] [Sat Aug 29 05:06:29.892732 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.49.130:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/xmini4.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4IQAABgk"] [Sat Aug 29 05:06:29.942377 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.147.79:32742] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "database.rfsoftware.com"] [uri "/1.php"] [unique_id "apK9NSJcY4fy7tP-rU0F9QAAAoQ"] [Sat Aug 29 05:06:29.942516 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.147.79:32742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/1.php"] [unique_id "apK9NSJcY4fy7tP-rU0F9QAAAoQ"] [Sat Aug 29 05:06:29.944151 2026] [security2:error] [pid 1018003:tid 1018182] [client 93.123.109.228:49664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9NTAh5Y1i2tUxg4H4IwAABdc"] [Sat Aug 29 05:06:29.944232 2026] [security2:error] [pid 1018003:tid 1018186] [client 93.123.109.228:49744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9NTAh5Y1i2tUxg4H4JAAABds"] [Sat Aug 29 05:06:29.945466 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.104.62:56341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/dbc.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4JQAABhA"] [Sat Aug 29 05:06:29.945719 2026] [security2:error] [pid 1017536:tid 1017773] [client 93.123.109.228:49546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9NSJcY4fy7tP-rU0F9gAAAn8"] [Sat Aug 29 05:06:29.946264 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.52.41.200:1166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/t.php"] [unique_id "apK9NSJcY4fy7tP-rU0F-AAAAiA"] [Sat Aug 29 05:06:29.951198 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.104.104.62:48727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/secret.php"] [unique_id "apK9NSJcY4fy7tP-rU0F-gAAAj8"] [Sat Aug 29 05:06:29.956793 2026] [core:error] [pid 1018003:tid 1018075] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.956814 2026] [core:error] [pid 1018003:tid 1018075] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.964009 2026] [security2:error] [pid 1017536:tid 1017698] [client 68.155.159.216:49189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/file17.php"] [unique_id "apK9NSJcY4fy7tP-rU0F-wAAAjQ"] [Sat Aug 29 05:06:29.973262 2026] [security2:error] [pid 1018003:tid 1018199] [client 168.107.94.195:58851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4KgAABeg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:29.974518 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.151.200.44:45894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/anz.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4KwAABd8"] [Sat Aug 29 05:06:29.978045 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.220.204.93:64285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/mini.php"] [unique_id "apK9NTAh5Y1i2tUxg4H4MAAABec"] [Sat Aug 29 05:06:29.979046 2026] [core:error] [pid 1018003:tid 1018089] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.979066 2026] [core:error] [pid 1018003:tid 1018089] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.980857 2026] [core:error] [pid 1018003:tid 1018070] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.980881 2026] [core:error] [pid 1018003:tid 1018070] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.981636 2026] [core:error] [pid 1018003:tid 1018087] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.981654 2026] [core:error] [pid 1018003:tid 1018087] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.981655 2026] [core:error] [pid 1018003:tid 1018083] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.981662 2026] [core:error] [pid 1018003:tid 1018083] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.981938 2026] [core:error] [pid 1018003:tid 1018146] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.981949 2026] [core:error] [pid 1018003:tid 1018146] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.983133 2026] [core:error] [pid 1018003:tid 1018089] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.983147 2026] [core:error] [pid 1018003:tid 1018089] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.983214 2026] [core:error] [pid 1018003:tid 1018076] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.983224 2026] [core:error] [pid 1018003:tid 1018076] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.984057 2026] [core:error] [pid 1018003:tid 1018092] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.984070 2026] [core:error] [pid 1018003:tid 1018092] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.985189 2026] [core:error] [pid 1018003:tid 1018097] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.985206 2026] [core:error] [pid 1018003:tid 1018097] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.985510 2026] [core:error] [pid 1018003:tid 1018079] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.985524 2026] [core:error] [pid 1018003:tid 1018079] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:29.988991 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.48.251.3:62100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/dd.php"] [unique_id "apK9NSJcY4fy7tP-rU0F_wAAAms"] [Sat Aug 29 05:06:30.007625 2026] [security2:error] [pid 1018003:tid 1018179] [client 52.139.37.240:31156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/jga.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4OAAABdQ"] [Sat Aug 29 05:06:30.008380 2026] [core:error] [pid 1018003:tid 1018065] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.008399 2026] [core:error] [pid 1018003:tid 1018065] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.008688 2026] [security2:error] [pid 1017536:tid 1017706] [client 74.7.175.153:59300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "strangeworxweddingfilms.com"] [uri "/robots.txt"] [unique_id "apK9NSJcY4fy7tP-rU0F9wACPGc"] [Sat Aug 29 05:06:30.037232 2026] [security2:error] [pid 1018003:tid 1018246] [client 52.139.37.240:15272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4OgAABhY"] [Sat Aug 29 05:06:30.048018 2026] [security2:error] [pid 1018003:tid 1018268] [client 93.123.109.228:49694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9NjAh5Y1i2tUxg4H4OwAABiw"] [Sat Aug 29 05:06:30.070596 2026] [security2:error] [pid 1017536:tid 1017717] [client 93.123.109.228:49580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/admin/phpinfo.php"] [unique_id "apK9NiJcY4fy7tP-rU0GCAAAAkc"] [Sat Aug 29 05:06:30.074136 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.23.147.79:25517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/classwithtostring.php"] [unique_id "apK9NiJcY4fy7tP-rU0GCQAAAmY"] [Sat Aug 29 05:06:30.080859 2026] [security2:error] [pid 1017536:tid 1017776] [client 93.123.109.228:49732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GCgAAAoI"] [Sat Aug 29 05:06:30.098984 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.104.62:64743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-content/f0x.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4PgAABd0"] [Sat Aug 29 05:06:30.102562 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.104.62:56383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/wp-wlx.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4PwAABhQ"] [Sat Aug 29 05:06:30.103033 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.220.204.93:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/zu.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4QAAABiU"] [Sat Aug 29 05:06:30.108411 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.48.250.41:25470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/elp.php"] [unique_id "apK9NiJcY4fy7tP-rU0GDAAAAlM"] [Sat Aug 29 05:06:30.108997 2026] [security2:error] [pid 1017536:tid 1017777] [client 20.151.200.44:64389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/sf9.php"] [unique_id "apK9NiJcY4fy7tP-rU0GDgAAAoM"] [Sat Aug 29 05:06:30.110110 2026] [security2:error] [pid 1017536:tid 1017724] [client 93.123.109.228:49708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GDQAAAk4"] [Sat Aug 29 05:06:30.113326 2026] [security2:error] [pid 1018003:tid 1018266] [client 93.123.109.228:49744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9NjAh5Y1i2tUxg4H4QQAABio"] [Sat Aug 29 05:06:30.117382 2026] [security2:error] [pid 1018003:tid 1018172] [client 93.123.109.228:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9NjAh5Y1i2tUxg4H4RgAABc0"] [Sat Aug 29 05:06:30.119456 2026] [core:error] [pid 1018003:tid 1018090] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.119473 2026] [core:error] [pid 1018003:tid 1018090] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.119519 2026] [core:error] [pid 1018003:tid 1018077] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.119530 2026] [core:error] [pid 1018003:tid 1018077] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.119547 2026] [core:error] [pid 1018003:tid 1018134] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.120636 2026] [core:error] [pid 1018003:tid 1018081] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.120652 2026] [core:error] [pid 1018003:tid 1018081] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.120778 2026] [core:error] [pid 1018003:tid 1018095] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.122993 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.48.251.3:61681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-tem.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4TQAABhg"] [Sat Aug 29 05:06:30.124265 2026] [core:error] [pid 1018003:tid 1018063] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.124796 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.184.117:59583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4TgAABik"] [Sat Aug 29 05:06:30.125033 2026] [core:error] [pid 1018003:tid 1018090] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.125037 2026] [core:error] [pid 1018003:tid 1018096] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.125049 2026] [core:error] [pid 1018003:tid 1018096] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.125323 2026] [core:error] [pid 1018003:tid 1018074] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.128904 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.104.62:48607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/pro.php"] [unique_id "apK9NiJcY4fy7tP-rU0GEAAAAjs"] [Sat Aug 29 05:06:30.129238 2026] [security2:error] [pid 1018003:tid 1018207] [client 93.123.109.228:49842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9NjAh5Y1i2tUxg4H4TwAABfA"] [Sat Aug 29 05:06:30.131314 2026] [security2:error] [pid 1017536:tid 1017705] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GEQAAAjs"] [Sat Aug 29 05:06:30.131811 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.151.200.44:62011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/file66.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4UAAABf4"] [Sat Aug 29 05:06:30.133562 2026] [security2:error] [pid 1018003:tid 1018221] [client 68.155.159.216:30607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4UQAABf4"] [Sat Aug 29 05:06:30.139941 2026] [core:error] [pid 1018003:tid 1018091] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.139958 2026] [core:error] [pid 1018003:tid 1018091] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.146389 2026] [security2:error] [pid 1018003:tid 1018224] [client 93.123.109.228:49798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9NjAh5Y1i2tUxg4H4VAAABgE"] [Sat Aug 29 05:06:30.149061 2026] [security2:error] [pid 1017536:tid 1017746] [client 93.123.109.228:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/admin_phpinfo.php"] [unique_id "apK9NiJcY4fy7tP-rU0GEgAAAmQ"] [Sat Aug 29 05:06:30.167048 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.158.54.35:7373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/w.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4VgAABdg"] [Sat Aug 29 05:06:30.174163 2026] [security2:error] [pid 1018003:tid 1018230] [client 68.155.159.216:51434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4VwAABgY"] [Sat Aug 29 05:06:30.179716 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.151.200.44:47359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/bge.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4WQAABdo"] [Sat Aug 29 05:06:30.187528 2026] [core:error] [pid 1018003:tid 1018104] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.187758 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.220.204.93:64904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/amp.php"] [unique_id "apK9NiJcY4fy7tP-rU0GGAAAAhs"] [Sat Aug 29 05:06:30.190809 2026] [core:error] [pid 1018003:tid 1018080] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.202684 2026] [security2:error] [pid 1018003:tid 1018227] [client 52.139.37.240:31111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/mac.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4XgAABgQ"] [Sat Aug 29 05:06:30.204922 2026] [core:error] [pid 1018003:tid 1018059] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.206699 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.196.209.81:16743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/as.php"] [unique_id "apK9NiJcY4fy7tP-rU0GGgAAAjI"] [Sat Aug 29 05:06:30.235813 2026] [core:error] [pid 1018003:tid 1018112] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.237070 2026] [security2:error] [pid 1017536:tid 1017778] [client 52.139.37.240:14915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-info.php"] [unique_id "apK9NiJcY4fy7tP-rU0GHgAAAoQ"] [Sat Aug 29 05:06:30.238161 2026] [core:error] [pid 1018003:tid 1018101] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.244581 2026] [security2:error] [pid 1017536:tid 1017713] [client 93.123.109.228:49868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GIAAAAkM"] [Sat Aug 29 05:06:30.249353 2026] [security2:error] [pid 1017536:tid 1017731] [client 93.123.109.228:49592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GIQAAAlU"] [Sat Aug 29 05:06:30.254823 2026] [security2:error] [pid 1017536:tid 1017686] [client 20.48.251.3:3341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/txets.php"] [unique_id "apK9NiJcY4fy7tP-rU0GIgAAAig"] [Sat Aug 29 05:06:30.254823 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.220.204.93:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/lanka.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4ZAAABgM"] [Sat Aug 29 05:06:30.256923 2026] [core:error] [pid 1018003:tid 1018066] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.267337 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.48.250.41:25494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/666.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4ZwAABcw"] [Sat Aug 29 05:06:30.268483 2026] [security2:error] [pid 1018003:tid 1018233] [client 158.23.147.79:26378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/file17.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4aAAABgk"] [Sat Aug 29 05:06:30.271102 2026] [security2:error] [pid 1018003:tid 1018191] [client 158.23.184.117:59549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4awAABeA"] [Sat Aug 29 05:06:30.271113 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.104.104.62:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/monso.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4agAABiM"] [Sat Aug 29 05:06:30.271128 2026] [core:error] [pid 1018003:tid 1018045] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.271141 2026] [core:error] [pid 1018003:tid 1018045] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.273745 2026] [security2:error] [pid 1017536:tid 1017687] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GJQAAAik"] [Sat Aug 29 05:06:30.285618 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.23.147.79:63828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9NiJcY4fy7tP-rU0GJwAAAmY"] [Sat Aug 29 05:06:30.287929 2026] [core:error] [pid 1018003:tid 1018105] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.299975 2026] [security2:error] [pid 1017536:tid 1017776] [client 4.205.62.107:21606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/phina.php"] [unique_id "apK9NiJcY4fy7tP-rU0GKQAAAoI"] [Sat Aug 29 05:06:30.322668 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.104.104.62:48624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/999.php"] [unique_id "apK9NiJcY4fy7tP-rU0GKwAAAnw"] [Sat Aug 29 05:06:30.327794 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.104.62:64660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/attack.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4dwAABdI"] [Sat Aug 29 05:06:30.328464 2026] [core:error] [pid 1018003:tid 1018107] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.328481 2026] [core:error] [pid 1018003:tid 1018107] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.331426 2026] [core:error] [pid 1018003:tid 1018093] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.331444 2026] [core:error] [pid 1018003:tid 1018093] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.334783 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.49.130:53673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/pfm.php"] [unique_id "apK9NiJcY4fy7tP-rU0GLgAAAow"] [Sat Aug 29 05:06:30.336731 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.220.204.93:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/cc13.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4eAAABdQ"] [Sat Aug 29 05:06:30.347790 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.147.79:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/dropdown.php"] [unique_id "apK9NiJcY4fy7tP-rU0GLwAAAlg"] [Sat Aug 29 05:06:30.351743 2026] [security2:error] [pid 1017536:tid 1017792] [client 4.205.62.107:22454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/update.php"] [unique_id "apK9NiJcY4fy7tP-rU0GMQAAApI"] [Sat Aug 29 05:06:30.355056 2026] [security2:error] [pid 1017536:tid 1017678] [client 168.107.94.195:59295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9NiJcY4fy7tP-rU0GMwAAAiA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:30.368511 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.104.62:64714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-admin/f0x.php"] [unique_id "apK9NiJcY4fy7tP-rU0GNwAAAjI"] [Sat Aug 29 05:06:30.382670 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.48.251.3:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/time.php"] [unique_id "apK9NiJcY4fy7tP-rU0GPAAAAhc"] [Sat Aug 29 05:06:30.384423 2026] [security2:error] [pid 1017536:tid 1017749] [client 93.123.109.228:49656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/api/info.php"] [unique_id "apK9NiJcY4fy7tP-rU0GPQAAAmc"] [Sat Aug 29 05:06:30.389598 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.220.204.93:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/gettest.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4fAAABhY"] [Sat Aug 29 05:06:30.392830 2026] [security2:error] [pid 1018003:tid 1018268] [client 40.83.93.50:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/user/f35.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4fQAABiw"] [Sat Aug 29 05:06:30.396240 2026] [security2:error] [pid 1017536:tid 1017705] [client 52.139.37.240:31622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9NiJcY4fy7tP-rU0GPwAAAjs"] [Sat Aug 29 05:06:30.409074 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.205.62.107:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/env.php"] [unique_id "apK9NiJcY4fy7tP-rU0GQwAAAh0"] [Sat Aug 29 05:06:30.414526 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.52.41.200:1177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/i.php"] [unique_id "apK9NiJcY4fy7tP-rU0GRQAAAmk"] [Sat Aug 29 05:06:30.416729 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.184.117:59559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/admin.php"] [unique_id "apK9NiJcY4fy7tP-rU0GRgAAAoc"] [Sat Aug 29 05:06:30.419469 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.151.200.44:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/zafir1.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4gAAABcI"] [Sat Aug 29 05:06:30.433591 2026] [security2:error] [pid 1017536:tid 1017698] [client 52.139.37.240:15255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK9NiJcY4fy7tP-rU0GSAAAAjQ"] [Sat Aug 29 05:06:30.437061 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.48.250.41:25514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/knmt.php"] [unique_id "apK9NiJcY4fy7tP-rU0GSgAAAik"] [Sat Aug 29 05:06:30.440063 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.151.200.44:65080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/lte7.php"] [unique_id "apK9NiJcY4fy7tP-rU0GSwAAAmY"] [Sat Aug 29 05:06:30.447509 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:30464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/cong.php"] [unique_id "apK9NiJcY4fy7tP-rU0GTQAAAkc"] [Sat Aug 29 05:06:30.455059 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.104.62:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/rce.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4hAAABio"] [Sat Aug 29 05:06:30.464535 2026] [security2:error] [pid 1018003:tid 1018248] [client 93.123.109.228:49842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4hgAABhg"] [Sat Aug 29 05:06:30.470275 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.147.79:48303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/admin.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4iAAABis"] [Sat Aug 29 05:06:30.487885 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.104.62:43049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/file66.php"] [unique_id "apK9NiJcY4fy7tP-rU0GUgAAAnk"] [Sat Aug 29 05:06:30.500349 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.104.62:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-content/uploads/meiwei.php"] [unique_id "apK9NiJcY4fy7tP-rU0GVAAAAn8"] [Sat Aug 29 05:06:30.513343 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.48.251.3:3343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/doc.php"] [unique_id "apK9NiJcY4fy7tP-rU0GVQAAAiA"] [Sat Aug 29 05:06:30.518988 2026] [security2:error] [pid 1017536:tid 1017696] [client 93.123.109.228:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/api/phpinfo.php"] [unique_id "apK9NiJcY4fy7tP-rU0GWAAAAjI"] [Sat Aug 29 05:06:30.525924 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.197.61.180:11647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/flower.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4jAAABbw"] [Sat Aug 29 05:06:30.533389 2026] [core:error] [pid 1018003:tid 1018098] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.533408 2026] [core:error] [pid 1018003:tid 1018098] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.543224 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.220.204.93:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/aa.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4jwAABh8"] [Sat Aug 29 05:06:30.547085 2026] [core:error] [pid 1018003:tid 1018148] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.547103 2026] [core:error] [pid 1018003:tid 1018148] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.549792 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.49.130:47869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/pfm.php"] [unique_id "apK9NiJcY4fy7tP-rU0GXAAAAjs"] [Sat Aug 29 05:06:30.560706 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.104.104.62:48650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/sef.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4kQAABdo"] [Sat Aug 29 05:06:30.561611 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.184.117:59547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/api.php"] [unique_id "apK9NiJcY4fy7tP-rU0GXgAAApI"] [Sat Aug 29 05:06:30.564672 2026] [core:error] [pid 1018003:tid 1018114] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.564689 2026] [core:error] [pid 1018003:tid 1018114] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.570672 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.250.41:25532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/sbhu.php"] [unique_id "apK9NiJcY4fy7tP-rU0GYAAAAis"] [Sat Aug 29 05:06:30.581439 2026] [core:error] [pid 1018003:tid 1018113] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.581454 2026] [core:error] [pid 1018003:tid 1018113] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.585874 2026] [security2:error] [pid 1018003:tid 1018029] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/phpinfo.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4lQAFwAg"] [Sat Aug 29 05:06:30.586864 2026] [security2:error] [pid 1017536:tid 1017704] [client 93.123.109.228:49754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GYgAAAjo"] [Sat Aug 29 05:06:30.611700 2026] [security2:error] [pid 1018003:tid 1018118] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/info.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4lwAFvmE"] [Sat Aug 29 05:06:30.611709 2026] [core:error] [pid 1017536:tid 1017753] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.611728 2026] [core:error] [pid 1017536:tid 1017753] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.612651 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.220.204.93:52331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/35.php"] [unique_id "apK9NiJcY4fy7tP-rU0GZgAAAhs"] [Sat Aug 29 05:06:30.614651 2026] [security2:error] [pid 1017536:tid 1017780] [client 52.139.37.240:31053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9NiJcY4fy7tP-rU0GaAAAAoY"] [Sat Aug 29 05:06:30.617773 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.158.54.35:2807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/ahax.php"] [unique_id "apK9NiJcY4fy7tP-rU0GaQAAAjE"] [Sat Aug 29 05:06:30.631785 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.196.209.81:11545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/room.php"] [unique_id "apK9NiJcY4fy7tP-rU0GbAAAAow"] [Sat Aug 29 05:06:30.631896 2026] [security2:error] [pid 1018003:tid 1018262] [client 52.139.37.240:14929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/ws49.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4mwAABiY"] [Sat Aug 29 05:06:30.642629 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.48.251.3:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/classsmtps.php"] [unique_id "apK9NiJcY4fy7tP-rU0GbgAAApM"] [Sat Aug 29 05:06:30.680623 2026] [security2:error] [pid 1017536:tid 1017686] [client 68.155.159.216:56525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9NiJcY4fy7tP-rU0GdQAAAig"] [Sat Aug 29 05:06:30.683252 2026] [security2:error] [pid 1017536:tid 1017675] [client 93.123.109.228:49548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GdgAAAh0"] [Sat Aug 29 05:06:30.701328 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.151.200.44:46643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/wp-ana.php"] [unique_id "apK9NiJcY4fy7tP-rU0GeQAAAoc"] [Sat Aug 29 05:06:30.706580 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.184.117:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/chosen.php"] [unique_id "apK9NiJcY4fy7tP-rU0GfAAAAiA"] [Sat Aug 29 05:06:30.711879 2026] [security2:error] [pid 1018003:tid 1018108] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/app_dev.php/_profiler"] [unique_id "apK9NjAh5Y1i2tUxg4H4oAAF-1c"] [Sat Aug 29 05:06:30.719787 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.104.104.62:64692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/zafir1.php"] [unique_id "apK9NiJcY4fy7tP-rU0GgAAAAik"] [Sat Aug 29 05:06:30.722033 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.250.41:25558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/a332.php"] [unique_id "apK9NiJcY4fy7tP-rU0GgQAAAjo"] [Sat Aug 29 05:06:30.724840 2026] [security2:error] [pid 1017536:tid 1017680] [client 93.123.109.228:49818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/admin/phpinfo.php"] [unique_id "apK9NiJcY4fy7tP-rU0GggAAAiI"] [Sat Aug 29 05:06:30.733823 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.205.62.107:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wp-konfig.backup.php"] [unique_id "apK9NiJcY4fy7tP-rU0GgwAAAlY"] [Sat Aug 29 05:06:30.741811 2026] [security2:error] [pid 1018003:tid 1018103] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/test.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4owAGI1I"] [Sat Aug 29 05:06:30.746204 2026] [security2:error] [pid 1018003:tid 1018109] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/app_dev.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4pAAF4Fg"] [Sat Aug 29 05:06:30.750176 2026] [security2:error] [pid 1017536:tid 1017695] [client 68.155.159.216:16138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/x/index.php"] [unique_id "apK9NiJcY4fy7tP-rU0GhwAAAjE"] [Sat Aug 29 05:06:30.751485 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.151.200.44:65477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/console.php"] [unique_id "apK9NiJcY4fy7tP-rU0GiAAAAi0"] [Sat Aug 29 05:06:30.753584 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.104.104.62:48511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/admin123.php"] [unique_id "apK9NiJcY4fy7tP-rU0GiQAAAhw"] [Sat Aug 29 05:06:30.754160 2026] [security2:error] [pid 1017536:tid 1017767] [client 168.107.94.195:59643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9NiJcY4fy7tP-rU0GigAAAnk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:30.755560 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.220.204.93:64994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/s1.php"] [unique_id "apK9NiJcY4fy7tP-rU0GiwAAAls"] [Sat Aug 29 05:06:30.759805 2026] [security2:error] [pid 1017536:tid 1017694] [client 93.123.109.228:49732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/admin_phpinfo.php"] [unique_id "apK9NiJcY4fy7tP-rU0GjAAAAjA"] [Sat Aug 29 05:06:30.760930 2026] [security2:error] [pid 1018003:tid 1018106] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/i.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4pwAFz1U"] [Sat Aug 29 05:06:30.765250 2026] [core:error] [pid 1018003:tid 1018069] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.765268 2026] [core:error] [pid 1018003:tid 1018069] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.765345 2026] [core:error] [pid 1018003:tid 1018111] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.765365 2026] [core:error] [pid 1018003:tid 1018111] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.767390 2026] [security2:error] [pid 1017536:tid 1017793] [client 93.123.109.228:49708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GjQAAApM"] [Sat Aug 29 05:06:30.770181 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.251.3:62132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/cache-compat.php"] [unique_id "apK9NiJcY4fy7tP-rU0GjgAAAj0"] [Sat Aug 29 05:06:30.774550 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.151.200.44:64973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/tanjiro.php"] [unique_id "apK9NiJcY4fy7tP-rU0GjwAAAhc"] [Sat Aug 29 05:06:30.781332 2026] [core:error] [pid 1018003:tid 1018068] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.781348 2026] [core:error] [pid 1018003:tid 1018068] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.781563 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.104.62:23397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/exec.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4qgAABdc"] [Sat Aug 29 05:06:30.787520 2026] [security2:error] [pid 1017536:tid 1017705] [client 93.123.109.228:49600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9NiJcY4fy7tP-rU0GkQAAAjs"] [Sat Aug 29 05:06:30.789493 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.104.62:40213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/f0x.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4qwAABgI"] [Sat Aug 29 05:06:30.799697 2026] [security2:error] [pid 1018003:tid 1018240] [client 93.123.109.228:49664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9NjAh5Y1i2tUxg4H4rAAABhA"] [Sat Aug 29 05:06:30.803837 2026] [security2:error] [pid 1018003:tid 1018164] [client 93.123.109.228:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9NjAh5Y1i2tUxg4H4rQAABcU"] [Sat Aug 29 05:06:30.808266 2026] [security2:error] [pid 1018003:tid 1018199] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9NjAh5Y1i2tUxg4H4rgAABeg"] [Sat Aug 29 05:06:30.811402 2026] [security2:error] [pid 1017536:tid 1017780] [client 52.139.37.240:31159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/zafir1.php"] [unique_id "apK9NiJcY4fy7tP-rU0GkwAAAoY"] [Sat Aug 29 05:06:30.840455 2026] [security2:error] [pid 1017536:tid 1017745] [client 52.139.37.240:14937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/xxx.php"] [unique_id "apK9NiJcY4fy7tP-rU0GmQAAAmM"] [Sat Aug 29 05:06:30.850024 2026] [security2:error] [pid 1017536:tid 1017680] [client 4.205.62.107:56022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/xa.php"] [unique_id "apK9NiJcY4fy7tP-rU0GnAAAAiI"] [Sat Aug 29 05:06:30.850060 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.220.204.93:52321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/maraz.php"] [unique_id "apK9NiJcY4fy7tP-rU0GmwAAAoI"] [Sat Aug 29 05:06:30.853159 2026] [core:error] [pid 1018003:tid 1018027] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.853173 2026] [core:error] [pid 1018003:tid 1018027] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.855668 2026] [core:error] [pid 1018003:tid 1018121] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.855683 2026] [core:error] [pid 1018003:tid 1018121] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.856777 2026] [security2:error] [pid 1017536:tid 1017773] [client 158.23.184.117:21532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/config.php"] [unique_id "apK9NiJcY4fy7tP-rU0GnQAAAn8"] [Sat Aug 29 05:06:30.861946 2026] [security2:error] [pid 1017536:tid 1017733] [client 40.83.93.50:23938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/user/min.php"] [unique_id "apK9NiJcY4fy7tP-rU0GoAAAAlc"] [Sat Aug 29 05:06:30.871538 2026] [core:error] [pid 1018003:tid 1018122] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.871554 2026] [core:error] [pid 1018003:tid 1018122] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.872018 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.52.41.200:1247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/deepseek_d.php"] [unique_id "apK9NiJcY4fy7tP-rU0GoQAAAmY"] [Sat Aug 29 05:06:30.895022 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.48.251.3:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/aws_keys.php"] [unique_id "apK9NiJcY4fy7tP-rU0GowAAAi0"] [Sat Aug 29 05:06:30.900164 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.250.41:25562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ws66.php"] [unique_id "apK9NiJcY4fy7tP-rU0GpQAAAow"] [Sat Aug 29 05:06:30.909851 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.63.81.20:43587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/esuutzzx.php"] [unique_id "apK9NiJcY4fy7tP-rU0GpwAAAmo"] [Sat Aug 29 05:06:30.920228 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.104.62:43013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/console.php"] [unique_id "apK9NiJcY4fy7tP-rU0GqgAAAjs"] [Sat Aug 29 05:06:30.921182 2026] [core:error] [pid 1018003:tid 1018116] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.921202 2026] [core:error] [pid 1018003:tid 1018116] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.921254 2026] [core:error] [pid 1018003:tid 1018117] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.921266 2026] [core:error] [pid 1018003:tid 1018117] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.934032 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.104.62:48694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/7h.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4ugAABjU"] [Sat Aug 29 05:06:30.942544 2026] [core:error] [pid 1018003:tid 1018123] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.942565 2026] [core:error] [pid 1018003:tid 1018123] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.958181 2026] [core:error] [pid 1018003:tid 1018126] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.958200 2026] [core:error] [pid 1018003:tid 1018126] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.959327 2026] [core:error] [pid 1018003:tid 1018138] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.959349 2026] [core:error] [pid 1018003:tid 1018138] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:30.960394 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.104.62:23364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/dbc.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4wgAABd0"] [Sat Aug 29 05:06:30.978926 2026] [security2:error] [pid 1017536:tid 1017711] [client 93.123.109.228:49804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/api/info.php"] [unique_id "apK9NiJcY4fy7tP-rU0GsQAAAkE"] [Sat Aug 29 05:06:31.000054 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.151.200.44:47334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/secret.php"] [unique_id "apK9NjAh5Y1i2tUxg4H4xgAABio"] [Sat Aug 29 05:06:31.000276 2026] [security2:error] [pid 1017536:tid 1017776] [client 35.198.240.194:64568] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NiJcY4fy7tP-rU0GswAAAoI"] [Sat Aug 29 05:06:31.000763 2026] [security2:error] [pid 1018003:tid 1018207] [client 35.198.240.194:64546] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/config/firebase-admin.json"] [unique_id "apK9NzAh5Y1i2tUxg4H4yAAABfA"] [Sat Aug 29 05:06:31.001939 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.184.117:59553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/core.php"] [unique_id "apK9NzAh5Y1i2tUxg4H4ywAABcg"] [Sat Aug 29 05:06:31.004461 2026] [security2:error] [pid 1017536:tid 1017773] [client 35.198.240.194:64530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.omni-staffing.com"] [uri "/config/gcp-credentials.json"] [unique_id "apK9NyJcY4fy7tP-rU0GuQAAAn8"] [Sat Aug 29 05:06:31.005840 2026] [security2:error] [pid 1018003:tid 1018244] [client 35.198.240.194:64516] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NjAh5Y1i2tUxg4H4xQAABhQ"] [Sat Aug 29 05:06:31.011445 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.63.81.20:46931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/mac.php"] [unique_id "apK9NyJcY4fy7tP-rU0GwwAAAnM"] [Sat Aug 29 05:06:31.013257 2026] [security2:error] [pid 1018003:tid 1018221] [client 35.198.240.194:64588] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NzAh5Y1i2tUxg4H40QAABf4"] [Sat Aug 29 05:06:31.017343 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.220.204.93:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/kbfr.php"] [unique_id "apK9NzAh5Y1i2tUxg4H41AAABgc"] [Sat Aug 29 05:06:31.018320 2026] [security2:error] [pid 1017536:tid 1017753] [client 35.198.240.194:64496] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NiJcY4fy7tP-rU0GtgAAAms"] [Sat Aug 29 05:06:31.020872 2026] [security2:error] [pid 1017536:tid 1017743] [client 35.198.240.194:64642] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NyJcY4fy7tP-rU0GwgAAAmE"] [Sat Aug 29 05:06:31.020962 2026] [security2:error] [pid 1017536:tid 1017694] [client 35.198.240.194:64684] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9NyJcY4fy7tP-rU0GxQAAAjA"] [Sat Aug 29 05:06:31.022136 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.48.251.3:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/umgebung.php"] [unique_id "apK9NyJcY4fy7tP-rU0GzAAAAow"] [Sat Aug 29 05:06:31.026768 2026] [security2:error] [pid 1018003:tid 1018212] [client 52.139.37.240:31147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/abc.php"] [unique_id "apK9NzAh5Y1i2tUxg4H41wAABfU"] [Sat Aug 29 05:06:31.038314 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.151.200.44:64967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/Rk41.php"] [unique_id "apK9NzAh5Y1i2tUxg4H42AAABbk"] [Sat Aug 29 05:06:31.040493 2026] [security2:error] [pid 1018003:tid 1018261] [client 52.139.37.240:15287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/0x.php"] [unique_id "apK9NzAh5Y1i2tUxg4H42QAABiU"] [Sat Aug 29 05:06:31.053384 2026] [security2:error] [pid 1018003:tid 1018170] [client 93.123.109.228:49910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/api/phpinfo.php"] [unique_id "apK9NzAh5Y1i2tUxg4H42gAABcs"] [Sat Aug 29 05:06:31.056503 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.147.79:32731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/ws.php"] [unique_id "apK9NzAh5Y1i2tUxg4H43AAABd4"] [Sat Aug 29 05:06:31.057468 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.48.250.41:25472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ws68.php"] [unique_id "apK9NyJcY4fy7tP-rU0G0AAAAk0"] [Sat Aug 29 05:06:31.065652 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.158.54.35:35225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/shell.php"] [unique_id "apK9NyJcY4fy7tP-rU0G0wAAAoQ"] [Sat Aug 29 05:06:31.068045 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.63.81.20:56931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/replace.php"] [unique_id "apK9NyJcY4fy7tP-rU0G1AAAAmM"] [Sat Aug 29 05:06:31.075499 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.104.62:64719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-includes/fw.php"] [unique_id "apK9NzAh5Y1i2tUxg4H43gAABb4"] [Sat Aug 29 05:06:31.090563 2026] [security2:error] [pid 1018003:tid 1018262] [client 68.155.159.216:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/file5.php"] [unique_id "apK9NzAh5Y1i2tUxg4H43wAABiY"] [Sat Aug 29 05:06:31.101546 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:48590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/wp-gzone.php"] [unique_id "apK9NyJcY4fy7tP-rU0G1wAAAlo"] [Sat Aug 29 05:06:31.103240 2026] [core:error] [pid 1018003:tid 1018119] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.103259 2026] [core:error] [pid 1018003:tid 1018119] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.107641 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.49.130:30066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/albin.php"] [unique_id "apK9NyJcY4fy7tP-rU0G2AAAAnk"] [Sat Aug 29 05:06:31.112845 2026] [core:error] [pid 1018003:tid 1018132] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.112866 2026] [core:error] [pid 1018003:tid 1018132] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.120261 2026] [security2:error] [pid 1017536:tid 1017743] [client 45.148.10.62:58036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ninaanddon.strangeworx.com"] [uri "/.env"] [unique_id "apK9NyJcY4fy7tP-rU0G2QAAAmE"] [Sat Aug 29 05:06:31.123381 2026] [core:error] [pid 1018003:tid 1018120] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.123399 2026] [core:error] [pid 1018003:tid 1018120] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.124252 2026] [core:error] [pid 1018003:tid 1018127] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.124254 2026] [core:error] [pid 1018003:tid 1018140] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.124263 2026] [core:error] [pid 1018003:tid 1018127] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.124269 2026] [core:error] [pid 1018003:tid 1018140] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.136780 2026] [security2:error] [pid 1017536:tid 1017737] [client 168.107.94.195:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9NyJcY4fy7tP-rU0G2gAAAls"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:31.141041 2026] [security2:error] [pid 1017536:tid 1017770] [client 93.123.109.228:49548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9NyJcY4fy7tP-rU0G3AAAAnw"] [Sat Aug 29 05:06:31.142737 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/blnux.php"] [unique_id "apK9NyJcY4fy7tP-rU0G3QAAAiU"] [Sat Aug 29 05:06:31.149400 2026] [security2:error] [pid 1017536:tid 1017781] [client 93.123.109.228:49892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9NyJcY4fy7tP-rU0G3gAAAoc"] [Sat Aug 29 05:06:31.149844 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:21515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/data.php"] [unique_id "apK9NyJcY4fy7tP-rU0G3wAAAjE"] [Sat Aug 29 05:06:31.152142 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.48.251.3:61243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/old_phpinfo.php"] [unique_id "apK9NzAh5Y1i2tUxg4H46wAABgk"] [Sat Aug 29 05:06:31.158189 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.63.81.20:46898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/simple.php"] [unique_id "apK9NzAh5Y1i2tUxg4H47QAABdc"] [Sat Aug 29 05:06:31.159709 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.104.62:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/wp-wlx.php"] [unique_id "apK9NzAh5Y1i2tUxg4H47gAABgI"] [Sat Aug 29 05:06:31.168537 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.151.200.44:65517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/blnux.php"] [unique_id "apK9NyJcY4fy7tP-rU0G5QAAAjo"] [Sat Aug 29 05:06:31.173323 2026] [access_compat:error] [pid 1018003:tid 1018130] [remote 34.23.124.185:45960] AH01797: client denied by server configuration: /home2/strangew/public_html/garyandelaine/server-status [Sat Aug 29 05:06:31.174619 2026] [core:error] [pid 1018003:tid 1018130] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.176979 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.220.204.93:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/0byte.php"] [unique_id "apK9NzAh5Y1i2tUxg4H48AAABcU"] [Sat Aug 29 05:06:31.195294 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.63.81.20:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/gulu.php"] [unique_id "apK9NyJcY4fy7tP-rU0G6gAAAoI"] [Sat Aug 29 05:06:31.203542 2026] [security2:error] [pid 1017536:tid 1017761] [client 93.123.109.228:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9NyJcY4fy7tP-rU0G7QAAAnM"] [Sat Aug 29 05:06:31.208939 2026] [core:error] [pid 1018003:tid 1018125] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.208960 2026] [core:error] [pid 1018003:tid 1018125] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.217026 2026] [security2:error] [pid 1018003:tid 1018258] [client 136.107.231.130:6350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H49AAABiI"] [Sat Aug 29 05:06:31.217149 2026] [security2:error] [pid 1018003:tid 1018258] [client 136.107.231.130:6350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H49AAABiI"] [Sat Aug 29 05:06:31.217551 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:25453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/users.php"] [unique_id "apK9NyJcY4fy7tP-rU0G8gAAAj0"] [Sat Aug 29 05:06:31.217999 2026] [security2:error] [pid 1017536:tid 1017793] [client 4.205.62.107:22449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/xda.php"] [unique_id "apK9NyJcY4fy7tP-rU0G8wAAApM"] [Sat Aug 29 05:06:31.219447 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.151.200.44:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/7logs.php"] [unique_id "apK9NyJcY4fy7tP-rU0G9AAAApM"] [Sat Aug 29 05:06:31.221110 2026] [core:error] [pid 1018003:tid 1018129] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.221129 2026] [core:error] [pid 1018003:tid 1018129] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.223432 2026] [security2:error] [pid 1017536:tid 1017694] [client 136.107.231.130:6342] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9NyJcY4fy7tP-rU0G9gAAAjA"] [Sat Aug 29 05:06:31.225335 2026] [security2:error] [pid 1018003:tid 1018139] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H49wAGFnY"] [Sat Aug 29 05:06:31.226170 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.196.209.81:3951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/class-wp-cmd.php"] [unique_id "apK9NzAh5Y1i2tUxg4H4-QAABgQ"] [Sat Aug 29 05:06:31.229080 2026] [security2:error] [pid 1017536:tid 1017778] [client 52.139.37.240:31658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/c1.php"] [unique_id "apK9NyJcY4fy7tP-rU0G-AAAAoQ"] [Sat Aug 29 05:06:31.233729 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.197.61.180:7757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/meta.php"] [unique_id "apK9NyJcY4fy7tP-rU0G-QAAAiA"] [Sat Aug 29 05:06:31.235421 2026] [security2:error] [pid 1017536:tid 1017790] [client 136.107.231.130:6326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/var/task/.env"] [unique_id "apK9NyJcY4fy7tP-rU0G-gAAApA"] [Sat Aug 29 05:06:31.236108 2026] [security2:error] [pid 1017536:tid 1017746] [client 52.139.37.240:15289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/CDX1.php"] [unique_id "apK9NyJcY4fy7tP-rU0G-wAAAmQ"] [Sat Aug 29 05:06:31.241393 2026] [security2:error] [pid 1017536:tid 1017786] [client 68.155.159.216:30676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/simple.php"] [unique_id "apK9NyJcY4fy7tP-rU0G_gAAAow"] [Sat Aug 29 05:06:31.243456 2026] [core:error] [pid 1018003:tid 1018128] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.243470 2026] [core:error] [pid 1018003:tid 1018128] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.244174 2026] [core:error] [pid 1018003:tid 1018137] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.244186 2026] [core:error] [pid 1018003:tid 1018137] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.245191 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.147.79:24565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9NyJcY4fy7tP-rU0G_wAAAnw"] [Sat Aug 29 05:06:31.248531 2026] [security2:error] [pid 1017536:tid 1017769] [client 20.104.104.62:48612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/str.php"] [unique_id "apK9NyJcY4fy7tP-rU0HAAAAAns"] [Sat Aug 29 05:06:31.269204 2026] [security2:error] [pid 1018003:tid 1018088] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env.backup"] [unique_id "apK9NzAh5Y1i2tUxg4H4_QAFwkM"] [Sat Aug 29 05:06:31.281528 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.251.3:3332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.h.marketingmagicsecrets.com"] [uri "/wp-act.php"] [unique_id "apK9NzAh5Y1i2tUxg4H4_wAABcE"] [Sat Aug 29 05:06:31.299554 2026] [security2:error] [pid 1017536:tid 1017709] [client 158.23.184.117:59552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/db-status.php"] [unique_id "apK9NyJcY4fy7tP-rU0HBAAAAj8"] [Sat Aug 29 05:06:31.299781 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.104.62:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-includes/wp_wrong_datlib.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5AQAABik"] [Sat Aug 29 05:06:31.307090 2026] [security2:error] [pid 1018003:tid 1018142] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env.old"] [unique_id "apK9NzAh5Y1i2tUxg4H5AgAGGXk"] [Sat Aug 29 05:06:31.307620 2026] [security2:error] [pid 1018003:tid 1018133] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/api/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H5AwAGGXA"] [Sat Aug 29 05:06:31.312375 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.63.81.20:46963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/xty.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5BAAABeQ"] [Sat Aug 29 05:06:31.316209 2026] [security2:error] [pid 1017536:tid 1017776] [client 136.107.231.130:6364] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9NyJcY4fy7tP-rU0HBgAAAoI"] [Sat Aug 29 05:06:31.316306 2026] [security2:error] [pid 1018003:tid 1018244] [client 93.123.109.228:49982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H5BgAABhQ"] [Sat Aug 29 05:06:31.324741 2026] [security2:error] [pid 1017536:tid 1017687] [client 45.148.10.62:58036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ninaanddon.strangeworx.com"] [uri "/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HCgAAAik"] [Sat Aug 29 05:06:31.325219 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.147.79:30660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9NyJcY4fy7tP-rU0HCwAAAlg"] [Sat Aug 29 05:06:31.326648 2026] [cgid:error] [pid 1018003:tid 1018186] [client 20.52.41.200:1275] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:31.329140 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.63.81.20:43594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/gtghklk.php"] [unique_id "apK9NyJcY4fy7tP-rU0HDQAAAnk"] [Sat Aug 29 05:06:31.336591 2026] [security2:error] [pid 1018003:tid 1018073] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/backend/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H5CQAF8DQ"] [Sat Aug 29 05:06:31.341481 2026] [security2:error] [pid 1018003:tid 1018234] [client 40.83.93.50:1746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/users.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5DAAABgo"] [Sat Aug 29 05:06:31.355089 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.220.204.93:59017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wp-act.php"] [unique_id "apK9NyJcY4fy7tP-rU0HEQAAAlc"] [Sat Aug 29 05:06:31.359159 2026] [security2:error] [pid 1018003:tid 1018141] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/config/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H5DgAFvHg"] [Sat Aug 29 05:06:31.362666 2026] [security2:error] [pid 1018003:tid 1018175] [client 68.155.159.216:18331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/makeasmtp.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5EAAABdA"] [Sat Aug 29 05:06:31.362722 2026] [core:error] [pid 1018003:tid 1018144] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.362743 2026] [core:error] [pid 1018003:tid 1018144] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.365509 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.104.62:43020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/pentest.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5EQAABc0"] [Sat Aug 29 05:06:31.387682 2026] [security2:error] [pid 1018003:tid 1018024] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env.bak"] [unique_id "apK9NzAh5Y1i2tUxg4H5EwAF3AM"] [Sat Aug 29 05:06:31.392626 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.48.250.41:25506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/bzjdlofz.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5FAAABgE"] [Sat Aug 29 05:06:31.404778 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.147.79:62658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5FgAABgY"] [Sat Aug 29 05:06:31.405681 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.147.79:26409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/file5.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5FwAABiU"] [Sat Aug 29 05:06:31.419424 2026] [security2:error] [pid 1017536:tid 1017711] [client 136.107.231.130:6252] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9NyJcY4fy7tP-rU0HGAAAAkE"] [Sat Aug 29 05:06:31.423385 2026] [security2:error] [pid 1018003:tid 1018221] [client 52.139.37.240:31648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/index.php/feed/atom/"] [unique_id "apK9NzAh5Y1i2tUxg4H5GQAABf4"] [Sat Aug 29 05:06:31.424481 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.104.104.62:48591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/mega.php"] [unique_id "apK9NyJcY4fy7tP-rU0HGQAAAjQ"] [Sat Aug 29 05:06:31.426087 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.104.62:23377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/attack.php"] [unique_id "apK9NyJcY4fy7tP-rU0HGwAAAl4"] [Sat Aug 29 05:06:31.426130 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.151.200.44:65068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/sf.php"] [unique_id "apK9NyJcY4fy7tP-rU0HGgAAAoc"] [Sat Aug 29 05:06:31.427304 2026] [core:error] [pid 1018003:tid 1018115] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.427317 2026] [core:error] [pid 1018003:tid 1018115] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.432185 2026] [security2:error] [pid 1018003:tid 1018166] [client 52.139.37.240:15274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/akcc.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5GwAABcc"] [Sat Aug 29 05:06:31.435408 2026] [core:error] [pid 1018003:tid 1018147] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.438970 2026] [security2:error] [pid 1018003:tid 1018157] [client 4.205.62.107:22235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/aws_secret_config.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5HgAABb4"] [Sat Aug 29 05:06:31.439931 2026] [core:error] [pid 1018003:tid 1018145] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.443610 2026] [core:error] [pid 1018003:tid 1018026] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.445369 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.184.117:21518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/f35.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5IAAABbk"] [Sat Aug 29 05:06:31.454996 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.220.204.93:63852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/xr.php"] [unique_id "apK9NyJcY4fy7tP-rU0HIgAAAlY"] [Sat Aug 29 05:06:31.456021 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.151.200.44:47306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/pro.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5IgAABiY"] [Sat Aug 29 05:06:31.465126 2026] [core:error] [pid 1018003:tid 1018030] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.474603 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.52.41.200:1275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5JgAABf8"] [Sat Aug 29 05:06:31.492769 2026] [security2:error] [pid 1017536:tid 1017687] [client 136.107.231.130:6326] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9NyJcY4fy7tP-rU0HJQAAAik"] [Sat Aug 29 05:06:31.508410 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:22419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/fns.php"] [unique_id "apK9NyJcY4fy7tP-rU0HJwAAAnk"] [Sat Aug 29 05:06:31.512298 2026] [core:error] [pid 1018003:tid 1018021] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.520867 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.23.147.79:35245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9NyJcY4fy7tP-rU0HKwAAAoY"] [Sat Aug 29 05:06:31.534135 2026] [core:error] [pid 1018003:tid 1018143] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.536211 2026] [core:error] [pid 1018003:tid 1018028] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.545400 2026] [security2:error] [pid 1018003:tid 1018245] [client 93.123.109.228:49798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H5MQAABhU"] [Sat Aug 29 05:06:31.547807 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.205.62.107:26677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/xve22.php"] [unique_id "apK9NyJcY4fy7tP-rU0HLwAAAi0"] [Sat Aug 29 05:06:31.547857 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.104.62:20804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-admin/wp_wrong_datlib.php"] [unique_id "apK9NyJcY4fy7tP-rU0HMAAAAkA"] [Sat Aug 29 05:06:31.548676 2026] [security2:error] [pid 1017536:tid 1017792] [client 136.107.231.130:6380] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9NyJcY4fy7tP-rU0HMQAAApI"] [Sat Aug 29 05:06:31.560477 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.158.54.35:7391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/elp.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5MgAABdg"] [Sat Aug 29 05:06:31.566137 2026] [security2:error] [pid 1017536:tid 1017731] [client 93.123.109.228:49754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HNQAAAlU"] [Sat Aug 29 05:06:31.569529 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:43057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/6y7t.php"] [unique_id "apK9NyJcY4fy7tP-rU0HNgAAAnM"] [Sat Aug 29 05:06:31.572384 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.48.250.41:25581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/selesai.php"] [unique_id "apK9NyJcY4fy7tP-rU0HNwAAAmc"] [Sat Aug 29 05:06:31.575102 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.104.62:48641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/ww3.php"] [unique_id "apK9NyJcY4fy7tP-rU0HOQAAAl4"] [Sat Aug 29 05:06:31.576711 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.147.79:48206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9NyJcY4fy7tP-rU0HOgAAAoc"] [Sat Aug 29 05:06:31.582283 2026] [security2:error] [pid 1017536:tid 1017680] [client 20.151.200.44:64976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/super.php"] [unique_id "apK9NyJcY4fy7tP-rU0HPAAAAiI"] [Sat Aug 29 05:06:31.592650 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.184.117:21535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5MwAABdQ"] [Sat Aug 29 05:06:31.604619 2026] [security2:error] [pid 1018003:tid 1018184] [client 136.107.231.130:6362] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9NzAh5Y1i2tUxg4H5NAAABdk"] [Sat Aug 29 05:06:31.612602 2026] [core:error] [pid 1018003:tid 1018023] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.612616 2026] [core:error] [pid 1018003:tid 1018023] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.617718 2026] [security2:error] [pid 1017536:tid 1017773] [client 52.139.37.240:31127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/root.php"] [unique_id "apK9NyJcY4fy7tP-rU0HQQAAAn8"] [Sat Aug 29 05:06:31.628365 2026] [security2:error] [pid 1017536:tid 1017673] [client 52.139.37.240:15270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9NyJcY4fy7tP-rU0HQwAAAhs"] [Sat Aug 29 05:06:31.628797 2026] [security2:error] [pid 1017536:tid 1017765] [client 60.243.207.176:60028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9NyJcY4fy7tP-rU0HRAAAAnc"] [Sat Aug 29 05:06:31.628900 2026] [security2:error] [pid 1017536:tid 1017765] [client 60.243.207.176:60028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9NyJcY4fy7tP-rU0HRAAAAnc"] [Sat Aug 29 05:06:31.629776 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.196.209.81:16758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/disagreed.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5NwAABiM"] [Sat Aug 29 05:06:31.639793 2026] [core:error] [pid 1018003:tid 1018033] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.639813 2026] [core:error] [pid 1018003:tid 1018033] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.640562 2026] [core:error] [pid 1018003:tid 1018136] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.640579 2026] [core:error] [pid 1018003:tid 1018136] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.640863 2026] [core:error] [pid 1018003:tid 1018131] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.643010 2026] [core:error] [pid 1018003:tid 1018124] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.644685 2026] [security2:error] [pid 1017536:tid 1017669] [client 93.123.109.228:49600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HRgAAAhc"] [Sat Aug 29 05:06:31.649697 2026] [security2:error] [pid 1018003:tid 1018036] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.github/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H5PgAFwg8"] [Sat Aug 29 05:06:31.669110 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.104.104.62:36929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/file66.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5QAAABcE"] [Sat Aug 29 05:06:31.682847 2026] [security2:error] [pid 1017536:tid 1017691] [client 93.123.109.228:49874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HSgAAAi0"] [Sat Aug 29 05:06:31.686203 2026] [core:error] [pid 1018003:tid 1018100] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.686220 2026] [core:error] [pid 1018003:tid 1018100] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.692037 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.151.200.44:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/pentest.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5RQAABhQ"] [Sat Aug 29 05:06:31.696549 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.220.204.93:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/24.php"] [unique_id "apK9NzAh5Y1i2tUxg4H5RwAABiA"] [Sat Aug 29 05:06:31.697950 2026] [security2:error] [pid 1017536:tid 1017786] [client 93.123.109.228:49636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HTAAAAow"] [Sat Aug 29 05:06:31.706965 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.49.130:43805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/jp.php"] [unique_id "apK9NyJcY4fy7tP-rU0HTgAAAnM"] [Sat Aug 29 05:06:31.709034 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.220.204.93:63816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/h02ugyh.php"] [unique_id "apK9NyJcY4fy7tP-rU0HTwAAAj8"] [Sat Aug 29 05:06:31.710112 2026] [security2:error] [pid 1017536:tid 1017746] [client 93.123.109.228:49652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HUAAAAmQ"] [Sat Aug 29 05:06:31.721795 2026] [security2:error] [pid 1017536:tid 1017729] [client 93.123.109.228:49518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HUwAAAlM"] [Sat Aug 29 05:06:31.725290 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.104.104.62:48579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/sko.php"] [unique_id "apK9NyJcY4fy7tP-rU0HVQAAAkM"] [Sat Aug 29 05:06:31.725810 2026] [core:error] [pid 1018003:tid 1018071] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.725824 2026] [core:error] [pid 1018003:tid 1018071] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.727845 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.250.41:25450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/shlo.php"] [unique_id "apK9NyJcY4fy7tP-rU0HVwAAAmY"] [Sat Aug 29 05:06:31.737569 2026] [security2:error] [pid 1017536:tid 1017686] [client 158.23.184.117:21512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/home.php"] [unique_id "apK9NyJcY4fy7tP-rU0HXAAAAig"] [Sat Aug 29 05:06:31.748268 2026] [core:error] [pid 1018003:tid 1018032] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.748289 2026] [core:error] [pid 1018003:tid 1018032] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.748759 2026] [authz_core:error] [pid 1018003:tid 1018031] [remote 34.23.124.185:45960] AH01630: client denied by server configuration: /home2/strangew/public_html/garyandelaine/.htpasswd [Sat Aug 29 05:06:31.749857 2026] [core:error] [pid 1018003:tid 1018031] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.760528 2026] [security2:error] [pid 1017536:tid 1017696] [client 103.240.76.112:43147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9NyJcY4fy7tP-rU0HYAAAAjI"] [Sat Aug 29 05:06:31.760647 2026] [security2:error] [pid 1017536:tid 1017696] [client 103.240.76.112:43147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9NyJcY4fy7tP-rU0HYAAAAjI"] [Sat Aug 29 05:06:31.764389 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.151.200.44:64404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/lufix1.php"] [unique_id "apK9NyJcY4fy7tP-rU0HYgAAAnc"] [Sat Aug 29 05:06:31.772616 2026] [security2:error] [pid 1017536:tid 1017740] [client 136.107.231.130:6396] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alanmossman.mossmanphoto.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9NyJcY4fy7tP-rU0HYwAAAl4"] [Sat Aug 29 05:06:31.810744 2026] [security2:error] [pid 1017536:tid 1017780] [client 40.83.93.50:1655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK9NyJcY4fy7tP-rU0HbAAAAoY"] [Sat Aug 29 05:06:31.812387 2026] [security2:error] [pid 1017536:tid 1017776] [client 52.139.37.240:31636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/shell.php"] [unique_id "apK9NyJcY4fy7tP-rU0HbQAAAoI"] [Sat Aug 29 05:06:31.818142 2026] [security2:error] [pid 1017536:tid 1017689] [client 52.139.37.240:15266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/s.php"] [unique_id "apK9NyJcY4fy7tP-rU0HbwAAAis"] [Sat Aug 29 05:06:31.821088 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.104.104.62:20614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-content/wp_wrong_datlib.php"] [unique_id "apK9NyJcY4fy7tP-rU0HcQAAAow"] [Sat Aug 29 05:06:31.822742 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.104.62:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/0xs.php"] [unique_id "apK9NyJcY4fy7tP-rU0HcgAAAnM"] [Sat Aug 29 05:06:31.837539 2026] [security2:error] [pid 1017536:tid 1017790] [client 68.155.159.216:9233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/banners/about.php"] [unique_id "apK9NyJcY4fy7tP-rU0HdgAAApA"] [Sat Aug 29 05:06:31.839694 2026] [core:error] [pid 1018003:tid 1018046] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.839715 2026] [core:error] [pid 1018003:tid 1018046] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.841403 2026] [core:error] [pid 1018003:tid 1018035] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.841423 2026] [core:error] [pid 1018003:tid 1018035] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.848318 2026] [core:error] [pid 1018003:tid 1018025] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.848334 2026] [core:error] [pid 1018003:tid 1018025] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.862490 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.220.204.93:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/xxw.php"] [unique_id "apK9NyJcY4fy7tP-rU0HdwAAAiU"] [Sat Aug 29 05:06:31.864897 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.104.62:52047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/zafir1.php"] [unique_id "apK9NyJcY4fy7tP-rU0HeQAAAiA"] [Sat Aug 29 05:06:31.867558 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.220.204.93:59054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/155.php"] [unique_id "apK9NyJcY4fy7tP-rU0HewAAAoI"] [Sat Aug 29 05:06:31.880308 2026] [core:error] [pid 1017536:tid 1017689] [client 45.148.10.62:58036] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.880327 2026] [core:error] [pid 1017536:tid 1017689] [client 45.148.10.62:58036] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.880638 2026] [core:error] [pid 1018003:tid 1018038] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.880656 2026] [core:error] [pid 1018003:tid 1018038] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.880669 2026] [core:error] [pid 1018003:tid 1018034] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.880679 2026] [core:error] [pid 1018003:tid 1018034] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.881456 2026] [security2:error] [pid 1017536:tid 1017709] [client 4.205.62.107:9177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9NyJcY4fy7tP-rU0HgAAAAj8"] [Sat Aug 29 05:06:31.885774 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.23.184.117:21505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/index.php"] [unique_id "apK9NyJcY4fy7tP-rU0HgQAAAms"] [Sat Aug 29 05:06:31.889374 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.151.200.44:46648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/999.php"] [unique_id "apK9NyJcY4fy7tP-rU0HggAAAlM"] [Sat Aug 29 05:06:31.892111 2026] [security2:error] [pid 1017536:tid 1017790] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HgwAAApA"] [Sat Aug 29 05:06:31.893768 2026] [security2:error] [pid 1017536:tid 1017773] [client 20.104.104.62:48745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/zoz.php"] [unique_id "apK9NyJcY4fy7tP-rU0HhAAAAn8"] [Sat Aug 29 05:06:31.901065 2026] [core:error] [pid 1018003:tid 1018043] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.901082 2026] [core:error] [pid 1018003:tid 1018043] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.901847 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.48.250.41:25355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/asax.php"] [unique_id "apK9NyJcY4fy7tP-rU0HhgAAAj0"] [Sat Aug 29 05:06:31.912609 2026] [security2:error] [pid 1017536:tid 1017740] [client 93.123.109.228:49892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HhwAAAl4"] [Sat Aug 29 05:06:31.923113 2026] [core:error] [pid 1018003:tid 1018037] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.928118 2026] [security2:error] [pid 1017536:tid 1017745] [client 197.219.150.206:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9NyJcY4fy7tP-rU0HiwAAAmM"] [Sat Aug 29 05:06:31.928302 2026] [security2:error] [pid 1017536:tid 1017745] [client 197.219.150.206:59746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9NyJcY4fy7tP-rU0HiwAAAmM"] [Sat Aug 29 05:06:31.932063 2026] [security2:error] [pid 1017536:tid 1017683] [client 93.123.109.228:49874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HjgAAAiU"] [Sat Aug 29 05:06:31.935017 2026] [cgid:error] [pid 1018003:tid 1018187] [client 20.52.41.200:1206] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:31.942702 2026] [security2:error] [pid 1018003:tid 1018102] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.ssh/id_rsa"] [unique_id "apK9NzAh5Y1i2tUxg4H5YgAF31E"] [Sat Aug 29 05:06:31.962853 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.197.61.180:7190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/randkeyword.php"] [unique_id "apK9NyJcY4fy7tP-rU0HkQAAAm8"] [Sat Aug 29 05:06:31.967927 2026] [security2:error] [pid 1017536:tid 1017773] [client 68.155.159.216:24551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/login.php"] [unique_id "apK9NyJcY4fy7tP-rU0HkwAAAn8"] [Sat Aug 29 05:06:31.968563 2026] [core:error] [pid 1018003:tid 1018047] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.968584 2026] [core:error] [pid 1018003:tid 1018047] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.970683 2026] [core:error] [pid 1018003:tid 1018052] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.970697 2026] [core:error] [pid 1018003:tid 1018052] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:31.975911 2026] [security2:error] [pid 1017536:tid 1017546] [remote 74.7.227.154:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9NyJcY4fy7tP-rU0HlAACdwk"], referer: https://goodtogo.store/sitemap_index.xml?p=%2Fhome4%2Fsortthru%2Fpublic_html%2Fgoodtogo%2Fwebapp%2Fwp-content%2Fplugins%2Fwp-easycart%2Fadmin%2Finc [Sat Aug 29 05:06:31.977715 2026] [security2:error] [pid 1018003:tid 1018240] [client 93.123.109.228:49744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9NzAh5Y1i2tUxg4H5ZQAABhA"] [Sat Aug 29 05:06:31.977718 2026] [security2:error] [pid 1017536:tid 1017672] [client 93.123.109.228:50032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HlQAAAho"] [Sat Aug 29 05:06:31.984431 2026] [security2:error] [pid 1017536:tid 1017743] [client 93.123.109.228:49754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9NyJcY4fy7tP-rU0HlgAAAmE"] [Sat Aug 29 05:06:31.985593 2026] [security2:error] [pid 1017536:tid 1017673] [client 4.205.62.107:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ws61.php"] [unique_id "apK9NyJcY4fy7tP-rU0HlwAAAhs"] [Sat Aug 29 05:06:32.008073 2026] [security2:error] [pid 1018003:tid 1018259] [client 93.123.109.228:49664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H5ZgAABiM"] [Sat Aug 29 05:06:32.010709 2026] [security2:error] [pid 1018003:tid 1018259] [client 93.123.109.228:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H5ZwAABiM"] [Sat Aug 29 05:06:32.014895 2026] [security2:error] [pid 1018003:tid 1018218] [client 52.139.37.240:31104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5aAAABfs"] [Sat Aug 29 05:06:32.017343 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:14957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/sagax.php"] [unique_id "apK9OCJcY4fy7tP-rU0HmwAAAiA"] [Sat Aug 29 05:06:32.027799 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.184.117:21521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/login.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5aQAABbo"] [Sat Aug 29 05:06:32.031159 2026] [security2:error] [pid 1017536:tid 1017713] [client 68.155.159.216:50261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9OCJcY4fy7tP-rU0HnQAAAkM"] [Sat Aug 29 05:06:32.033838 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.104.62:48467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/mmm.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5awAABiw"] [Sat Aug 29 05:06:32.044441 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.23.147.79:30639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/index.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5bgAABcI"] [Sat Aug 29 05:06:32.045833 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.184.117:46975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wk/admin.php"] [unique_id "apK9OCJcY4fy7tP-rU0HogAAAmE"] [Sat Aug 29 05:06:32.048661 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.158.54.35:14136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/cong.php"] [unique_id "apK9OCJcY4fy7tP-rU0HowAAAh0"] [Sat Aug 29 05:06:32.051953 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.250.41:25467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/fetch.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5bwAABjU"] [Sat Aug 29 05:06:32.061110 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.196.209.81:19453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/class_api.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5cgAABgI"] [Sat Aug 29 05:06:32.062014 2026] [security2:error] [pid 1017536:tid 1017751] [client 93.123.109.228:49892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9OCJcY4fy7tP-rU0HpgAAAmk"] [Sat Aug 29 05:06:32.070969 2026] [core:error] [pid 1018003:tid 1018054] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.073322 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.104.104.62:4825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/waf.php"] [unique_id "apK9OCJcY4fy7tP-rU0HqAAAAoY"] [Sat Aug 29 05:06:32.088864 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.52.41.200:1206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5dQAABds"] [Sat Aug 29 05:06:32.091709 2026] [security2:error] [pid 1017536:tid 1017673] [client 57.141.14.95:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/38/"] [unique_id "apK9OCJcY4fy7tP-rU0HqQAAAhs"] [Sat Aug 29 05:06:32.097640 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.104.62:64722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-content/fw.php"] [unique_id "apK9OCJcY4fy7tP-rU0HrQAAAiU"] [Sat Aug 29 05:06:32.101852 2026] [security2:error] [pid 1017536:tid 1017752] [client 93.123.109.228:49874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9OCJcY4fy7tP-rU0HrgAAAmo"] [Sat Aug 29 05:06:32.107907 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.151.200.44:64413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/hack.php"] [unique_id "apK9OCJcY4fy7tP-rU0HrwAAAoY"] [Sat Aug 29 05:06:32.117587 2026] [core:error] [pid 1018003:tid 1018056] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.117601 2026] [core:error] [pid 1018003:tid 1018056] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.121734 2026] [security2:error] [pid 1018003:tid 1018044] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.ssh/id_dsa"] [unique_id "apK9ODAh5Y1i2tUxg4H5egAF0Bc"] [Sat Aug 29 05:06:32.121966 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:60477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/console.php"] [unique_id "apK9OCJcY4fy7tP-rU0HsQAAAlo"] [Sat Aug 29 05:06:32.122677 2026] [core:error] [pid 1018003:tid 1018048] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.122689 2026] [core:error] [pid 1018003:tid 1018048] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.123756 2026] [core:error] [pid 1018003:tid 1018041] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.123769 2026] [core:error] [pid 1018003:tid 1018041] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.130225 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.151.200.44:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/6y7t.php"] [unique_id "apK9OCJcY4fy7tP-rU0HtQAAAkE"] [Sat Aug 29 05:06:32.137529 2026] [proxy_http:error] [pid 1017536:tid 1017785] (20014)Internal error (specific information not available): [client 34.21.253.104:1152] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.137545 2026] [proxy:error] [pid 1017536:tid 1017785] [client 34.21.253.104:1152] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.bash_profile [Sat Aug 29 05:06:32.143335 2026] [proxy_http:error] [pid 1018003:tid 1018245] (20014)Internal error (specific information not available): [client 34.21.253.104:1204] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.143348 2026] [proxy:error] [pid 1018003:tid 1018245] [client 34.21.253.104:1204] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/service-principal.json [Sat Aug 29 05:06:32.148852 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.220.204.93:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/bolt.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5gwAABdo"] [Sat Aug 29 05:06:32.151390 2026] [security2:error] [pid 1017536:tid 1017696] [client 34.21.253.104:1302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/config.env"] [unique_id "apK9OCJcY4fy7tP-rU0HwQAAAjI"] [Sat Aug 29 05:06:32.156447 2026] [security2:error] [pid 1018003:tid 1018039] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/id_rsa"] [unique_id "apK9ODAh5Y1i2tUxg4H5hQAF3hI"] [Sat Aug 29 05:06:32.162216 2026] [proxy_http:error] [pid 1018003:tid 1018198] (20014)Internal error (specific information not available): [client 34.21.253.104:1280] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.162231 2026] [proxy:error] [pid 1018003:tid 1018198] [client 34.21.253.104:1280] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/openai.json [Sat Aug 29 05:06:32.169645 2026] [security2:error] [pid 1018003:tid 1018049] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/id_dsa"] [unique_id "apK9ODAh5Y1i2tUxg4H5jgAGHxw"] [Sat Aug 29 05:06:32.170412 2026] [security2:error] [pid 1017536:tid 1017736] [client 93.123.109.228:49898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9OCJcY4fy7tP-rU0HzQAAAlo"] [Sat Aug 29 05:06:32.170699 2026] [security2:error] [pid 1017536:tid 1017673] [client 93.123.109.228:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config.php"] [unique_id "apK9OCJcY4fy7tP-rU0HzgAAAhs"] [Sat Aug 29 05:06:32.174081 2026] [proxy_http:error] [pid 1017536:tid 1017746] (20014)Internal error (specific information not available): [client 34.21.253.104:1176] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.174096 2026] [proxy:error] [pid 1017536:tid 1017746] [client 34.21.253.104:1176] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.gcp/service-account.json [Sat Aug 29 05:06:32.176046 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.23.184.117:59520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/logs233/index.php"] [unique_id "apK9OCJcY4fy7tP-rU0HzwAAAnM"] [Sat Aug 29 05:06:32.178802 2026] [security2:error] [pid 1018003:tid 1018166] [client 158.23.147.79:32662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5kAAABcc"] [Sat Aug 29 05:06:32.181147 2026] [proxy_http:error] [pid 1017536:tid 1017705] (20014)Internal error (specific information not available): [client 34.21.253.104:1188] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.181162 2026] [proxy:error] [pid 1017536:tid 1017705] [client 34.21.253.104:1188] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/gcp-service-account.json [Sat Aug 29 05:06:32.187013 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.104.104.62:48687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/advanced.php"] [unique_id "apK9OCJcY4fy7tP-rU0H0QAAAmc"] [Sat Aug 29 05:06:32.187145 2026] [proxy_http:error] [pid 1017536:tid 1017740] (20014)Internal error (specific information not available): [client 34.21.253.104:1342] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.187159 2026] [proxy:error] [pid 1017536:tid 1017740] [client 34.21.253.104:1342] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/client/.env [Sat Aug 29 05:06:32.187939 2026] [security2:error] [pid 1017536:tid 1017711] [client 93.123.109.228:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9OCJcY4fy7tP-rU0H0AAAAkE"] [Sat Aug 29 05:06:32.188978 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.48.250.41:25425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/vx.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5kwAABi4"] [Sat Aug 29 05:06:32.190379 2026] [proxy_http:error] [pid 1018003:tid 1018213] (20014)Internal error (specific information not available): [client 34.21.253.104:1388] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.190397 2026] [proxy:error] [pid 1018003:tid 1018213] [client 34.21.253.104:1388] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.docker [Sat Aug 29 05:06:32.193028 2026] [core:error] [pid 1018003:tid 1018062] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.193046 2026] [core:error] [pid 1018003:tid 1018062] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.194980 2026] [security2:error] [pid 1018003:tid 1018051] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/key.pem"] [unique_id "apK9ODAh5Y1i2tUxg4H5lAAFvh4"] [Sat Aug 29 05:06:32.197698 2026] [proxy_http:error] [pid 1018003:tid 1018198] (20014)Internal error (specific information not available): [client 34.21.253.104:1280] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.197712 2026] [proxy:error] [pid 1018003:tid 1018198] [client 34.21.253.104:1280] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:06:32.198713 2026] [security2:error] [pid 1018003:tid 1018170] [client 158.23.184.117:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/admin.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5lQAABcs"] [Sat Aug 29 05:06:32.205305 2026] [core:error] [pid 1018003:tid 1018040] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.205321 2026] [core:error] [pid 1018003:tid 1018040] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.212629 2026] [security2:error] [pid 1017536:tid 1017773] [client 52.139.37.240:31139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK9OCJcY4fy7tP-rU0H1AAAAn8"] [Sat Aug 29 05:06:32.215125 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.220.204.93:59033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/file.php"] [unique_id "apK9OCJcY4fy7tP-rU0H1QAAAj8"] [Sat Aug 29 05:06:32.216452 2026] [proxy_http:error] [pid 1017536:tid 1017792] (20014)Internal error (specific information not available): [client 34.21.253.104:1372] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:32.216467 2026] [proxy:error] [pid 1017536:tid 1017792] [client 34.21.253.104:1372] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/production/.env [Sat Aug 29 05:06:32.219804 2026] [core:error] [pid 1018003:tid 1018050] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.219818 2026] [core:error] [pid 1018003:tid 1018050] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.220727 2026] [security2:error] [pid 1018003:tid 1018262] [client 93.123.109.228:49982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H5mQAABiY"] [Sat Aug 29 05:06:32.223947 2026] [cgid:error] [pid 1017536:tid 1017689] [client 34.7.40.70:25202] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.224376 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.147.79:25574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/install.php"] [unique_id "apK9OCJcY4fy7tP-rU0H3QAAAlo"] [Sat Aug 29 05:06:32.224440 2026] [cgid:error] [pid 1017536:tid 1017781] [client 34.7.40.70:25226] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.224784 2026] [security2:error] [pid 1018003:tid 1018244] [client 34.7.40.70:25196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.40.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/pi.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5nAAABhQ"] [Sat Aug 29 05:06:32.225659 2026] [security2:error] [pid 1017536:tid 1017723] [client 34.7.40.70:25164] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.htpasswd"] [unique_id "apK9OCJcY4fy7tP-rU0H3wAAAk0"] [Sat Aug 29 05:06:32.225848 2026] [security2:error] [pid 1018003:tid 1018203] [client 34.7.40.70:25274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.bash_history"] [unique_id "apK9ODAh5Y1i2tUxg4H5nQAABew"] [Sat Aug 29 05:06:32.226045 2026] [security2:error] [pid 1017536:tid 1017757] [client 34.7.40.70:25180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.40.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/i.php"] [unique_id "apK9OCJcY4fy7tP-rU0H4AAAAm8"] [Sat Aug 29 05:06:32.226124 2026] [security2:error] [pid 1017536:tid 1017757] [client 34.7.40.70:25180] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/i.php"] [unique_id "apK9OCJcY4fy7tP-rU0H4AAAAm8"] [Sat Aug 29 05:06:32.226171 2026] [security2:error] [pid 1018003:tid 1018256] [client 34.7.40.70:25246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env~"] [unique_id "apK9ODAh5Y1i2tUxg4H5mwAABiA"] [Sat Aug 29 05:06:32.226263 2026] [cgid:error] [pid 1017536:tid 1017767] [client 34.7.40.70:25140] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.226323 2026] [cgid:error] [pid 1017536:tid 1017731] [client 34.7.40.70:25152] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.226622 2026] [cgid:error] [pid 1018003:tid 1018195] [client 34.7.40.70:25212] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.227386 2026] [cgid:error] [pid 1017536:tid 1017678] [client 34.7.40.70:25270] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.229088 2026] [security2:error] [pid 1017536:tid 1017695] [client 34.7.40.70:25258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.env"] [unique_id "apK9OCJcY4fy7tP-rU0H4gAAAjE"] [Sat Aug 29 05:06:32.230410 2026] [security2:error] [pid 1017536:tid 1017675] [client 34.7.40.70:25266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/_next/.env"] [unique_id "apK9OCJcY4fy7tP-rU0H5QAAAh0"] [Sat Aug 29 05:06:32.231164 2026] [cgid:error] [pid 1017536:tid 1017793] [client 34.7.40.70:25244] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.231828 2026] [cgid:error] [pid 1017536:tid 1017713] [client 34.7.40.70:25254] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.232066 2026] [cgid:error] [pid 1017536:tid 1017743] [client 34.7.40.70:25234] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:32.251230 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.104.62:4832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/bnnof6.php"] [unique_id "apK9OCJcY4fy7tP-rU0H6QAAAhc"] [Sat Aug 29 05:06:32.281495 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.104.62:20809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-admin/fw.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5oQAABfU"] [Sat Aug 29 05:06:32.285236 2026] [security2:error] [pid 1018003:tid 1018053] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/privatekey.key"] [unique_id "apK9ODAh5Y1i2tUxg4H5owAF6CA"] [Sat Aug 29 05:06:32.287959 2026] [core:error] [pid 1018003:tid 1018057] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.287977 2026] [core:error] [pid 1018003:tid 1018057] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.288793 2026] [security2:error] [pid 1018003:tid 1018190] [client 52.139.37.240:14963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-content/plugins/ftde.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5pQAABd8"] [Sat Aug 29 05:06:32.290435 2026] [security2:error] [pid 1017536:tid 1017706] [client 93.123.109.228:49548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9OCJcY4fy7tP-rU0H7QAAAjw"] [Sat Aug 29 05:06:32.291693 2026] [security2:error] [pid 1018003:tid 1018155] [client 40.83.93.50:1766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5pgAABbw"] [Sat Aug 29 05:06:32.318495 2026] [security2:error] [pid 1017536:tid 1017781] [client 93.123.109.228:49898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9OCJcY4fy7tP-rU0H8gAAAoc"] [Sat Aug 29 05:06:32.324529 2026] [security2:error] [pid 1018003:tid 1018271] [client 158.23.184.117:21531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/maintenance.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5qgAABi8"] [Sat Aug 29 05:06:32.329480 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.49.130:57517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/yawa.php"] [unique_id "apK9OCJcY4fy7tP-rU0H9wAAAjE"] [Sat Aug 29 05:06:32.335081 2026] [core:error] [pid 1018003:tid 1018060] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.335098 2026] [core:error] [pid 1018003:tid 1018060] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.336953 2026] [security2:error] [pid 1018003:tid 1018161] [client 93.123.109.228:49872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/aws.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5sQAABcI"] [Sat Aug 29 05:06:32.337014 2026] [core:error] [pid 1018003:tid 1018061] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.337026 2026] [core:error] [pid 1018003:tid 1018061] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.337457 2026] [core:error] [pid 1018003:tid 1018072] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.337470 2026] [core:error] [pid 1018003:tid 1018072] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.340101 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.104.62:48586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/blox.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5sgAABjU"] [Sat Aug 29 05:06:32.340241 2026] [core:error] [pid 1018003:tid 1018084] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.340250 2026] [core:error] [pid 1018003:tid 1018084] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.342285 2026] [security2:error] [pid 1017536:tid 1017743] [client 93.123.109.228:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9OCJcY4fy7tP-rU0H-QAAAmE"] [Sat Aug 29 05:06:32.344907 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.184.117:62297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/goods.php"] [unique_id "apK9OCJcY4fy7tP-rU0H-gAAAhw"] [Sat Aug 29 05:06:32.349160 2026] [security2:error] [pid 1017536:tid 1017734] [client 68.155.159.216:30673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-admin/about.php"] [unique_id "apK9OCJcY4fy7tP-rU0H_AAAAlg"] [Sat Aug 29 05:06:32.351495 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.147.79:24532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9OCJcY4fy7tP-rU0H_QAAAiU"] [Sat Aug 29 05:06:32.354116 2026] [security2:error] [pid 1017536:tid 1017732] [client 4.205.62.107:21588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/pinfo.php"] [unique_id "apK9OCJcY4fy7tP-rU0H_wAAAlY"] [Sat Aug 29 05:06:32.359558 2026] [security2:error] [pid 1018003:tid 1018186] [client 68.155.159.216:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5tQAABds"] [Sat Aug 29 05:06:32.366431 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.220.204.93:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9OCJcY4fy7tP-rU0IAQAAAlc"] [Sat Aug 29 05:06:32.367616 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.220.204.93:63835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/rtx.php"] [unique_id "apK9OCJcY4fy7tP-rU0IAgAAAi0"] [Sat Aug 29 05:06:32.370843 2026] [security2:error] [pid 1017536:tid 1017707] [client 93.123.109.228:49500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/config.inc.php"] [unique_id "apK9OCJcY4fy7tP-rU0IAwAAAj0"] [Sat Aug 29 05:06:32.398881 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.250.41:25466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/global.php"] [unique_id "apK9OCJcY4fy7tP-rU0IBwAAAis"] [Sat Aug 29 05:06:32.399469 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.104.104.62:42691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/blnux.php"] [unique_id "apK9OCJcY4fy7tP-rU0ICAAAAk0"] [Sat Aug 29 05:06:32.402290 2026] [security2:error] [pid 1017536:tid 1017724] [client 68.155.159.216:33634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/cong.php"] [unique_id "apK9OCJcY4fy7tP-rU0ICQAAAk4"] [Sat Aug 29 05:06:32.411283 2026] [security2:error] [pid 1018003:tid 1018276] [client 52.139.37.240:31048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-header-json.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5uAAABjQ"] [Sat Aug 29 05:06:32.415718 2026] [security2:error] [pid 1017536:tid 1017678] [client 68.155.159.216:64460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9OCJcY4fy7tP-rU0ICwAAAiA"] [Sat Aug 29 05:06:32.423527 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:30629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/about/function.php"] [unique_id "apK9OCJcY4fy7tP-rU0IDwAAApI"] [Sat Aug 29 05:06:32.435613 2026] [security2:error] [pid 1017536:tid 1017749] [client 93.123.109.228:49548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/config.php"] [unique_id "apK9OCJcY4fy7tP-rU0IEQAAAmc"] [Sat Aug 29 05:06:32.436304 2026] [security2:error] [pid 1018003:tid 1018189] [client 93.123.109.228:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5ugAABd4"] [Sat Aug 29 05:06:32.445236 2026] [security2:error] [pid 1017536:tid 1017778] [client 213.202.253.4:52601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aantec.com"] [uri "/wp-content/schallfuns.php"] [unique_id "apK9OCJcY4fy7tP-rU0IEwAAAoQ"], referer: www.google.com [Sat Aug 29 05:06:32.463001 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.151.200.44:64223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/0xs.php"] [unique_id "apK9OCJcY4fy7tP-rU0IGAAAAlc"] [Sat Aug 29 05:06:32.469189 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.23.184.117:21520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/min.php"] [unique_id "apK9OCJcY4fy7tP-rU0IGQAAApM"] [Sat Aug 29 05:06:32.475451 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.63.81.20:60470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/comand.php"] [unique_id "apK9OCJcY4fy7tP-rU0IGgAAAik"] [Sat Aug 29 05:06:32.480714 2026] [security2:error] [pid 1018003:tid 1018067] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/app/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H5wQAGMy4"] [Sat Aug 29 05:06:32.480895 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.104.62:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/ah24.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5xQAABi4"] [Sat Aug 29 05:06:32.483141 2026] [core:error] [pid 1018003:tid 1018022] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.483160 2026] [core:error] [pid 1018003:tid 1018022] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.483471 2026] [core:error] [pid 1018003:tid 1018070] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.483474 2026] [core:error] [pid 1018003:tid 1018058] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.483489 2026] [core:error] [pid 1018003:tid 1018070] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.483498 2026] [core:error] [pid 1018003:tid 1018058] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.483552 2026] [core:error] [pid 1018003:tid 1018075] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.483558 2026] [core:error] [pid 1018003:tid 1018075] [remote 34.23.124.185:45960] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:32.487053 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.196.209.81:16750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/aksinet.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5yQAABfA"] [Sat Aug 29 05:06:32.489730 2026] [security2:error] [pid 1017536:tid 1017731] [client 158.23.184.117:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/w.php"] [unique_id "apK9OCJcY4fy7tP-rU0IHgAAAlU"] [Sat Aug 29 05:06:32.489808 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.147.79:59872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/.well-known/index.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5ywAABfA"] [Sat Aug 29 05:06:32.492608 2026] [security2:error] [pid 1017536:tid 1017770] [client 52.139.37.240:15251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9OCJcY4fy7tP-rU0IHwAAAnw"] [Sat Aug 29 05:06:32.494927 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.63.81.20:44488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/sallu.php"] [unique_id "apK9OCJcY4fy7tP-rU0IIQAAAm8"] [Sat Aug 29 05:06:32.495808 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.158.54.35:35226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5zQAABcg"] [Sat Aug 29 05:06:32.496247 2026] [security2:error] [pid 1017536:tid 1017689] [client 93.123.109.228:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9OCJcY4fy7tP-rU0IIAAAAis"] [Sat Aug 29 05:06:32.500710 2026] [security2:error] [pid 1018003:tid 1018078] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/src/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H5zgAFuTk"] [Sat Aug 29 05:06:32.506222 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.220.204.93:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/ckk.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5zwAABgw"] [Sat Aug 29 05:06:32.511587 2026] [security2:error] [pid 1017536:tid 1017724] [client 93.123.109.228:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/env.php"] [unique_id "apK9OCJcY4fy7tP-rU0IIgAAAk4"] [Sat Aug 29 05:06:32.513683 2026] [security2:error] [pid 1018003:tid 1018244] [client 158.23.147.79:63834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9ODAh5Y1i2tUxg4H50gAABhQ"] [Sat Aug 29 05:06:32.525773 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.151.200.44:65048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/155.php"] [unique_id "apK9OCJcY4fy7tP-rU0IJQAAApI"] [Sat Aug 29 05:06:32.530505 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.151.200.44:46649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/sef.php"] [unique_id "apK9OCJcY4fy7tP-rU0IJgAAAkM"] [Sat Aug 29 05:06:32.533720 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.52.41.200:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/assets/images/doc.php"] [unique_id "apK9OCJcY4fy7tP-rU0IJwAAAmk"] [Sat Aug 29 05:06:32.539955 2026] [security2:error] [pid 1018003:tid 1018256] [client 68.155.159.216:18192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9ODAh5Y1i2tUxg4H51QAABiA"] [Sat Aug 29 05:06:32.545208 2026] [security2:error] [pid 1018003:tid 1018243] [client 93.123.109.228:49702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/aws.php"] [unique_id "apK9ODAh5Y1i2tUxg4H51gAABhM"] [Sat Aug 29 05:06:32.553366 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.147.79:26611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/file88.php"] [unique_id "apK9OCJcY4fy7tP-rU0IKQAAAhs"] [Sat Aug 29 05:06:32.560558 2026] [security2:error] [pid 1018003:tid 1018083] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H51wAF_z4"] [Sat Aug 29 05:06:32.562463 2026] [security2:error] [pid 1017536:tid 1017669] [client 93.123.109.228:49592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/module.config.php"] [unique_id "apK9OCJcY4fy7tP-rU0ILAAAAhc"] [Sat Aug 29 05:06:32.563310 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.48.250.41:25362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/fs.php"] [unique_id "apK9OCJcY4fy7tP-rU0ILQAAAmo"] [Sat Aug 29 05:06:32.577585 2026] [security2:error] [pid 1017536:tid 1017706] [client 4.205.62.107:22503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/greem_res.php"] [unique_id "apK9OCJcY4fy7tP-rU0ILgAAAjw"] [Sat Aug 29 05:06:32.583990 2026] [security2:error] [pid 1018003:tid 1018180] [client 93.123.109.228:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/config.inc.php"] [unique_id "apK9ODAh5Y1i2tUxg4H52QAABdU"] [Sat Aug 29 05:06:32.588700 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.104.62:48697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/kcs.php"] [unique_id "apK9ODAh5Y1i2tUxg4H52gAABc8"] [Sat Aug 29 05:06:32.598147 2026] [security2:error] [pid 1017536:tid 1017734] [client 93.123.109.228:49530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/nexmo.php"] [unique_id "apK9OCJcY4fy7tP-rU0IMAAAAlg"] [Sat Aug 29 05:06:32.603644 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.63.81.20:60530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apK9OCJcY4fy7tP-rU0IMQAAAlo"] [Sat Aug 29 05:06:32.603952 2026] [security2:error] [pid 1018003:tid 1018273] [client 45.148.10.62:58040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ninaanddon.strangeworx.com"] [uri "/api/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H52wAABjE"] [Sat Aug 29 05:06:32.607319 2026] [security2:error] [pid 1017536:tid 1017683] [client 52.139.37.240:31618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/zup.php"] [unique_id "apK9OCJcY4fy7tP-rU0IMgAAAiU"] [Sat Aug 29 05:06:32.611766 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.220.204.93:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/06.php"] [unique_id "apK9ODAh5Y1i2tUxg4H53AAABdw"] [Sat Aug 29 05:06:32.618614 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.23.184.117:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/module.php"] [unique_id "apK9ODAh5Y1i2tUxg4H53gAABfo"] [Sat Aug 29 05:06:32.624916 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.63.81.20:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/codex.php"] [unique_id "apK9ODAh5Y1i2tUxg4H54AAABbw"] [Sat Aug 29 05:06:32.627730 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.104.49.130:51514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/wp-login.php"] [unique_id "apK9ODAh5Y1i2tUxg4H53QAABd8"] [Sat Aug 29 05:06:32.630885 2026] [security2:error] [pid 1018003:tid 1018087] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/media../.env"] [unique_id "apK9ODAh5Y1i2tUxg4H54gAGL0I"] [Sat Aug 29 05:06:32.634301 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.184.117:46962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/new.php"] [unique_id "apK9OCJcY4fy7tP-rU0INgAAAj0"] [Sat Aug 29 05:06:32.639667 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.23.147.79:35796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9ODAh5Y1i2tUxg4H55AAABiw"] [Sat Aug 29 05:06:32.643135 2026] [security2:error] [pid 1018003:tid 1018146] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/static../.env"] [unique_id "apK9ODAh5Y1i2tUxg4H55QAFun0"] [Sat Aug 29 05:06:32.643223 2026] [security2:error] [pid 1018003:tid 1018089] [remote 34.23.124.185:45960] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK9ODAh5Y1i2tUxg4H55gAFukQ"] [Sat Aug 29 05:06:32.646613 2026] [security2:error] [pid 1018003:tid 1018076] [remote 34.23.124.185:45960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H55wAFujc"] [Sat Aug 29 05:06:32.657529 2026] [security2:error] [pid 1017536:tid 1017678] [client 4.205.62.107:22254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/25.php"] [unique_id "apK9OCJcY4fy7tP-rU0IOAAAAiA"] [Sat Aug 29 05:06:32.660100 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.104.62:43067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/ztv.php"] [unique_id "apK9OCJcY4fy7tP-rU0IOQAAAkA"] [Sat Aug 29 05:06:32.674020 2026] [security2:error] [pid 1017536:tid 1017713] [client 93.123.109.228:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/config/stripe.php"] [unique_id "apK9OCJcY4fy7tP-rU0IPAAAAkM"] [Sat Aug 29 05:06:32.674157 2026] [security2:error] [pid 1017536:tid 1017751] [client 93.123.109.228:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/config.php"] [unique_id "apK9OCJcY4fy7tP-rU0IPQAAAmk"] [Sat Aug 29 05:06:32.685193 2026] [security2:error] [pid 1017536:tid 1017733] [client 158.23.147.79:48323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/classwithtostring.php"] [unique_id "apK9OCJcY4fy7tP-rU0IPwAAAlc"] [Sat Aug 29 05:06:32.685824 2026] [security2:error] [pid 1017536:tid 1017674] [client 4.205.62.107:26631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/06.php"] [unique_id "apK9OCJcY4fy7tP-rU0IQAAAAhw"] [Sat Aug 29 05:06:32.687674 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.197.61.180:11604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/goods.php"] [unique_id "apK9ODAh5Y1i2tUxg4H56gAABdQ"] [Sat Aug 29 05:06:32.691027 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.104.62:20856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wordpress/fw.php"] [unique_id "apK9OCJcY4fy7tP-rU0IQwAAAhc"] [Sat Aug 29 05:06:32.709073 2026] [security2:error] [pid 1018003:tid 1018265] [client 93.123.109.228:49982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/env.php"] [unique_id "apK9ODAh5Y1i2tUxg4H57AAABik"] [Sat Aug 29 05:06:32.722477 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.250.41:25512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ioxi.php"] [unique_id "apK9OCJcY4fy7tP-rU0IRQAAAlY"] [Sat Aug 29 05:06:32.730876 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.220.204.93:64916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldwestradio.livingthecode.org"] [uri "/R57.php"] [unique_id "apK9OCJcY4fy7tP-rU0IRgAAAlo"] [Sat Aug 29 05:06:32.734280 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.63.81.20:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apK9ODAh5Y1i2tUxg4H57wAABdI"] [Sat Aug 29 05:06:32.738027 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.104.62:48755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/wsz.php"] [unique_id "apK9ODAh5Y1i2tUxg4H58AAABeE"] [Sat Aug 29 05:06:32.760004 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.196.209.81:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/post.php"] [unique_id "apK9OCJcY4fy7tP-rU0ISQAAAk4"] [Sat Aug 29 05:06:32.761164 2026] [security2:error] [pid 1017536:tid 1017776] [client 52.139.37.240:14934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/z.php"] [unique_id "apK9OCJcY4fy7tP-rU0ISgAAAoI"] [Sat Aug 29 05:06:32.764778 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.23.184.117:59531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/options.php"] [unique_id "apK9ODAh5Y1i2tUxg4H58wAABio"] [Sat Aug 29 05:06:32.765081 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.151.200.44:65521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/waf.php"] [unique_id "apK9ODAh5Y1i2tUxg4H59AAABcQ"] [Sat Aug 29 05:06:32.773106 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.63.81.20:44465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/5656.php"] [unique_id "apK9ODAh5Y1i2tUxg4H59QAABgY"] [Sat Aug 29 05:06:32.773105 2026] [security2:error] [pid 1017536:tid 1017778] [client 93.123.109.228:49898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/module.config.php"] [unique_id "apK9OCJcY4fy7tP-rU0ITAAAAoQ"] [Sat Aug 29 05:06:32.774052 2026] [security2:error] [pid 1017536:tid 1017731] [client 40.83.93.50:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/wp-load.php"] [unique_id "apK9OCJcY4fy7tP-rU0ITQAAAlU"] [Sat Aug 29 05:06:32.780025 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.184.117:46944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/php8.php"] [unique_id "apK9OCJcY4fy7tP-rU0ITwAAAoc"] [Sat Aug 29 05:06:32.804051 2026] [security2:error] [pid 1017536:tid 1017689] [client 52.139.37.240:31092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/a9.php"] [unique_id "apK9OCJcY4fy7tP-rU0IUQAAAis"] [Sat Aug 29 05:06:32.807469 2026] [security2:error] [pid 1018003:tid 1018194] [client 45.148.10.62:58040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ninaanddon.strangeworx.com"] [uri "/.env.bak"] [unique_id "apK9ODAh5Y1i2tUxg4H5-QAABeM"] [Sat Aug 29 05:06:32.810331 2026] [security2:error] [pid 1018003:tid 1018270] [client 93.123.109.228:50006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/nexmo.php"] [unique_id "apK9ODAh5Y1i2tUxg4H5-gAABi4"] [Sat Aug 29 05:06:32.822970 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.151.200.44:64403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/mcd.php"] [unique_id "apK9OCJcY4fy7tP-rU0IUwAAAkM"] [Sat Aug 29 05:06:32.825335 2026] [security2:error] [pid 1017536:tid 1017753] [client 93.123.109.228:49738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/config/stripe.php"] [unique_id "apK9OCJcY4fy7tP-rU0IVAAAAms"] [Sat Aug 29 05:06:32.840239 2026] [security2:error] [pid 1017536:tid 1017748] [client 66.248.203.2:21518] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheerfulmonk.com"] [uri "/2020/08/21/kbs-bear-story/"] [unique_id "apK9OCJcY4fy7tP-rU0IVwAAAmY"] [Sat Aug 29 05:06:32.854933 2026] [security2:error] [pid 1018003:tid 1018079] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/static/app/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H5_gAFvTo"] [Sat Aug 29 05:06:32.856299 2026] [security2:error] [pid 1018003:tid 1018134] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/static/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H6AQAFvXE"] [Sat Aug 29 05:06:32.856319 2026] [security2:error] [pid 1018003:tid 1018077] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H6AAAFvTg"] [Sat Aug 29 05:06:32.856428 2026] [security2:error] [pid 1018003:tid 1018065] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H5_wAFvSw"] [Sat Aug 29 05:06:32.856636 2026] [security2:error] [pid 1018003:tid 1018097] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/files../.env"] [unique_id "apK9ODAh5Y1i2tUxg4H5_QAFvUw"] [Sat Aug 29 05:06:32.856649 2026] [security2:error] [pid 1018003:tid 1018079] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/static/home/user/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H6AgAFvTo"] [Sat Aug 29 05:06:32.857174 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.104.104.62:5116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/kure.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6BAAABfY"] [Sat Aug 29 05:06:32.865387 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.63.81.20:60461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/edit.php"] [unique_id "apK9OCJcY4fy7tP-rU0IWwAAAks"] [Sat Aug 29 05:06:32.880535 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.49.130:46081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greatvalleyplants.com"] [uri "/ty.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6BgAABiA"] [Sat Aug 29 05:06:32.886373 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.196.209.81:3845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/alfa-rex1.php"] [unique_id "apK9OCJcY4fy7tP-rU0IXgAAAj0"] [Sat Aug 29 05:06:32.919731 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.104.62:48630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/msy.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6DAAABc8"] [Sat Aug 29 05:06:32.924443 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.104.62:52055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/pentest.php"] [unique_id "apK9OCJcY4fy7tP-rU0IZAAAAnc"] [Sat Aug 29 05:06:32.930387 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.184.117:46350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9OCJcY4fy7tP-rU0IZgAAAlg"] [Sat Aug 29 05:06:32.930389 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.184.117:21544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/panel.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6DwAABiY"] [Sat Aug 29 05:06:32.932064 2026] [security2:error] [pid 1017536:tid 1017752] [client 93.123.109.228:50038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9OCJcY4fy7tP-rU0IYwAAAmo"] [Sat Aug 29 05:06:32.943052 2026] [security2:error] [pid 1017536:tid 1017765] [client 93.123.109.228:50044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9OCJcY4fy7tP-rU0IZQAAAnc"] [Sat Aug 29 05:06:32.957243 2026] [security2:error] [pid 1018003:tid 1018169] [client 52.139.37.240:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/f35.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6EQAABco"] [Sat Aug 29 05:06:32.957651 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:50116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H6EAAABdw"] [Sat Aug 29 05:06:32.959758 2026] [security2:error] [pid 1018003:tid 1018217] [client 68.155.159.216:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6EgAABfo"] [Sat Aug 29 05:06:32.960670 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.151.200.44:64294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/bnnof6.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6EwAABbw"] [Sat Aug 29 05:06:32.961312 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.250.41:25445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/bootstrap.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6FAAABcU"] [Sat Aug 29 05:06:32.961313 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.104.62:20845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-content/dg.php"] [unique_id "apK9OCJcY4fy7tP-rU0IaQAAAms"] [Sat Aug 29 05:06:32.966908 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.220.204.93:59107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/class.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6FQAABd8"] [Sat Aug 29 05:06:32.974086 2026] [security2:error] [pid 1017536:tid 1017717] [client 103.168.67.159:28098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9OCJcY4fy7tP-rU0IawAAAkc"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:06:32.978985 2026] [security2:error] [pid 1018003:tid 1018063] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env"] [unique_id "apK9ODAh5Y1i2tUxg4H6FgAGECo"] [Sat Aug 29 05:06:32.978988 2026] [security2:error] [pid 1017536:tid 1017710] [client 93.123.109.228:50046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9OCJcY4fy7tP-rU0IbAAAAkA"] [Sat Aug 29 05:06:32.979895 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.158.54.35:11194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-mail.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6GAAABcg"] [Sat Aug 29 05:06:32.984427 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.52.41.200:1224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/bgymj.php"] [unique_id "apK9ODAh5Y1i2tUxg4H6GQAABhY"] [Sat Aug 29 05:06:33.005666 2026] [security2:error] [pid 1018003:tid 1018096] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/assets../.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6GwAGB0s"] [Sat Aug 29 05:06:33.006271 2026] [security2:error] [pid 1018003:tid 1018090] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/api/.env/public/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6HAAGB0U"] [Sat Aug 29 05:06:33.007909 2026] [core:error] [pid 1018003:tid 1018104] [remote 34.23.124.185:45966] AH10244: invalid URI path (/%2e%2e/.env) [Sat Aug 29 05:06:33.010304 2026] [security2:error] [pid 1017536:tid 1017788] [client 93.123.109.228:50090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9OSJcY4fy7tP-rU0IbwAAAo4"] [Sat Aug 29 05:06:33.010605 2026] [core:error] [pid 1018003:tid 1018104] [remote 34.23.124.185:45966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.018814 2026] [security2:error] [pid 1017536:tid 1017713] [client 52.139.37.240:31146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/admin/index.php"] [unique_id "apK9OSJcY4fy7tP-rU0IcwAAAkM"] [Sat Aug 29 05:06:33.024507 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:9003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/nlnub.php"] [unique_id "apK9OSJcY4fy7tP-rU0IdQAAAnk"] [Sat Aug 29 05:06:33.038945 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.151.200.44:65007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/waw.php"] [unique_id "apK9OSJcY4fy7tP-rU0IdwAAAis"] [Sat Aug 29 05:06:33.045324 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.104.62:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/cafe.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6IQAABeE"] [Sat Aug 29 05:06:33.053898 2026] [security2:error] [pid 1018003:tid 1018266] [client 93.123.109.228:49612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6IgAABio"] [Sat Aug 29 05:06:33.055922 2026] [security2:error] [pid 1017536:tid 1017674] [client 68.155.159.216:51294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/index.php"] [unique_id "apK9OSJcY4fy7tP-rU0IegAAAhw"] [Sat Aug 29 05:06:33.072500 2026] [security2:error] [pid 1018003:tid 1018230] [client 17.166.232.46:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/ingredient/le-jus-dun-demi-citron/"] [unique_id "apK9OTAh5Y1i2tUxg4H6IwAABgY"] [Sat Aug 29 05:06:33.075502 2026] [security2:error] [pid 1017536:tid 1017723] [client 158.23.184.117:62309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/txets.php"] [unique_id "apK9OSJcY4fy7tP-rU0IfAAAAk0"] [Sat Aug 29 05:06:33.075731 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.184.117:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "apK9OSJcY4fy7tP-rU0IewAAAmc"] [Sat Aug 29 05:06:33.098313 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.48.250.41:25352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/export.php"] [unique_id "apK9OSJcY4fy7tP-rU0IfgAAAm8"] [Sat Aug 29 05:06:33.100935 2026] [security2:error] [pid 1017536:tid 1017793] [client 93.123.109.228:50038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9OSJcY4fy7tP-rU0IfwAAApM"] [Sat Aug 29 05:06:33.101135 2026] [security2:error] [pid 1017536:tid 1017705] [client 171.61.160.196:22087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9OSJcY4fy7tP-rU0IgAAAAjs"] [Sat Aug 29 05:06:33.101238 2026] [security2:error] [pid 1017536:tid 1017705] [client 171.61.160.196:22087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9OSJcY4fy7tP-rU0IgAAAAjs"] [Sat Aug 29 05:06:33.103924 2026] [security2:error] [pid 1017536:tid 1017695] [client 93.123.109.228:50044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9OSJcY4fy7tP-rU0IggAAAjE"] [Sat Aug 29 05:06:33.108634 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:48723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/siln.php"] [unique_id "apK9OSJcY4fy7tP-rU0IgwAAAlo"] [Sat Aug 29 05:06:33.112820 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.220.204.93:52299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/8.php"] [unique_id "apK9OSJcY4fy7tP-rU0IhAAAAjA"] [Sat Aug 29 05:06:33.128152 2026] [security2:error] [pid 1018003:tid 1018152] [client 4.205.62.107:55969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/xza.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6JgAABbk"] [Sat Aug 29 05:06:33.155611 2026] [security2:error] [pid 1018003:tid 1018194] [client 52.139.37.240:14956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/file61.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6KgAABeM"] [Sat Aug 29 05:06:33.155917 2026] [security2:error] [pid 1017536:tid 1017689] [client 68.155.159.216:50325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9OSJcY4fy7tP-rU0IiQAAAis"] [Sat Aug 29 05:06:33.162543 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.196.209.81:17857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/flower.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6KwAABik"] [Sat Aug 29 05:06:33.165066 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.23.147.79:30624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6LAAABho"] [Sat Aug 29 05:06:33.187875 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.151.200.44:46633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/admin123.php"] [unique_id "apK9OSJcY4fy7tP-rU0IjwAAAhw"] [Sat Aug 29 05:06:33.215506 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.104.62:56321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/eval.php"] [unique_id "apK9OSJcY4fy7tP-rU0IkgAAAh0"] [Sat Aug 29 05:06:33.216048 2026] [security2:error] [pid 1018003:tid 1018213] [client 52.139.37.240:31057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/makeasmtp.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6MwAABfY"] [Sat Aug 29 05:06:33.220154 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.23.184.117:60054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/pki-validation/pl.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6NAAABcM"] [Sat Aug 29 05:06:33.222385 2026] [security2:error] [pid 1017536:tid 1017752] [client 158.23.184.117:57101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/adminfuns.php"] [unique_id "apK9OSJcY4fy7tP-rU0IkwAAAmo"] [Sat Aug 29 05:06:33.241930 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.104.104.62:20842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-content/mek.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6NgAABeg"] [Sat Aug 29 05:06:33.245255 2026] [security2:error] [pid 1017536:tid 1017717] [client 40.83.93.50:1609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK9OSJcY4fy7tP-rU0IlQAAAkc"] [Sat Aug 29 05:06:33.248461 2026] [security2:error] [pid 1018003:tid 1018217] [client 68.155.159.216:49253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/file88.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6OAAABfo"] [Sat Aug 29 05:06:33.254033 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.48.250.41:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/gk.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6OQAABbw"] [Sat Aug 29 05:06:33.259164 2026] [security2:error] [pid 1018003:tid 1018059] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/img../.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6OgAFxSY"] [Sat Aug 29 05:06:33.278818 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.220.204.93:52316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/0x0x.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6QgAABfU"] [Sat Aug 29 05:06:33.279489 2026] [security2:error] [pid 1018003:tid 1018112] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/images../.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6QAAFuls"] [Sat Aug 29 05:06:33.281877 2026] [core:error] [pid 1018003:tid 1018066] [remote 34.23.124.185:45966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.281891 2026] [core:error] [pid 1018003:tid 1018066] [remote 34.23.124.185:45966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.282740 2026] [security2:error] [pid 1018003:tid 1018045] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/uploads../.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6QwAFuhg"] [Sat Aug 29 05:06:33.283471 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.147.79:32743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6RQAABcg"] [Sat Aug 29 05:06:33.283621 2026] [core:error] [pid 1018003:tid 1018086] [remote 34.23.124.185:45966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.283633 2026] [core:error] [pid 1018003:tid 1018086] [remote 34.23.124.185:45966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.283932 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.151.200.44:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/ah24.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6RgAABiM"] [Sat Aug 29 05:06:33.284528 2026] [core:error] [pid 1018003:tid 1018101] [remote 34.23.124.185:45966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.284539 2026] [core:error] [pid 1018003:tid 1018101] [remote 34.23.124.185:45966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.286975 2026] [security2:error] [pid 1017536:tid 1017710] [client 93.123.109.228:50044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9OSJcY4fy7tP-rU0ImQAAAkA"] [Sat Aug 29 05:06:33.293707 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.196.209.81:16724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/headerg.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6RwAABiI"] [Sat Aug 29 05:06:33.297853 2026] [security2:error] [pid 1018003:tid 1018216] [client 78.142.18.40:60371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printingbyjoe.com"] [uri "/wp-login.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6RAAABfk"], referer: https://www.facebook.com/ [Sat Aug 29 05:06:33.312606 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.151.200.44:64999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/x23.php"] [unique_id "apK9OSJcY4fy7tP-rU0ImgAAAos"] [Sat Aug 29 05:06:33.324182 2026] [security2:error] [pid 1017536:tid 1017706] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9OSJcY4fy7tP-rU0ImwAAAjw"] [Sat Aug 29 05:06:33.326575 2026] [security2:error] [pid 1017536:tid 1017743] [client 93.123.109.228:50164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9OSJcY4fy7tP-rU0InAAAAmE"] [Sat Aug 29 05:06:33.326864 2026] [security2:error] [pid 1018003:tid 1018105] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/var/task/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6SQAGA1Q"] [Sat Aug 29 05:06:33.334172 2026] [security2:error] [pid 1018003:tid 1018161] [client 93.123.109.228:50116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6SgAABcI"] [Sat Aug 29 05:06:33.340196 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.147.79:25561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6SwAABis"] [Sat Aug 29 05:06:33.350552 2026] [security2:error] [pid 1018003:tid 1018182] [client 52.139.37.240:14930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/mah.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6TAAABdc"] [Sat Aug 29 05:06:33.366653 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.184.117:59530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/pki-validation/x.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6TgAABgc"] [Sat Aug 29 05:06:33.368157 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.184.117:46951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/403.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6TwAABgI"] [Sat Aug 29 05:06:33.368258 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.104.104.62:4115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/sao.php"] [unique_id "apK9OSJcY4fy7tP-rU0IoAAAAlo"] [Sat Aug 29 05:06:33.371343 2026] [security2:error] [pid 1018003:tid 1018093] [remote 34.23.124.185:45966] ModSecurity: Access denied with code 500 (phase 1) (Error: Connection drop requested but failed to close the socket). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9OTAh5Y1i2tUxg4H6UQAF20g"] [Sat Aug 29 05:06:33.371372 2026] [security2:error] [pid 1018003:tid 1018107] [remote 34.23.124.185:45966] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "apK9OTAh5Y1i2tUxg4H6UAAF21Y"] [Sat Aug 29 05:06:33.373057 2026] [security2:error] [pid 1017536:tid 1017673] [client 93.123.109.228:49892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9OSJcY4fy7tP-rU0IoQAAAhs"] [Sat Aug 29 05:06:33.396285 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.104.62:48594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/f-401.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6UgAABh8"] [Sat Aug 29 05:06:33.397869 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.48.250.41:25365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/logs1.php"] [unique_id "apK9OSJcY4fy7tP-rU0IowAAAis"] [Sat Aug 29 05:06:33.406146 2026] [security2:error] [pid 1018003:tid 1018230] [client 93.123.109.228:49612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6UwAABgY"] [Sat Aug 29 05:06:33.415757 2026] [security2:error] [pid 1017536:tid 1017732] [client 52.139.37.240:30799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/paku.php"] [unique_id "apK9OSJcY4fy7tP-rU0IpQAAAlY"] [Sat Aug 29 05:06:33.417465 2026] [security2:error] [pid 1017536:tid 1017786] [client 195.178.110.247:34398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.leedscastlepunting.co.uk"] [uri "/index.php"] [unique_id "apK9OSJcY4fy7tP-rU0IpgAAAow"] [Sat Aug 29 05:06:33.430547 2026] [core:error] [pid 1018003:tid 1018156] [client 45.148.10.62:58040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.430868 2026] [security2:error] [pid 1017536:tid 1017709] [client 185.104.184.230:52476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK9OSJcY4fy7tP-rU0IpwAAAj8"] [Sat Aug 29 05:06:33.443148 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.52.41.200:1776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6WQAABfs"] [Sat Aug 29 05:06:33.449298 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.197.61.180:7886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/hehe.php"] [unique_id "apK9OSJcY4fy7tP-rU0IqQAAApA"] [Sat Aug 29 05:06:33.460511 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.158.54.35:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6XAAABiw"] [Sat Aug 29 05:06:33.490904 2026] [security2:error] [pid 1017536:tid 1017757] [client 68.155.159.216:51425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9OSJcY4fy7tP-rU0IsQAAAm8"] [Sat Aug 29 05:06:33.494295 2026] [security2:error] [pid 1017536:tid 1017785] [client 4.205.62.107:22257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/X57.php"] [unique_id "apK9OSJcY4fy7tP-rU0IsgAAAos"] [Sat Aug 29 05:06:33.496684 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.104.49.130:29983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/ohct.php"] [unique_id "apK9OSJcY4fy7tP-rU0IswAAApM"] [Sat Aug 29 05:06:33.503510 2026] [security2:error] [pid 1018003:tid 1018262] [client 93.123.109.228:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/info.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6YQAABiY"] [Sat Aug 29 05:06:33.510454 2026] [security2:error] [pid 1017536:tid 1017669] [client 158.23.184.117:21529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "apK9OSJcY4fy7tP-rU0ItwAAAhc"] [Sat Aug 29 05:06:33.524912 2026] [security2:error] [pid 1017536:tid 1017695] [client 93.123.109.228:50046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/infophp.php"] [unique_id "apK9OSJcY4fy7tP-rU0IuAAAAjE"] [Sat Aug 29 05:06:33.529334 2026] [security2:error] [pid 1017536:tid 1017788] [client 68.155.159.216:64464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9OSJcY4fy7tP-rU0IuQAAAo4"] [Sat Aug 29 05:06:33.530204 2026] [security2:error] [pid 1018003:tid 1018244] [client 149.34.210.141:42145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6ZQAABhQ"] [Sat Aug 29 05:06:33.530313 2026] [security2:error] [pid 1018003:tid 1018244] [client 149.34.210.141:42145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6ZQAABhQ"] [Sat Aug 29 05:06:33.530491 2026] [security2:error] [pid 1017536:tid 1017736] [client 93.123.109.228:49892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/infos.php"] [unique_id "apK9OSJcY4fy7tP-rU0IugAAAlo"] [Sat Aug 29 05:06:33.531584 2026] [security2:error] [pid 1017536:tid 1017694] [client 158.23.147.79:30711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/index.php"] [unique_id "apK9OSJcY4fy7tP-rU0IuwAAAjA"] [Sat Aug 29 05:06:33.539952 2026] [security2:error] [pid 1017536:tid 1017673] [client 68.155.159.216:33748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9OSJcY4fy7tP-rU0IvAAAAhs"] [Sat Aug 29 05:06:33.542447 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.48.250.41:25351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/inege.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6aAAABhA"] [Sat Aug 29 05:06:33.546781 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:14676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/mini.php"] [unique_id "apK9OSJcY4fy7tP-rU0IvgAAAiA"] [Sat Aug 29 05:06:33.563132 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.184.117:46913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/.trash7206/index.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6aQAABcg"] [Sat Aug 29 05:06:33.564267 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.104.104.62:48622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/hq.php"] [unique_id "apK9OSJcY4fy7tP-rU0IvwAAAoQ"] [Sat Aug 29 05:06:33.572232 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.196.209.81:9443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/meta.php"] [unique_id "apK9OSJcY4fy7tP-rU0IwAAAAh0"] [Sat Aug 29 05:06:33.584744 2026] [security2:error] [pid 1018003:tid 1018238] [client 195.178.110.247:17736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.leedscastlepunting.co.uk"] [uri "/index.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6bAAABg4"] [Sat Aug 29 05:06:33.586148 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.220.204.93:59047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/166.php"] [unique_id "apK9OSJcY4fy7tP-rU0IxQAAAj8"] [Sat Aug 29 05:06:33.586249 2026] [security2:error] [pid 1017536:tid 1017765] [client 93.123.109.228:49546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9OSJcY4fy7tP-rU0IxAAAAnc"] [Sat Aug 29 05:06:33.590395 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.151.200.44:64923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/ztv.php"] [unique_id "apK9OSJcY4fy7tP-rU0IxgAAApA"] [Sat Aug 29 05:06:33.593073 2026] [security2:error] [pid 1017536:tid 1017753] [client 93.123.109.228:50090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9OSJcY4fy7tP-rU0IyAAAAms"] [Sat Aug 29 05:06:33.593766 2026] [security2:error] [pid 1017536:tid 1017710] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9OSJcY4fy7tP-rU0IygAAAkA"] [Sat Aug 29 05:06:33.602388 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.104.62:36961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/6y7t.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6bgAABi8"] [Sat Aug 29 05:06:33.612232 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:31157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/rtx.php"] [unique_id "apK9OSJcY4fy7tP-rU0IzgAAAiA"] [Sat Aug 29 05:06:33.628845 2026] [security2:error] [pid 1017536:tid 1017598] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/.env"] [unique_id "apK9OSJcY4fy7tP-rU0IzwACkz0"] [Sat Aug 29 05:06:33.628884 2026] [security2:error] [pid 1017536:tid 1017606] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I0gACk0U"] [Sat Aug 29 05:06:33.632589 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.151.200.44:45467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/7h.php"] [unique_id "apK9OSJcY4fy7tP-rU0I0wAAAl4"] [Sat Aug 29 05:06:33.637875 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.104.62:64664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/uuu.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6cAAABcI"] [Sat Aug 29 05:06:33.647066 2026] [security2:error] [pid 1018003:tid 1018191] [client 68.155.159.216:18131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6cQAABeA"] [Sat Aug 29 05:06:33.655677 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.23.184.117:21509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/security.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6cgAABfk"] [Sat Aug 29 05:06:33.658128 2026] [security2:error] [pid 1018003:tid 1018172] [client 93.123.109.228:49884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6cwAABc0"] [Sat Aug 29 05:06:33.666401 2026] [security2:error] [pid 1017536:tid 1017694] [client 158.23.147.79:59218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9OSJcY4fy7tP-rU0I2AAAAjA"] [Sat Aug 29 05:06:33.669738 2026] [security2:error] [pid 1017536:tid 1017537] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I2QACUwA"] [Sat Aug 29 05:06:33.671456 2026] [security2:error] [pid 1017536:tid 1017673] [client 93.123.109.228:49600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I2gAAAhs"] [Sat Aug 29 05:06:33.682592 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.48.250.41:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wp-link10.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6dQAABeQ"] [Sat Aug 29 05:06:33.685427 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.151.200.44:65086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/ws66.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6dgAABgc"] [Sat Aug 29 05:06:33.694321 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.147.79:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/NewFile.php/"] [unique_id "apK9OTAh5Y1i2tUxg4H6dwAABgI"] [Sat Aug 29 05:06:33.697376 2026] [security2:error] [pid 1017536:tid 1017778] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I3QAAAoQ"] [Sat Aug 29 05:06:33.698728 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.104.104.62:48728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/mh.php"] [unique_id "apK9OSJcY4fy7tP-rU0I3gAAAlg"] [Sat Aug 29 05:06:33.708353 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.184.117:46353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/.trash7206/admin.php"] [unique_id "apK9OSJcY4fy7tP-rU0I3wAAAlo"] [Sat Aug 29 05:06:33.714905 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.49.130:34500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/dex.php"] [unique_id "apK9OSJcY4fy7tP-rU0I4QAAAls"] [Sat Aug 29 05:06:33.714944 2026] [security2:error] [pid 1017536:tid 1017616] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/wp-config.php.old"] [unique_id "apK9OSJcY4fy7tP-rU0I4gACHE8"] [Sat Aug 29 05:06:33.719596 2026] [security2:error] [pid 1017536:tid 1017689] [client 40.83.93.50:23968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/wp-settings.php"] [unique_id "apK9OSJcY4fy7tP-rU0I4wAAAis"] [Sat Aug 29 05:06:33.724352 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.220.204.93:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/h2a2ck.php"] [unique_id "apK9OSJcY4fy7tP-rU0I5QAAAj8"] [Sat Aug 29 05:06:33.725195 2026] [security2:error] [pid 1017536:tid 1017573] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/wp-config.php.bak"] [unique_id "apK9OSJcY4fy7tP-rU0I5wACaiQ"] [Sat Aug 29 05:06:33.725699 2026] [core:error] [pid 1017536:tid 1017639] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.725714 2026] [core:error] [pid 1017536:tid 1017639] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.732114 2026] [security2:error] [pid 1017536:tid 1017691] [client 4.205.62.107:21616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apK9OSJcY4fy7tP-rU0I6wAAAi0"] [Sat Aug 29 05:06:33.732533 2026] [security2:error] [pid 1017536:tid 1017706] [client 93.123.109.228:49546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I6gAAAjw"] [Sat Aug 29 05:06:33.736199 2026] [security2:error] [pid 1017536:tid 1017721] [client 93.123.109.228:50148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I7AAAAks"] [Sat Aug 29 05:06:33.738303 2026] [security2:error] [pid 1017536:tid 1017575] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/laravel/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I7QACkiY"] [Sat Aug 29 05:06:33.738829 2026] [security2:error] [pid 1017536:tid 1017765] [client 185.104.184.230:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "apK9OSJcY4fy7tP-rU0I5gAAAnc"] [Sat Aug 29 05:06:33.742731 2026] [security2:error] [pid 1017536:tid 1017757] [client 93.123.109.228:50090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I7wAAAm8"] [Sat Aug 29 05:06:33.744590 2026] [security2:error] [pid 1018003:tid 1018221] [client 52.139.37.240:14685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/v.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6fQAABf4"] [Sat Aug 29 05:06:33.744872 2026] [security2:error] [pid 1017536:tid 1017548] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/config/.env.php"] [unique_id "apK9OSJcY4fy7tP-rU0I8AACIAs"] [Sat Aug 29 05:06:33.753680 2026] [security2:error] [pid 1017536:tid 1017740] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I8gAAAl4"] [Sat Aug 29 05:06:33.758118 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.196.209.81:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/meta.php"] [unique_id "apK9OSJcY4fy7tP-rU0I8wAAAos"] [Sat Aug 29 05:06:33.759762 2026] [security2:error] [pid 1018003:tid 1018189] [client 93.123.109.228:49612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6fgAABd4"] [Sat Aug 29 05:06:33.760830 2026] [security2:error] [pid 1017536:tid 1017748] [client 93.123.109.228:49788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I9AAAAmY"] [Sat Aug 29 05:06:33.764008 2026] [security2:error] [pid 1017536:tid 1017681] [client 93.123.109.228:50164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I9gAAAiM"] [Sat Aug 29 05:06:33.765289 2026] [security2:error] [pid 1017536:tid 1017694] [client 93.123.109.228:49636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9OSJcY4fy7tP-rU0I9wAAAjA"] [Sat Aug 29 05:06:33.769678 2026] [security2:error] [pid 1018003:tid 1018157] [client 93.123.109.228:49994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6fwAABb4"] [Sat Aug 29 05:06:33.774044 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.147.79:35837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9OSJcY4fy7tP-rU0I-AAAAhs"] [Sat Aug 29 05:06:33.793055 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.205.62.107:22396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/public/vx.php"] [unique_id "apK9OSJcY4fy7tP-rU0I-wAAAh0"] [Sat Aug 29 05:06:33.798850 2026] [security2:error] [pid 1017536:tid 1017731] [client 158.23.184.117:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/system.php"] [unique_id "apK9OSJcY4fy7tP-rU0I_gAAAlU"] [Sat Aug 29 05:06:33.817173 2026] [security2:error] [pid 1017536:tid 1017788] [client 93.123.109.228:49708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9OSJcY4fy7tP-rU0JAgAAAo4"] [Sat Aug 29 05:06:33.821847 2026] [security2:error] [pid 1017536:tid 1017749] [client 93.123.109.228:50038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9OSJcY4fy7tP-rU0JBQAAAmc"] [Sat Aug 29 05:06:33.823011 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.104.62:20806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/bypass.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6gwAABbk"] [Sat Aug 29 05:06:33.824307 2026] [security2:error] [pid 1018003:tid 1018219] [client 4.205.62.107:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/xin1.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6hAAABfw"] [Sat Aug 29 05:06:33.825693 2026] [security2:error] [pid 1018003:tid 1018245] [client 52.139.37.240:31512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/update/da222.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6hQAABhU"] [Sat Aug 29 05:06:33.829997 2026] [security2:error] [pid 1017536:tid 1017751] [client 93.123.109.228:49754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9OSJcY4fy7tP-rU0JCAAAAmk"] [Sat Aug 29 05:06:33.831713 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.250.41:25451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ww.php"] [unique_id "apK9OSJcY4fy7tP-rU0JCgAAAkA"] [Sat Aug 29 05:06:33.845165 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.104.104.62:48462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/f2r4.php"] [unique_id "apK9OSJcY4fy7tP-rU0JDAAAAnc"] [Sat Aug 29 05:06:33.848432 2026] [security2:error] [pid 1017536:tid 1017757] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9OSJcY4fy7tP-rU0JDgAAAm8"] [Sat Aug 29 05:06:33.850125 2026] [security2:error] [pid 1017536:tid 1017770] [client 93.123.109.228:49996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9OSJcY4fy7tP-rU0JEAAAAnw"] [Sat Aug 29 05:06:33.852533 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.184.117:62274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-content/admin.php"] [unique_id "apK9OSJcY4fy7tP-rU0JEQAAAhw"] [Sat Aug 29 05:06:33.857541 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.151.200.44:64287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/kure.php"] [unique_id "apK9OSJcY4fy7tP-rU0JEwAAApM"] [Sat Aug 29 05:06:33.883301 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.104.62:43064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/private.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6iwAABec"] [Sat Aug 29 05:06:33.893881 2026] [security2:error] [pid 1017536:tid 1017785] [client 93.123.109.228:49966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9OSJcY4fy7tP-rU0JFgAAAos"] [Sat Aug 29 05:06:33.904502 2026] [security2:error] [pid 1018003:tid 1018190] [client 61.9.8.62:4096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6igAABd8"] [Sat Aug 29 05:06:33.904665 2026] [security2:error] [pid 1018003:tid 1018190] [client 61.9.8.62:4096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6igAABd8"] [Sat Aug 29 05:06:33.916203 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.220.204.93:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/error_log.php"] [unique_id "apK9OSJcY4fy7tP-rU0JGgAAAhs"] [Sat Aug 29 05:06:33.922278 2026] [security2:error] [pid 1018003:tid 1018199] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9OTAh5Y1i2tUxg4H6jgAABeg"] [Sat Aug 29 05:06:33.922501 2026] [security2:error] [pid 1018003:tid 1018098] [remote 198.52.231.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.231.52.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6kAAF2U0"] [Sat Aug 29 05:06:33.927104 2026] [cgid:error] [pid 1017536:tid 1017729] [client 20.52.41.200:1763] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:33.938365 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.104.62:52081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/0xs.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6kgAABik"] [Sat Aug 29 05:06:33.946112 2026] [security2:error] [pid 1018003:tid 1018180] [client 158.23.184.117:21510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/users.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6kwAABdU"] [Sat Aug 29 05:06:33.950400 2026] [security2:error] [pid 1017536:tid 1017723] [client 52.139.37.240:15278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9OSJcY4fy7tP-rU0JHAAAAk0"] [Sat Aug 29 05:06:33.954171 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.63.81.20:46889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/w3lls.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6lAAABfo"] [Sat Aug 29 05:06:33.968736 2026] [security2:error] [pid 1017536:tid 1017675] [client 93.123.109.228:49974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9OSJcY4fy7tP-rU0JHgAAAh0"] [Sat Aug 29 05:06:33.976114 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.158.54.35:11178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "apK9OTAh5Y1i2tUxg4H6kQAABiA"] [Sat Aug 29 05:06:33.980673 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.250.41:25422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/w1px.php"] [unique_id "apK9OSJcY4fy7tP-rU0JIAAAAo4"] [Sat Aug 29 05:06:33.983476 2026] [security2:error] [pid 1017536:tid 1017653] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/config.php.bak"] [unique_id "apK9OSJcY4fy7tP-rU0JIgACK3Q"] [Sat Aug 29 05:06:33.986873 2026] [security2:error] [pid 1017536:tid 1017588] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/core/.env"] [unique_id "apK9OSJcY4fy7tP-rU0JIwACQDM"] [Sat Aug 29 05:06:33.991237 2026] [security2:error] [pid 1017536:tid 1017590] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env.php.bak"] [unique_id "apK9OSJcY4fy7tP-rU0JJgACajU"] [Sat Aug 29 05:06:33.993247 2026] [security2:error] [pid 1017536:tid 1017603] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/configuration.php.bak"] [unique_id "apK9OSJcY4fy7tP-rU0JKAACakI"] [Sat Aug 29 05:06:33.993566 2026] [core:error] [pid 1017536:tid 1017601] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.993580 2026] [core:error] [pid 1017536:tid 1017601] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:33.994668 2026] [core:error] [pid 1017536:tid 1017596] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.006056 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.151.200.44:65023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/Cok.php"] [unique_id "apK9OiJcY4fy7tP-rU0JKwAAAnw"] [Sat Aug 29 05:06:34.008140 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.63.81.20:43525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/tqkdqbbv.php"] [unique_id "apK9OiJcY4fy7tP-rU0JLAAAAjw"] [Sat Aug 29 05:06:34.015852 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.184.117:46974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-mail.php"] [unique_id "apK9OiJcY4fy7tP-rU0JLQAAAlg"] [Sat Aug 29 05:06:34.068596 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:52806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/asd.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6nwAABco"] [Sat Aug 29 05:06:34.068676 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.151.200.44:64242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/cafe.php"] [unique_id "apK9OiJcY4fy7tP-rU0JMQAAAlM"] [Sat Aug 29 05:06:34.072762 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.104.104.62:20810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/w50.php"] [unique_id "apK9OiJcY4fy7tP-rU0JMwAAAnk"] [Sat Aug 29 05:06:34.072982 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.151.200.44:45440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/wp-gzone.php"] [unique_id "apK9OiJcY4fy7tP-rU0JMgAAAj0"] [Sat Aug 29 05:06:34.076822 2026] [security2:error] [pid 1017536:tid 1017541] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/web/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JNAACZwQ"] [Sat Aug 29 05:06:34.077068 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.220.204.93:52300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/403.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6oAAABcQ"] [Sat Aug 29 05:06:34.077662 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.104.104.62:48663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/sadis.php"] [unique_id "apK9OiJcY4fy7tP-rU0JOAAAAmk"] [Sat Aug 29 05:06:34.078058 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.52.41.200:1763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-load.php"] [unique_id "apK9OiJcY4fy7tP-rU0JNwAAAo4"] [Sat Aug 29 05:06:34.078439 2026] [security2:error] [pid 1017536:tid 1017567] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env.swp"] [unique_id "apK9OiJcY4fy7tP-rU0JNgACZx4"] [Sat Aug 29 05:06:34.083892 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.63.81.20:46861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/fpwch.php"] [unique_id "apK9OiJcY4fy7tP-rU0JOgAAAoY"] [Sat Aug 29 05:06:34.083953 2026] [core:error] [pid 1017536:tid 1017550] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.084373 2026] [security2:error] [pid 1017536:tid 1017562] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/wp/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JOQACZxk"] [Sat Aug 29 05:06:34.088129 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.184.117:60049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/wp-blog-header.php"] [unique_id "apK9OiJcY4fy7tP-rU0JOwAAApI"] [Sat Aug 29 05:06:34.089876 2026] [autoindex:error] [pid 1018003:tid 1018244] [client 52.139.37.240:31117] AH01276: Cannot serve directory /home4/swumccom/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:34.090720 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.196.209.81:25048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/randkeyword.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6ogAABew"] [Sat Aug 29 05:06:34.095117 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.104.62:43055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/lfi.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6owAABfA"] [Sat Aug 29 05:06:34.099732 2026] [security2:error] [pid 1017536:tid 1017551] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/storage/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JPQACag4"] [Sat Aug 29 05:06:34.100901 2026] [security2:error] [pid 1017536:tid 1017786] [client 93.123.109.228:50090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/php-info.php"] [unique_id "apK9OiJcY4fy7tP-rU0JPgAAAow"] [Sat Aug 29 05:06:34.108731 2026] [security2:error] [pid 1017536:tid 1017563] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/public/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JQQACHBo"] [Sat Aug 29 05:06:34.108926 2026] [security2:error] [pid 1018003:tid 1018243] [client 136.107.231.130:6448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/images../.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6pgAABhM"] [Sat Aug 29 05:06:34.109337 2026] [security2:error] [pid 1017536:tid 1017669] [client 136.107.231.130:6436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/assets../.env"] [unique_id "apK9OiJcY4fy7tP-rU0JQAAAAhc"] [Sat Aug 29 05:06:34.113286 2026] [security2:error] [pid 1017536:tid 1017696] [client 136.107.231.130:6464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/v1/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JQwAAAjI"] [Sat Aug 29 05:06:34.114772 2026] [security2:error] [pid 1018003:tid 1018161] [client 136.107.231.130:6560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.env.backup"] [unique_id "apK9OjAh5Y1i2tUxg4H6qAAABcI"] [Sat Aug 29 05:06:34.115933 2026] [security2:error] [pid 1018003:tid 1018191] [client 136.107.231.130:6412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/uploads../.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6qQAABeA"] [Sat Aug 29 05:06:34.117136 2026] [security2:error] [pid 1018003:tid 1018160] [client 136.107.231.130:6476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6qgAABcE"] [Sat Aug 29 05:06:34.117693 2026] [security2:error] [pid 1017536:tid 1017785] [client 136.107.231.130:6422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/img../.env"] [unique_id "apK9OiJcY4fy7tP-rU0JRQAAAos"] [Sat Aug 29 05:06:34.118099 2026] [security2:error] [pid 1017536:tid 1017745] [client 136.107.231.130:6666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/config/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JRgAAAmM"] [Sat Aug 29 05:06:34.118660 2026] [security2:error] [pid 1018003:tid 1018267] [client 136.107.231.130:6504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/v2/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6qwAABis"] [Sat Aug 29 05:06:34.118767 2026] [security2:error] [pid 1018003:tid 1018267] [client 136.107.231.130:6504] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/v2/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6qwAABis"] [Sat Aug 29 05:06:34.120522 2026] [security2:error] [pid 1017536:tid 1017695] [client 136.107.231.130:6596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/docker/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JRwAAAjE"] [Sat Aug 29 05:06:34.121709 2026] [security2:error] [pid 1018003:tid 1018206] [client 136.107.231.130:6546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.env.bak"] [unique_id "apK9OjAh5Y1i2tUxg4H6rAAABe8"] [Sat Aug 29 05:06:34.121892 2026] [security2:error] [pid 1017536:tid 1017748] [client 136.107.231.130:6406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JSAAAAmY"] [Sat Aug 29 05:06:34.121894 2026] [security2:error] [pid 1017536:tid 1017744] [client 136.107.231.130:6636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/core/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JSQAAAmI"] [Sat Aug 29 05:06:34.121993 2026] [security2:error] [pid 1017536:tid 1017744] [client 136.107.231.130:6636] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/core/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JSQAAAmI"] [Sat Aug 29 05:06:34.122649 2026] [security2:error] [pid 1017536:tid 1017705] [client 93.123.109.228:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/phpinfo.php"] [unique_id "apK9OiJcY4fy7tP-rU0JSgAAAjs"] [Sat Aug 29 05:06:34.125512 2026] [security2:error] [pid 1017536:tid 1017683] [client 136.107.231.130:6700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/web/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JTAAAAiU"] [Sat Aug 29 05:06:34.126508 2026] [security2:error] [pid 1017536:tid 1017717] [client 136.107.231.130:6564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/app/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JSwAAAkc"] [Sat Aug 29 05:06:34.127566 2026] [security2:error] [pid 1018003:tid 1018189] [client 93.123.109.228:50136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/php.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6tAAABd4"] [Sat Aug 29 05:06:34.127664 2026] [security2:error] [pid 1018003:tid 1018172] [client 136.107.231.130:6676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.env.old"] [unique_id "apK9OjAh5Y1i2tUxg4H6sQAABc0"] [Sat Aug 29 05:06:34.129046 2026] [security2:error] [pid 1018003:tid 1018248] [client 136.107.231.130:6532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9OjAh5Y1i2tUxg4H6rwAABhg"] [Sat Aug 29 05:06:34.129246 2026] [security2:error] [pid 1018003:tid 1018231] [client 136.107.231.130:6566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/backend/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6sgAABgc"] [Sat Aug 29 05:06:34.129336 2026] [security2:error] [pid 1018003:tid 1018192] [client 136.107.231.130:6678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/server/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6tQAABeE"] [Sat Aug 29 05:06:34.130014 2026] [security2:error] [pid 1018003:tid 1018182] [client 136.107.231.130:6650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/src/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6swAABdc"] [Sat Aug 29 05:06:34.130134 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.104.62:36963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/waf.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6uAAABb4"] [Sat Aug 29 05:06:34.130718 2026] [security2:error] [pid 1018003:tid 1018186] [client 136.107.231.130:6608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.env.swp"] [unique_id "apK9OjAh5Y1i2tUxg4H6twAABds"] [Sat Aug 29 05:06:34.130824 2026] [security2:error] [pid 1017536:tid 1017711] [client 93.123.109.228:49546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/php_info.php"] [unique_id "apK9OiJcY4fy7tP-rU0JTwAAAkE"] [Sat Aug 29 05:06:34.131274 2026] [security2:error] [pid 1017536:tid 1017765] [client 93.123.109.228:50148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JTgAAAnc"] [Sat Aug 29 05:06:34.131643 2026] [security2:error] [pid 1018003:tid 1018266] [client 136.107.231.130:6600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/laravel/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6uQAABio"] [Sat Aug 29 05:06:34.131887 2026] [security2:error] [pid 1018003:tid 1018175] [client 136.107.231.130:6642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/api/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6uwAABdA"] [Sat Aug 29 05:06:34.131974 2026] [security2:error] [pid 1018003:tid 1018175] [client 136.107.231.130:6642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/api/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6uwAABdA"] [Sat Aug 29 05:06:34.132145 2026] [security2:error] [pid 1018003:tid 1018185] [client 136.107.231.130:6692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/frontend/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6ugAABdo"] [Sat Aug 29 05:06:34.132241 2026] [security2:error] [pid 1018003:tid 1018185] [client 136.107.231.130:6692] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/frontend/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6ugAABdo"] [Sat Aug 29 05:06:34.132312 2026] [security2:error] [pid 1018003:tid 1018177] [client 136.107.231.130:6450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.docker/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6vQAABdI"] [Sat Aug 29 05:06:34.132408 2026] [security2:error] [pid 1018003:tid 1018177] [client 136.107.231.130:6450] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.docker/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6vQAABdI"] [Sat Aug 29 05:06:34.138208 2026] [security2:error] [pid 1018003:tid 1018224] [client 103.171.189.88:55125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6vgAABgE"] [Sat Aug 29 05:06:34.138285 2026] [security2:error] [pid 1018003:tid 1018224] [client 103.171.189.88:55125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6vgAABgE"] [Sat Aug 29 05:06:34.142486 2026] [security2:error] [pid 1017536:tid 1017713] [client 52.139.37.240:14923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apK9OiJcY4fy7tP-rU0JUQAAAkM"] [Sat Aug 29 05:06:34.144067 2026] [security2:error] [pid 1017536:tid 1017740] [client 68.155.159.216:24462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/hehehehe.php"] [unique_id "apK9OiJcY4fy7tP-rU0JUgAAAl4"] [Sat Aug 29 05:06:34.145815 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.197.61.180:7893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6wAAABcA"] [Sat Aug 29 05:06:34.151814 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.48.250.41:25458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/to.php"] [unique_id "apK9OiJcY4fy7tP-rU0JVAAAAjA"] [Sat Aug 29 05:06:34.153350 2026] [security2:error] [pid 1017536:tid 1017571] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/wp-config.old"] [unique_id "apK9OiJcY4fy7tP-rU0JUwACNCI"] [Sat Aug 29 05:06:34.154278 2026] [security2:error] [pid 1018003:tid 1018219] [client 52.139.37.240:31117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-admin/min.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6wQAABfw"] [Sat Aug 29 05:06:34.161454 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.63.81.20:43597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/kjyehoxl.php"] [unique_id "apK9OiJcY4fy7tP-rU0JVwAAAj0"] [Sat Aug 29 05:06:34.166977 2026] [security2:error] [pid 1018003:tid 1018268] [client 93.123.109.228:49884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H6wwAABiw"] [Sat Aug 29 05:06:34.170537 2026] [security2:error] [pid 1017536:tid 1017586] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/wp-config.php.swp"] [unique_id "apK9OiJcY4fy7tP-rU0JWQACYTE"] [Sat Aug 29 05:06:34.171475 2026] [core:error] [pid 1017536:tid 1017612] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.171492 2026] [core:error] [pid 1017536:tid 1017612] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.172445 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:51497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9OiJcY4fy7tP-rU0JWwAAAks"] [Sat Aug 29 05:06:34.174304 2026] [security2:error] [pid 1017536:tid 1017721] [client 4.205.62.107:53429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wpver.php"] [unique_id "apK9OiJcY4fy7tP-rU0JXAAAAks"] [Sat Aug 29 05:06:34.175711 2026] [security2:error] [pid 1018003:tid 1018109] [remote 34.75.89.130:51724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/wp-config.old"] [unique_id "apK9OjAh5Y1i2tUxg4H6yAAGGlg"] [Sat Aug 29 05:06:34.175724 2026] [security2:error] [pid 1018003:tid 1018111] [remote 34.75.89.130:51724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "freejohnstuart.com"] [uri "/wp-config.php.swp"] [unique_id "apK9OjAh5Y1i2tUxg4H6ywAGGlo"] [Sat Aug 29 05:06:34.180332 2026] [core:error] [pid 1017536:tid 1017625] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.180346 2026] [core:error] [pid 1017536:tid 1017625] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.184230 2026] [security2:error] [pid 1017536:tid 1017689] [client 93.123.109.228:49600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JXgAAAis"] [Sat Aug 29 05:06:34.188249 2026] [security2:error] [pid 1017536:tid 1017664] [remote 34.23.124.185:45974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/wp-config.php~"] [unique_id "apK9OiJcY4fy7tP-rU0JYAACkn8"] [Sat Aug 29 05:06:34.191066 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.196.209.81:11561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/dxc.php"] [unique_id "apK9OiJcY4fy7tP-rU0JYQAAAiA"] [Sat Aug 29 05:06:34.203083 2026] [core:error] [pid 1017536:tid 1017587] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.203100 2026] [core:error] [pid 1017536:tid 1017587] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.207075 2026] [security2:error] [pid 1017536:tid 1017704] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JZQAAAjo"] [Sat Aug 29 05:06:34.207243 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.151.200.44:64394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/X7T6.php"] [unique_id "apK9OiJcY4fy7tP-rU0JZgAAAos"] [Sat Aug 29 05:06:34.209946 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:46923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/3.php"] [unique_id "apK9OiJcY4fy7tP-rU0JZwAAAjE"] [Sat Aug 29 05:06:34.213622 2026] [core:error] [pid 1018003:tid 1018271] [client 45.148.10.62:38768] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.213641 2026] [core:error] [pid 1018003:tid 1018271] [client 45.148.10.62:38768] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.224301 2026] [security2:error] [pid 1018003:tid 1018194] [client 185.104.184.230:52492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9OjAh5Y1i2tUxg4H6zgAABeM"] [Sat Aug 29 05:06:34.225028 2026] [security2:error] [pid 1017536:tid 1017790] [client 168.107.94.195:60481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9OiJcY4fy7tP-rU0JagAAApA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:34.232892 2026] [security2:error] [pid 1017536:tid 1017749] [client 158.23.184.117:59544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/wp-links-opml.php"] [unique_id "apK9OiJcY4fy7tP-rU0JawAAAmc"] [Sat Aug 29 05:06:34.237473 2026] [core:error] [pid 1017536:tid 1017583] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.237490 2026] [core:error] [pid 1017536:tid 1017583] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.238342 2026] [security2:error] [pid 1017536:tid 1017723] [client 40.83.93.50:1658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK9OiJcY4fy7tP-rU0JbgAAAk0"] [Sat Aug 29 05:06:34.255704 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.104.62:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/quoys.php"] [unique_id "apK9OjAh5Y1i2tUxg4H60QAABiY"] [Sat Aug 29 05:06:34.257704 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.104.104.62:48463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/xcre1.php"] [unique_id "apK9OiJcY4fy7tP-rU0JbwAAAl4"] [Sat Aug 29 05:06:34.260792 2026] [security2:error] [pid 1017536:tid 1017675] [client 93.123.109.228:50128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JcAAAAh0"] [Sat Aug 29 05:06:34.262947 2026] [security2:error] [pid 1017536:tid 1017698] [client 68.155.159.216:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9OiJcY4fy7tP-rU0JcQAAAjQ"] [Sat Aug 29 05:06:34.264008 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:55972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ms-edit.php"] [unique_id "apK9OiJcY4fy7tP-rU0JcgAAAnk"] [Sat Aug 29 05:06:34.271371 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.147.79:30655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9OiJcY4fy7tP-rU0JcwAAAj0"] [Sat Aug 29 05:06:34.285487 2026] [security2:error] [pid 1017536:tid 1017731] [client 93.123.109.228:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/public/phpinfo.php"] [unique_id "apK9OiJcY4fy7tP-rU0JdQAAAlU"] [Sat Aug 29 05:06:34.291572 2026] [security2:error] [pid 1017536:tid 1017792] [client 93.123.109.228:50124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JdgAAApI"] [Sat Aug 29 05:06:34.294624 2026] [security2:error] [pid 1017536:tid 1017786] [client 93.123.109.228:49518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JdwAAAow"] [Sat Aug 29 05:06:34.294851 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:49612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H60wAABdw"] [Sat Aug 29 05:06:34.301823 2026] [security2:error] [pid 1017536:tid 1017678] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JeAAAAiA"] [Sat Aug 29 05:06:34.325077 2026] [core:error] [pid 1017536:tid 1017552] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.325092 2026] [core:error] [pid 1017536:tid 1017552] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.326802 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.250.41:25379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/thui.php"] [unique_id "apK9OjAh5Y1i2tUxg4H61gAABbo"] [Sat Aug 29 05:06:34.338619 2026] [core:error] [pid 1017536:tid 1017595] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.338642 2026] [core:error] [pid 1017536:tid 1017595] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.338697 2026] [core:error] [pid 1017536:tid 1017557] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.338705 2026] [core:error] [pid 1017536:tid 1017557] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.341461 2026] [security2:error] [pid 1018003:tid 1018265] [client 52.139.37.240:14913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9OjAh5Y1i2tUxg4H61wAABik"] [Sat Aug 29 05:06:34.345325 2026] [core:error] [pid 1017536:tid 1017549] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.345337 2026] [core:error] [pid 1017536:tid 1017549] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.350982 2026] [security2:error] [pid 1017536:tid 1017721] [client 52.139.37.240:31088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK9OiJcY4fy7tP-rU0JhAAAAks"] [Sat Aug 29 05:06:34.352131 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.151.200.44:65033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/see.php"] [unique_id "apK9OiJcY4fy7tP-rU0JhgAAAkc"] [Sat Aug 29 05:06:34.352772 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.184.117:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK9OjAh5Y1i2tUxg4H62AAABfU"] [Sat Aug 29 05:06:34.353476 2026] [core:error] [pid 1017536:tid 1017600] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.353486 2026] [core:error] [pid 1017536:tid 1017600] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.366260 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.220.204.93:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/cytyr.php"] [unique_id "apK9OiJcY4fy7tP-rU0JiAAAAmc"] [Sat Aug 29 05:06:34.375929 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.184.117:60061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/wp-load.php"] [unique_id "apK9OjAh5Y1i2tUxg4H62gAABhY"] [Sat Aug 29 05:06:34.384272 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.104.62:4098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/vbbn.php"] [unique_id "apK9OjAh5Y1i2tUxg4H63AAABfs"] [Sat Aug 29 05:06:34.387256 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.104.104.62:20807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/xccc.php"] [unique_id "apK9OjAh5Y1i2tUxg4H63QAABiI"] [Sat Aug 29 05:06:34.388446 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.147.79:32660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/cong.php"] [unique_id "apK9OjAh5Y1i2tUxg4H63gAABdQ"] [Sat Aug 29 05:06:34.397745 2026] [core:error] [pid 1017536:tid 1017578] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.397799 2026] [core:error] [pid 1017536:tid 1017578] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.405694 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.104.104.62:36935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/bnnof6.php"] [unique_id "apK9OiJcY4fy7tP-rU0JjQAAAkA"] [Sat Aug 29 05:06:34.407568 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.151.200.44:47418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/str.php"] [unique_id "apK9OiJcY4fy7tP-rU0JjgAAAoc"] [Sat Aug 29 05:06:34.407923 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.104.62:48703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/motu.php"] [unique_id "apK9OiJcY4fy7tP-rU0JjwAAAkE"] [Sat Aug 29 05:06:34.422778 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.151.200.44:64835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/eval.php"] [unique_id "apK9OiJcY4fy7tP-rU0JkQAAAh0"] [Sat Aug 29 05:06:34.437250 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.23.147.79:25592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9OjAh5Y1i2tUxg4H66QAABhM"] [Sat Aug 29 05:06:34.439891 2026] [security2:error] [pid 1017536:tid 1017558] [remote 34.23.124.185:45974] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9OiJcY4fy7tP-rU0JlQACNBU"] [Sat Aug 29 05:06:34.440805 2026] [core:error] [pid 1017536:tid 1017570] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.440819 2026] [core:error] [pid 1017536:tid 1017570] [remote 34.23.124.185:45974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.442152 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.158.54.35:17098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/css/wp-login.php"] [unique_id "apK9OjAh5Y1i2tUxg4H66wAABfo"] [Sat Aug 29 05:06:34.465686 2026] [security2:error] [pid 1017536:tid 1017611] [remote 91.226.251.15:42594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.251.226.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eastsidepride.com"] [uri "/wp-login.php"] [unique_id "apK9OiJcY4fy7tP-rU0JlwACU0o"] [Sat Aug 29 05:06:34.469337 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.48.250.41:25515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/Jcrop.php"] [unique_id "apK9OjAh5Y1i2tUxg4H68AAABjM"] [Sat Aug 29 05:06:34.469396 2026] [security2:error] [pid 1018003:tid 1018206] [client 158.23.147.79:24503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/nf_tracking.php"] [unique_id "apK9OjAh5Y1i2tUxg4H67wAABe8"] [Sat Aug 29 05:06:34.503756 2026] [security2:error] [pid 1017536:tid 1017704] [client 93.123.109.228:49974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JoAAAAjo"] [Sat Aug 29 05:06:34.505193 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.196.209.81:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/goods.php"] [unique_id "apK9OiJcY4fy7tP-rU0JoQAAAmY"] [Sat Aug 29 05:06:34.519997 2026] [security2:error] [pid 1017536:tid 1017749] [client 185.104.184.230:52506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9OiJcY4fy7tP-rU0JpAAAAmc"] [Sat Aug 29 05:06:34.522654 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.184.117:21526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/wp-mail.php"] [unique_id "apK9OjAh5Y1i2tUxg4H69AAABd4"] [Sat Aug 29 05:06:34.541092 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.104.104.62:48756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/wefile.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6_QAABgY"] [Sat Aug 29 05:06:34.543584 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.104.104.62:64659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/rfi.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6_gAABfY"] [Sat Aug 29 05:06:34.544018 2026] [cgid:error] [pid 1018003:tid 1018164] [client 20.52.41.200:1252] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:34.547626 2026] [security2:error] [pid 1018003:tid 1018195] [client 52.139.37.240:31640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK9OjAh5Y1i2tUxg4H6_wAABeQ"] [Sat Aug 29 05:06:34.573095 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.151.200.44:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/horeg.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7AQAABc8"] [Sat Aug 29 05:06:34.574509 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.220.204.93:59073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/galer.php"] [unique_id "apK9OiJcY4fy7tP-rU0JpgAAAk0"] [Sat Aug 29 05:06:34.575794 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.23.184.117:62276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-admin/css/admin.php"] [unique_id "apK9OiJcY4fy7tP-rU0JpwAAApM"] [Sat Aug 29 05:06:34.600518 2026] [security2:error] [pid 1018003:tid 1018252] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9OjAh5Y1i2tUxg4H7BQAABhw"] [Sat Aug 29 05:06:34.603956 2026] [security2:error] [pid 1018003:tid 1018222] [client 52.139.37.240:15246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/wp-index.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7BgAABf8"] [Sat Aug 29 05:06:34.605144 2026] [security2:error] [pid 1018003:tid 1018187] [client 168.107.94.195:63121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7BwAABdw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:34.616173 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.104.104.62:28588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ronsseptic.com"] [uri "/wp-content/index.php"] [unique_id "apK9OiJcY4fy7tP-rU0JqwAAAkE"] [Sat Aug 29 05:06:34.617897 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.104.104.62:42626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/ah24.php"] [unique_id "apK9OiJcY4fy7tP-rU0JrAAAAjs"] [Sat Aug 29 05:06:34.618079 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.196.209.81:16755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/wp-2019.php"] [unique_id "apK9OiJcY4fy7tP-rU0JrQAAAlU"] [Sat Aug 29 05:06:34.633316 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.205.62.107:22375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/register.php"] [unique_id "apK9OiJcY4fy7tP-rU0JrwAAAh0"] [Sat Aug 29 05:06:34.637764 2026] [security2:error] [pid 1017536:tid 1017698] [client 158.23.147.79:30592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/about.php"] [unique_id "apK9OiJcY4fy7tP-rU0JsQAAAjQ"] [Sat Aug 29 05:06:34.646488 2026] [security2:error] [pid 1018003:tid 1018167] [client 68.155.159.216:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/simple.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7CwAABcg"] [Sat Aug 29 05:06:34.649661 2026] [security2:error] [pid 1018003:tid 1018246] [client 93.123.109.228:49994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9OjAh5Y1i2tUxg4H7DAAABhY"] [Sat Aug 29 05:06:34.651906 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.48.250.41:25436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ws58.php"] [unique_id "apK9OiJcY4fy7tP-rU0JswAAAoY"] [Sat Aug 29 05:06:34.653081 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.147.79:61623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7DQAABfs"] [Sat Aug 29 05:06:34.655753 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.104.62:20841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/moon.php"] [unique_id "apK9OiJcY4fy7tP-rU0JtAAAAis"] [Sat Aug 29 05:06:34.661168 2026] [security2:error] [pid 1017536:tid 1017743] [client 93.123.109.228:50068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9OiJcY4fy7tP-rU0JtQAAAmE"] [Sat Aug 29 05:06:34.668229 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.184.117:59575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/wp-settings.php"] [unique_id "apK9OiJcY4fy7tP-rU0JtgAAAjs"] [Sat Aug 29 05:06:34.672042 2026] [security2:error] [pid 1017536:tid 1017751] [client 93.123.109.228:49708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JtwAAAmk"] [Sat Aug 29 05:06:34.694027 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.52.41.200:1252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/a.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7EAAABcQ"] [Sat Aug 29 05:06:34.700392 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.151.200.44:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/sao.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7EQAABjQ"] [Sat Aug 29 05:06:34.701631 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.104.62:43011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/tajj.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7EgAABhQ"] [Sat Aug 29 05:06:34.721028 2026] [security2:error] [pid 1017536:tid 1017669] [client 158.23.184.117:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/bthil.php"] [unique_id "apK9OiJcY4fy7tP-rU0JugAAAhc"] [Sat Aug 29 05:06:34.726477 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.104.62:48500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/EM.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7FQAABe8"] [Sat Aug 29 05:06:34.728031 2026] [security2:error] [pid 1017536:tid 1017790] [client 40.83.93.50:1769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-blog-header.php"] [unique_id "apK9OiJcY4fy7tP-rU0JvQAAApA"] [Sat Aug 29 05:06:34.734811 2026] [core:error] [pid 1017536:tid 1017538] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.734817 2026] [core:error] [pid 1017536:tid 1017585] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.734827 2026] [core:error] [pid 1017536:tid 1017538] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.734831 2026] [core:error] [pid 1017536:tid 1017585] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.735212 2026] [security2:error] [pid 1017536:tid 1017569] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/web.config"] [unique_id "apK9OiJcY4fy7tP-rU0JwwACjCA"] [Sat Aug 29 05:06:34.735842 2026] [core:error] [pid 1017536:tid 1017572] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.735851 2026] [core:error] [pid 1017536:tid 1017608] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.737073 2026] [core:error] [pid 1017536:tid 1017621] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.742839 2026] [security2:error] [pid 1018003:tid 1018179] [client 52.139.37.240:31655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7FgAABdQ"] [Sat Aug 29 05:06:34.751036 2026] [security2:error] [pid 1017536:tid 1017736] [client 93.123.109.228:49766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JxQAAAlo"] [Sat Aug 29 05:06:34.757479 2026] [security2:error] [pid 1017536:tid 1017694] [client 93.123.109.228:49996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JxgAAAjA"] [Sat Aug 29 05:06:34.790763 2026] [security2:error] [pid 1018003:tid 1018275] [client 52.139.37.240:52644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/aged.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7GQAABjM"] [Sat Aug 29 05:06:34.799391 2026] [security2:error] [pid 1017536:tid 1017749] [client 52.139.37.240:14954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/ww2.php"] [unique_id "apK9OiJcY4fy7tP-rU0JyQAAAmc"] [Sat Aug 29 05:06:34.802337 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:37897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7GgAABb4"] [Sat Aug 29 05:06:34.818612 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.184.117:60065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/.well-known/wp-signup.php"] [unique_id "apK9OiJcY4fy7tP-rU0JzwAAAhs"] [Sat Aug 29 05:06:34.818737 2026] [security2:error] [pid 1017536:tid 1017753] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9OiJcY4fy7tP-rU0JzgAAAms"] [Sat Aug 29 05:06:34.819412 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.48.250.41:25570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/xs.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7HAAABdA"] [Sat Aug 29 05:06:34.820131 2026] [security2:error] [pid 1018003:tid 1018185] [client 185.104.184.230:52530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK9OjAh5Y1i2tUxg4H7HQAABdo"] [Sat Aug 29 05:06:34.823369 2026] [security2:error] [pid 1017536:tid 1017729] [client 93.123.109.228:50068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9OiJcY4fy7tP-rU0J0QAAAlM"] [Sat Aug 29 05:06:34.833925 2026] [security2:error] [pid 1018003:tid 1018255] [client 93.123.109.228:49612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H7HwAABh8"] [Sat Aug 29 05:06:34.841311 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.151.200.44:64395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/basic.php"] [unique_id "apK9OiJcY4fy7tP-rU0J1AAAAoY"] [Sat Aug 29 05:06:34.843248 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:26536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/dropdown.php"] [unique_id "apK9OiJcY4fy7tP-rU0J1QAAApI"] [Sat Aug 29 05:06:34.846484 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.147.79:48255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/install.php"] [unique_id "apK9OiJcY4fy7tP-rU0J1wAAAmE"] [Sat Aug 29 05:06:34.850863 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.104.62:60471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/ztv.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7IQAABcA"] [Sat Aug 29 05:06:34.856705 2026] [security2:error] [pid 1018003:tid 1018245] [client 20.220.204.93:59106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/baixy.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7IgAABhU"] [Sat Aug 29 05:06:34.866043 2026] [security2:error] [pid 1017536:tid 1017675] [client 158.23.184.117:46338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/file.php"] [unique_id "apK9OiJcY4fy7tP-rU0J2gAAAh0"] [Sat Aug 29 05:06:34.868007 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.197.61.180:7557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/wp-contentt.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7IwAABhA"] [Sat Aug 29 05:06:34.868155 2026] [security2:error] [pid 1018003:tid 1018156] [client 4.205.62.107:22376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wp-jufsis.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7JAAABb0"] [Sat Aug 29 05:06:34.872682 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.151.200.44:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/uuu.php"] [unique_id "apK9OiJcY4fy7tP-rU0J3QAAAlY"] [Sat Aug 29 05:06:34.879703 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.104.104.62:28556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ronsseptic.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9OiJcY4fy7tP-rU0J3wAAAiM"] [Sat Aug 29 05:06:34.894502 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.158.54.35:14140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/images/index.php"] [unique_id "apK9OiJcY4fy7tP-rU0J4AAAAi0"] [Sat Aug 29 05:06:34.895070 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.147.79:35738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/asd.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7KwAABfY"] [Sat Aug 29 05:06:34.903498 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.196.209.81:17907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/hehe.php"] [unique_id "apK9OiJcY4fy7tP-rU0J4gAAApM"] [Sat Aug 29 05:06:34.903997 2026] [security2:error] [pid 1017536:tid 1017564] [remote 52.167.144.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9OiJcY4fy7tP-rU0J4wACXhs"] [Sat Aug 29 05:06:34.910325 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.104.104.62:43032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/grsiuk.php"] [unique_id "apK9OiJcY4fy7tP-rU0J5AAAAhc"] [Sat Aug 29 05:06:34.911473 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:49297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/NewFile.php/"] [unique_id "apK9OjAh5Y1i2tUxg4H7MwAABd8"] [Sat Aug 29 05:06:34.916168 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.104.49.130:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/log.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7NAAABeM"] [Sat Aug 29 05:06:34.926387 2026] [security2:error] [pid 1018003:tid 1018199] [client 20.104.104.62:48659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/ca4.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7NwAABeg"] [Sat Aug 29 05:06:34.931020 2026] [security2:error] [pid 1017536:tid 1017709] [client 4.205.62.107:22288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/333.php"] [unique_id "apK9OiJcY4fy7tP-rU0J5wAAAj8"] [Sat Aug 29 05:06:34.942029 2026] [security2:error] [pid 1017536:tid 1017695] [client 93.123.109.228:49754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/info.php"] [unique_id "apK9OiJcY4fy7tP-rU0J6QAAAjE"] [Sat Aug 29 05:06:34.948811 2026] [security2:error] [pid 1017536:tid 1017734] [client 93.123.109.228:49708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/infophp.php"] [unique_id "apK9OiJcY4fy7tP-rU0J6wAAAlg"] [Sat Aug 29 05:06:34.961107 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.104.62:20862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wkwk.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7PQAABiA"] [Sat Aug 29 05:06:34.962035 2026] [security2:error] [pid 1017536:tid 1017776] [client 4.205.62.107:26639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/sadd.php"] [unique_id "apK9OiJcY4fy7tP-rU0J7AAAAoI"] [Sat Aug 29 05:06:34.966470 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.184.117:59571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/002.php"] [unique_id "apK9OiJcY4fy7tP-rU0J7gAAAho"] [Sat Aug 29 05:06:34.968861 2026] [security2:error] [pid 1017536:tid 1017711] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9OiJcY4fy7tP-rU0J8AAAAkE"] [Sat Aug 29 05:06:34.971892 2026] [security2:error] [pid 1018003:tid 1018259] [client 93.123.109.228:50102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9OjAh5Y1i2tUxg4H7PwAABiM"] [Sat Aug 29 05:06:34.977339 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.184.117:34695] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.miketowery.net"] [uri "/1.php"] [unique_id "apK9OiJcY4fy7tP-rU0J8wAAAj0"] [Sat Aug 29 05:06:34.977463 2026] [security2:error] [pid 1017536:tid 1017707] [client 158.23.184.117:34695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/1.php"] [unique_id "apK9OiJcY4fy7tP-rU0J8wAAAj0"] [Sat Aug 29 05:06:34.985592 2026] [security2:error] [pid 1018003:tid 1018218] [client 168.107.94.195:63445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7QAAABfs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:34.987758 2026] [core:error] [pid 1017536:tid 1017580] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.987781 2026] [core:error] [pid 1017536:tid 1017580] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.989489 2026] [core:error] [pid 1017536:tid 1017610] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.989505 2026] [core:error] [pid 1017536:tid 1017610] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.989518 2026] [core:error] [pid 1017536:tid 1017646] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.989531 2026] [core:error] [pid 1017536:tid 1017646] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.990242 2026] [core:error] [pid 1017536:tid 1017634] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.990255 2026] [core:error] [pid 1017536:tid 1017634] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.990256 2026] [core:error] [pid 1017536:tid 1017577] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.990265 2026] [core:error] [pid 1017536:tid 1017577] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.990467 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.48.250.41:25361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/zu.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7QQAABik"] [Sat Aug 29 05:06:34.991380 2026] [core:error] [pid 1017536:tid 1017648] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.991396 2026] [core:error] [pid 1017536:tid 1017648] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:34.997763 2026] [security2:error] [pid 1017536:tid 1017736] [client 52.139.37.240:15236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/7logs.php"] [unique_id "apK9OiJcY4fy7tP-rU0J-wAAAlo"] [Sat Aug 29 05:06:34.998112 2026] [security2:error] [pid 1018003:tid 1018233] [client 93.123.109.228:50016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/infos.php"] [unique_id "apK9OjAh5Y1i2tUxg4H7RAAABgk"] [Sat Aug 29 05:06:35.010783 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.184.117:62320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/lock360.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7RgAABbo"] [Sat Aug 29 05:06:35.011604 2026] [security2:error] [pid 1018003:tid 1018252] [client 52.139.37.240:52614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/essexec.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7SAAABhw"] [Sat Aug 29 05:06:35.015605 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.104.104.62:23402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/kure.php"] [unique_id "apK9OyJcY4fy7tP-rU0J_gAAApI"] [Sat Aug 29 05:06:35.026065 2026] [autoindex:error] [pid 1018003:tid 1018171] [client 52.139.37.240:0] AH01276: Cannot serve directory /home4/swumccom/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:35.027022 2026] [security2:error] [pid 1018003:tid 1018207] [client 93.123.109.228:49954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7SQAABfA"] [Sat Aug 29 05:06:35.027452 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.220.204.93:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ava.php"] [unique_id "apK9OyJcY4fy7tP-rU0J_wAAAh0"] [Sat Aug 29 05:06:35.035023 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.196.209.81:19423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/menu.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7SgAABcU"] [Sat Aug 29 05:06:35.044717 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.184.117:34547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/2.php"] [unique_id "apK9OyJcY4fy7tP-rU0KAAAAAhs"] [Sat Aug 29 05:06:35.052224 2026] [security2:error] [pid 1017536:tid 1017748] [client 93.123.109.228:50038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KAQAAAmY"] [Sat Aug 29 05:06:35.072787 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.151.200.44:46629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/mega.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7TAAABjU"] [Sat Aug 29 05:06:35.075320 2026] [security2:error] [pid 1018003:tid 1018267] [client 93.123.109.228:50058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7TQAABis"] [Sat Aug 29 05:06:35.102379 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.151.200.44:65034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/monso.php"] [unique_id "apK9OyJcY4fy7tP-rU0KAgAAApM"] [Sat Aug 29 05:06:35.109035 2026] [security2:error] [pid 1018003:tid 1018217] [client 52.139.37.240:31546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7UQAABfo"] [Sat Aug 29 05:06:35.115824 2026] [security2:error] [pid 1017536:tid 1017761] [client 158.23.184.117:60067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/0x.php"] [unique_id "apK9OyJcY4fy7tP-rU0KAwAAAnM"] [Sat Aug 29 05:06:35.116693 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.104.104.62:4816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/ahy66.php"] [unique_id "apK9OyJcY4fy7tP-rU0KBgAAApA"] [Sat Aug 29 05:06:35.119085 2026] [core:error] [pid 1017536:tid 1017631] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.119100 2026] [core:error] [pid 1017536:tid 1017631] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.119870 2026] [core:error] [pid 1017536:tid 1017615] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.119886 2026] [core:error] [pid 1017536:tid 1017615] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.122816 2026] [security2:error] [pid 1018003:tid 1018160] [client 185.104.184.230:52538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9OzAh5Y1i2tUxg4H7UwAABcE"] [Sat Aug 29 05:06:35.136710 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.48.250.41:25526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/lanka.php"] [unique_id "apK9OyJcY4fy7tP-rU0KCgAAAlg"] [Sat Aug 29 05:06:35.138117 2026] [security2:error] [pid 1017536:tid 1017786] [client 93.123.109.228:50176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KCwAAAow"] [Sat Aug 29 05:06:35.138701 2026] [security2:error] [pid 1017536:tid 1017776] [client 93.123.109.228:49974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KDAAAAoI"] [Sat Aug 29 05:06:35.151167 2026] [security2:error] [pid 1017536:tid 1017781] [client 111.235.68.106:35756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9OyJcY4fy7tP-rU0KDQAAAoc"] [Sat Aug 29 05:06:35.151285 2026] [security2:error] [pid 1017536:tid 1017781] [client 111.235.68.106:35756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9OyJcY4fy7tP-rU0KDQAAAoc"] [Sat Aug 29 05:06:35.152130 2026] [security2:error] [pid 1017536:tid 1017669] [client 158.23.184.117:46358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/fpwch.php"] [unique_id "apK9OyJcY4fy7tP-rU0KDgAAAhc"] [Sat Aug 29 05:06:35.166272 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.52.41.200:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/u.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7WAAABgM"] [Sat Aug 29 05:06:35.189453 2026] [security2:error] [pid 1017536:tid 1017780] [client 68.155.159.216:33671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9OyJcY4fy7tP-rU0KEgAAAoY"] [Sat Aug 29 05:06:35.192438 2026] [security2:error] [pid 1018003:tid 1018261] [client 68.155.159.216:52738] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.philadelphialawworks.org"] [uri "/1.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7WgAABiU"] [Sat Aug 29 05:06:35.192461 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.184.117:34702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/7.php"] [unique_id "apK9OyJcY4fy7tP-rU0KFQAAAho"] [Sat Aug 29 05:06:35.192512 2026] [security2:error] [pid 1018003:tid 1018261] [client 68.155.159.216:52738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/1.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7WgAABiU"] [Sat Aug 29 05:06:35.195986 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:14657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/ac.php"] [unique_id "apK9OyJcY4fy7tP-rU0KFwAAAiA"] [Sat Aug 29 05:06:35.203389 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.104.104.62:64735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wpvitamins.php"] [unique_id "apK9OyJcY4fy7tP-rU0KGQAAAls"] [Sat Aug 29 05:06:35.207014 2026] [security2:error] [pid 1017536:tid 1017689] [client 20.104.104.62:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newfweiler.marklutton.com"] [uri "/x0x.php"] [unique_id "apK9OyJcY4fy7tP-rU0KGwAAAis"] [Sat Aug 29 05:06:35.208978 2026] [security2:error] [pid 1017536:tid 1017731] [client 52.139.37.240:52640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/fw.php"] [unique_id "apK9OyJcY4fy7tP-rU0KHAAAAlU"] [Sat Aug 29 05:06:35.221971 2026] [security2:error] [pid 1017536:tid 1017691] [client 40.83.93.50:1762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-blogs.php"] [unique_id "apK9OyJcY4fy7tP-rU0KHgAAAi0"] [Sat Aug 29 05:06:35.227813 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.104.62:28562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ronsseptic.com"] [uri "/403.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7XQAABec"] [Sat Aug 29 05:06:35.228096 2026] [security2:error] [pid 1018003:tid 1018240] [client 93.123.109.228:49798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7XAAABhA"] [Sat Aug 29 05:06:35.235917 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.63.81.20:46937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/domvf.php"] [unique_id "apK9OyJcY4fy7tP-rU0KIQAAAmY"] [Sat Aug 29 05:06:35.242160 2026] [security2:error] [pid 1018003:tid 1018243] [client 103.162.125.59:54109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7XgAABhM"] [Sat Aug 29 05:06:35.242239 2026] [security2:error] [pid 1018003:tid 1018243] [client 103.162.125.59:54109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7XgAABhM"] [Sat Aug 29 05:06:35.244011 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.104.62:60426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/cafe.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7XwAABiw"] [Sat Aug 29 05:06:35.249726 2026] [core:error] [pid 1017536:tid 1017644] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.249740 2026] [core:error] [pid 1017536:tid 1017644] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.259295 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.220.204.93:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/gdn.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7YQAABgY"] [Sat Aug 29 05:06:35.264944 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.151.200.44:64416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/rce.php"] [unique_id "apK9OyJcY4fy7tP-rU0KJAAAApA"] [Sat Aug 29 05:06:35.270042 2026] [core:error] [pid 1017536:tid 1017661] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.270060 2026] [core:error] [pid 1017536:tid 1017661] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.271406 2026] [security2:error] [pid 1017536:tid 1017734] [client 20.48.250.41:25372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/gettest.php"] [unique_id "apK9OyJcY4fy7tP-rU0KKAAAAlg"] [Sat Aug 29 05:06:35.271691 2026] [core:error] [pid 1017536:tid 1017651] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.271698 2026] [core:error] [pid 1017536:tid 1017651] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.272326 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.104.104.62:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/gaje.php"] [unique_id "apK9OyJcY4fy7tP-rU0KKQAAAoI"] [Sat Aug 29 05:06:35.278540 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.184.117:21507] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/1.php"] [unique_id "apK9OyJcY4fy7tP-rU0KKwAAAi0"] [Sat Aug 29 05:06:35.278627 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.184.117:21507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/1.php"] [unique_id "apK9OyJcY4fy7tP-rU0KKwAAAi0"] [Sat Aug 29 05:06:35.278740 2026] [security2:error] [pid 1017536:tid 1017669] [client 68.155.159.216:51441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/about.php"] [unique_id "apK9OyJcY4fy7tP-rU0KLAAAAhc"] [Sat Aug 29 05:06:35.278988 2026] [security2:error] [pid 1017536:tid 1017781] [client 93.123.109.228:50044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KKgAAAoc"] [Sat Aug 29 05:06:35.279793 2026] [security2:error] [pid 1017536:tid 1017717] [client 68.155.159.216:18332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9OyJcY4fy7tP-rU0KLgAAAkc"] [Sat Aug 29 05:06:35.281083 2026] [security2:error] [pid 1017536:tid 1017710] [client 93.123.109.228:50032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KLwAAAkA"] [Sat Aug 29 05:06:35.285012 2026] [security2:error] [pid 1018003:tid 1018195] [client 93.123.109.228:50102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7YwAABeQ"] [Sat Aug 29 05:06:35.291961 2026] [security2:error] [pid 1017536:tid 1017736] [client 93.123.109.228:50176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KMQAAAlo"] [Sat Aug 29 05:06:35.295597 2026] [core:error] [pid 1017536:tid 1017643] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.295611 2026] [core:error] [pid 1017536:tid 1017643] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.296661 2026] [core:error] [pid 1017536:tid 1017554] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.296673 2026] [core:error] [pid 1017536:tid 1017554] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.298113 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.184.117:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/storage/index.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7ZAAABd4"] [Sat Aug 29 05:06:35.300487 2026] [core:error] [pid 1017536:tid 1017614] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.300499 2026] [core:error] [pid 1017536:tid 1017614] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.304062 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.63.81.20:56885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/llyuxaqd.php"] [unique_id "apK9OyJcY4fy7tP-rU0KNwAAAk0"] [Sat Aug 29 05:06:35.309764 2026] [security2:error] [pid 1017536:tid 1017733] [client 52.139.37.240:31617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-info.php"] [unique_id "apK9OyJcY4fy7tP-rU0KOQAAAlc"] [Sat Aug 29 05:06:35.313413 2026] [core:error] [pid 1017536:tid 1017630] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.313430 2026] [core:error] [pid 1017536:tid 1017630] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.336673 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.23.184.117:34516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/10.php"] [unique_id "apK9OyJcY4fy7tP-rU0KOwAAAo4"] [Sat Aug 29 05:06:35.338679 2026] [security2:error] [pid 1017536:tid 1017731] [client 93.123.109.228:49518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KPAAAAlU"] [Sat Aug 29 05:06:35.343030 2026] [security2:error] [pid 1017536:tid 1017622] [remote 198.52.231.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.231.52.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/wp-comments-post.php"] [unique_id "apK9OyJcY4fy7tP-rU0KNgACi1U"] [Sat Aug 29 05:06:35.343201 2026] [security2:error] [pid 1017536:tid 1017785] [client 198.52.231.183:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "giantsfans.net"] [uri "/wp-comments-post.php"] [unique_id "apK9OyJcY4fy7tP-rU0KNgACi1U"] [Sat Aug 29 05:06:35.359696 2026] [security2:error] [pid 1017536:tid 1017792] [client 4.205.62.107:53437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/autogooey.php"] [unique_id "apK9OyJcY4fy7tP-rU0KPwAAApI"] [Sat Aug 29 05:06:35.362439 2026] [core:error] [pid 1017536:tid 1017729] [client 158.158.54.35:2856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.362453 2026] [core:error] [pid 1017536:tid 1017729] [client 158.158.54.35:2856] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.367572 2026] [security2:error] [pid 1018003:tid 1018188] [client 168.107.94.195:63844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7ZwAABd0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:35.368242 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.151.200.44:64277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/private.php"] [unique_id "apK9OyJcY4fy7tP-rU0KQQAAAmc"] [Sat Aug 29 05:06:35.368858 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.151.200.44:47358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/ww3.php"] [unique_id "apK9OyJcY4fy7tP-rU0KQgAAAiM"] [Sat Aug 29 05:06:35.377654 2026] [security2:error] [pid 1018003:tid 1018256] [client 68.155.159.216:50275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/goat1.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7aAAABiA"] [Sat Aug 29 05:06:35.381680 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.147.79:30637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9OyJcY4fy7tP-rU0KRAAAAow"] [Sat Aug 29 05:06:35.386304 2026] [security2:error] [pid 1018003:tid 1018212] [client 93.123.109.228:49664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7agAABfU"] [Sat Aug 29 05:06:35.389484 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.63.81.20:46901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/biufile.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7bAAABiY"] [Sat Aug 29 05:06:35.390246 2026] [security2:error] [pid 1017536:tid 1017705] [client 52.139.37.240:15277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/ctex1.php"] [unique_id "apK9OyJcY4fy7tP-rU0KRgAAAjs"] [Sat Aug 29 05:06:35.391078 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.220.204.93:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/f2.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7bQAABcg"] [Sat Aug 29 05:06:35.400317 2026] [security2:error] [pid 1017536:tid 1017724] [client 4.205.62.107:55990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/lmfi2.php"] [unique_id "apK9OyJcY4fy7tP-rU0KSgAAAk4"] [Sat Aug 29 05:06:35.401652 2026] [security2:error] [pid 1018003:tid 1018030] [remote 34.75.89.130:51724] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "freejohnstuart.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9OzAh5Y1i2tUxg4H7cQAGCQk"] [Sat Aug 29 05:06:35.415098 2026] [core:error] [pid 1017536:tid 1017628] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.415117 2026] [core:error] [pid 1017536:tid 1017628] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.418104 2026] [security2:error] [pid 1018003:tid 1018222] [client 52.139.37.240:52623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/zwso.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7dQAABf8"] [Sat Aug 29 05:06:35.418451 2026] [security2:error] [pid 1017536:tid 1017547] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/app/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KTgACQAo"] [Sat Aug 29 05:06:35.418964 2026] [security2:error] [pid 1017536:tid 1017709] [client 158.23.184.117:22274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/10.php"] [unique_id "apK9OyJcY4fy7tP-rU0KUQAAAj8"] [Sat Aug 29 05:06:35.419159 2026] [security2:error] [pid 1017536:tid 1017669] [client 93.123.109.228:49600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KTQAAAhc"] [Sat Aug 29 05:06:35.419177 2026] [security2:error] [pid 1017536:tid 1017565] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/server/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KTwACQBw"] [Sat Aug 29 05:06:35.419470 2026] [security2:error] [pid 1017536:tid 1017663] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/dev/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KUAACQH4"] [Sat Aug 29 05:06:35.425192 2026] [security2:error] [pid 1017536:tid 1017713] [client 185.104.184.230:52546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9OyJcY4fy7tP-rU0KUgAAAkM"] [Sat Aug 29 05:06:35.426188 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.104.62:28565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ronsseptic.com"] [uri "/ava.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7dgAABdw"] [Sat Aug 29 05:06:35.433841 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.220.204.93:59091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7eAAABhw"] [Sat Aug 29 05:06:35.436007 2026] [security2:error] [pid 1017536:tid 1017584] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/frontend/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KVAACJS8"] [Sat Aug 29 05:06:35.436030 2026] [security2:error] [pid 1017536:tid 1017638] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/src/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KVQACJWU"] [Sat Aug 29 05:06:35.436394 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.250.41:25349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/35.php"] [unique_id "apK9OyJcY4fy7tP-rU0KVgAAAnc"] [Sat Aug 29 05:06:35.441179 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.63.81.20:60451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/nbwxolou.php"] [unique_id "apK9OyJcY4fy7tP-rU0KWAAAAjI"] [Sat Aug 29 05:06:35.445938 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.196.209.81:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7ewAABdg"] [Sat Aug 29 05:06:35.482745 2026] [security2:error] [pid 1017536:tid 1017780] [client 158.23.184.117:34737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/13.php"] [unique_id "apK9OyJcY4fy7tP-rU0KXAAAAoY"] [Sat Aug 29 05:06:35.490238 2026] [security2:error] [pid 1018003:tid 1018170] [client 93.123.109.228:49954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7fgAABcs"] [Sat Aug 29 05:06:35.491868 2026] [security2:error] [pid 1017536:tid 1017674] [client 93.123.109.228:49518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9OyJcY4fy7tP-rU0KXQAAAhw"] [Sat Aug 29 05:06:35.496663 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.23.184.117:46947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-includes/blocks/search/index.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7fwAABcI"] [Sat Aug 29 05:06:35.498965 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.196.209.81:3900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/alfa.php"] [unique_id "apK9OyJcY4fy7tP-rU0KXwAAAlY"] [Sat Aug 29 05:06:35.503146 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:31130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK9OyJcY4fy7tP-rU0KYQAAAiA"] [Sat Aug 29 05:06:35.503775 2026] [security2:error] [pid 1017536:tid 1017743] [client 93.123.109.228:49966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KYAAAAmE"] [Sat Aug 29 05:06:35.511287 2026] [security2:error] [pid 1017536:tid 1017706] [client 93.123.109.228:49940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KYgAAAjw"] [Sat Aug 29 05:06:35.518045 2026] [security2:error] [pid 1017536:tid 1017649] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/production/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KZQACjHA"] [Sat Aug 29 05:06:35.518579 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.63.81.20:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/blacks.php"] [unique_id "apK9OyJcY4fy7tP-rU0KZwAAAjE"] [Sat Aug 29 05:06:35.519814 2026] [security2:error] [pid 1017536:tid 1017623] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/docker/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KZgACjFY"] [Sat Aug 29 05:06:35.537132 2026] [security2:error] [pid 1017536:tid 1017724] [client 93.123.109.228:50068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/test.php"] [unique_id "apK9OyJcY4fy7tP-rU0KaAAAAk4"] [Sat Aug 29 05:06:35.539568 2026] [security2:error] [pid 1017536:tid 1017637] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/apps/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KaQACWGQ"] [Sat Aug 29 05:06:35.539569 2026] [security2:error] [pid 1017536:tid 1017553] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/staging/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KagACWBA"] [Sat Aug 29 05:06:35.540034 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.147.79:32685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9OyJcY4fy7tP-rU0KawAAAi0"] [Sat Aug 29 05:06:35.542997 2026] [security2:error] [pid 1017536:tid 1017717] [client 93.123.109.228:50164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KbAAAAkc"] [Sat Aug 29 05:06:35.544612 2026] [security2:error] [pid 1017536:tid 1017753] [client 158.23.147.79:25504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9OyJcY4fy7tP-rU0KbQAAAms"] [Sat Aug 29 05:06:35.548633 2026] [security2:error] [pid 1017536:tid 1017568] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/v2/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KbgACPR8"] [Sat Aug 29 05:06:35.552862 2026] [security2:error] [pid 1017536:tid 1017704] [client 45.148.10.62:38770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ninaanddon.strangeworx.com"] [uri "/stripe/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KbwAAAjo"] [Sat Aug 29 05:06:35.559226 2026] [security2:error] [pid 1017536:tid 1017681] [client 158.23.184.117:21517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/100.php"] [unique_id "apK9OyJcY4fy7tP-rU0KcAAAAiM"] [Sat Aug 29 05:06:35.566429 2026] [security2:error] [pid 1017536:tid 1017713] [client 93.123.109.228:49600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KcgAAAkM"] [Sat Aug 29 05:06:35.567430 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.151.200.44:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/exec.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7gwAABcE"] [Sat Aug 29 05:06:35.568782 2026] [security2:error] [pid 1017536:tid 1017593] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/v1/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KdAACMjg"] [Sat Aug 29 05:06:35.574830 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.63.81.20:60539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/nsxeubyv.php"] [unique_id "apK9OyJcY4fy7tP-rU0KdQAAAho"] [Sat Aug 29 05:06:35.581483 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.220.204.93:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/grsiuk.php"] [unique_id "apK9OyJcY4fy7tP-rU0KdgAAAh0"] [Sat Aug 29 05:06:35.584934 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:24323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wzy.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7hAAABgc"] [Sat Aug 29 05:06:35.586709 2026] [security2:error] [pid 1018003:tid 1018206] [client 52.139.37.240:14941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/defaults.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7hQAABe8"] [Sat Aug 29 05:06:35.591582 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.197.61.180:9405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/theme.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7hgAABfk"] [Sat Aug 29 05:06:35.600224 2026] [security2:error] [pid 1018003:tid 1018192] [client 93.123.109.228:50102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7hwAABeE"] [Sat Aug 29 05:06:35.603120 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.151.200.44:47308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/sko.php"] [unique_id "apK9OyJcY4fy7tP-rU0KeAAAAos"] [Sat Aug 29 05:06:35.605804 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.48.250.41:25471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/maraz.php"] [unique_id "apK9OyJcY4fy7tP-rU0KeQAAAoI"] [Sat Aug 29 05:06:35.608674 2026] [security2:error] [pid 1017536:tid 1017740] [client 93.123.109.228:49782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KegAAAl4"] [Sat Aug 29 05:06:35.613713 2026] [security2:error] [pid 1018003:tid 1018179] [client 52.139.37.240:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/admin/function.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7iQAABdQ"] [Sat Aug 29 05:06:35.614535 2026] [security2:error] [pid 1017536:tid 1017731] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KewAAAlU"] [Sat Aug 29 05:06:35.619202 2026] [security2:error] [pid 1017536:tid 1017656] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/old/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KfAAChnc"] [Sat Aug 29 05:06:35.620509 2026] [security2:error] [pid 1017536:tid 1017652] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/site/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KfQAChnM"] [Sat Aug 29 05:06:35.623343 2026] [security2:error] [pid 1018003:tid 1018171] [client 20.52.41.200:1229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/r.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7igAABcw"] [Sat Aug 29 05:06:35.625280 2026] [security2:error] [pid 1017536:tid 1017751] [client 158.23.184.117:34722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/100.php"] [unique_id "apK9OyJcY4fy7tP-rU0KfgAAAmk"] [Sat Aug 29 05:06:35.634234 2026] [security2:error] [pid 1017536:tid 1017641] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/env.bak"] [unique_id "apK9OyJcY4fy7tP-rU0KgAACYWg"] [Sat Aug 29 05:06:35.634621 2026] [security2:error] [pid 1017536:tid 1017793] [client 93.123.109.228:50128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KgQAAApM"] [Sat Aug 29 05:06:35.635245 2026] [security2:error] [pid 1017536:tid 1017556] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/portal/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KggACYRM"] [Sat Aug 29 05:06:35.637550 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.220.204.93:59103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7iwAABdk"] [Sat Aug 29 05:06:35.641188 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.23.184.117:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-signup.php"] [unique_id "apK9OyJcY4fy7tP-rU0KgwAAAo4"] [Sat Aug 29 05:06:35.659836 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.63.81.20:46888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/beck.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7jQAABdo"] [Sat Aug 29 05:06:35.665545 2026] [security2:error] [pid 1018003:tid 1018177] [client 93.123.109.228:49798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7jgAABdI"] [Sat Aug 29 05:06:35.667527 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.151.200.44:64293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/lfi.php"] [unique_id "apK9OyJcY4fy7tP-rU0KhwAAAkc"] [Sat Aug 29 05:06:35.676735 2026] [security2:error] [pid 1017536:tid 1017654] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.docker/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KiAACP3U"] [Sat Aug 29 05:06:35.697705 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:31098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/ws49.php"] [unique_id "apK9OyJcY4fy7tP-rU0KiwAAAiA"] [Sat Aug 29 05:06:35.700198 2026] [security2:error] [pid 1018003:tid 1018219] [client 93.123.109.228:49664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7kgAABfw"] [Sat Aug 29 05:06:35.703792 2026] [security2:error] [pid 1017536:tid 1017748] [client 158.23.184.117:21534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/2.php"] [unique_id "apK9OyJcY4fy7tP-rU0KjAAAAmY"] [Sat Aug 29 05:06:35.704295 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.63.81.20:56904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/zfqipfss.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7lAAABec"] [Sat Aug 29 05:06:35.705261 2026] [security2:error] [pid 1018003:tid 1018261] [client 93.123.109.228:49932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7kwAABiU"] [Sat Aug 29 05:06:35.721526 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.220.204.93:59056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wp-scr1pts.php"] [unique_id "apK9OyJcY4fy7tP-rU0KkQAAAh0"] [Sat Aug 29 05:06:35.724880 2026] [core:error] [pid 1017536:tid 1017770] [client 45.148.10.62:38770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.724900 2026] [core:error] [pid 1017536:tid 1017770] [client 45.148.10.62:38770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.725545 2026] [security2:error] [pid 1018003:tid 1018266] [client 93.123.109.228:49994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7lgAABio"] [Sat Aug 29 05:06:35.726803 2026] [security2:error] [pid 1017536:tid 1017669] [client 40.83.93.50:23999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-comments-post.php"] [unique_id "apK9OyJcY4fy7tP-rU0KkwAAAhc"] [Sat Aug 29 05:06:35.735878 2026] [security2:error] [pid 1017536:tid 1017778] [client 185.104.184.230:52562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9OyJcY4fy7tP-rU0KlAAAAoQ"] [Sat Aug 29 05:06:35.740121 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.48.250.41:25402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/kbfr.php"] [unique_id "apK9OyJcY4fy7tP-rU0KlgAAAlc"] [Sat Aug 29 05:06:35.745914 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.23.147.79:30470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/themes.php"] [unique_id "apK9OyJcY4fy7tP-rU0KlwAAAm8"] [Sat Aug 29 05:06:35.752635 2026] [security2:error] [pid 1018003:tid 1018230] [client 168.107.94.195:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7lwAABgY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:35.764859 2026] [security2:error] [pid 1017536:tid 1017740] [client 93.123.109.228:49766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KmQAAAl4"] [Sat Aug 29 05:06:35.771225 2026] [security2:error] [pid 1017536:tid 1017751] [client 4.205.62.107:22228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/xqq.php"] [unique_id "apK9OyJcY4fy7tP-rU0KnAAAAmk"] [Sat Aug 29 05:06:35.771245 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.184.117:34747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/222.php"] [unique_id "apK9OyJcY4fy7tP-rU0KmwAAAiU"] [Sat Aug 29 05:06:35.773226 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.220.204.93:52332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ff1.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7mgAABg8"] [Sat Aug 29 05:06:35.785398 2026] [security2:error] [pid 1017536:tid 1017710] [client 52.139.37.240:14514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/domains.php"] [unique_id "apK9OyJcY4fy7tP-rU0KngAAAkA"] [Sat Aug 29 05:06:35.787104 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.23.184.117:46377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/404.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7nAAABhM"] [Sat Aug 29 05:06:35.800409 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.63.81.20:44485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/t3.php"] [unique_id "apK9OyJcY4fy7tP-rU0KoQAAAo4"] [Sat Aug 29 05:06:35.806559 2026] [security2:error] [pid 1017536:tid 1017761] [client 68.155.159.216:38585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9OyJcY4fy7tP-rU0KowAAAnM"] [Sat Aug 29 05:06:35.809022 2026] [security2:error] [pid 1018003:tid 1018268] [client 52.139.37.240:6770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/zoom1.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7nQAABiw"] [Sat Aug 29 05:06:35.809022 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:59893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/radio.php"] [unique_id "apK9OyJcY4fy7tP-rU0KpAAAAjE"] [Sat Aug 29 05:06:35.817855 2026] [core:error] [pid 1017536:tid 1017576] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.817876 2026] [core:error] [pid 1017536:tid 1017576] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.818754 2026] [security2:error] [pid 1017536:tid 1017632] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/env.old"] [unique_id "apK9OyJcY4fy7tP-rU0KpgACjF8"] [Sat Aug 29 05:06:35.818754 2026] [security2:error] [pid 1017536:tid 1017633] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/api/.env.bak"] [unique_id "apK9OyJcY4fy7tP-rU0KpwACjGA"] [Sat Aug 29 05:06:35.824552 2026] [security2:error] [pid 1017536:tid 1017752] [client 93.123.109.228:49518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KqAAAAmo"] [Sat Aug 29 05:06:35.832317 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.158.54.35:4870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/inputs.php"] [unique_id "apK9OyJcY4fy7tP-rU0KqQAAAkE"] [Sat Aug 29 05:06:35.836382 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.63.81.20:56947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tonewarpstudio.com"] [uri "/zrjuyoos.php"] [unique_id "apK9OyJcY4fy7tP-rU0KqgAAAnk"] [Sat Aug 29 05:06:35.841850 2026] [security2:error] [pid 1017536:tid 1017594] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KqwACazk"] [Sat Aug 29 05:06:35.848648 2026] [security2:error] [pid 1018003:tid 1018180] [client 93.123.109.228:49612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7nwAABdU"] [Sat Aug 29 05:06:35.850793 2026] [security2:error] [pid 1018003:tid 1018271] [client 158.23.184.117:59550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/222.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7ogAABi8"] [Sat Aug 29 05:06:35.854865 2026] [security2:error] [pid 1017536:tid 1017681] [client 20.220.204.93:59085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/num.php"] [unique_id "apK9OyJcY4fy7tP-rU0KrQAAAiM"] [Sat Aug 29 05:06:35.860974 2026] [security2:error] [pid 1017536:tid 1017647] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env.production.bak"] [unique_id "apK9OyJcY4fy7tP-rU0KrgACZm4"] [Sat Aug 29 05:06:35.860979 2026] [security2:error] [pid 1017536:tid 1017609] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/.env.prod.bak"] [unique_id "apK9OyJcY4fy7tP-rU0KrwACZkg"] [Sat Aug 29 05:06:35.867346 2026] [security2:error] [pid 1018003:tid 1018262] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7owAABiY"] [Sat Aug 29 05:06:35.870964 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.49.130:50608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/ws85.php"] [unique_id "apK9OyJcY4fy7tP-rU0KsQAAAh0"] [Sat Aug 29 05:06:35.878390 2026] [security2:error] [pid 1018003:tid 1018233] [client 93.123.109.228:50058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9OzAh5Y1i2tUxg4H7pAAABgk"] [Sat Aug 29 05:06:35.880405 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.196.209.81:13260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/wp-contentt.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7pQAABho"] [Sat Aug 29 05:06:35.895567 2026] [security2:error] [pid 1017536:tid 1017687] [client 52.139.37.240:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/xxx.php"] [unique_id "apK9OyJcY4fy7tP-rU0KswAAAik"] [Sat Aug 29 05:06:35.901149 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.196.209.81:16717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/feed-rss2-queue.php"] [unique_id "apK9OyJcY4fy7tP-rU0KtQAAAoY"] [Sat Aug 29 05:06:35.915926 2026] [security2:error] [pid 1017536:tid 1017640] [remote 34.23.124.185:45990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/root/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KtwACi2c"] [Sat Aug 29 05:06:35.916800 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.220.204.93:52268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/t.php"] [unique_id "apK9OyJcY4fy7tP-rU0KuAAAAmM"] [Sat Aug 29 05:06:35.921151 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.184.117:34505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/adminfuns.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7pwAABcg"] [Sat Aug 29 05:06:35.924855 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.48.250.41:25290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wp-act.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7qAAABdw"] [Sat Aug 29 05:06:35.925649 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.151.200.44:65001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/dbc.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7qQAABhw"] [Sat Aug 29 05:06:35.950571 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.184.117:46948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/as.php"] [unique_id "apK9OyJcY4fy7tP-rU0KvgAAAoQ"] [Sat Aug 29 05:06:35.954229 2026] [core:error] [pid 1017536:tid 1017642] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.957595 2026] [core:error] [pid 1017536:tid 1017659] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.960132 2026] [core:error] [pid 1017536:tid 1017574] [remote 34.23.124.185:45990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:35.961124 2026] [security2:error] [pid 1017536:tid 1017591] [remote 34.23.124.185:45990] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9OyJcY4fy7tP-rU0KwgACjjY"] [Sat Aug 29 05:06:35.962788 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.23.147.79:38748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9OyJcY4fy7tP-rU0KwwAAAlY"] [Sat Aug 29 05:06:35.971695 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.63.81.20:46973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7rgAABew"] [Sat Aug 29 05:06:35.975056 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.151.200.44:46650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/zoz.php"] [unique_id "apK9OyJcY4fy7tP-rU0KxwAAAjQ"] [Sat Aug 29 05:06:35.987634 2026] [security2:error] [pid 1017536:tid 1017736] [client 52.139.37.240:14949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/dropdown.php"] [unique_id "apK9OyJcY4fy7tP-rU0KyAAAAlo"] [Sat Aug 29 05:06:35.991435 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.220.204.93:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/a4.php"] [unique_id "apK9OzAh5Y1i2tUxg4H7sQAABek"] [Sat Aug 29 05:06:36.000000 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.184.117:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/24.php"] [unique_id "apK9OyJcY4fy7tP-rU0KygAAAoI"] [Sat Aug 29 05:06:36.001664 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.49.130:43020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/reviall.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7swAABcI"] [Sat Aug 29 05:06:36.002562 2026] [security2:error] [pid 1017536:tid 1017752] [client 93.123.109.228:49622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9OyJcY4fy7tP-rU0KywAAAmo"] [Sat Aug 29 05:06:36.008216 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:22262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wp-content/admin.php"] [unique_id "apK9PCJcY4fy7tP-rU0KzAAAAnk"] [Sat Aug 29 05:06:36.016508 2026] [security2:error] [pid 1017536:tid 1017710] [client 52.139.37.240:52615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/about.php7"] [unique_id "apK9PCJcY4fy7tP-rU0KzQAAAkA"] [Sat Aug 29 05:06:36.016742 2026] [security2:error] [pid 1018003:tid 1018276] [client 68.155.159.216:49196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/dropdown.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7twAABjQ"] [Sat Aug 29 05:06:36.025746 2026] [security2:error] [pid 1018003:tid 1018217] [client 93.123.109.228:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.evecreative.co"] [uri "/wp-config.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7uAAABfo"] [Sat Aug 29 05:06:36.026435 2026] [security2:error] [pid 1018003:tid 1018155] [client 93.123.109.228:36996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.evecreative.co"] [uri "/wp-config.php.bak"] [unique_id "apK9PDAh5Y1i2tUxg4H7uQAABbw"] [Sat Aug 29 05:06:36.039498 2026] [security2:error] [pid 1017536:tid 1017724] [client 185.104.184.230:52566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK9PCJcY4fy7tP-rU0KzwAAAk4"] [Sat Aug 29 05:06:36.060333 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.147.79:35786] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/1.php"] [unique_id "apK9PCJcY4fy7tP-rU0K0gAAAnc"] [Sat Aug 29 05:06:36.060448 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.147.79:35786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/1.php"] [unique_id "apK9PCJcY4fy7tP-rU0K0gAAAnc"] [Sat Aug 29 05:06:36.065227 2026] [security2:error] [pid 1018003:tid 1018206] [client 93.123.109.228:37014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.evecreative.co"] [uri "/wp-config.php.new"] [unique_id "apK9PDAh5Y1i2tUxg4H7uwAABe8"] [Sat Aug 29 05:06:36.069811 2026] [security2:error] [pid 1017536:tid 1017687] [client 93.123.109.228:49540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.evecreative.co"] [uri "/wp-config.php.old"] [unique_id "apK9PCJcY4fy7tP-rU0K0wAAAik"] [Sat Aug 29 05:06:36.075301 2026] [security2:error] [pid 1017536:tid 1017729] [client 185.104.184.230:38160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "apK9PCJcY4fy7tP-rU0K1AAAAlM"] [Sat Aug 29 05:06:36.078316 2026] [security2:error] [pid 1017536:tid 1017780] [client 4.205.62.107:22219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/a1vx.php"] [unique_id "apK9PCJcY4fy7tP-rU0K1QAAAoY"] [Sat Aug 29 05:06:36.082234 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.52.41.200:1166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-blog.php"] [unique_id "apK9PCJcY4fy7tP-rU0K1gAAAho"] [Sat Aug 29 05:06:36.082270 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.250.41:25566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/24.php"] [unique_id "apK9PCJcY4fy7tP-rU0K1wAAAos"] [Sat Aug 29 05:06:36.096089 2026] [security2:error] [pid 1017536:tid 1017704] [client 158.23.184.117:46348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/php.php"] [unique_id "apK9PCJcY4fy7tP-rU0K2QAAAjo"] [Sat Aug 29 05:06:36.096732 2026] [security2:error] [pid 1017536:tid 1017751] [client 4.205.62.107:26628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/application.config.php"] [unique_id "apK9PCJcY4fy7tP-rU0K2gAAAmk"] [Sat Aug 29 05:06:36.096751 2026] [security2:error] [pid 1018003:tid 1018202] [client 52.139.37.240:31133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/0x.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7vAAABes"] [Sat Aug 29 05:06:36.099204 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.151.200.44:62015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/quoys.php"] [unique_id "apK9PCJcY4fy7tP-rU0K2wAAAoQ"] [Sat Aug 29 05:06:36.103844 2026] [security2:error] [pid 1018003:tid 1018171] [client 93.123.109.228:50102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.evecreative.co"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9PDAh5Y1i2tUxg4H7vQAABcw"] [Sat Aug 29 05:06:36.106563 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.63.81.20:44492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/abcd.php"] [unique_id "apK9PCJcY4fy7tP-rU0K3AAAAnM"] [Sat Aug 29 05:06:36.107540 2026] [security2:error] [pid 1017536:tid 1017669] [client 158.23.184.117:34496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/abcd.php"] [unique_id "apK9PCJcY4fy7tP-rU0K3QAAAhc"] [Sat Aug 29 05:06:36.134321 2026] [security2:error] [pid 1017536:tid 1017786] [client 168.107.94.195:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9PCJcY4fy7tP-rU0K4AAAAow"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:36.143490 2026] [security2:error] [pid 1017536:tid 1017683] [client 158.23.184.117:60047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/3pjcpmfsd8b.php"] [unique_id "apK9PCJcY4fy7tP-rU0K4wAAAiU"] [Sat Aug 29 05:06:36.182508 2026] [security2:error] [pid 1017536:tid 1017793] [client 52.139.37.240:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/files/index.php"] [unique_id "apK9PCJcY4fy7tP-rU0K5AAAApM"] [Sat Aug 29 05:06:36.196608 2026] [security2:error] [pid 1017536:tid 1017645] [remote 34.23.124.185:45994] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/_image"] [unique_id "apK9PCJcY4fy7tP-rU0K6gACkmw"] [Sat Aug 29 05:06:36.196886 2026] [security2:error] [pid 1017536:tid 1017629] [remote 34.23.124.185:45994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:href. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:href"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/_image"] [unique_id "apK9PCJcY4fy7tP-rU0K5wACklw"] [Sat Aug 29 05:06:36.197810 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.220.204.93:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/erty.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7wgAABgE"] [Sat Aug 29 05:06:36.198710 2026] [core:error] [pid 1017536:tid 1017592] [remote 34.23.124.185:45994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.198726 2026] [core:error] [pid 1017536:tid 1017658] [remote 34.23.124.185:45994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.199051 2026] [core:error] [pid 1017536:tid 1017599] [remote 34.23.124.185:45994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.199637 2026] [core:error] [pid 1017536:tid 1017546] [remote 34.23.124.185:45994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.207081 2026] [security2:error] [pid 1017536:tid 1017752] [client 52.139.37.240:6754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/cron.php"] [unique_id "apK9PCJcY4fy7tP-rU0K6wAAAmo"] [Sat Aug 29 05:06:36.210846 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.220.204.93:52307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/tfm.php"] [unique_id "apK9PCJcY4fy7tP-rU0K7AAAAj0"] [Sat Aug 29 05:06:36.221084 2026] [security2:error] [pid 1017536:tid 1017675] [client 40.83.93.50:1623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-config.php"] [unique_id "apK9PCJcY4fy7tP-rU0K7wAAAh0"] [Sat Aug 29 05:06:36.242591 2026] [security2:error] [pid 1017536:tid 1017724] [client 158.23.184.117:46971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/term.php"] [unique_id "apK9PCJcY4fy7tP-rU0K8QAAAk4"] [Sat Aug 29 05:06:36.243247 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.63.81.20:44448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/nofile.php"] [unique_id "apK9PCJcY4fy7tP-rU0K8gAAAlM"] [Sat Aug 29 05:06:36.251671 2026] [security2:error] [pid 1017536:tid 1017734] [client 158.23.184.117:33949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/al.php"] [unique_id "apK9PCJcY4fy7tP-rU0K9AAAAlg"] [Sat Aug 29 05:06:36.269930 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.48.250.41:25469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/155.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7xgAABhA"] [Sat Aug 29 05:06:36.285462 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.158.54.35:8709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/alfa.php"] [unique_id "apK9PCJcY4fy7tP-rU0K9gAAAmE"] [Sat Aug 29 05:06:36.285472 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.196.209.81:9462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/theme.php"] [unique_id "apK9PCJcY4fy7tP-rU0K9QAAAkc"] [Sat Aug 29 05:06:36.289536 2026] [security2:error] [pid 1017536:tid 1017745] [client 68.155.159.216:33649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9PCJcY4fy7tP-rU0K9wAAAmM"] [Sat Aug 29 05:06:36.290209 2026] [security2:error] [pid 1017536:tid 1017696] [client 158.23.184.117:59526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hurricanewindowfilm.com"] [uri "/403.php"] [unique_id "apK9PCJcY4fy7tP-rU0K-AAAAjI"] [Sat Aug 29 05:06:36.290839 2026] [security2:error] [pid 1017536:tid 1017751] [client 93.123.109.228:49782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/php-info.php"] [unique_id "apK9PCJcY4fy7tP-rU0K-QAAAmk"] [Sat Aug 29 05:06:36.291651 2026] [security2:error] [pid 1017536:tid 1017790] [client 52.139.37.240:31120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/CDX1.php"] [unique_id "apK9PCJcY4fy7tP-rU0K-gAAApA"] [Sat Aug 29 05:06:36.300276 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.196.209.81:11547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/inputs.php"] [unique_id "apK9PCJcY4fy7tP-rU0K-wAAAkA"] [Sat Aug 29 05:06:36.309863 2026] [security2:error] [pid 1017536:tid 1017732] [client 93.123.109.228:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/php.php"] [unique_id "apK9PCJcY4fy7tP-rU0K_AAAAlY"] [Sat Aug 29 05:06:36.318395 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.151.200.44:46636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/mmm.php"] [unique_id "apK9PCJcY4fy7tP-rU0K_QAAAjQ"] [Sat Aug 29 05:06:36.333247 2026] [security2:error] [pid 1018003:tid 1018213] [client 185.104.184.230:52582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9PDAh5Y1i2tUxg4H7yQAABfY"] [Sat Aug 29 05:06:36.350882 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.220.204.93:59124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/Geforce.php"] [unique_id "apK9PCJcY4fy7tP-rU0LAQAAAi0"] [Sat Aug 29 05:06:36.361758 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.151.200.44:64983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/wp-wlx.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7ygAABhM"] [Sat Aug 29 05:06:36.364308 2026] [autoindex:error] [pid 1017536:tid 1017544] [remote 87.58.197.202:42512] AH01276: Cannot serve directory /home3/zkrrogmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:36.373386 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.63.81.20:46849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/run.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7zQAABgI"] [Sat Aug 29 05:06:36.373600 2026] [security2:error] [pid 1017536:tid 1017669] [client 52.139.37.240:15282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulroyce.com"] [uri "/flower.php"] [unique_id "apK9PCJcY4fy7tP-rU0LBAAAAhc"] [Sat Aug 29 05:06:36.381574 2026] [security2:error] [pid 1018003:tid 1018199] [client 68.155.159.216:51473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7zgAABeg"] [Sat Aug 29 05:06:36.381575 2026] [security2:error] [pid 1017536:tid 1017752] [client 68.155.159.216:18360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9PCJcY4fy7tP-rU0LBgAAAmo"] [Sat Aug 29 05:06:36.384946 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.184.117:46399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/Ov-Simple1.php"] [unique_id "apK9PCJcY4fy7tP-rU0LCQAAAlo"] [Sat Aug 29 05:06:36.389043 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.220.204.93:59082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/0x.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7zwAABd0"] [Sat Aug 29 05:06:36.390145 2026] [security2:error] [pid 1017536:tid 1017675] [client 93.123.109.228:49974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/php_info.php"] [unique_id "apK9PCJcY4fy7tP-rU0LCgAAAh0"] [Sat Aug 29 05:06:36.397505 2026] [security2:error] [pid 1017536:tid 1017706] [client 158.23.184.117:34732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/alfa.php"] [unique_id "apK9PCJcY4fy7tP-rU0LCwAAAjw"] [Sat Aug 29 05:06:36.398596 2026] [security2:error] [pid 1017536:tid 1017683] [client 52.139.37.240:55761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/wp-2019.php"] [unique_id "apK9PCJcY4fy7tP-rU0LDAAAAiU"] [Sat Aug 29 05:06:36.401696 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.197.61.180:8908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/alumni_reg.php"] [unique_id "apK9PCJcY4fy7tP-rU0LDQAAAoc"] [Sat Aug 29 05:06:36.408926 2026] [security2:error] [pid 1017536:tid 1017607] [remote 193.24.211.70:49898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.211.24.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "interpressglobal.com"] [uri "/wp-login.php"] [unique_id "apK9PCJcY4fy7tP-rU0LCAACMEY"] [Sat Aug 29 05:06:36.419940 2026] [security2:error] [pid 1018003:tid 1018166] [client 93.123.109.228:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/phpinfo.php"] [unique_id "apK9PDAh5Y1i2tUxg4H70AAABcc"] [Sat Aug 29 05:06:36.437910 2026] [security2:error] [pid 1017536:tid 1017751] [client 93.123.109.228:50032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9PCJcY4fy7tP-rU0LDwAAAmk"] [Sat Aug 29 05:06:36.445226 2026] [security2:error] [pid 1018003:tid 1018256] [client 136.107.231.130:28854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.git/HEAD"] [unique_id "apK9PDAh5Y1i2tUxg4H70gAABiA"] [Sat Aug 29 05:06:36.446895 2026] [security2:error] [pid 1018003:tid 1018180] [client 136.107.231.130:28884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.github/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H71AAABdU"] [Sat Aug 29 05:06:36.447372 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.48.250.41:25511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/file.php"] [unique_id "apK9PCJcY4fy7tP-rU0LFAAAAkA"] [Sat Aug 29 05:06:36.447391 2026] [security2:error] [pid 1018003:tid 1018248] [client 136.107.231.130:28836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/public/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H70wAABhg"] [Sat Aug 29 05:06:36.447484 2026] [security2:error] [pid 1018003:tid 1018248] [client 136.107.231.130:28836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/public/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H70wAABhg"] [Sat Aug 29 05:06:36.450071 2026] [security2:error] [pid 1017536:tid 1017770] [client 136.107.231.130:28892] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9PCJcY4fy7tP-rU0LFgAAAnw"] [Sat Aug 29 05:06:36.454913 2026] [security2:error] [pid 1018003:tid 1018271] [client 136.107.231.130:28926] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9PDAh5Y1i2tUxg4H71QAABi8"] [Sat Aug 29 05:06:36.456440 2026] [core:error] [pid 1017536:tid 1017579] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.459155 2026] [security2:error] [pid 1017536:tid 1017780] [client 136.107.231.130:28958] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9PCJcY4fy7tP-rU0LHAAAAoY"] [Sat Aug 29 05:06:36.465222 2026] [core:error] [pid 1017536:tid 1017662] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.466637 2026] [core:error] [pid 1018003:tid 1018230] [client 45.148.10.62:38778] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.466652 2026] [core:error] [pid 1018003:tid 1018230] [client 45.148.10.62:38778] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.476618 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.147.79:48253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/x/index.php"] [unique_id "apK9PDAh5Y1i2tUxg4H72QAABhw"] [Sat Aug 29 05:06:36.481964 2026] [security2:error] [pid 1018003:tid 1018259] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H72gAABiM"] [Sat Aug 29 05:06:36.485230 2026] [core:error] [pid 1017536:tid 1017597] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.486782 2026] [core:error] [pid 1017536:tid 1017635] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.487003 2026] [core:error] [pid 1017536:tid 1017581] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.487003 2026] [core:error] [pid 1017536:tid 1017655] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.489968 2026] [security2:error] [pid 1018003:tid 1018265] [client 52.139.37.240:31045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/akcc.php"] [unique_id "apK9PDAh5Y1i2tUxg4H72wAABik"] [Sat Aug 29 05:06:36.500272 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.151.200.44:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/attack.php"] [unique_id "apK9PDAh5Y1i2tUxg4H73AAABf4"] [Sat Aug 29 05:06:36.506825 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.63.81.20:46896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/new.php"] [unique_id "apK9PDAh5Y1i2tUxg4H73QAABfA"] [Sat Aug 29 05:06:36.510111 2026] [security2:error] [pid 1017536:tid 1017749] [client 4.205.62.107:53323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/aws_keys.php"] [unique_id "apK9PCJcY4fy7tP-rU0LIwAAAmc"] [Sat Aug 29 05:06:36.511368 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.23.147.79:30478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-mail.php"] [unique_id "apK9PDAh5Y1i2tUxg4H73gAABek"] [Sat Aug 29 05:06:36.531366 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.184.117:46957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/atomlib.php"] [unique_id "apK9PDAh5Y1i2tUxg4H74AAABfs"] [Sat Aug 29 05:06:36.537118 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.52.41.200:1222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/xxx.php"] [unique_id "apK9PCJcY4fy7tP-rU0LJAAAAiA"] [Sat Aug 29 05:06:36.539194 2026] [security2:error] [pid 1017536:tid 1017707] [client 4.205.62.107:56013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wpver.php"] [unique_id "apK9PCJcY4fy7tP-rU0LJQAAAj0"] [Sat Aug 29 05:06:36.539202 2026] [security2:error] [pid 1018003:tid 1018162] [client 93.123.109.228:49798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H74QAABcM"] [Sat Aug 29 05:06:36.542053 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.220.204.93:59122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/66.php"] [unique_id "apK9PCJcY4fy7tP-rU0LJwAAAmo"] [Sat Aug 29 05:06:36.542675 2026] [security2:error] [pid 1018003:tid 1018191] [client 168.107.94.195:64844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9PDAh5Y1i2tUxg4H74gAABeA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:36.542914 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.184.117:34729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/as.php"] [unique_id "apK9PDAh5Y1i2tUxg4H74wAABew"] [Sat Aug 29 05:06:36.547783 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.220.204.93:52293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/click.php"] [unique_id "apK9PDAh5Y1i2tUxg4H75AAABjQ"] [Sat Aug 29 05:06:36.548906 2026] [security2:error] [pid 1018003:tid 1018170] [client 93.123.109.228:49664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H75QAABcs"] [Sat Aug 29 05:06:36.551455 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.151.200.44:46014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/advanced.php"] [unique_id "apK9PDAh5Y1i2tUxg4H75wAABbw"] [Sat Aug 29 05:06:36.567071 2026] [core:error] [pid 1017536:tid 1017602] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.575434 2026] [security2:error] [pid 1017536:tid 1017667] [client 52.139.37.240:8476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/aged.php"] [unique_id "apK9PCJcY4fy7tP-rU0LKgAAAhU"] [Sat Aug 29 05:06:36.587952 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.48.250.41:25382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9PCJcY4fy7tP-rU0LLAAAAoc"] [Sat Aug 29 05:06:36.590468 2026] [security2:error] [pid 1018003:tid 1018161] [client 52.139.37.240:6665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/gecko-new.php"] [unique_id "apK9PDAh5Y1i2tUxg4H77AAABcI"] [Sat Aug 29 05:06:36.606911 2026] [core:error] [pid 1017536:tid 1017598] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.607342 2026] [core:error] [pid 1017536:tid 1017606] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.607993 2026] [core:error] [pid 1017536:tid 1017650] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.609722 2026] [core:error] [pid 1017536:tid 1017537] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.616788 2026] [security2:error] [pid 1018003:tid 1018179] [client 68.155.159.216:51230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/goat1.php"] [unique_id "apK9PDAh5Y1i2tUxg4H77QAABdQ"] [Sat Aug 29 05:06:36.630681 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.151.200.44:64919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/vbbn.php"] [unique_id "apK9PCJcY4fy7tP-rU0LMwAAAnc"] [Sat Aug 29 05:06:36.632208 2026] [security2:error] [pid 1017536:tid 1017710] [client 158.23.147.79:17436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9PCJcY4fy7tP-rU0LNAAAAkA"] [Sat Aug 29 05:06:36.638209 2026] [security2:error] [pid 1017536:tid 1017731] [client 185.104.184.230:52590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9PCJcY4fy7tP-rU0LNQAAAlU"] [Sat Aug 29 05:06:36.638963 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.63.81.20:44484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/inx.php"] [unique_id "apK9PCJcY4fy7tP-rU0LNgAAAhs"] [Sat Aug 29 05:06:36.646153 2026] [core:error] [pid 1017536:tid 1017616] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.648149 2026] [security2:error] [pid 1018003:tid 1018273] [client 158.23.147.79:50172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9PDAh5Y1i2tUxg4H77gAABjE"] [Sat Aug 29 05:06:36.652028 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:32747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9PDAh5Y1i2tUxg4H77wAABdA"] [Sat Aug 29 05:06:36.669674 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.104.49.130:50576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/wp-the.php"] [unique_id "apK9PCJcY4fy7tP-rU0LOAAAAnM"] [Sat Aug 29 05:06:36.671988 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.151.200.44:64990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/file66.php"] [unique_id "apK9PCJcY4fy7tP-rU0LOgAAAj8"] [Sat Aug 29 05:06:36.674467 2026] [core:error] [pid 1017536:tid 1017573] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.676993 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.23.184.117:46959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/edit.php"] [unique_id "apK9PDAh5Y1i2tUxg4H78AAABdk"] [Sat Aug 29 05:06:36.681886 2026] [security2:error] [pid 1018003:tid 1018172] [client 185.104.184.230:38164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "apK9PDAh5Y1i2tUxg4H78QAABc0"] [Sat Aug 29 05:06:36.685257 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.23.147.79:24409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9PCJcY4fy7tP-rU0LOwAAAlY"] [Sat Aug 29 05:06:36.688259 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.184.117:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/aa.php"] [unique_id "apK9PDAh5Y1i2tUxg4H78gAABgo"] [Sat Aug 29 05:06:36.692216 2026] [core:error] [pid 1017536:tid 1017639] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.692230 2026] [core:error] [pid 1017536:tid 1017639] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.698443 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.220.204.93:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ms.php"] [unique_id "apK9PCJcY4fy7tP-rU0LPgAAAi0"] [Sat Aug 29 05:06:36.705768 2026] [security2:error] [pid 1017536:tid 1017736] [client 40.83.93.50:23969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-configs.php"] [unique_id "apK9PCJcY4fy7tP-rU0LPwAAAlo"] [Sat Aug 29 05:06:36.710500 2026] [core:error] [pid 1017536:tid 1017589] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.710501 2026] [core:error] [pid 1017536:tid 1017548] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.710513 2026] [core:error] [pid 1017536:tid 1017589] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.710518 2026] [core:error] [pid 1017536:tid 1017548] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.711478 2026] [core:error] [pid 1017536:tid 1017575] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.720225 2026] [security2:error] [pid 1017536:tid 1017669] [client 93.123.109.228:49940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9PCJcY4fy7tP-rU0LQwAAAhc"] [Sat Aug 29 05:06:36.729436 2026] [core:error] [pid 1017536:tid 1017653] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.729453 2026] [core:error] [pid 1017536:tid 1017653] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.731999 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.158.54.35:14096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/403.php"] [unique_id "apK9PCJcY4fy7tP-rU0LRQAAAm8"] [Sat Aug 29 05:06:36.738429 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.196.209.81:17892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/alumni_reg.php"] [unique_id "apK9PDAh5Y1i2tUxg4H78wAABfo"] [Sat Aug 29 05:06:36.753021 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.48.250.41:25428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/06.php"] [unique_id "apK9PCJcY4fy7tP-rU0LRwAAAhU"] [Sat Aug 29 05:06:36.759795 2026] [core:error] [pid 1017536:tid 1017588] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.759808 2026] [core:error] [pid 1017536:tid 1017588] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.770020 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.196.209.81:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK9PCJcY4fy7tP-rU0LSQAAAoQ"] [Sat Aug 29 05:06:36.770923 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.63.81.20:46869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/vpn.php"] [unique_id "apK9PCJcY4fy7tP-rU0LSgAAAos"] [Sat Aug 29 05:06:36.785262 2026] [core:error] [pid 1017536:tid 1017590] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.785277 2026] [core:error] [pid 1017536:tid 1017590] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.791164 2026] [core:error] [pid 1017536:tid 1017601] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.791189 2026] [core:error] [pid 1017536:tid 1017603] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.802676 2026] [security2:error] [pid 1018003:tid 1018266] [client 93.123.109.228:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/public/phpinfo.php"] [unique_id "apK9PDAh5Y1i2tUxg4H79AAABio"] [Sat Aug 29 05:06:36.813245 2026] [core:error] [pid 1017536:tid 1017596] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.813255 2026] [core:error] [pid 1017536:tid 1017596] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.821008 2026] [security2:error] [pid 1018003:tid 1018159] [client 93.123.109.228:49994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H79QAABcA"] [Sat Aug 29 05:06:36.821029 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.151.200.44:64285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/rfi.php"] [unique_id "apK9PCJcY4fy7tP-rU0LTwAAAmY"] [Sat Aug 29 05:06:36.821459 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.184.117:46340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/7.php"] [unique_id "apK9PCJcY4fy7tP-rU0LUQAAAkc"] [Sat Aug 29 05:06:36.823728 2026] [core:error] [pid 1017536:tid 1017561] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.828500 2026] [security2:error] [pid 1017536:tid 1017540] [remote 74.7.227.154:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9PCJcY4fy7tP-rU0LUwACGwM"], referer: https://goodtogo.store/sitemap_index.xml?p=%2Fhome4%2Fsortthru%2Fpublic_html%2Fgoodtogo%2Fwebapp%2Fwp-content%2Fplugins%2Fwp-easycart%2Fdesign%2Flayout%2Fbase-responsive-v3 [Sat Aug 29 05:06:36.829721 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.184.117:34534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/abc.php"] [unique_id "apK9PCJcY4fy7tP-rU0LVQAAAmE"] [Sat Aug 29 05:06:36.830581 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.220.204.93:59092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/f35.php"] [unique_id "apK9PCJcY4fy7tP-rU0LVgAAAnw"] [Sat Aug 29 05:06:36.857220 2026] [security2:error] [pid 1018003:tid 1018177] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H79gAABdI"] [Sat Aug 29 05:06:36.859252 2026] [core:error] [pid 1017536:tid 1017541] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.864606 2026] [core:error] [pid 1017536:tid 1017567] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.865460 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.151.200.44:47376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/blox.php"] [unique_id "apK9PCJcY4fy7tP-rU0LXAAAAj8"] [Sat Aug 29 05:06:36.866295 2026] [core:error] [pid 1017536:tid 1017550] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.866368 2026] [core:error] [pid 1017536:tid 1017562] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.889564 2026] [security2:error] [pid 1017536:tid 1017749] [client 20.220.204.93:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/zxekqlxb.php"] [unique_id "apK9PCJcY4fy7tP-rU0LXQAAAmc"] [Sat Aug 29 05:06:36.909089 2026] [security2:error] [pid 1018003:tid 1018166] [client 4.205.62.107:21905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/a1vx.php"] [unique_id "apK9PDAh5Y1i2tUxg4H79wAABcc"] [Sat Aug 29 05:06:36.913284 2026] [security2:error] [pid 1018003:tid 1018233] [client 158.23.147.79:59860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7-AAABgk"] [Sat Aug 29 05:06:36.923600 2026] [core:error] [pid 1017536:tid 1017551] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.923623 2026] [core:error] [pid 1017536:tid 1017551] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.923818 2026] [security2:error] [pid 1017536:tid 1017713] [client 168.107.94.195:65195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9PCJcY4fy7tP-rU0LYQAAAkM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:36.924102 2026] [core:error] [pid 1017536:tid 1017563] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.937047 2026] [security2:error] [pid 1018003:tid 1018248] [client 93.123.109.228:49954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H7-QAABhg"] [Sat Aug 29 05:06:36.937759 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.63.81.20:44417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/shiny.php"] [unique_id "apK9PDAh5Y1i2tUxg4H7-gAABdU"] [Sat Aug 29 05:06:36.939671 2026] [security2:error] [pid 1018003:tid 1018167] [client 93.123.109.228:49664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9PDAh5Y1i2tUxg4H7_gAABcg"] [Sat Aug 29 05:06:36.939675 2026] [security2:error] [pid 1018003:tid 1018036] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/web.config"] [unique_id "apK9PDAh5Y1i2tUxg4H7_AAGLw8"] [Sat Aug 29 05:06:36.943154 2026] [security2:error] [pid 1017536:tid 1017695] [client 185.104.184.230:52602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9PCJcY4fy7tP-rU0LYgAAAjE"] [Sat Aug 29 05:06:36.946516 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.151.200.44:64446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/zafir1.php"] [unique_id "apK9PDAh5Y1i2tUxg4H8AwAABdw"] [Sat Aug 29 05:06:36.947148 2026] [core:error] [pid 1017536:tid 1017571] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.947596 2026] [core:error] [pid 1017536:tid 1017586] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.949442 2026] [core:error] [pid 1017536:tid 1017612] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.949456 2026] [core:error] [pid 1017536:tid 1017612] [remote 34.23.124.185:46008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:36.949476 2026] [security2:error] [pid 1017536:tid 1017625] [remote 34.23.124.185:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.124.23.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/pi.php"] [unique_id "apK9PCJcY4fy7tP-rU0LZgACHVg"] [Sat Aug 29 05:06:36.951627 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.147.79:25532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-login.php"] [unique_id "apK9PDAh5Y1i2tUxg4H8BAAABbk"] [Sat Aug 29 05:06:36.962863 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.220.204.93:59069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wen.php"] [unique_id "apK9PCJcY4fy7tP-rU0LZwAAAiU"] [Sat Aug 29 05:06:36.967588 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.184.117:46351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/black.php"] [unique_id "apK9PDAh5Y1i2tUxg4H8BQAABhY"] [Sat Aug 29 05:06:36.968538 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.151.200.44:64901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/tajj.php"] [unique_id "apK9PCJcY4fy7tP-rU0LaAAAAhU"] [Sat Aug 29 05:06:36.975033 2026] [security2:error] [pid 1017536:tid 1017672] [client 158.23.147.79:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/.well-known/index.php"] [unique_id "apK9PCJcY4fy7tP-rU0LaQAAAho"] [Sat Aug 29 05:06:36.975771 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.184.117:34503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/av.php"] [unique_id "apK9PDAh5Y1i2tUxg4H8BgAABiA"] [Sat Aug 29 05:06:36.988804 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.48.250.41:25567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/class.php"] [unique_id "apK9PDAh5Y1i2tUxg4H8BwAABg4"] [Sat Aug 29 05:06:36.992154 2026] [cgid:error] [pid 1017536:tid 1017767] [client 20.52.41.200:1732] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:37.051851 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.220.204.93:52342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/init.php"] [unique_id "apK9PSJcY4fy7tP-rU0LbgAAAk4"] [Sat Aug 29 05:06:37.065449 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.147.79:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/images/index.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8CQAABfs"] [Sat Aug 29 05:06:37.068786 2026] [security2:error] [pid 1017536:tid 1017664] [remote 34.23.124.185:46008] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "www.garyandelaine.strangeworx.com"] [uri "/server-info"] [unique_id "apK9PSJcY4fy7tP-rU0LbwACfH8"] [Sat Aug 29 05:06:37.089735 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.63.81.20:46892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/goods.php"] [unique_id "apK9PSJcY4fy7tP-rU0LcQAAAlM"] [Sat Aug 29 05:06:37.117315 2026] [security2:error] [pid 1017536:tid 1017731] [client 158.23.184.117:62330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-blog-header.php"] [unique_id "apK9PSJcY4fy7tP-rU0LdAAAAlU"] [Sat Aug 29 05:06:37.117699 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.197.61.180:11611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/colors.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8DQAABgI"] [Sat Aug 29 05:06:37.119294 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.23.184.117:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/autoload_classmap.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8DgAABcM"] [Sat Aug 29 05:06:37.122985 2026] [security2:error] [pid 1018003:tid 1018170] [client 68.155.159.216:49216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/.well-known/index.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8DwAABcs"] [Sat Aug 29 05:06:37.134978 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.220.204.93:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/inc.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8EQAABgc"] [Sat Aug 29 05:06:37.145086 2026] [cgid:error] [pid 1017536:tid 1017732] [client 20.52.41.200:1732] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:37.145928 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.250.41:25350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/8.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8EgAABcE"] [Sat Aug 29 05:06:37.150783 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.151.200.44:65024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/console.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8EwAABe8"] [Sat Aug 29 05:06:37.153494 2026] [security2:error] [pid 1018003:tid 1018190] [client 4.205.62.107:22370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/124.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8FAAABd8"] [Sat Aug 29 05:06:37.173529 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.151.200.44:64957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/grsiuk.php"] [unique_id "apK9PSJcY4fy7tP-rU0LdgAAAl4"] [Sat Aug 29 05:06:37.175769 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.158.54.35:2788] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/1.php"] [unique_id "apK9PSJcY4fy7tP-rU0LdwAAAkc"] [Sat Aug 29 05:06:37.175837 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.158.54.35:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/1.php"] [unique_id "apK9PSJcY4fy7tP-rU0LdwAAAkc"] [Sat Aug 29 05:06:37.182048 2026] [security2:error] [pid 1017536:tid 1017751] [client 40.83.93.50:23954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-conflg.php"] [unique_id "apK9PSJcY4fy7tP-rU0LeAAAAmk"] [Sat Aug 29 05:06:37.185569 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.147.79:35798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/ws.php"] [unique_id "apK9PSJcY4fy7tP-rU0LeQAAAjs"] [Sat Aug 29 05:06:37.189836 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.196.209.81:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/colors.php"] [unique_id "apK9PSJcY4fy7tP-rU0LegAAAmE"] [Sat Aug 29 05:06:37.193600 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.220.204.93:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/term.php"] [unique_id "apK9PSJcY4fy7tP-rU0LfAAAAoI"] [Sat Aug 29 05:06:37.194679 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.196.209.81:11542] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.merlynscatering.net"] [uri "/1.php7"] [unique_id "apK9PTAh5Y1i2tUxg4H8FgAABek"] [Sat Aug 29 05:06:37.194761 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.196.209.81:11542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/1.php7"] [unique_id "apK9PTAh5Y1i2tUxg4H8FgAABek"] [Sat Aug 29 05:06:37.223256 2026] [security2:error] [pid 1017536:tid 1017793] [client 4.205.62.107:22258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/phpsysinfo.php"] [unique_id "apK9PSJcY4fy7tP-rU0LfgAAApM"] [Sat Aug 29 05:06:37.237683 2026] [security2:error] [pid 1017536:tid 1017778] [client 4.205.62.107:65445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/xp.php"] [unique_id "apK9PSJcY4fy7tP-rU0LfwAAAoQ"] [Sat Aug 29 05:06:37.241457 2026] [security2:error] [pid 1017536:tid 1017673] [client 185.104.184.230:52612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9PSJcY4fy7tP-rU0LgAAAAhs"] [Sat Aug 29 05:06:37.246858 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.63.81.20:46956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/alfa.php"] [unique_id "apK9PSJcY4fy7tP-rU0LgQAAAnc"] [Sat Aug 29 05:06:37.259579 2026] [core:error] [pid 1018003:tid 1018153] [client 45.148.10.62:38782] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:37.259598 2026] [core:error] [pid 1018003:tid 1018153] [client 45.148.10.62:38782] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:37.268592 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.151.200.44:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/kcs.php"] [unique_id "apK9PSJcY4fy7tP-rU0LhAAAAjw"] [Sat Aug 29 05:06:37.277899 2026] [security2:error] [pid 1018003:tid 1018195] [client 35.198.240.194:2580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.240.198.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.omni-staffing.com"] [uri "/configuration.php.bak"] [unique_id "apK9PTAh5Y1i2tUxg4H8HQAABeQ"] [Sat Aug 29 05:06:37.278006 2026] [security2:error] [pid 1018003:tid 1018195] [client 35.198.240.194:2580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "mail.omni-staffing.com"] [uri "/configuration.php.bak"] [unique_id "apK9PTAh5Y1i2tUxg4H8HQAABeQ"] [Sat Aug 29 05:06:37.279058 2026] [security2:error] [pid 1018003:tid 1018268] [client 35.198.240.194:2502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "mail.omni-staffing.com"] [uri "/web.config"] [unique_id "apK9PTAh5Y1i2tUxg4H8HAAABiw"] [Sat Aug 29 05:06:37.280442 2026] [security2:error] [pid 1018003:tid 1018245] [client 35.198.240.194:2544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.omni-staffing.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9PTAh5Y1i2tUxg4H8HgAABhU"] [Sat Aug 29 05:06:37.282146 2026] [security2:error] [pid 1018003:tid 1018266] [client 35.198.240.194:2616] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.omni-staffing.com"] [uri "/runtime.js"] [unique_id "apK9PTAh5Y1i2tUxg4H8IwAABio"] [Sat Aug 29 05:06:37.294080 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.52.41.200:1732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/tool.php"] [unique_id "apK9PSJcY4fy7tP-rU0LiQAAAlU"] [Sat Aug 29 05:06:37.298998 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.48.250.41:25380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/0x0x.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8KAAABhM"] [Sat Aug 29 05:06:37.303504 2026] [security2:error] [pid 1018003:tid 1018189] [client 168.107.94.195:49153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8KQAABd4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:37.307696 2026] [security2:error] [pid 1017536:tid 1017788] [client 158.23.184.117:46960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/2.php"] [unique_id "apK9PSJcY4fy7tP-rU0LigAAAo4"] [Sat Aug 29 05:06:37.309135 2026] [security2:error] [pid 1017536:tid 1017587] [remote 74.7.227.154:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9PSJcY4fy7tP-rU0LjAACWDI"], referer: https://goodtogo.store/sitemap_index.xml?p=%2Fhome4%2Fsortthru%2Fpublic_html%2Fgoodtogo%2Fwebapp%2Fwp-content%2Fplugins%2Fwp-easycart%2Fdesign%2Flayout%2Fbase-responsive-v3 [Sat Aug 29 05:06:37.318610 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.151.200.44:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/ahy66.php"] [unique_id "apK9PSJcY4fy7tP-rU0LjQAAAi0"] [Sat Aug 29 05:06:37.358097 2026] [security2:error] [pid 1018003:tid 1018172] [client 158.23.184.117:34529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/asus.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8MgAABc0"] [Sat Aug 29 05:06:37.359294 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.147.79:30555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/cgi-bin/index.php"] [unique_id "apK9PSJcY4fy7tP-rU0LjwAAAjs"] [Sat Aug 29 05:06:37.360164 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.220.204.93:59125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/6bcwiqwj.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8MwAABhg"] [Sat Aug 29 05:06:37.367798 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.220.204.93:59053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/aaa.php"] [unique_id "apK9PSJcY4fy7tP-rU0LkgAAAmE"] [Sat Aug 29 05:06:37.368565 2026] [cgid:error] [pid 1017536:tid 1017678] [client 34.7.40.70:25370] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.368644 2026] [cgid:error] [pid 1018003:tid 1018161] [client 34.7.40.70:25340] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.369014 2026] [cgid:error] [pid 1017536:tid 1017711] [client 34.7.40.70:25304] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.369110 2026] [security2:error] [pid 1017536:tid 1017711] [client 34.7.40.70:25304] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9PSJcY4fy7tP-rU0LkAAAAkE"] [Sat Aug 29 05:06:37.371073 2026] [cgid:error] [pid 1018003:tid 1018202] [client 34.7.40.70:25404] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.371101 2026] [cgid:error] [pid 1017536:tid 1017713] [client 34.7.40.70:25290] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.371178 2026] [cgid:error] [pid 1017536:tid 1017737] [client 34.7.40.70:25430] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.371797 2026] [cgid:error] [pid 1017536:tid 1017669] [client 34.7.40.70:25308] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.371797 2026] [cgid:error] [pid 1018003:tid 1018192] [client 34.7.40.70:25334] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.371905 2026] [security2:error] [pid 1017536:tid 1017669] [client 34.7.40.70:25308] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9PSJcY4fy7tP-rU0LkwAAAhc"] [Sat Aug 29 05:06:37.372369 2026] [cgid:error] [pid 1017536:tid 1017757] [client 34.7.40.70:25362] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.373071 2026] [cgid:error] [pid 1018003:tid 1018169] [client 34.7.40.70:25506] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.373224 2026] [cgid:error] [pid 1018003:tid 1018157] [client 34.7.40.70:25458] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.373470 2026] [cgid:error] [pid 1017536:tid 1017752] [client 34.7.40.70:25298] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.373470 2026] [cgid:error] [pid 1017536:tid 1017695] [client 34.7.40.70:25424] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.373473 2026] [cgid:error] [pid 1018003:tid 1018179] [client 34.7.40.70:25390] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.373515 2026] [security2:error] [pid 1018003:tid 1018182] [client 34.7.40.70:25532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/dev/.env"] [unique_id "apK9PTAh5Y1i2tUxg4H8OwAABdc"] [Sat Aug 29 05:06:37.373711 2026] [security2:error] [pid 1018003:tid 1018175] [client 34.7.40.70:25570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/production/.env"] [unique_id "apK9PTAh5Y1i2tUxg4H8PAAABdA"] [Sat Aug 29 05:06:37.373835 2026] [security2:error] [pid 1017536:tid 1017744] [client 34.7.40.70:25504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/client/.env"] [unique_id "apK9PSJcY4fy7tP-rU0LmQAAAmI"] [Sat Aug 29 05:06:37.374592 2026] [cgid:error] [pid 1018003:tid 1018171] [client 34.7.40.70:25346] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.375145 2026] [security2:error] [pid 1017536:tid 1017781] [client 34.7.40.70:25518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/backup/.env"] [unique_id "apK9PSJcY4fy7tP-rU0LnAAAAoc"] [Sat Aug 29 05:06:37.375398 2026] [cgid:error] [pid 1017536:tid 1017707] [client 34.7.40.70:25318] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.376927 2026] [cgid:error] [pid 1017536:tid 1017675] [client 34.7.40.70:25378] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.377330 2026] [cgid:error] [pid 1018003:tid 1018224] [client 34.7.40.70:25580] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.377478 2026] [cgid:error] [pid 1017536:tid 1017667] [client 34.7.40.70:25490] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.377478 2026] [cgid:error] [pid 1018003:tid 1018273] [client 34.7.40.70:25460] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.377709 2026] [cgid:error] [pid 1017536:tid 1017683] [client 34.7.40.70:25418] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.379369 2026] [cgid:error] [pid 1018003:tid 1018185] [client 34.7.40.70:25486] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.380991 2026] [security2:error] [pid 1017536:tid 1017767] [client 34.7.40.70:25546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/staging/.env"] [unique_id "apK9PSJcY4fy7tP-rU0LoQAAAnk"] [Sat Aug 29 05:06:37.382764 2026] [cgid:error] [pid 1017536:tid 1017672] [client 34.7.40.70:25444] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.382904 2026] [cgid:error] [pid 1017536:tid 1017785] [client 34.7.40.70:25560] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.382927 2026] [cgid:error] [pid 1017536:tid 1017745] [client 34.7.40.70:25604] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.383326 2026] [cgid:error] [pid 1017536:tid 1017696] [client 34.7.40.70:25582] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.383393 2026] [security2:error] [pid 1017536:tid 1017745] [client 34.7.40.70:25604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9PSJcY4fy7tP-rU0LnwAAAmM"] [Sat Aug 29 05:06:37.383456 2026] [security2:error] [pid 1017536:tid 1017696] [client 34.7.40.70:25582] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9PSJcY4fy7tP-rU0LowAAAjI"] [Sat Aug 29 05:06:37.384602 2026] [cgid:error] [pid 1017536:tid 1017748] [client 34.7.40.70:25578] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:37.389551 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.63.81.20:44511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/33.php"] [unique_id "apK9PSJcY4fy7tP-rU0LpgAAApM"] [Sat Aug 29 05:06:37.412209 2026] [security2:error] [pid 1018003:tid 1018216] [client 87.219.197.128:54293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8QgAABfk"] [Sat Aug 29 05:06:37.412298 2026] [security2:error] [pid 1018003:tid 1018216] [client 87.219.197.128:54293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8QgAABfk"] [Sat Aug 29 05:06:37.434825 2026] [security2:error] [pid 1017536:tid 1017710] [client 68.155.159.216:33612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/radio.php"] [unique_id "apK9PSJcY4fy7tP-rU0LqAAAAkA"] [Sat Aug 29 05:06:37.446800 2026] [security2:error] [pid 1017536:tid 1017761] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9PSJcY4fy7tP-rU0LjgACcy0"] [Sat Aug 29 05:06:37.447643 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:25290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/166.php"] [unique_id "apK9PSJcY4fy7tP-rU0LqQAAAnw"] [Sat Aug 29 05:06:37.451144 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.184.117:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/index/function.php"] [unique_id "apK9PSJcY4fy7tP-rU0LqgAAAoQ"] [Sat Aug 29 05:06:37.454105 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.151.200.44:64427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/blnux.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8QwAABiY"] [Sat Aug 29 05:06:37.454952 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.151.200.44:47315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/wsz.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8RAAABgY"] [Sat Aug 29 05:06:37.500999 2026] [security2:error] [pid 1017536:tid 1017729] [client 158.23.184.117:34750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/about.php"] [unique_id "apK9PSJcY4fy7tP-rU0LrgAAAlM"] [Sat Aug 29 05:06:37.523315 2026] [security2:error] [pid 1017536:tid 1017740] [client 57.141.14.111:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/34/"] [unique_id "apK9PSJcY4fy7tP-rU0LsAAAAl4"] [Sat Aug 29 05:06:37.534397 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.63.81.20:46916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/133.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8SAAABfs"] [Sat Aug 29 05:06:37.534808 2026] [security2:error] [pid 1017536:tid 1017732] [client 185.104.184.230:52618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9PSJcY4fy7tP-rU0LsQAAAlY"] [Sat Aug 29 05:06:37.548304 2026] [security2:error] [pid 1018003:tid 1018170] [client 68.155.159.216:50307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8TAAABcs"] [Sat Aug 29 05:06:37.568473 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.220.204.93:52302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/easy.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8TwAABe8"] [Sat Aug 29 05:06:37.583391 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.220.204.93:59057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/xsox.php"] [unique_id "apK9PSJcY4fy7tP-rU0LswAAAiA"] [Sat Aug 29 05:06:37.585011 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.23.147.79:48210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9PSJcY4fy7tP-rU0LtAAAAkE"] [Sat Aug 29 05:06:37.590517 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.196.209.81:11524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/ds.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8UQAABg4"] [Sat Aug 29 05:06:37.595421 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.184.117:62294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8UgAABgI"] [Sat Aug 29 05:06:37.598219 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:25520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/h2a2ck.php"] [unique_id "apK9PSJcY4fy7tP-rU0LtQAAAls"] [Sat Aug 29 05:06:37.607903 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.151.200.44:46600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/msy.php"] [unique_id "apK9PSJcY4fy7tP-rU0LtwAAAjE"] [Sat Aug 29 05:06:37.613445 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.196.209.81:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/Js.php"] [unique_id "apK9PSJcY4fy7tP-rU0LuAAAApA"] [Sat Aug 29 05:06:37.627268 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.147.79:30615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8VQAABbo"] [Sat Aug 29 05:06:37.634020 2026] [security2:error] [pid 1017536:tid 1017707] [client 114.119.139.78:60653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_info.php/cPath/3/products_id/681/osCsid/56aa4ec5dc57dc42f82c493b0191f57d"] [unique_id "apK9PSJcY4fy7tP-rU0LuwAAAj0"], referer: http://www.classiclightingusa.com/catalog/index.php/cPath/3/osCsid/56aa4ec5dc57dc42f82c493b0191f57d [Sat Aug 29 05:06:37.634724 2026] [core:error] [pid 1017536:tid 1017731] [client 158.158.54.35:11187] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:37.634736 2026] [core:error] [pid 1017536:tid 1017731] [client 158.158.54.35:11187] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:37.643054 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.184.117:33939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/atomlib.php"] [unique_id "apK9PSJcY4fy7tP-rU0LvAAAAkM"] [Sat Aug 29 05:06:37.648528 2026] [security2:error] [pid 1018003:tid 1018259] [client 40.83.93.50:1752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8VgAABiM"] [Sat Aug 29 05:06:37.663543 2026] [security2:error] [pid 1017536:tid 1017672] [client 68.155.159.216:14294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/x.php"] [unique_id "apK9PSJcY4fy7tP-rU0LvgAAAho"] [Sat Aug 29 05:06:37.664674 2026] [security2:error] [pid 1017536:tid 1017745] [client 4.205.62.107:53338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apK9PSJcY4fy7tP-rU0LvwAAAmM"] [Sat Aug 29 05:06:37.674140 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.151.200.44:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/pentest.php"] [unique_id "apK9PSJcY4fy7tP-rU0LwAAAAjI"] [Sat Aug 29 05:06:37.676235 2026] [security2:error] [pid 1017536:tid 1017704] [client 4.205.62.107:53263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ah25.php"] [unique_id "apK9PSJcY4fy7tP-rU0LwQAAAjo"] [Sat Aug 29 05:06:37.676488 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.63.81.20:44491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/sym.php"] [unique_id "apK9PSJcY4fy7tP-rU0LwgAAApM"] [Sat Aug 29 05:06:37.682391 2026] [security2:error] [pid 1017536:tid 1017765] [client 168.107.94.195:49406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9PSJcY4fy7tP-rU0LwwAAAnc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:37.695322 2026] [security2:error] [pid 1017536:tid 1017781] [client 52.139.37.240:31627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9PSJcY4fy7tP-rU0LxAAAAoc"] [Sat Aug 29 05:06:37.706697 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.23.184.117:19218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.dj/index.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8WQAABio"] [Sat Aug 29 05:06:37.708215 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.220.204.93:52254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/fresh3.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8WgAABiw"] [Sat Aug 29 05:06:37.712883 2026] [security2:error] [pid 1018003:tid 1018240] [client 68.155.159.216:51417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8WwAABhA"] [Sat Aug 29 05:06:37.728723 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.220.204.93:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/lkui.php"] [unique_id "apK9PSJcY4fy7tP-rU0LygAAAoY"] [Sat Aug 29 05:06:37.740052 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.147.79:17430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8XAAABbw"] [Sat Aug 29 05:06:37.747854 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.52.41.200:1758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/k.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8XQAABjM"] [Sat Aug 29 05:06:37.749330 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.48.250.41:25531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/error_log.php"] [unique_id "apK9PSJcY4fy7tP-rU0LzAAAAi0"] [Sat Aug 29 05:06:37.759043 2026] [security2:error] [pid 1017536:tid 1017717] [client 68.155.159.216:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-admin/about.php"] [unique_id "apK9PSJcY4fy7tP-rU0LzQAAAkc"] [Sat Aug 29 05:06:37.777368 2026] [security2:error] [pid 1017536:tid 1017778] [client 52.139.37.240:8626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/essexec.php"] [unique_id "apK9PSJcY4fy7tP-rU0LzwAAAoQ"] [Sat Aug 29 05:06:37.777789 2026] [security2:error] [pid 1018003:tid 1018217] [client 52.139.37.240:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/add_actualites.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8XwAABfo"] [Sat Aug 29 05:06:37.784722 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.184.117:46973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9PSJcY4fy7tP-rU0L0AAAAhw"] [Sat Aug 29 05:06:37.788652 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.184.117:34704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/alfa-rex.php7"] [unique_id "apK9PSJcY4fy7tP-rU0L0QAAAks"] [Sat Aug 29 05:06:37.791579 2026] [security2:error] [pid 1017536:tid 1017776] [client 158.23.147.79:24482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9PSJcY4fy7tP-rU0L0gAAAoI"] [Sat Aug 29 05:06:37.805100 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.63.81.20:46852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/8.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8ZAAABcc"] [Sat Aug 29 05:06:37.822582 2026] [security2:error] [pid 1017536:tid 1017752] [client 45.148.10.62:38786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ninaanddon.strangeworx.com"] [uri "/backend/.env"] [unique_id "apK9PSJcY4fy7tP-rU0L0wAAAmo"] [Sat Aug 29 05:06:37.831037 2026] [security2:error] [pid 1017536:tid 1017757] [client 185.104.184.230:52634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9PSJcY4fy7tP-rU0L1AAAAm8"] [Sat Aug 29 05:06:37.831411 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.104.49.130:53722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jacintoastiazaran.com"] [uri "/albin.php"] [unique_id "apK9PSJcY4fy7tP-rU0L1QAAAj0"] [Sat Aug 29 05:06:37.835274 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.104.49.130:36087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/155.php"] [unique_id "apK9PSJcY4fy7tP-rU0L1gAAAhU"] [Sat Aug 29 05:06:37.840446 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.197.61.180:11596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/Js.php"] [unique_id "apK9PSJcY4fy7tP-rU0L1wAAAhc"] [Sat Aug 29 05:06:37.851822 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.23.184.117:19223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.info.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8ZgAABho"] [Sat Aug 29 05:06:37.864220 2026] [security2:error] [pid 1018003:tid 1018174] [client 114.119.150.158:31579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "femaleurinal.org"] [uri "/women-urinating-standing/female-urination-standing-up/"] [unique_id "apK9PTAh5Y1i2tUxg4H8ZwAABc8"], referer: https://femaleurinal.org/women-urinating-standing/ [Sat Aug 29 05:06:37.867852 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.220.204.93:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8aAAABc0"] [Sat Aug 29 05:06:37.880387 2026] [security2:error] [pid 1018003:tid 1018194] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9PTAh5Y1i2tUxg4H8aQAABeM"] [Sat Aug 29 05:06:37.892603 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.220.204.93:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/bgymj.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8bgAABco"] [Sat Aug 29 05:06:37.897095 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.48.250.41:25363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/403.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8bwAABb4"] [Sat Aug 29 05:06:37.897569 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.151.200.44:65087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/6y7t.php"] [unique_id "apK9PSJcY4fy7tP-rU0L2QAAAnc"] [Sat Aug 29 05:06:37.905678 2026] [security2:error] [pid 1017536:tid 1017767] [client 52.139.37.240:31665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/s.php"] [unique_id "apK9PSJcY4fy7tP-rU0L2wAAAnk"] [Sat Aug 29 05:06:37.910952 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.151.200.44:47375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/siln.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8cAAABdA"] [Sat Aug 29 05:06:37.913968 2026] [security2:error] [pid 1018003:tid 1018212] [client 103.185.242.143:63013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8cQAABfU"] [Sat Aug 29 05:06:37.914098 2026] [security2:error] [pid 1018003:tid 1018212] [client 103.185.242.143:63013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8cQAABfU"] [Sat Aug 29 05:06:37.932771 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.184.117:46946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/xda.php"] [unique_id "apK9PTAh5Y1i2tUxg4H8cgAABhw"] [Sat Aug 29 05:06:37.934982 2026] [security2:error] [pid 1017536:tid 1017673] [client 158.23.184.117:34498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/b.php"] [unique_id "apK9PSJcY4fy7tP-rU0L3AAAAhs"] [Sat Aug 29 05:06:37.958540 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.63.81.20:41931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/goods.php"] [unique_id "apK9PSJcY4fy7tP-rU0L3gAAAk4"] [Sat Aug 29 05:06:37.966120 2026] [security2:error] [pid 1017536:tid 1017748] [client 185.104.184.230:38180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9PSJcY4fy7tP-rU0L3wAAAmY"] [Sat Aug 29 05:06:37.973403 2026] [security2:error] [pid 1017536:tid 1017767] [client 52.139.37.240:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/browse.php"] [unique_id "apK9PSJcY4fy7tP-rU0L4gAAAnk"] [Sat Aug 29 05:06:37.988902 2026] [security2:error] [pid 1017536:tid 1017751] [client 45.148.10.62:38786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninaanddon.strangeworx.com"] [uri "/test.php"] [unique_id "apK9PSJcY4fy7tP-rU0L4wAAAmk"] [Sat Aug 29 05:06:37.990035 2026] [security2:error] [pid 1017536:tid 1017613] [remote 67.223.118.10:47448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.118.223.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eastsidepride.barhashing.com"] [uri "/wp-login.php"] [unique_id "apK9PSJcY4fy7tP-rU0L4AACY0w"] [Sat Aug 29 05:06:37.995115 2026] [security2:error] [pid 1017536:tid 1017709] [client 158.23.184.117:18453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.trash7206/index.php"] [unique_id "apK9PSJcY4fy7tP-rU0L5AAAAj8"] [Sat Aug 29 05:06:38.008972 2026] [security2:error] [pid 1017536:tid 1017780] [client 52.139.37.240:8490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/fw.php"] [unique_id "apK9PiJcY4fy7tP-rU0L5QAAAoY"] [Sat Aug 29 05:06:38.021329 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.220.204.93:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/motu.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8dgAABgQ"] [Sat Aug 29 05:06:38.022327 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.196.209.81:9463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/access.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8dwAABeE"] [Sat Aug 29 05:06:38.041859 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.147.79:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/makeasmtp.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8eAAABiY"] [Sat Aug 29 05:06:38.046082 2026] [security2:error] [pid 1017536:tid 1017752] [client 4.205.62.107:21593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/public/vx.php"] [unique_id "apK9PiJcY4fy7tP-rU0L6wAAAmo"] [Sat Aug 29 05:06:38.046105 2026] [security2:error] [pid 1017536:tid 1017731] [client 68.155.159.216:38559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0L6gAAAlU"] [Sat Aug 29 05:06:38.054929 2026] [security2:error] [pid 1017536:tid 1017710] [client 20.196.209.81:11555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/GOD.php"] [unique_id "apK9PiJcY4fy7tP-rU0L7AAAAkA"] [Sat Aug 29 05:06:38.060636 2026] [security2:error] [pid 1017536:tid 1017552] [remote 67.223.118.10:47438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.118.223.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eastsidepride.barhashing.com"] [uri "/wp-login.php"] [unique_id "apK9PiJcY4fy7tP-rU0L7QACPQ8"] [Sat Aug 29 05:06:38.062472 2026] [security2:error] [pid 1017536:tid 1017713] [client 168.107.94.195:49734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9PiJcY4fy7tP-rU0L7gAAAkM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:38.067259 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.48.250.41:25446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/cytyr.php"] [unique_id "apK9PiJcY4fy7tP-rU0L7wAAAmI"] [Sat Aug 29 05:06:38.079000 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.184.117:46922] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "devlop3d.airviewconcept.com"] [uri "/1.php"] [unique_id "apK9PiJcY4fy7tP-rU0L8AAAAhw"] [Sat Aug 29 05:06:38.079107 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.184.117:46922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/1.php"] [unique_id "apK9PiJcY4fy7tP-rU0L8AAAAhw"] [Sat Aug 29 05:06:38.080051 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.184.117:34713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/buy.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8fgAABhY"] [Sat Aug 29 05:06:38.091225 2026] [security2:error] [pid 1017536:tid 1017706] [client 158.158.54.35:28673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/s.php"] [unique_id "apK9PiJcY4fy7tP-rU0L8QAAAjw"] [Sat Aug 29 05:06:38.099448 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.151.200.44:64260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/gaje.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8fwAABcM"] [Sat Aug 29 05:06:38.100056 2026] [security2:error] [pid 1017536:tid 1017721] [client 52.139.37.240:30802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/sagax.php"] [unique_id "apK9PiJcY4fy7tP-rU0L8gAAAks"] [Sat Aug 29 05:06:38.104218 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.151.200.44:46635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/f-401.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8gAAABh8"] [Sat Aug 29 05:06:38.112987 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.49.130:52519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/about.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8gQAABjU"] [Sat Aug 29 05:06:38.121216 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.81.20:44467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ah.php"] [unique_id "apK9PiJcY4fy7tP-rU0L9QAAAkc"] [Sat Aug 29 05:06:38.122186 2026] [security2:error] [pid 1017536:tid 1017695] [client 185.104.184.230:52640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wlu.rog.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK9PiJcY4fy7tP-rU0L9gAAAjE"] [Sat Aug 29 05:06:38.141413 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.23.184.117:18438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.trash7206/min.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8hwAABdg"] [Sat Aug 29 05:06:38.150459 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.49.130:57680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/wp-login.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8iAAABdk"] [Sat Aug 29 05:06:38.150490 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.147.79:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/themes/too.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8iQAABfw"] [Sat Aug 29 05:06:38.157264 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.220.204.93:52349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/Ov-Simple1.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8iwAABb0"] [Sat Aug 29 05:06:38.166001 2026] [security2:error] [pid 1017536:tid 1017781] [client 52.139.37.240:6740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/contentloader1.php"] [unique_id "apK9PiJcY4fy7tP-rU0L-gAAAoc"] [Sat Aug 29 05:06:38.171313 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.147.79:59223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0L-wAAAkM"] [Sat Aug 29 05:06:38.198682 2026] [security2:error] [pid 1018003:tid 1018234] [client 52.139.37.240:8467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/zwso.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8kAAABgo"] [Sat Aug 29 05:06:38.202956 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.52.41.200:1231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/root.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8kgAABiA"] [Sat Aug 29 05:06:38.212142 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.250.41:25292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/galer.php"] [unique_id "apK9PiJcY4fy7tP-rU0L_gAAAnc"] [Sat Aug 29 05:06:38.222371 2026] [security2:error] [pid 1018003:tid 1018248] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8lAAABhg"] [Sat Aug 29 05:06:38.225005 2026] [security2:error] [pid 1017536:tid 1017744] [client 158.23.184.117:34745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/bless.php"] [unique_id "apK9PiJcY4fy7tP-rU0MAQAAAmI"] [Sat Aug 29 05:06:38.225024 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.184.117:46355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MAgAAAlo"] [Sat Aug 29 05:06:38.226197 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.220.204.93:59025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ws69.php"] [unique_id "apK9PiJcY4fy7tP-rU0MAwAAAhs"] [Sat Aug 29 05:06:38.229759 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:49217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8lQAABco"] [Sat Aug 29 05:06:38.230804 2026] [security2:error] [pid 1017536:tid 1017691] [client 93.123.109.228:50032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9PiJcY4fy7tP-rU0MBAAAAi0"] [Sat Aug 29 05:06:38.243610 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.151.200.44:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/0xs.php"] [unique_id "apK9PiJcY4fy7tP-rU0MBQAAAjs"] [Sat Aug 29 05:06:38.258004 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.63.81.20:44498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ws55.php"] [unique_id "apK9PiJcY4fy7tP-rU0MBwAAAoY"] [Sat Aug 29 05:06:38.285596 2026] [security2:error] [pid 1017536:tid 1017767] [client 158.23.184.117:19202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known//index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MCAAAAnk"] [Sat Aug 29 05:06:38.289308 2026] [security2:error] [pid 1017536:tid 1017734] [client 40.83.93.50:1741] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/1.php"] [unique_id "apK9PiJcY4fy7tP-rU0MCQAAAlg"] [Sat Aug 29 05:06:38.289400 2026] [security2:error] [pid 1017536:tid 1017734] [client 40.83.93.50:1741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/1.php"] [unique_id "apK9PiJcY4fy7tP-rU0MCQAAAlg"] [Sat Aug 29 05:06:38.290894 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.147.79:35806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MCgAAApA"] [Sat Aug 29 05:06:38.303111 2026] [security2:error] [pid 1017536:tid 1017675] [client 93.123.109.228:37086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9PiJcY4fy7tP-rU0MDQAAAh0"] [Sat Aug 29 05:06:38.304004 2026] [security2:error] [pid 1018003:tid 1018180] [client 68.155.159.216:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/ws.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8mAAABdU"] [Sat Aug 29 05:06:38.308238 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.151.200.44:46536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/hq.php"] [unique_id "apK9PiJcY4fy7tP-rU0MDgAAAm8"] [Sat Aug 29 05:06:38.309346 2026] [security2:error] [pid 1018003:tid 1018224] [client 4.205.62.107:22409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/cu.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8mgAABgE"] [Sat Aug 29 05:06:38.340499 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.48.250.41:25493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/baixy.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8nAAABg8"] [Sat Aug 29 05:06:38.360324 2026] [security2:error] [pid 1017536:tid 1017785] [client 4.205.62.107:21908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/koiy.php"] [unique_id "apK9PiJcY4fy7tP-rU0MEAAAAos"] [Sat Aug 29 05:06:38.360649 2026] [security2:error] [pid 1018003:tid 1018273] [client 52.139.37.240:6748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/upfile.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8nQAABjE"] [Sat Aug 29 05:06:38.376811 2026] [security2:error] [pid 1017536:tid 1017761] [client 4.205.62.107:26670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/g3.php"] [unique_id "apK9PiJcY4fy7tP-rU0MEgAAAnM"] [Sat Aug 29 05:06:38.387644 2026] [security2:error] [pid 1017536:tid 1017667] [client 158.23.184.117:34504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/class-t.api.php"] [unique_id "apK9PiJcY4fy7tP-rU0MEwAAAhU"] [Sat Aug 29 05:06:38.389460 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.63.81.20:44521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/drykl.php"] [unique_id "apK9PiJcY4fy7tP-rU0MFAAAAhs"] [Sat Aug 29 05:06:38.389903 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.151.200.44:64283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/wp-admin/zwso.php"] [unique_id "apK9PiJcY4fy7tP-rU0MFQAAAms"] [Sat Aug 29 05:06:38.395001 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.220.204.93:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/wp-blogs.php"] [unique_id "apK9PiJcY4fy7tP-rU0MFgAAAoI"] [Sat Aug 29 05:06:38.396108 2026] [security2:error] [pid 1017536:tid 1017696] [client 52.139.37.240:8452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/admin/function.php"] [unique_id "apK9PiJcY4fy7tP-rU0MFwAAAjI"] [Sat Aug 29 05:06:38.406953 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.220.204.93:59112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ccs.php"] [unique_id "apK9PiJcY4fy7tP-rU0MGgAAAl4"] [Sat Aug 29 05:06:38.415212 2026] [security2:error] [pid 1017536:tid 1017745] [client 158.23.184.117:46343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-includes/admin.php"] [unique_id "apK9PiJcY4fy7tP-rU0MGwAAAmM"] [Sat Aug 29 05:06:38.431024 2026] [security2:error] [pid 1017536:tid 1017721] [client 158.23.184.117:18490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/about.php"] [unique_id "apK9PiJcY4fy7tP-rU0MHAAAAks"] [Sat Aug 29 05:06:38.438076 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.151.200.44:46652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/mh.php"] [unique_id "apK9PiJcY4fy7tP-rU0MHQAAAls"] [Sat Aug 29 05:06:38.441999 2026] [security2:error] [pid 1017536:tid 1017695] [client 168.107.94.195:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MHgAAAjE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:38.446604 2026] [security2:error] [pid 1017536:tid 1017709] [client 193.56.28.190:48171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.28.56.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9PiJcY4fy7tP-rU0MGAAAAj8"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:38.474872 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.48.250.41:25560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ava.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8oQAABik"] [Sat Aug 29 05:06:38.476688 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.151.200.44:64419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/waf.php"] [unique_id "apK9PiJcY4fy7tP-rU0MIAAAAj0"] [Sat Aug 29 05:06:38.477388 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.196.209.81:19409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/ggfi.php"] [unique_id "apK9PiJcY4fy7tP-rU0MIQAAAjw"] [Sat Aug 29 05:06:38.504758 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.23.147.79:30646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/content.php"] [unique_id "apK9PiJcY4fy7tP-rU0MJAAAAlo"] [Sat Aug 29 05:06:38.538762 2026] [security2:error] [pid 1017536:tid 1017776] [client 68.155.159.216:33684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9PiJcY4fy7tP-rU0MJwAAAoI"] [Sat Aug 29 05:06:38.539025 2026] [security2:error] [pid 1018003:tid 1018227] [client 158.158.54.35:14105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/test1.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8pAAABgQ"] [Sat Aug 29 05:06:38.539782 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.63.81.20:44416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/backup.php"] [unique_id "apK9PiJcY4fy7tP-rU0MKAAAAjI"] [Sat Aug 29 05:06:38.543304 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.220.204.93:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/mar.php"] [unique_id "apK9PiJcY4fy7tP-rU0MKQAAAlM"] [Sat Aug 29 05:06:38.546843 2026] [security2:error] [pid 1017536:tid 1017786] [client 158.23.184.117:34724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/cache.php"] [unique_id "apK9PiJcY4fy7tP-rU0MKgAAAow"] [Sat Aug 29 05:06:38.546935 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.23.147.79:25424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9PiJcY4fy7tP-rU0MKwAAAi0"] [Sat Aug 29 05:06:38.554069 2026] [security2:error] [pid 1017536:tid 1017781] [client 52.139.37.240:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/form.php"] [unique_id "apK9PiJcY4fy7tP-rU0MLAAAAoc"] [Sat Aug 29 05:06:38.559565 2026] [security2:error] [pid 1018003:tid 1018206] [client 68.155.159.216:18188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8pgAABe8"] [Sat Aug 29 05:06:38.559894 2026] [security2:error] [pid 1017536:tid 1017667] [client 158.23.184.117:46342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-themes.php"] [unique_id "apK9PiJcY4fy7tP-rU0MLgAAAhU"] [Sat Aug 29 05:06:38.561575 2026] [security2:error] [pid 1017536:tid 1017678] [client 185.104.184.230:38184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9PiJcY4fy7tP-rU0MLwAAAiA"] [Sat Aug 29 05:06:38.572258 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.197.61.180:8929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/access.php"] [unique_id "apK9PiJcY4fy7tP-rU0MMAAAAhc"] [Sat Aug 29 05:06:38.583267 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.196.209.81:4121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/classsmtps.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8pwAABi4"] [Sat Aug 29 05:06:38.584364 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.151.200.44:47323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/f2r4.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8qAAABcM"] [Sat Aug 29 05:06:38.587672 2026] [security2:error] [pid 1018003:tid 1018244] [client 52.139.37.240:8603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/zoom1.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8qQAABhQ"] [Sat Aug 29 05:06:38.592878 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.151.200.44:64282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/Contrller.php"] [unique_id "apK9PiJcY4fy7tP-rU0MMwAAAjE"] [Sat Aug 29 05:06:38.607931 2026] [security2:error] [pid 1017536:tid 1017704] [client 213.202.253.4:61112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/txets.php"] [unique_id "apK9PiJcY4fy7tP-rU0MNwAAAjo"], referer: www.google.com [Sat Aug 29 05:06:38.612911 2026] [security2:error] [pid 1018003:tid 1018160] [client 93.123.109.228:49744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8qgAABcE"] [Sat Aug 29 05:06:38.614438 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.48.250.41:25493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/gdn.php"] [unique_id "apK9PiJcY4fy7tP-rU0MOAAAAlY"] [Sat Aug 29 05:06:38.631681 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.220.204.93:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/mini.php"] [unique_id "apK9PiJcY4fy7tP-rU0MOgAAAnw"] [Sat Aug 29 05:06:38.650976 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.151.200.44:65004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/bnnof6.php"] [unique_id "apK9PiJcY4fy7tP-rU0MOwAAAhs"] [Sat Aug 29 05:06:38.653106 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.52.41.200:1250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/p.php"] [unique_id "apK9PiJcY4fy7tP-rU0MPAAAAmI"] [Sat Aug 29 05:06:38.664026 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.23.184.117:18478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9PiJcY4fy7tP-rU0MPQAAApM"] [Sat Aug 29 05:06:38.674873 2026] [security2:error] [pid 1017536:tid 1017776] [client 93.123.109.228:37086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9PiJcY4fy7tP-rU0MPwAAAoI"] [Sat Aug 29 05:06:38.680759 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.220.204.93:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ccu.php"] [unique_id "apK9PiJcY4fy7tP-rU0MQAAAAjI"] [Sat Aug 29 05:06:38.689716 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.23.184.117:34541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/content.php"] [unique_id "apK9PiJcY4fy7tP-rU0MQQAAAoQ"] [Sat Aug 29 05:06:38.701156 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.63.81.20:44436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/indo.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8rQAABfA"] [Sat Aug 29 05:06:38.704250 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.23.184.117:46958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8rgAABek"] [Sat Aug 29 05:06:38.739744 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.151.200.44:47345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/sadis.php"] [unique_id "apK9PiJcY4fy7tP-rU0MRgAAAo4"] [Sat Aug 29 05:06:38.746597 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:30652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MSAAAAkc"] [Sat Aug 29 05:06:38.749808 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:32744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9PiJcY4fy7tP-rU0MSgAAAjE"] [Sat Aug 29 05:06:38.749955 2026] [security2:error] [pid 1018003:tid 1018153] [client 52.139.37.240:52637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/wp-sigunq.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8tAAABbo"] [Sat Aug 29 05:06:38.764330 2026] [security2:error] [pid 1018003:tid 1018156] [client 68.155.159.216:14237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8tQAABb0"] [Sat Aug 29 05:06:38.768670 2026] [security2:error] [pid 1017536:tid 1017751] [client 40.83.93.50:23946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/about.php"] [unique_id "apK9PiJcY4fy7tP-rU0MSwAAAmk"] [Sat Aug 29 05:06:38.773967 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.48.250.41:25461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/f2.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8tgAABec"] [Sat Aug 29 05:06:38.774023 2026] [security2:error] [pid 1017536:tid 1017781] [client 52.139.37.240:8459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/about.php7"] [unique_id "apK9PiJcY4fy7tP-rU0MTAAAAoc"] [Sat Aug 29 05:06:38.792874 2026] [security2:error] [pid 1017536:tid 1017704] [client 158.23.147.79:50081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9PiJcY4fy7tP-rU0MTQAAAjo"] [Sat Aug 29 05:06:38.803662 2026] [security2:error] [pid 1017536:tid 1017674] [client 4.205.62.107:9006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/api.php"] [unique_id "apK9PiJcY4fy7tP-rU0MTgAAAhw"] [Sat Aug 29 05:06:38.805986 2026] [security2:error] [pid 1018003:tid 1018155] [client 93.123.109.228:37160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8uQAABbw"] [Sat Aug 29 05:06:38.806937 2026] [security2:error] [pid 1018003:tid 1018245] [client 158.23.184.117:18486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8ugAABhU"] [Sat Aug 29 05:06:38.813559 2026] [security2:error] [pid 1017536:tid 1017765] [client 4.205.62.107:56053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/groceries/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MTwAAAnc"] [Sat Aug 29 05:06:38.817547 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.220.204.93:52343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ak.php"] [unique_id "apK9PiJcY4fy7tP-rU0MUAAAAkI"] [Sat Aug 29 05:06:38.818758 2026] [security2:error] [pid 1017536:tid 1017785] [client 68.155.159.216:51583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MUQAAAos"] [Sat Aug 29 05:06:38.824966 2026] [security2:error] [pid 1018003:tid 1018258] [client 168.107.94.195:50396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8uwAABiI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:38.831288 2026] [security2:error] [pid 1018003:tid 1018203] [client 93.123.109.228:37156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8vAAABew"] [Sat Aug 29 05:06:38.837548 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.63.81.20:46894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/sign.php"] [unique_id "apK9PiJcY4fy7tP-rU0MUgAAAmI"] [Sat Aug 29 05:06:38.840995 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.184.117:34555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/classwithtostring.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8vQAABhA"] [Sat Aug 29 05:06:38.853961 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.151.200.44:64392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/ah24.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8vgAABcU"] [Sat Aug 29 05:06:38.854847 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.220.204.93:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/amp.php"] [unique_id "apK9PiJcY4fy7tP-rU0MVAAAApM"] [Sat Aug 29 05:06:38.865175 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:65112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MVgAAAjI"] [Sat Aug 29 05:06:38.871046 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.196.209.81:3852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/alfa-rex.php"] [unique_id "apK9PiJcY4fy7tP-rU0MVwAAAks"] [Sat Aug 29 05:06:38.880862 2026] [security2:error] [pid 1017536:tid 1017740] [client 45.148.10.62:38798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "ninaanddon.strangeworx.com"] [uri "/.env.backup"] [unique_id "apK9PiJcY4fy7tP-rU0MWAAAAl4"] [Sat Aug 29 05:06:38.898665 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:24386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9PiJcY4fy7tP-rU0MWQAAApI"] [Sat Aug 29 05:06:38.902424 2026] [security2:error] [pid 1017536:tid 1017745] [client 158.23.184.117:46339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MWgAAAmM"] [Sat Aug 29 05:06:38.914643 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:25586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/grsiuk.php"] [unique_id "apK9PiJcY4fy7tP-rU0MWwAAAls"] [Sat Aug 29 05:06:38.916835 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.151.200.44:47408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/xcre1.php"] [unique_id "apK9PiJcY4fy7tP-rU0MXAAAAmo"] [Sat Aug 29 05:06:38.924798 2026] [security2:error] [pid 1018003:tid 1018065] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/production/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8wQAF3Sw"] [Sat Aug 29 05:06:38.939689 2026] [security2:error] [pid 1017536:tid 1017748] [client 52.139.37.240:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/07.php"] [unique_id "apK9PiJcY4fy7tP-rU0MXgAAAmY"] [Sat Aug 29 05:06:38.949526 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.220.204.93:52297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/lib.php"] [unique_id "apK9PiJcY4fy7tP-rU0MXwAAAmk"] [Sat Aug 29 05:06:38.952679 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.23.147.79:17417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9PiJcY4fy7tP-rU0MYAAAAm8"] [Sat Aug 29 05:06:38.970175 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:8638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/cron.php"] [unique_id "apK9PiJcY4fy7tP-rU0MYgAAAiA"] [Sat Aug 29 05:06:38.971047 2026] [security2:error] [pid 1017536:tid 1017736] [client 158.158.54.35:4902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/ws.php"] [unique_id "apK9PiJcY4fy7tP-rU0MYwAAAlo"] [Sat Aug 29 05:06:38.972202 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.81.20:46942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wnnjpsby.php"] [unique_id "apK9PiJcY4fy7tP-rU0MZAAAAlY"] [Sat Aug 29 05:06:38.972556 2026] [security2:error] [pid 1018003:tid 1018097] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/server/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8wwAGIEw"] [Sat Aug 29 05:06:38.973867 2026] [security2:error] [pid 1018003:tid 1018063] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/frontend/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8xgAGICo"] [Sat Aug 29 05:06:38.973874 2026] [security2:error] [pid 1018003:tid 1018079] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/src/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8xAAGIDo"] [Sat Aug 29 05:06:38.973886 2026] [security2:error] [pid 1018003:tid 1018096] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/app/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8xwAGIEs"] [Sat Aug 29 05:06:38.973976 2026] [security2:error] [pid 1018003:tid 1018081] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/dev/.env"] [unique_id "apK9PjAh5Y1i2tUxg4H8xQAGIDw"] [Sat Aug 29 05:06:38.987868 2026] [security2:error] [pid 1018003:tid 1018233] [client 158.23.184.117:34691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/css.php"] [unique_id "apK9PjAh5Y1i2tUxg4H8yAAABgk"] [Sat Aug 29 05:06:38.988475 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.196.209.81:17894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/contentloader1.php"] [unique_id "apK9PiJcY4fy7tP-rU0MaAAAAoI"] [Sat Aug 29 05:06:38.996936 2026] [core:error] [pid 1018003:tid 1018174] [client 20.197.61.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:38.996952 2026] [core:error] [pid 1018003:tid 1018174] [client 20.197.61.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:39.002543 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.220.204.93:52322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/cc13.php"] [unique_id "apK9PyJcY4fy7tP-rU0MaQAAAkI"] [Sat Aug 29 05:06:39.026267 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.184.117:18450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9PzAh5Y1i2tUxg4H8ygAABhw"] [Sat Aug 29 05:06:39.046639 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.23.184.117:62326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devlop3d.airviewconcept.com"] [uri "/11.php"] [unique_id "apK9PzAh5Y1i2tUxg4H8ywAABho"] [Sat Aug 29 05:06:39.054132 2026] [security2:error] [pid 1017536:tid 1017770] [client 195.63.31.115:46163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9PyJcY4fy7tP-rU0MagAAAnw"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:39.061096 2026] [security2:error] [pid 1017536:tid 1017778] [client 136.107.231.130:29072] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9PyJcY4fy7tP-rU0McAAAAoQ"] [Sat Aug 29 05:06:39.063210 2026] [security2:error] [pid 1017536:tid 1017729] [client 136.107.231.130:29206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.ssh/id_rsa"] [unique_id "apK9PyJcY4fy7tP-rU0McwAAAlM"] [Sat Aug 29 05:06:39.066770 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.48.250.41:25513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wp-scr1pts.php"] [unique_id "apK9PyJcY4fy7tP-rU0MdwAAAks"] [Sat Aug 29 05:06:39.069325 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.151.200.44:45908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/motu.php"] [unique_id "apK9PzAh5Y1i2tUxg4H82AAABbk"] [Sat Aug 29 05:06:39.070106 2026] [security2:error] [pid 1018003:tid 1018212] [client 136.107.231.130:29220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.ssh/id_dsa"] [unique_id "apK9PzAh5Y1i2tUxg4H81wAABfU"] [Sat Aug 29 05:06:39.089533 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.220.204.93:52315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wp-style.php"] [unique_id "apK9PzAh5Y1i2tUxg4H82QAABjQ"] [Sat Aug 29 05:06:39.093913 2026] [security2:error] [pid 1018003:tid 1018206] [client 93.123.109.228:37156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H82wAABe8"] [Sat Aug 29 05:06:39.096378 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.52.41.200:1270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/a1.php"] [unique_id "apK9PyJcY4fy7tP-rU0MgAAAAmE"] [Sat Aug 29 05:06:39.098493 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.151.200.44:64232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/Zeiss.php"] [unique_id "apK9PyJcY4fy7tP-rU0MgQAAAoc"] [Sat Aug 29 05:06:39.107404 2026] [security2:error] [pid 1018003:tid 1018090] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/staging/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H83AAGFEU"] [Sat Aug 29 05:06:39.107470 2026] [security2:error] [pid 1018003:tid 1018074] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/v1/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H83QAGFDU"] [Sat Aug 29 05:06:39.109318 2026] [security2:error] [pid 1018003:tid 1018059] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/v2/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H84AAGFCY"] [Sat Aug 29 05:06:39.109450 2026] [security2:error] [pid 1018003:tid 1018095] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/docker/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H83wAGFEo"] [Sat Aug 29 05:06:39.109450 2026] [security2:error] [pid 1018003:tid 1018091] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/apps/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H83gAGFEY"] [Sat Aug 29 05:06:39.109830 2026] [security2:error] [pid 1018003:tid 1018104] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/old/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H84QAGFFM"] [Sat Aug 29 05:06:39.128731 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.63.81.20:44513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/gigi.php"] [unique_id "apK9PzAh5Y1i2tUxg4H84gAABis"] [Sat Aug 29 05:06:39.132797 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.23.184.117:34535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/chosen.php"] [unique_id "apK9PzAh5Y1i2tUxg4H84wAABfk"] [Sat Aug 29 05:06:39.160314 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.220.204.93:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/aa.php"] [unique_id "apK9PzAh5Y1i2tUxg4H85gAABgI"] [Sat Aug 29 05:06:39.163803 2026] [security2:error] [pid 1017536:tid 1017786] [client 185.104.184.230:36220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9PyJcY4fy7tP-rU0MhgAAAow"] [Sat Aug 29 05:06:39.164930 2026] [security2:error] [pid 1018003:tid 1018162] [client 52.139.37.240:52633] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/c99.php"] [unique_id "apK9PzAh5Y1i2tUxg4H85wAABcM"] [Sat Aug 29 05:06:39.170902 2026] [security2:error] [pid 1017536:tid 1017732] [client 158.23.184.117:19241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "apK9PyJcY4fy7tP-rU0MhwAAAlY"] [Sat Aug 29 05:06:39.174880 2026] [security2:error] [pid 1017536:tid 1017757] [client 52.139.37.240:8505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/wp-2019.php"] [unique_id "apK9PyJcY4fy7tP-rU0MiAAAAm8"] [Sat Aug 29 05:06:39.189256 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.23.147.79:61611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9PyJcY4fy7tP-rU0MiQAAAkE"] [Sat Aug 29 05:06:39.197144 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.250.41:25347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/num.php"] [unique_id "apK9PzAh5Y1i2tUxg4H86gAABbo"] [Sat Aug 29 05:06:39.204341 2026] [security2:error] [pid 1017536:tid 1017765] [client 168.107.94.195:50752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9PyJcY4fy7tP-rU0MigAAAnc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:39.205896 2026] [security2:error] [pid 1017536:tid 1017765] [client 4.205.62.107:22358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/log.php"] [unique_id "apK9PyJcY4fy7tP-rU0MjAAAAnc"] [Sat Aug 29 05:06:39.230805 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.220.204.93:59119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/browse.php"] [unique_id "apK9PyJcY4fy7tP-rU0MjwAAAmo"] [Sat Aug 29 05:06:39.248083 2026] [fcgid:warn] [pid 1018003:tid 1018198] (70014)End of file found: [client 199.45.155.15:56200] mod_fcgid: can't get data from http client [Sat Aug 29 05:06:39.258142 2026] [proxy_http:error] [pid 1018003:tid 1018159] (20014)Internal error (specific information not available): [client 35.228.2.165:40490] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:39.258156 2026] [proxy:error] [pid 1018003:tid 1018159] [client 35.228.2.165:40490] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.git/config [Sat Aug 29 05:06:39.261562 2026] [security2:error] [pid 1017536:tid 1017729] [client 158.23.147.79:26566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/radio.php"] [unique_id "apK9PyJcY4fy7tP-rU0MkQAAAlM"] [Sat Aug 29 05:06:39.263700 2026] [proxy_http:error] [pid 1018003:tid 1018265] (20014)Internal error (specific information not available): [client 35.228.2.165:40496] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:39.263713 2026] [proxy:error] [pid 1018003:tid 1018265] [client 35.228.2.165:40496] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/public/.git/config [Sat Aug 29 05:06:39.269319 2026] [proxy_http:error] [pid 1018003:tid 1018163] (20014)Internal error (specific information not available): [client 35.228.2.165:40548] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:39.269333 2026] [proxy:error] [pid 1018003:tid 1018163] [client 35.228.2.165:40548] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/src/.git/config [Sat Aug 29 05:06:39.272089 2026] [security2:error] [pid 1017536:tid 1017751] [client 40.83.93.50:1604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/admin-header.php"] [unique_id "apK9PyJcY4fy7tP-rU0MkwAAAmk"] [Sat Aug 29 05:06:39.273214 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.63.81.20:46884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/info.php/new.php"] [unique_id "apK9PyJcY4fy7tP-rU0MlAAAAjs"] [Sat Aug 29 05:06:39.274461 2026] [security2:error] [pid 1017536:tid 1017698] [client 45.148.10.62:38798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "ninaanddon.strangeworx.com"] [uri "/.env.old"] [unique_id "apK9PyJcY4fy7tP-rU0MkgAAAjQ"] [Sat Aug 29 05:06:39.274477 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.151.200.44:64993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/ztv.php"] [unique_id "apK9PzAh5Y1i2tUxg4H89QAABbw"] [Sat Aug 29 05:06:39.278098 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.184.117:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/doc.php"] [unique_id "apK9PyJcY4fy7tP-rU0MlQAAAjE"] [Sat Aug 29 05:06:39.278201 2026] [security2:error] [pid 1018003:tid 1018245] [client 158.23.147.79:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9PzAh5Y1i2tUxg4H89gAABhU"] [Sat Aug 29 05:06:39.279794 2026] [security2:error] [pid 1018003:tid 1018112] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/portal/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H89wAGM1s"] [Sat Aug 29 05:06:39.304344 2026] [security2:error] [pid 1018003:tid 1018066] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/.docker/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H8-AAGIi0"] [Sat Aug 29 05:06:39.305107 2026] [security2:error] [pid 1018003:tid 1018086] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/env.old"] [unique_id "apK9PzAh5Y1i2tUxg4H8-QAGIkE"] [Sat Aug 29 05:06:39.307021 2026] [security2:error] [pid 1018003:tid 1018105] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/site/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H8_AAF7FQ"] [Sat Aug 29 05:06:39.307525 2026] [security2:error] [pid 1018003:tid 1018045] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/env.bak"] [unique_id "apK9PzAh5Y1i2tUxg4H8-wAF7Bg"] [Sat Aug 29 05:06:39.307627 2026] [security2:error] [pid 1018003:tid 1018101] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/api/.env.bak"] [unique_id "apK9PzAh5Y1i2tUxg4H8-gAF7FA"] [Sat Aug 29 05:06:39.323620 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.48.250.41:25523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/a4.php"] [unique_id "apK9PyJcY4fy7tP-rU0MlgAAAo4"] [Sat Aug 29 05:06:39.329029 2026] [proxy_http:error] [pid 1018003:tid 1018196] (20014)Internal error (specific information not available): [client 35.228.2.165:40574] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:39.329041 2026] [proxy:error] [pid 1018003:tid 1018196] [client 35.228.2.165:40574] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/var/www/.git/config [Sat Aug 29 05:06:39.329343 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.197.61.180:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/classsmtps.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9AAAABhY"] [Sat Aug 29 05:06:39.350683 2026] [security2:error] [pid 1017536:tid 1017743] [client 68.155.159.216:49211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/radio.php"] [unique_id "apK9PyJcY4fy7tP-rU0MlwAAAmE"] [Sat Aug 29 05:06:39.352052 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.220.204.93:52318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/s1.php"] [unique_id "apK9PyJcY4fy7tP-rU0MmAAAAoc"] [Sat Aug 29 05:06:39.356301 2026] [security2:error] [pid 1018003:tid 1018189] [client 52.139.37.240:52617] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/c99.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9AgAABd4"] [Sat Aug 29 05:06:39.371177 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.196.209.81:3948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/cookie.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9BAAABio"] [Sat Aug 29 05:06:39.373810 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.220.204.93:59110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/zoo.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9BQAABfo"] [Sat Aug 29 05:06:39.383641 2026] [security2:error] [pid 1017536:tid 1017723] [client 52.139.37.240:8625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/gecko-new.php"] [unique_id "apK9PyJcY4fy7tP-rU0MmwAAAk0"] [Sat Aug 29 05:06:39.385901 2026] [security2:error] [pid 1017536:tid 1017687] [client 52.139.37.240:33573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/aged.php"] [unique_id "apK9PyJcY4fy7tP-rU0MnAAAAik"] [Sat Aug 29 05:06:39.390111 2026] [security2:error] [pid 1017536:tid 1017780] [client 52.139.37.240:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/ahax.php"] [unique_id "apK9PyJcY4fy7tP-rU0MnQAAAoY"] [Sat Aug 29 05:06:39.398033 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.196.209.81:4138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/al.php"] [unique_id "apK9PyJcY4fy7tP-rU0MnwAAAoQ"] [Sat Aug 29 05:06:39.411186 2026] [security2:error] [pid 1018003:tid 1018185] [client 93.123.109.228:37160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H9BgAABdo"] [Sat Aug 29 05:06:39.412332 2026] [security2:error] [pid 1017536:tid 1017691] [client 158.158.54.35:20648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-themes.php"] [unique_id "apK9PyJcY4fy7tP-rU0MoAAAAi0"] [Sat Aug 29 05:06:39.413860 2026] [security2:error] [pid 1017536:tid 1017751] [client 158.23.147.79:35746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9PyJcY4fy7tP-rU0MoQAAAmk"] [Sat Aug 29 05:06:39.421222 2026] [security2:error] [pid 1017536:tid 1017698] [client 93.123.109.228:50032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9PyJcY4fy7tP-rU0MowAAAjQ"] [Sat Aug 29 05:06:39.452632 2026] [security2:error] [pid 1017536:tid 1017788] [client 4.205.62.107:22385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/ok.php"] [unique_id "apK9PyJcY4fy7tP-rU0MpQAAAo4"] [Sat Aug 29 05:06:39.455542 2026] [security2:error] [pid 1017536:tid 1017709] [client 68.155.159.216:52768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-includes/css/index.php"] [unique_id "apK9PyJcY4fy7tP-rU0MpgAAAj8"] [Sat Aug 29 05:06:39.461690 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.151.200.44:47415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/wefile.php"] [unique_id "apK9PyJcY4fy7tP-rU0MqAAAAiA"] [Sat Aug 29 05:06:39.462098 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.48.250.41:25460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/tfm.php"] [unique_id "apK9PyJcY4fy7tP-rU0MqQAAAlo"] [Sat Aug 29 05:06:39.463868 2026] [core:error] [pid 1017536:tid 1017743] [client 45.148.10.62:38798] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:39.463884 2026] [core:error] [pid 1017536:tid 1017743] [client 45.148.10.62:38798] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:39.480797 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.151.200.44:64978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/kure.php"] [unique_id "apK9PyJcY4fy7tP-rU0MqgAAAjw"] [Sat Aug 29 05:06:39.500541 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.63.81.20:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/w.php"] [unique_id "apK9PyJcY4fy7tP-rU0MqwAAAow"] [Sat Aug 29 05:06:39.501910 2026] [security2:error] [pid 1018003:tid 1018194] [client 68.155.159.216:51495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/themes.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9CQAABeM"] [Sat Aug 29 05:06:39.514298 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.220.204.93:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/elp.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9CwAABdQ"] [Sat Aug 29 05:06:39.514332 2026] [security2:error] [pid 1018003:tid 1018157] [client 4.205.62.107:65439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/wp-konfig.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9DAAABb4"] [Sat Aug 29 05:06:39.515205 2026] [security2:error] [pid 1018003:tid 1018157] [client 4.205.62.107:22232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/test1.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9DQAABb4"] [Sat Aug 29 05:06:39.544059 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.220.204.93:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/0byte.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9EgAABjQ"] [Sat Aug 29 05:06:39.546829 2026] [security2:error] [pid 1018003:tid 1018250] [client 52.139.37.240:6743] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcalendars.healthysmilestoday.com"] [uri "/c99.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9FAAABho"] [Sat Aug 29 05:06:39.567778 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.151.200.44:64211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/ww2.php"] [unique_id "apK9PyJcY4fy7tP-rU0MrAAAAoQ"] [Sat Aug 29 05:06:39.569688 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.52.41.200:1187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9PyJcY4fy7tP-rU0MrQAAAjs"] [Sat Aug 29 05:06:39.581813 2026] [security2:error] [pid 1018003:tid 1018182] [client 52.139.37.240:33561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/essexec.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9FwAABdc"] [Sat Aug 29 05:06:39.583412 2026] [security2:error] [pid 1018003:tid 1018179] [client 52.139.37.240:8582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/add_actualites.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9GAAABdQ"] [Sat Aug 29 05:06:39.584399 2026] [security2:error] [pid 1018003:tid 1018261] [client 168.107.94.195:51129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9GQAABiU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:39.600753 2026] [security2:error] [pid 1018003:tid 1018212] [client 52.139.37.240:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/breads1.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9HAAABfU"] [Sat Aug 29 05:06:39.601214 2026] [security2:error] [pid 1018003:tid 1018162] [client 93.123.109.228:37160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H9GwAABcM"] [Sat Aug 29 05:06:39.611905 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:25370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/Geforce.php"] [unique_id "apK9PyJcY4fy7tP-rU0MswAAAnw"] [Sat Aug 29 05:06:39.621192 2026] [proxy_http:error] [pid 1017536:tid 1017696] (20014)Internal error (specific information not available): [client 35.228.2.165:60050] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:39.621209 2026] [proxy:error] [pid 1017536:tid 1017696] [client 35.228.2.165:60050] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.git/config [Sat Aug 29 05:06:39.627834 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.63.81.20:46897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/x.php"] [unique_id "apK9PyJcY4fy7tP-rU0MtwAAAkc"] [Sat Aug 29 05:06:39.629644 2026] [proxy_http:error] [pid 1018003:tid 1018156] (20014)Internal error (specific information not available): [client 35.228.2.165:60080] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:39.629661 2026] [proxy:error] [pid 1018003:tid 1018156] [client 35.228.2.165:60080] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/src/.git/config [Sat Aug 29 05:06:39.633271 2026] [security2:error] [pid 1017536:tid 1017691] [client 93.123.109.228:49966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9PyJcY4fy7tP-rU0MuQAAAi0"] [Sat Aug 29 05:06:39.634914 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.147.79:30583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9IQAABec"] [Sat Aug 29 05:06:39.642062 2026] [security2:error] [pid 1017536:tid 1017698] [client 68.155.159.216:33769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/login.php"] [unique_id "apK9PyJcY4fy7tP-rU0MuwAAAjQ"] [Sat Aug 29 05:06:39.645642 2026] [security2:error] [pid 1017536:tid 1017761] [client 68.155.159.216:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9PyJcY4fy7tP-rU0MvAAAAnM"] [Sat Aug 29 05:06:39.653173 2026] [security2:error] [pid 1017536:tid 1017740] [client 158.23.147.79:25570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9PyJcY4fy7tP-rU0MvgAAAl4"] [Sat Aug 29 05:06:39.655140 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.151.200.44:45895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/EM.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9IgAABeA"] [Sat Aug 29 05:06:39.662733 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.220.204.93:52292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/666.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9JAAABbw"] [Sat Aug 29 05:06:39.665553 2026] [security2:error] [pid 1017536:tid 1017745] [client 216.26.243.152:41233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.243.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bfcorrigan.com"] [uri "/wp-login.php"] [unique_id "apK9PyJcY4fy7tP-rU0MugAAAmM"], referer: https://bfcorrigan.com/wp-login.php [Sat Aug 29 05:06:39.666048 2026] [security2:error] [pid 1018003:tid 1018159] [client 68.155.159.216:18255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/asd.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9JgAABcA"] [Sat Aug 29 05:06:39.680545 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.220.204.93:52241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/xr.php"] [unique_id "apK9PyJcY4fy7tP-rU0MwAAAAhU"] [Sat Aug 29 05:06:39.710371 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.147.79:48273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9KwAABhY"] [Sat Aug 29 05:06:39.755969 2026] [security2:error] [pid 1017536:tid 1017776] [client 40.83.93.50:1603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/admin.php"] [unique_id "apK9PyJcY4fy7tP-rU0MwgAAAoI"] [Sat Aug 29 05:06:39.758335 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.151.200.44:65050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/cafe.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9LAAABhA"] [Sat Aug 29 05:06:39.765120 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.63.81.20:44480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ssla.php"] [unique_id "apK9PyJcY4fy7tP-rU0MxAAAAmE"] [Sat Aug 29 05:06:39.770052 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.196.209.81:4477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/NewFile.php"] [unique_id "apK9PyJcY4fy7tP-rU0MxQAAAmk"] [Sat Aug 29 05:06:39.772199 2026] [security2:error] [pid 1017536:tid 1017694] [client 185.104.184.230:36222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "apK9PyJcY4fy7tP-rU0MxgAAAjA"] [Sat Aug 29 05:06:39.777663 2026] [security2:error] [pid 1018003:tid 1018196] [client 52.139.37.240:8631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/browse.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9LQAABeU"] [Sat Aug 29 05:06:39.787564 2026] [security2:error] [pid 1017536:tid 1017748] [client 20.48.250.41:25344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/click.php"] [unique_id "apK9PyJcY4fy7tP-rU0MxwAAAmY"] [Sat Aug 29 05:06:39.795530 2026] [security2:error] [pid 1017536:tid 1017704] [client 52.139.37.240:32840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/fw.php"] [unique_id "apK9PyJcY4fy7tP-rU0MyAAAAjo"] [Sat Aug 29 05:06:39.798152 2026] [security2:error] [pid 1017536:tid 1017678] [client 52.139.37.240:32087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/must.php"] [unique_id "apK9PyJcY4fy7tP-rU0MyQAAAiA"] [Sat Aug 29 05:06:39.814840 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.151.200.44:46651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/ca4.php"] [unique_id "apK9PyJcY4fy7tP-rU0MygAAAlY"] [Sat Aug 29 05:06:39.836024 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.220.204.93:52324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/knmt.php"] [unique_id "apK9PyJcY4fy7tP-rU0MywAAAos"] [Sat Aug 29 05:06:39.858423 2026] [security2:error] [pid 1018003:tid 1018213] [client 52.139.37.240:21126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/ahax.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9MwAABfY"] [Sat Aug 29 05:06:39.858676 2026] [security2:error] [pid 1017536:tid 1017689] [client 158.23.147.79:30577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/index.php"] [unique_id "apK9PyJcY4fy7tP-rU0MzAAAAis"] [Sat Aug 29 05:06:39.861388 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.158.54.35:20665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-trackback.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9NAAABhM"] [Sat Aug 29 05:06:39.864586 2026] [security2:error] [pid 1017536:tid 1017765] [client 158.23.147.79:32663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/radio.php"] [unique_id "apK9PyJcY4fy7tP-rU0MzgAAAnc"] [Sat Aug 29 05:06:39.865696 2026] [security2:error] [pid 1017536:tid 1017669] [client 93.123.109.228:50032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9PyJcY4fy7tP-rU0MzQAAAhc"] [Sat Aug 29 05:06:39.871232 2026] [security2:error] [pid 1017536:tid 1017705] [client 68.155.159.216:14242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/log-mama/function.php"] [unique_id "apK9PyJcY4fy7tP-rU0MzwAAAjs"] [Sat Aug 29 05:06:39.891794 2026] [security2:error] [pid 1018003:tid 1018099] [remote 34.75.89.130:51736] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "freejohnstuart.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9PzAh5Y1i2tUxg4H9NgAGL04"] [Sat Aug 29 05:06:39.891853 2026] [security2:error] [pid 1018003:tid 1018107] [remote 34.75.89.130:51736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "freejohnstuart.com"] [uri "/@fs/root/.env"] [unique_id "apK9PzAh5Y1i2tUxg4H9NQAGL1Y"] [Sat Aug 29 05:06:39.922645 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.63.81.20:46928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9OQAABf4"] [Sat Aug 29 05:06:39.928771 2026] [security2:error] [pid 1018003:tid 1018175] [client 68.155.159.216:51321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9OgAABdA"] [Sat Aug 29 05:06:39.931377 2026] [security2:error] [pid 1017536:tid 1017729] [client 52.139.37.240:30806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-content/plugins/ftde.php"] [unique_id "apK9PyJcY4fy7tP-rU0M0gAAAlM"] [Sat Aug 29 05:06:39.933731 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.48.250.41:25381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ms.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9OwAABb4"] [Sat Aug 29 05:06:39.942845 2026] [security2:error] [pid 1018003:tid 1018171] [client 4.205.62.107:53415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/txets.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9PAAABcw"] [Sat Aug 29 05:06:39.954917 2026] [security2:error] [pid 1018003:tid 1018169] [client 4.205.62.107:56036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/konfig.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9PQAABco"] [Sat Aug 29 05:06:39.963249 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.220.204.93:59093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/h02ugyh.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9PgAABdU"] [Sat Aug 29 05:06:39.964139 2026] [security2:error] [pid 1017536:tid 1017753] [client 168.107.94.195:51423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9PyJcY4fy7tP-rU0M0wAAAms"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:39.965998 2026] [security2:error] [pid 1018003:tid 1018167] [client 68.155.159.216:65110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9PwAABcg"] [Sat Aug 29 05:06:39.970800 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.220.204.93:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/sbhu.php"] [unique_id "apK9PyJcY4fy7tP-rU0M1AAAAl4"] [Sat Aug 29 05:06:39.976941 2026] [security2:error] [pid 1018003:tid 1018248] [client 52.139.37.240:8608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/contentloader1.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9QAAABhg"] [Sat Aug 29 05:06:39.982475 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.151.200.44:47336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/x0x.php"] [unique_id "apK9PzAh5Y1i2tUxg4H9QQAABjQ"] [Sat Aug 29 05:06:40.010400 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.52.41.200:1200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/alfa-rex.php7"] [unique_id "apK9QDAh5Y1i2tUxg4H9QwAABg8"] [Sat Aug 29 05:06:40.013207 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:24420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9QCJcY4fy7tP-rU0M1gAAApI"] [Sat Aug 29 05:06:40.016232 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.151.200.44:64379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/eval.php"] [unique_id "apK9QCJcY4fy7tP-rU0M1wAAAiU"] [Sat Aug 29 05:06:40.053971 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.63.81.20:46874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-aothait.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9RAAABho"] [Sat Aug 29 05:06:40.055300 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.197.61.180:7897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/contentloader1.php"] [unique_id "apK9QCJcY4fy7tP-rU0M2QAAAow"] [Sat Aug 29 05:06:40.082325 2026] [security2:error] [pid 1017536:tid 1017691] [client 20.196.209.81:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/global.php"] [unique_id "apK9QCJcY4fy7tP-rU0M2gAAAi0"] [Sat Aug 29 05:06:40.090681 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.48.250.41:25387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/zxekqlxb.php"] [unique_id "apK9QCJcY4fy7tP-rU0M3QAAAjo"] [Sat Aug 29 05:06:40.106310 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.220.204.93:59078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/xxw.php"] [unique_id "apK9QCJcY4fy7tP-rU0M3gAAAiA"] [Sat Aug 29 05:06:40.114098 2026] [security2:error] [pid 1018003:tid 1018200] [client 93.123.109.228:37156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9QDAh5Y1i2tUxg4H9RgAABek"] [Sat Aug 29 05:06:40.123665 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.220.204.93:59037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/a332.php"] [unique_id "apK9QCJcY4fy7tP-rU0M4gAAAlU"] [Sat Aug 29 05:06:40.125052 2026] [security2:error] [pid 1017536:tid 1017724] [client 93.123.109.228:37208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/test.php"] [unique_id "apK9QCJcY4fy7tP-rU0M5AAAAk4"] [Sat Aug 29 05:06:40.128143 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.49.130:43780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/wen.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9RwAABdc"] [Sat Aug 29 05:06:40.169172 2026] [security2:error] [pid 1017536:tid 1017788] [client 20.196.209.81:3933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/config.php"] [unique_id "apK9QCJcY4fy7tP-rU0M6AAAAo4"] [Sat Aug 29 05:06:40.191472 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.63.81.20:46971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-includes/index.php"] [unique_id "apK9QCJcY4fy7tP-rU0M6QAAAks"] [Sat Aug 29 05:06:40.199299 2026] [security2:error] [pid 1018003:tid 1018198] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9QDAh5Y1i2tUxg4H9SgAABec"] [Sat Aug 29 05:06:40.221767 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.151.200.44:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/sao.php"] [unique_id "apK9QCJcY4fy7tP-rU0M7QAAAjE"] [Sat Aug 29 05:06:40.224130 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.48.250.41:25459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/init.php"] [unique_id "apK9QCJcY4fy7tP-rU0M7gAAAmM"] [Sat Aug 29 05:06:40.231695 2026] [security2:error] [pid 1017536:tid 1017683] [client 68.155.159.216:12116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/images/index.php"] [unique_id "apK9QCJcY4fy7tP-rU0M7wAAAiU"] [Sat Aug 29 05:06:40.232253 2026] [security2:error] [pid 1017536:tid 1017694] [client 40.83.93.50:10820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK9QCJcY4fy7tP-rU0M8AAAAjA"] [Sat Aug 29 05:06:40.249322 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.151.200.44:47321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.thomaslmcdonell.com"] [uri "/fesa.php"] [unique_id "apK9QCJcY4fy7tP-rU0M8QAAAoc"] [Sat Aug 29 05:06:40.258958 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.220.204.93:52273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ws66.php"] [unique_id "apK9QCJcY4fy7tP-rU0M8gAAAmE"] [Sat Aug 29 05:06:40.266997 2026] [security2:error] [pid 1018003:tid 1018191] [client 93.123.109.228:49994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9QDAh5Y1i2tUxg4H9TAAABeA"] [Sat Aug 29 05:06:40.289815 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.147.79:61585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9QCJcY4fy7tP-rU0M9QAAAiA"] [Sat Aug 29 05:06:40.324898 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.63.81.20:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/file31.php"] [unique_id "apK9QCJcY4fy7tP-rU0M9wAAAj0"] [Sat Aug 29 05:06:40.327262 2026] [core:error] [pid 1018003:tid 1018219] [client 158.158.54.35:15199] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:40.327277 2026] [core:error] [pid 1018003:tid 1018219] [client 158.158.54.35:15199] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:40.343867 2026] [security2:error] [pid 1017536:tid 1017788] [client 168.107.94.195:51806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9QCJcY4fy7tP-rU0M_AAAAo4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:40.344923 2026] [proxy_http:error] [pid 1017536:tid 1017778] (20014)Internal error (specific information not available): [client 34.21.253.104:18054] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:40.344936 2026] [proxy:error] [pid 1017536:tid 1017778] [client 34.21.253.104:18054] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/google-service-account.json [Sat Aug 29 05:06:40.348330 2026] [security2:error] [pid 1018003:tid 1018207] [client 34.21.253.104:17968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.replenishink.com"] [uri "/creds.json"] [unique_id "apK9QDAh5Y1i2tUxg4H9TwAABfA"] [Sat Aug 29 05:06:40.350527 2026] [proxy_http:error] [pid 1017536:tid 1017669] (20014)Internal error (specific information not available): [client 34.21.253.104:17974] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:40.350539 2026] [proxy:error] [pid 1017536:tid 1017669] [client 34.21.253.104:17974] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/secret.json [Sat Aug 29 05:06:40.354832 2026] [proxy_http:error] [pid 1018003:tid 1018183] (20014)Internal error (specific information not available): [client 34.21.253.104:18088] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:40.354847 2026] [proxy:error] [pid 1018003:tid 1018183] [client 34.21.253.104:18088] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/firebase.json [Sat Aug 29 05:06:40.355522 2026] [security2:error] [pid 1017536:tid 1017717] [client 4.205.62.107:22387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/ebahvhhh.php"] [unique_id "apK9QCJcY4fy7tP-rU0NBAAAAkc"] [Sat Aug 29 05:06:40.355682 2026] [proxy_http:error] [pid 1017536:tid 1017778] (20014)Internal error (specific information not available): [client 34.21.253.104:18054] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:40.355698 2026] [proxy:error] [pid 1017536:tid 1017778] [client 34.21.253.104:18054] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:06:40.356073 2026] [security2:error] [pid 1017536:tid 1017696] [client 34.21.253.104:18096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.replenishink.com"] [uri "/api-keys.json"] [unique_id "apK9QCJcY4fy7tP-rU0NBgAAAjI"] [Sat Aug 29 05:06:40.356257 2026] [security2:error] [pid 1017536:tid 1017751] [client 185.104.184.230:36226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9QCJcY4fy7tP-rU0NBQAAAmk"] [Sat Aug 29 05:06:40.356540 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.220.204.93:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/bolt.php"] [unique_id "apK9QCJcY4fy7tP-rU0NBwAAAks"] [Sat Aug 29 05:06:40.361073 2026] [proxy_http:error] [pid 1017536:tid 1017770] (20014)Internal error (specific information not available): [client 34.21.253.104:18072] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:40.361088 2026] [proxy:error] [pid 1017536:tid 1017770] [client 34.21.253.104:18072] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/firebase-admin.json [Sat Aug 29 05:06:40.366898 2026] [proxy_http:error] [pid 1017536:tid 1017669] (20014)Internal error (specific information not available): [client 34.21.253.104:17974] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:40.366912 2026] [proxy:error] [pid 1017536:tid 1017669] [client 34.21.253.104:17974] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Sat Aug 29 05:06:40.371907 2026] [proxy_http:error] [pid 1017536:tid 1017713] (20014)Internal error (specific information not available): [client 34.21.253.104:18018] AH01102: error reading status line from remote server 127.0.0.1:2082 [Sat Aug 29 05:06:40.371920 2026] [proxy:error] [pid 1017536:tid 1017713] [client 34.21.253.104:18018] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/service-account-key.json [Sat Aug 29 05:06:40.373926 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.48.250.41:25437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/term.php"] [unique_id "apK9QCJcY4fy7tP-rU0NCAAAAl4"] [Sat Aug 29 05:06:40.378675 2026] [security2:error] [pid 1017536:tid 1017761] [client 45.148.10.62:38808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninaanddon.strangeworx.com"] [uri "/.env.php.bak"] [unique_id "apK9QCJcY4fy7tP-rU0NCQAAAnM"] [Sat Aug 29 05:06:40.383835 2026] [security2:error] [pid 1017536:tid 1017689] [client 158.23.147.79:63843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9QCJcY4fy7tP-rU0NCgAAAis"] [Sat Aug 29 05:06:40.390486 2026] [security2:error] [pid 1017536:tid 1017745] [client 20.151.200.44:65017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/uuu.php"] [unique_id "apK9QCJcY4fy7tP-rU0NCwAAAmM"] [Sat Aug 29 05:06:40.395504 2026] [security2:error] [pid 1017536:tid 1017709] [client 93.123.109.228:37218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9QCJcY4fy7tP-rU0NDAAAAj8"] [Sat Aug 29 05:06:40.396043 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.220.204.93:50787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ws68.php"] [unique_id "apK9QCJcY4fy7tP-rU0NDQAAAjA"] [Sat Aug 29 05:06:40.403268 2026] [security2:error] [pid 1017536:tid 1017781] [client 158.23.147.79:26569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9QCJcY4fy7tP-rU0NDwAAAoc"] [Sat Aug 29 05:06:40.418696 2026] [security2:error] [pid 1017536:tid 1017743] [client 93.123.109.228:50032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9QCJcY4fy7tP-rU0NEgAAAmE"] [Sat Aug 29 05:06:40.425515 2026] [security2:error] [pid 1018003:tid 1018245] [client 93.123.109.228:37160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9QDAh5Y1i2tUxg4H9UwAABhU"] [Sat Aug 29 05:06:40.460944 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.52.41.200:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK9QCJcY4fy7tP-rU0NEwAAAhw"] [Sat Aug 29 05:06:40.462776 2026] [security2:error] [pid 1017536:tid 1017790] [client 20.63.81.20:46870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/dk.php"] [unique_id "apK9QCJcY4fy7tP-rU0NFAAAApA"] [Sat Aug 29 05:06:40.487881 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.196.209.81:9415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/update.php"] [unique_id "apK9QCJcY4fy7tP-rU0NFQAAApM"] [Sat Aug 29 05:06:40.497272 2026] [security2:error] [pid 1017536:tid 1017780] [client 20.220.204.93:52333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/rtx.php"] [unique_id "apK9QCJcY4fy7tP-rU0NFgAAAoY"] [Sat Aug 29 05:06:40.499419 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.151.200.44:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/anz.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9VgAABbk"] [Sat Aug 29 05:06:40.505401 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.147.79:17445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9VwAABik"] [Sat Aug 29 05:06:40.515234 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.250.41:25389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/aaa.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9WQAABh8"] [Sat Aug 29 05:06:40.516385 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.23.147.79:35713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/cong.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9WgAABjU"] [Sat Aug 29 05:06:40.537494 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.220.204.93:50695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/users.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9XAAABd0"] [Sat Aug 29 05:06:40.539591 2026] [security2:error] [pid 1018003:tid 1018177] [client 147.182.236.246:35810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "nashtones.com"] [uri "/"] [unique_id "apK9QDAh5Y1i2tUxg4H9WwAABdI"] [Sat Aug 29 05:06:40.568864 2026] [security2:error] [pid 1018003:tid 1018189] [client 147.182.236.246:35810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=:"] [hostname "nashtones.com"] [uri "/"] [unique_id "apK9QDAh5Y1i2tUxg4H9XQAABd4"] [Sat Aug 29 05:06:40.578626 2026] [security2:error] [pid 1018003:tid 1018266] [client 74.248.24.12:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "djiboutifresh.eastacare.com"] [uri "/"] [unique_id "apK9QDAh5Y1i2tUxg4H9XgAABio"] [Sat Aug 29 05:06:40.580554 2026] [security2:error] [pid 1017536:tid 1017744] [client 68.155.159.216:52791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9QCJcY4fy7tP-rU0NHQAAAmI"] [Sat Aug 29 05:06:40.599015 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.63.81.20:46942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/ta.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9YQAABcI"] [Sat Aug 29 05:06:40.604056 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.196.209.81:11544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/22.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9YgAABcQ"] [Sat Aug 29 05:06:40.609102 2026] [security2:error] [pid 1018003:tid 1018174] [client 4.205.62.107:22339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/test.config.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9YwAABc8"] [Sat Aug 29 05:06:40.634461 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.220.204.93:52301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/ckk.php"] [unique_id "apK9QCJcY4fy7tP-rU0NIwAAAjE"] [Sat Aug 29 05:06:40.650488 2026] [security2:error] [pid 1017536:tid 1017694] [client 4.205.62.107:65466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/25.php"] [unique_id "apK9QCJcY4fy7tP-rU0NJAAAAjA"] [Sat Aug 29 05:06:40.652222 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.151.200.44:64963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/private.php"] [unique_id "apK9QCJcY4fy7tP-rU0NJQAAApI"] [Sat Aug 29 05:06:40.652811 2026] [security2:error] [pid 1017536:tid 1017781] [client 4.205.62.107:22443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/lmfi2.php"] [unique_id "apK9QCJcY4fy7tP-rU0NJgAAAoc"] [Sat Aug 29 05:06:40.664767 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:25555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/xsox.php"] [unique_id "apK9QCJcY4fy7tP-rU0NKAAAAmE"] [Sat Aug 29 05:06:40.674792 2026] [security2:error] [pid 1017536:tid 1017786] [client 20.220.204.93:52350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/bzjdlofz.php"] [unique_id "apK9QCJcY4fy7tP-rU0NKQAAAow"] [Sat Aug 29 05:06:40.706631 2026] [security2:error] [pid 1018003:tid 1018166] [client 40.83.93.50:23947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9ZQAABcc"] [Sat Aug 29 05:06:40.724498 2026] [security2:error] [pid 1018003:tid 1018175] [client 168.107.94.195:52101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9ZgAABdA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:40.732112 2026] [security2:error] [pid 1017536:tid 1017687] [client 20.63.81.20:46872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/bo.php"] [unique_id "apK9QCJcY4fy7tP-rU0NLgAAAik"] [Sat Aug 29 05:06:40.734202 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.147.79:30506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/mah.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9ZwAABgY"] [Sat Aug 29 05:06:40.752381 2026] [security2:error] [pid 1018003:tid 1018231] [client 93.123.109.228:49994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9QDAh5Y1i2tUxg4H9aAAABgc"] [Sat Aug 29 05:06:40.785507 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.158.54.35:4920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/222.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9aQAABhM"] [Sat Aug 29 05:06:40.788407 2026] [security2:error] [pid 1017536:tid 1017780] [client 93.123.109.228:37192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9QCJcY4fy7tP-rU0NLwAAAoY"] [Sat Aug 29 05:06:40.791140 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.220.204.93:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vivaboxhomes.com"] [uri "/R57.php"] [unique_id "apK9QCJcY4fy7tP-rU0NMAAAAoo"] [Sat Aug 29 05:06:40.815817 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.220.204.93:52309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/selesai.php"] [unique_id "apK9QCJcY4fy7tP-rU0NMQAAAlM"] [Sat Aug 29 05:06:40.828643 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:48181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-login.php"] [unique_id "apK9QCJcY4fy7tP-rU0NMwAAAkc"] [Sat Aug 29 05:06:40.830333 2026] [security2:error] [pid 1018003:tid 1018276] [client 20.48.250.41:25384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/lkui.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9awAABjQ"] [Sat Aug 29 05:06:40.832342 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.151.200.44:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/lfi.php"] [unique_id "apK9QCJcY4fy7tP-rU0NNAAAAjs"] [Sat Aug 29 05:06:40.860216 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.63.81.20:41962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/44.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9bAAABe8"] [Sat Aug 29 05:06:40.860332 2026] [security2:error] [pid 1017536:tid 1017778] [client 68.155.159.216:16342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9QCJcY4fy7tP-rU0NNQAAAoQ"] [Sat Aug 29 05:06:40.917777 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.52.41.200:1256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/upload.php"] [unique_id "apK9QCJcY4fy7tP-rU0NNgAAAoI"] [Sat Aug 29 05:06:40.932987 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.197.61.180:7877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/al.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9bgAABf4"] [Sat Aug 29 05:06:40.936734 2026] [security2:error] [pid 1017536:tid 1017740] [client 93.123.109.228:37100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9QCJcY4fy7tP-rU0NNwAAAl4"] [Sat Aug 29 05:06:40.956467 2026] [security2:error] [pid 1018003:tid 1018267] [client 74.7.175.136:59830] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rlmitchellrealestate.alabamaracingrealtor.com"] [uri "/index.php"] [unique_id "apK9QDAh5Y1i2tUxg4H9cAAGK38"] [Sat Aug 29 05:06:40.961399 2026] [security2:error] [pid 1018003:tid 1018259] [client 185.104.184.230:36240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9QDAh5Y1i2tUxg4H9cQAABiM"] [Sat Aug 29 05:06:40.964383 2026] [security2:error] [pid 1017536:tid 1017770] [client 158.23.147.79:30656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-blog-header.php"] [unique_id "apK9QCJcY4fy7tP-rU0NOwAAAnw"] [Sat Aug 29 05:06:40.971906 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.151.200.44:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/quoys.php"] [unique_id "apK9QCJcY4fy7tP-rU0NPAAAAkM"] [Sat Aug 29 05:06:40.973997 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.220.204.93:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/shlo.php"] [unique_id "apK9QCJcY4fy7tP-rU0NPQAAAmo"] [Sat Aug 29 05:06:40.979717 2026] [security2:error] [pid 1017536:tid 1017761] [client 68.155.159.216:14224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/bk/index.php"] [unique_id "apK9QCJcY4fy7tP-rU0NPgAAAnM"] [Sat Aug 29 05:06:40.992339 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:32658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9QCJcY4fy7tP-rU0NPwAAAjE"] [Sat Aug 29 05:06:41.011275 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.63.81.20:46864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/h2.php"] [unique_id "apK9QSJcY4fy7tP-rU0NRAAAApI"] [Sat Aug 29 05:06:41.026337 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.196.209.81:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/blog.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9cwAABco"] [Sat Aug 29 05:06:41.028433 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.196.209.81:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/bak.phps"] [unique_id "apK9QTAh5Y1i2tUxg4H9dAAABhQ"] [Sat Aug 29 05:06:41.063047 2026] [security2:error] [pid 1017536:tid 1017731] [client 68.155.159.216:65143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/chosen.php"] [unique_id "apK9QSJcY4fy7tP-rU0NRgAAAlU"] [Sat Aug 29 05:06:41.092798 2026] [security2:error] [pid 1017536:tid 1017707] [client 68.155.159.216:51579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9QSJcY4fy7tP-rU0NSAAAAj0"] [Sat Aug 29 05:06:41.103554 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.220.204.93:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/asax.php"] [unique_id "apK9QSJcY4fy7tP-rU0NSgAAAlY"] [Sat Aug 29 05:06:41.104364 2026] [security2:error] [pid 1017536:tid 1017793] [client 168.107.94.195:52416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9QSJcY4fy7tP-rU0NSwAAApM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:41.105401 2026] [security2:error] [pid 1017536:tid 1017780] [client 4.205.62.107:56020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/paths.php"] [unique_id "apK9QSJcY4fy7tP-rU0NTAAAAoY"] [Sat Aug 29 05:06:41.107627 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.48.250.41:25419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9eAAABdQ"] [Sat Aug 29 05:06:41.132909 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.147.79:24551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9eQAABec"] [Sat Aug 29 05:06:41.153804 2026] [security2:error] [pid 1017536:tid 1017744] [client 4.205.62.107:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/public/mah.php.php"] [unique_id "apK9QSJcY4fy7tP-rU0NUAAAAmI"] [Sat Aug 29 05:06:41.158641 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.63.81.20:44517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9egAABeE"] [Sat Aug 29 05:06:41.195332 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.151.200.44:65055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/vbbn.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9ewAABfw"] [Sat Aug 29 05:06:41.195624 2026] [security2:error] [pid 1017536:tid 1017683] [client 93.123.109.228:37100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9QSJcY4fy7tP-rU0NVAAAAiU"] [Sat Aug 29 05:06:41.206364 2026] [security2:error] [pid 1017536:tid 1017736] [client 40.83.93.50:1771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9QSJcY4fy7tP-rU0NVQAAAlo"] [Sat Aug 29 05:06:41.207291 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.151.200.44:64850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/bge.php"] [unique_id "apK9QSJcY4fy7tP-rU0NVgAAAjQ"] [Sat Aug 29 05:06:41.240524 2026] [security2:error] [pid 1017536:tid 1017790] [client 45.148.10.62:38812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninaanddon.strangeworx.com"] [uri "/.env.php"] [unique_id "apK9QSJcY4fy7tP-rU0NVwAAApA"] [Sat Aug 29 05:06:41.243235 2026] [security2:error] [pid 1017536:tid 1017757] [client 158.158.54.35:2878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/x.php"] [unique_id "apK9QSJcY4fy7tP-rU0NWAAAAm8"] [Sat Aug 29 05:06:41.245662 2026] [security2:error] [pid 1018003:tid 1018245] [client 68.155.159.216:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9fQAABhU"] [Sat Aug 29 05:06:41.248850 2026] [security2:error] [pid 1017536:tid 1017667] [client 20.220.204.93:52294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/fetch.php"] [unique_id "apK9QSJcY4fy7tP-rU0NWQAAAhU"] [Sat Aug 29 05:06:41.265928 2026] [security2:error] [pid 1018003:tid 1018227] [client 158.23.147.79:25594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9fwAABgQ"] [Sat Aug 29 05:06:41.282369 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.49.130:63433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/fs.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9gAAABew"] [Sat Aug 29 05:06:41.289923 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.250.41:25394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/motu.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9gQAABes"] [Sat Aug 29 05:06:41.293989 2026] [security2:error] [pid 1018003:tid 1018159] [client 93.123.109.228:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-config.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9ggAABcA"] [Sat Aug 29 05:06:41.331311 2026] [security2:error] [pid 1018003:tid 1018240] [client 93.123.109.228:37160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-config.php.bak"] [unique_id "apK9QTAh5Y1i2tUxg4H9hAAABhA"] [Sat Aug 29 05:06:41.338960 2026] [security2:error] [pid 1018003:tid 1018234] [client 68.155.159.216:12255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/index.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9hgAABgo"] [Sat Aug 29 05:06:41.358744 2026] [security2:error] [pid 1018003:tid 1018266] [client 93.123.109.228:49832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-config.php.old"] [unique_id "apK9QTAh5Y1i2tUxg4H9iAAABio"] [Sat Aug 29 05:06:41.358868 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.49.130:60761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/xwpg.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9hwAABf8"] [Sat Aug 29 05:06:41.361789 2026] [security2:error] [pid 1017536:tid 1017678] [client 93.123.109.228:37188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.ewenclan.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9QSJcY4fy7tP-rU0NZQAAAiA"] [Sat Aug 29 05:06:41.372274 2026] [cgid:error] [pid 1018003:tid 1018275] [client 20.52.41.200:1158] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:41.373266 2026] [security2:error] [pid 1017536:tid 1017710] [client 93.123.109.228:49916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-config.php.new"] [unique_id "apK9QSJcY4fy7tP-rU0NZwAAAkA"] [Sat Aug 29 05:06:41.375628 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.63.81.20:44462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/sao.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9iwAABhw"] [Sat Aug 29 05:06:41.405302 2026] [security2:error] [pid 1017536:tid 1017753] [client 68.155.159.216:30713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9QSJcY4fy7tP-rU0NaQAAAms"] [Sat Aug 29 05:06:41.412799 2026] [security2:error] [pid 1018003:tid 1018188] [client 45.61.187.50:63158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "succulentideas.com"] [uri "/wp-json/batch/v1"] [unique_id "apK9QTAh5Y1i2tUxg4H9jQAABd0"] [Sat Aug 29 05:06:41.414440 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.220.204.93:52253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/vx.php"] [unique_id "apK9QSJcY4fy7tP-rU0NagAAAkI"] [Sat Aug 29 05:06:41.426630 2026] [security2:error] [pid 1017536:tid 1017713] [client 158.23.147.79:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9QSJcY4fy7tP-rU0NbAAAAkM"] [Sat Aug 29 05:06:41.427613 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.196.209.81:19437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/install.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9jgAABik"] [Sat Aug 29 05:06:41.446527 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.196.209.81:17891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/bypass.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9kAAABh8"] [Sat Aug 29 05:06:41.450602 2026] [security2:error] [pid 1017536:tid 1017732] [client 136.107.231.130:29314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanmossman.mossmanphoto.com"] [uri "/wp-config.php.bak"] [unique_id "apK9QSJcY4fy7tP-rU0NbwAAAlY"] [Sat Aug 29 05:06:41.454309 2026] [security2:error] [pid 1017536:tid 1017793] [client 136.107.231.130:29278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/key.pem"] [unique_id "apK9QSJcY4fy7tP-rU0NcAAAApM"] [Sat Aug 29 05:06:41.456263 2026] [security2:error] [pid 1018003:tid 1018224] [client 136.107.231.130:29268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/id_dsa"] [unique_id "apK9QTAh5Y1i2tUxg4H9kwAABgE"] [Sat Aug 29 05:06:41.457190 2026] [security2:error] [pid 1017536:tid 1017784] [client 136.107.231.130:29286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9QSJcY4fy7tP-rU0NcwAAAoo"] [Sat Aug 29 05:06:41.457205 2026] [security2:error] [pid 1018003:tid 1018218] [client 136.107.231.130:29256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/id_rsa"] [unique_id "apK9QTAh5Y1i2tUxg4H9lAAABfs"] [Sat Aug 29 05:06:41.458599 2026] [security2:error] [pid 1017536:tid 1017721] [client 136.107.231.130:29318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alanmossman.mossmanphoto.com"] [uri "/wp-config.php.old"] [unique_id "apK9QSJcY4fy7tP-rU0NdgAAAks"] [Sat Aug 29 05:06:41.458852 2026] [security2:error] [pid 1018003:tid 1018213] [client 136.107.231.130:29296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/privatekey.key"] [unique_id "apK9QTAh5Y1i2tUxg4H9lgAABfY"] [Sat Aug 29 05:06:41.466710 2026] [security2:error] [pid 1017536:tid 1017757] [client 68.155.159.216:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9QSJcY4fy7tP-rU0NeAAAAm8"] [Sat Aug 29 05:06:41.467409 2026] [security2:error] [pid 1017536:tid 1017767] [client 136.107.231.130:29312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.231.107.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanmossman.mossmanphoto.com"] [uri "/wp-config.php"] [unique_id "apK9QSJcY4fy7tP-rU0NcQAAAnk"] [Sat Aug 29 05:06:41.468779 2026] [security2:error] [pid 1017536:tid 1017669] [client 136.107.231.130:29332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.231.107.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanmossman.mossmanphoto.com"] [uri "/config.php.bak"] [unique_id "apK9QSJcY4fy7tP-rU0NdQAAAhc"] [Sat Aug 29 05:06:41.469210 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.48.250.41:25457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/Ov-Simple1.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9mAAABdU"] [Sat Aug 29 05:06:41.484830 2026] [security2:error] [pid 1017536:tid 1017709] [client 168.107.94.195:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9QSJcY4fy7tP-rU0NegAAAj8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:41.491619 2026] [security2:error] [pid 1018003:tid 1018271] [client 136.107.231.130:29324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.231.107.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanmossman.mossmanphoto.com"] [uri "/config.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9lQAABi8"] [Sat Aug 29 05:06:41.496889 2026] [security2:error] [pid 1018003:tid 1018167] [client 4.205.62.107:22395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/asa.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9mQAABcg"] [Sat Aug 29 05:06:41.497717 2026] [security2:error] [pid 1018003:tid 1018276] [client 158.23.147.79:62651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9mgAABjQ"] [Sat Aug 29 05:06:41.504334 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.63.81.20:44430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/dapa.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9mwAABg8"] [Sat Aug 29 05:06:41.524534 2026] [cgid:error] [pid 1018003:tid 1018216] [client 20.52.41.200:1158] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:41.543714 2026] [security2:error] [pid 1018003:tid 1018186] [client 158.23.147.79:26480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/makeasmtp.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9nQAABds"] [Sat Aug 29 05:06:41.557331 2026] [security2:error] [pid 1017536:tid 1017792] [client 185.104.184.230:36246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9QSJcY4fy7tP-rU0NfQAAApI"] [Sat Aug 29 05:06:41.568061 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.151.200.44:65028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/rfi.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9ngAABek"] [Sat Aug 29 05:06:41.579885 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.151.200.44:65491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/wp-ana.php"] [unique_id "apK9QSJcY4fy7tP-rU0NfgAAAjI"] [Sat Aug 29 05:06:41.585568 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.104.49.130:48540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/ohct.php"] [unique_id "apK9QSJcY4fy7tP-rU0NgQAAAkI"] [Sat Aug 29 05:06:41.587042 2026] [security2:error] [pid 1017536:tid 1017564] [remote 34.75.89.130:51744] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "freejohnstuart.com"] [uri "/_image"] [unique_id "apK9QSJcY4fy7tP-rU0NggACaxs"] [Sat Aug 29 05:06:41.626749 2026] [security2:error] [pid 1017536:tid 1017752] [client 20.220.204.93:52298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/global.php"] [unique_id "apK9QSJcY4fy7tP-rU0NgwAAAmo"] [Sat Aug 29 05:06:41.639137 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.147.79:17472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/simple.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9nwAABb0"] [Sat Aug 29 05:06:41.647858 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:51460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-mail.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9oAAABd8"] [Sat Aug 29 05:06:41.666201 2026] [security2:error] [pid 1017536:tid 1017737] [client 20.48.250.41:25439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/wp-blogs.php"] [unique_id "apK9QSJcY4fy7tP-rU0NhAAAAls"] [Sat Aug 29 05:06:41.673716 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.52.41.200:1158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/file.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9oQAABcM"] [Sat Aug 29 05:06:41.675373 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.197.61.180:7874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/global.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9ogAABdA"] [Sat Aug 29 05:06:41.676227 2026] [security2:error] [pid 1018003:tid 1018238] [client 40.83.93.50:1619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/config.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9owAABg4"] [Sat Aug 29 05:06:41.682753 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.63.81.20:44518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-content/l.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9pAAABiI"] [Sat Aug 29 05:06:41.695724 2026] [security2:error] [pid 1017536:tid 1017793] [client 158.23.147.79:35801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9QSJcY4fy7tP-rU0NhQAAApM"] [Sat Aug 29 05:06:41.715204 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.158.54.35:2835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/new.php"] [unique_id "apK9QSJcY4fy7tP-rU0NhgAAAkc"] [Sat Aug 29 05:06:41.732229 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.151.200.44:64421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/tajj.php"] [unique_id "apK9QSJcY4fy7tP-rU0NhwAAAkE"] [Sat Aug 29 05:06:41.758160 2026] [security2:error] [pid 1018003:tid 1018219] [client 45.61.187.50:63220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "succulentideas.com"] [uri "/wp-json/batch/v1"] [unique_id "apK9QTAh5Y1i2tUxg4H9pwAABfw"] [Sat Aug 29 05:06:41.762519 2026] [security2:error] [pid 1017536:tid 1017767] [client 4.205.62.107:22347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/apikeys.php"] [unique_id "apK9QSJcY4fy7tP-rU0NiAAAAnk"] [Sat Aug 29 05:06:41.772264 2026] [security2:error] [pid 1017536:tid 1017674] [client 68.155.159.216:33753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/hehehehe.php"] [unique_id "apK9QSJcY4fy7tP-rU0NiQAAAhw"] [Sat Aug 29 05:06:41.786766 2026] [security2:error] [pid 1017536:tid 1017748] [client 4.205.62.107:65484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/nlnub.php"] [unique_id "apK9QSJcY4fy7tP-rU0NigAAAmY"] [Sat Aug 29 05:06:41.790772 2026] [security2:error] [pid 1017536:tid 1017743] [client 4.205.62.107:22475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/aws_sdk_settings.php"] [unique_id "apK9QSJcY4fy7tP-rU0NiwAAAmE"] [Sat Aug 29 05:06:41.802095 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.48.250.41:25507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/mini.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9qAAABcA"] [Sat Aug 29 05:06:41.804582 2026] [ssl:error] [pid 1017536:tid 1017675] [client 13.219.121.241:50756] AH02032: Hostname host2038.hostmonster.com (default host as no SNI was provided) and hostname whm.haverhillmasonry.org provided via HTTP have no compatible SSL setup for policy 'secure' [Sat Aug 29 05:06:41.812280 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.63.81.20:44499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-admin/w.php"] [unique_id "apK9QSJcY4fy7tP-rU0NjQAAAos"] [Sat Aug 29 05:06:41.825928 2026] [core:error] [pid 1017536:tid 1017761] [client 45.148.10.62:38818] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:41.826922 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.196.209.81:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/colour.php"] [unique_id "apK9QSJcY4fy7tP-rU0NjwAAAoo"] [Sat Aug 29 05:06:41.844104 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.196.209.81:17881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/extractable-loader-head.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9qQAABew"] [Sat Aug 29 05:06:41.851637 2026] [security2:error] [pid 1018003:tid 1018184] [client 45.61.187.50:63220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "succulentideas.com"] [uri "/wp-json/batch/v1"] [unique_id "apK9QTAh5Y1i2tUxg4H9qgAABdk"] [Sat Aug 29 05:06:41.859398 2026] [security2:error] [pid 1018003:tid 1018164] [client 158.23.147.79:30706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9qwAABcU"] [Sat Aug 29 05:06:41.863664 2026] [security2:error] [pid 1018003:tid 1018177] [client 168.107.94.195:53063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9rAAABdI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:41.866920 2026] [security2:error] [pid 1017536:tid 1017707] [client 20.151.200.44:65011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/grsiuk.php"] [unique_id "apK9QSJcY4fy7tP-rU0NkQAAAj0"] [Sat Aug 29 05:06:41.920213 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.220.204.93:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/fs.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9rQAABcQ"] [Sat Aug 29 05:06:41.930701 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.151.200.44:64286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/secret.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9rgAABik"] [Sat Aug 29 05:06:41.932193 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.147.79:48163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9QTAh5Y1i2tUxg4H9sAAABd0"] [Sat Aug 29 05:06:41.941071 2026] [security2:error] [pid 1017536:tid 1017740] [client 20.63.81.20:44538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-content/k.php"] [unique_id "apK9QSJcY4fy7tP-rU0NkwAAAl4"] [Sat Aug 29 05:06:41.956784 2026] [security2:error] [pid 1017536:tid 1017713] [client 68.155.159.216:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9QSJcY4fy7tP-rU0NlQAAAkM"] [Sat Aug 29 05:06:41.975377 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.48.250.41:25421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/amp.php"] [unique_id "apK9QSJcY4fy7tP-rU0NlgAAAjQ"] [Sat Aug 29 05:06:42.001217 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.49.130:60746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9sQAABfs"] [Sat Aug 29 05:06:42.069441 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.151.200.44:64965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/ahy66.php"] [unique_id "apK9QiJcY4fy7tP-rU0NmgAAAiU"] [Sat Aug 29 05:06:42.072683 2026] [security2:error] [pid 1017536:tid 1017674] [client 20.63.81.20:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/os.php"] [unique_id "apK9QiJcY4fy7tP-rU0NmwAAAhw"] [Sat Aug 29 05:06:42.077286 2026] [security2:error] [pid 1017536:tid 1017669] [client 158.23.147.79:30659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9QiJcY4fy7tP-rU0NnAAAAhc"] [Sat Aug 29 05:06:42.091176 2026] [security2:error] [pid 1018003:tid 1018167] [client 68.155.159.216:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.questconsultantsme.co"] [uri "/first.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9swAABcg"] [Sat Aug 29 05:06:42.106955 2026] [security2:error] [pid 1017536:tid 1017743] [client 20.48.250.41:25303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/cc13.php"] [unique_id "apK9QiJcY4fy7tP-rU0NngAAAmE"] [Sat Aug 29 05:06:42.117676 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.220.204.93:59065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ioxi.php"] [unique_id "apK9QiJcY4fy7tP-rU0NoAAAAh0"] [Sat Aug 29 05:06:42.129580 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.52.41.200:1745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/files.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9tQAABc8"] [Sat Aug 29 05:06:42.141063 2026] [security2:error] [pid 1017536:tid 1017786] [client 185.104.184.230:36250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK9QiJcY4fy7tP-rU0NpAAAAow"] [Sat Aug 29 05:06:42.155768 2026] [security2:error] [pid 1017536:tid 1017793] [client 40.83.93.50:1756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/cong.php"] [unique_id "apK9QiJcY4fy7tP-rU0NpwAAApM"] [Sat Aug 29 05:06:42.158619 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.158.54.35:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/menu.php"] [unique_id "apK9QiJcY4fy7tP-rU0NqAAAAkE"] [Sat Aug 29 05:06:42.168820 2026] [security2:error] [pid 1017536:tid 1017723] [client 68.155.159.216:64458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/goods.php"] [unique_id "apK9QiJcY4fy7tP-rU0NqQAAAk0"] [Sat Aug 29 05:06:42.174118 2026] [security2:error] [pid 1017536:tid 1017792] [client 68.155.159.216:56558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9QiJcY4fy7tP-rU0NqgAAApI"] [Sat Aug 29 05:06:42.210247 2026] [security2:error] [pid 1017536:tid 1017713] [client 20.151.200.44:65008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/gaje.php"] [unique_id "apK9QiJcY4fy7tP-rU0NrQAAAkM"] [Sat Aug 29 05:06:42.212095 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.63.81.20:44512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/htio.php"] [unique_id "apK9QiJcY4fy7tP-rU0NrgAAAjQ"] [Sat Aug 29 05:06:42.219657 2026] [security2:error] [pid 1017536:tid 1017729] [client 68.155.159.216:51809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9QiJcY4fy7tP-rU0NsAAAAlM"] [Sat Aug 29 05:06:42.220688 2026] [security2:error] [pid 1017536:tid 1017721] [client 103.240.76.112:49710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9QiJcY4fy7tP-rU0NsQAAAks"] [Sat Aug 29 05:06:42.220789 2026] [security2:error] [pid 1017536:tid 1017721] [client 103.240.76.112:49710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9QiJcY4fy7tP-rU0NsQAAAks"] [Sat Aug 29 05:06:42.222999 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.196.209.81:3883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/OK.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9uAAABi8"] [Sat Aug 29 05:06:42.241220 2026] [security2:error] [pid 1017536:tid 1017781] [client 45.61.187.50:63344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "succulentideas.com"] [uri "/wp-json/batch/v1"] [unique_id "apK9QiJcY4fy7tP-rU0NsgAAAoc"] [Sat Aug 29 05:06:42.244152 2026] [security2:error] [pid 1018003:tid 1018270] [client 4.205.62.107:56052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/olfclass.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9uQAABi4"] [Sat Aug 29 05:06:42.245437 2026] [security2:error] [pid 1018003:tid 1018216] [client 168.107.94.195:53562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9ugAABfk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:42.251914 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.48.250.41:25377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/aa.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9uwAABgI"] [Sat Aug 29 05:06:42.260783 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.220.204.93:50767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/bootstrap.php"] [unique_id "apK9QiJcY4fy7tP-rU0NswAAAnc"] [Sat Aug 29 05:06:42.265110 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.147.79:24430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/packed.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9vQAABis"] [Sat Aug 29 05:06:42.304219 2026] [security2:error] [pid 1017536:tid 1017705] [client 4.205.62.107:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apK9QiJcY4fy7tP-rU0NtAAAAjs"] [Sat Aug 29 05:06:42.310433 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.196.209.81:17910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/defaults.php"] [unique_id "apK9QiJcY4fy7tP-rU0NtQAAAjo"] [Sat Aug 29 05:06:42.345293 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.63.81.20:46890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/dev.php"] [unique_id "apK9QiJcY4fy7tP-rU0NuAAAAk4"] [Sat Aug 29 05:06:42.362242 2026] [security2:error] [pid 1017536:tid 1017785] [client 60.243.207.176:60677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9QiJcY4fy7tP-rU0NuQAAAos"] [Sat Aug 29 05:06:42.362803 2026] [security2:error] [pid 1017536:tid 1017785] [client 60.243.207.176:60677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9QiJcY4fy7tP-rU0NuQAAAos"] [Sat Aug 29 05:06:42.371810 2026] [security2:error] [pid 1017536:tid 1017711] [client 158.23.147.79:25490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin.php"] [unique_id "apK9QiJcY4fy7tP-rU0NugAAAkE"] [Sat Aug 29 05:06:42.375401 2026] [security2:error] [pid 1017536:tid 1017723] [client 45.61.187.50:63344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "succulentideas.com"] [uri "/"] [unique_id "apK9QiJcY4fy7tP-rU0NuwAAAk0"] [Sat Aug 29 05:06:42.383330 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.250.41:25420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/s1.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9vgAABcE"] [Sat Aug 29 05:06:42.390686 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.151.200.44:64317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/pro.php"] [unique_id "apK9QiJcY4fy7tP-rU0NvAAAAkI"] [Sat Aug 29 05:06:42.393168 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.197.61.180:7202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/update.php"] [unique_id "apK9QiJcY4fy7tP-rU0NvgAAAhs"] [Sat Aug 29 05:06:42.399731 2026] [security2:error] [pid 1017536:tid 1017717] [client 20.220.204.93:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/export.php"] [unique_id "apK9QiJcY4fy7tP-rU0NvwAAAkc"] [Sat Aug 29 05:06:42.414019 2026] [security2:error] [pid 1018003:tid 1018212] [client 68.155.159.216:6143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9wAAABfU"] [Sat Aug 29 05:06:42.447851 2026] [security2:error] [pid 1018003:tid 1018198] [client 68.155.159.216:12204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/mah.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9wgAABec"] [Sat Aug 29 05:06:42.471835 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.151.200.44:65051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/wp-admin/zwso.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9wwAABiU"] [Sat Aug 29 05:06:42.472711 2026] [security2:error] [pid 1017536:tid 1017784] [client 45.61.187.50:63344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "succulentideas.com"] [uri "/wp-json/batch/v1"] [unique_id "apK9QiJcY4fy7tP-rU0NwgAAAoo"] [Sat Aug 29 05:06:42.480025 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.63.81.20:46873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/gos.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9xAAABcM"] [Sat Aug 29 05:06:42.509800 2026] [security2:error] [pid 1018003:tid 1018175] [client 68.155.159.216:30687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9xQAABdA"] [Sat Aug 29 05:06:42.515649 2026] [core:error] [pid 1017536:tid 1017786] [client 45.148.10.62:38824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:42.515666 2026] [core:error] [pid 1017536:tid 1017786] [client 45.148.10.62:38824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:42.516816 2026] [cgid:error] [pid 1017536:tid 1017792] [client 34.7.40.70:4840] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.522103 2026] [cgid:error] [pid 1017536:tid 1017751] [client 34.7.40.70:4946] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.523657 2026] [cgid:error] [pid 1017536:tid 1017696] [client 34.7.40.70:4928] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.524652 2026] [cgid:error] [pid 1017536:tid 1017753] [client 34.7.40.70:4874] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.524954 2026] [security2:error] [pid 1017536:tid 1017745] [client 34.7.40.70:4830] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/creds.json"] [unique_id "apK9QiJcY4fy7tP-rU0NzAAAAmM"] [Sat Aug 29 05:06:42.525136 2026] [cgid:error] [pid 1017536:tid 1017776] [client 34.7.40.70:4848] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.525452 2026] [cgid:error] [pid 1017536:tid 1017748] [client 34.7.40.70:4956] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.525926 2026] [cgid:error] [pid 1017536:tid 1017780] [client 34.7.40.70:4898] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.526041 2026] [cgid:error] [pid 1018003:tid 1018195] [client 34.7.40.70:4870] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.527471 2026] [cgid:error] [pid 1017536:tid 1017695] [client 34.7.40.70:4922] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.527578 2026] [cgid:error] [pid 1017536:tid 1017698] [client 34.7.40.70:4864] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.527834 2026] [cgid:error] [pid 1017536:tid 1017732] [client 34.7.40.70:4892] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.528435 2026] [cgid:error] [pid 1018003:tid 1018250] [client 34.7.40.70:4934] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.528488 2026] [cgid:error] [pid 1017536:tid 1017713] [client 34.7.40.70:4884] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.531081 2026] [cgid:error] [pid 1017536:tid 1017752] [client 34.7.40.70:4902] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.531605 2026] [cgid:error] [pid 1017536:tid 1017790] [client 34.7.40.70:4910] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:42.534779 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.23.147.79:53784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9yAAABg4"] [Sat Aug 29 05:06:42.547146 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.220.204.93:50759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/gk.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9yQAABfA"] [Sat Aug 29 05:06:42.567826 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.48.250.41:25284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/0byte.php"] [unique_id "apK9QiJcY4fy7tP-rU0N0wAAAos"] [Sat Aug 29 05:06:42.569081 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.49.130:34533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/css.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9ygAABdw"] [Sat Aug 29 05:06:42.572541 2026] [security2:error] [pid 1017536:tid 1017710] [client 213.202.253.4:50110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/txets.php"] [unique_id "apK9QiJcY4fy7tP-rU0N1QAAAkA"], referer: www.google.com [Sat Aug 29 05:06:42.580549 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.52.41.200:1774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/o.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9ywAABdc"] [Sat Aug 29 05:06:42.583171 2026] [security2:error] [pid 1017536:tid 1017770] [client 45.61.187.50:63344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "succulentideas.com"] [uri "/"] [unique_id "apK9QiJcY4fy7tP-rU0N1gAAAnw"] [Sat Aug 29 05:06:42.617256 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.63.81.20:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/132.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9zAAABfw"] [Sat Aug 29 05:06:42.626933 2026] [security2:error] [pid 1017536:tid 1017733] [client 168.107.94.195:53984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9QiJcY4fy7tP-rU0N2wAAAlc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:42.628565 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.158.54.35:4865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9zQAABb0"] [Sat Aug 29 05:06:42.629030 2026] [security2:error] [pid 1017536:tid 1017683] [client 4.205.62.107:22275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/radio.php"] [unique_id "apK9QiJcY4fy7tP-rU0N3QAAAiU"] [Sat Aug 29 05:06:42.629050 2026] [security2:error] [pid 1018003:tid 1018191] [client 40.83.93.50:10842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/content.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9zgAABeA"] [Sat Aug 29 05:06:42.677407 2026] [security2:error] [pid 1017536:tid 1017743] [client 158.23.147.79:26605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9QiJcY4fy7tP-rU0N4AAAAmE"] [Sat Aug 29 05:06:42.683273 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.196.209.81:19414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.merlynscatering.net"] [uri "/aaa.php"] [unique_id "apK9QiJcY4fy7tP-rU0N4QAAAlU"] [Sat Aug 29 05:06:42.683923 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.220.204.93:52313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/logs1.php"] [unique_id "apK9QiJcY4fy7tP-rU0N4gAAAh0"] [Sat Aug 29 05:06:42.689147 2026] [security2:error] [pid 1017536:tid 1017744] [client 20.151.200.44:64997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/Contrller.php"] [unique_id "apK9QiJcY4fy7tP-rU0N5AAAAmI"] [Sat Aug 29 05:06:42.690221 2026] [security2:error] [pid 1017536:tid 1017761] [client 45.61.187.50:63344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "succulentideas.com"] [uri "/wp-json/batch/v1"] [unique_id "apK9QiJcY4fy7tP-rU0N4wAAAnM"] [Sat Aug 29 05:06:42.702986 2026] [security2:error] [pid 1017536:tid 1017792] [client 158.23.147.79:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/nf_tracking.php"] [unique_id "apK9QiJcY4fy7tP-rU0N5QAAApI"] [Sat Aug 29 05:06:42.713043 2026] [security2:error] [pid 1017536:tid 1017751] [client 20.48.250.41:25416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/xr.php"] [unique_id "apK9QiJcY4fy7tP-rU0N5gAAAmk"] [Sat Aug 29 05:06:42.720086 2026] [security2:error] [pid 1018003:tid 1018177] [client 68.155.159.216:52743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/cong.php"] [unique_id "apK9QjAh5Y1i2tUxg4H9zwAABdI"] [Sat Aug 29 05:06:42.748778 2026] [security2:error] [pid 1017536:tid 1017704] [client 20.63.81.20:41885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/v22.php"] [unique_id "apK9QiJcY4fy7tP-rU0N5wAAAjo"] [Sat Aug 29 05:06:42.749384 2026] [security2:error] [pid 1017536:tid 1017736] [client 20.196.209.81:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/post.php"] [unique_id "apK9QiJcY4fy7tP-rU0N6AAAAlo"] [Sat Aug 29 05:06:42.749408 2026] [security2:error] [pid 1018003:tid 1018196] [client 158.23.147.79:17475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-admin/about.php"] [unique_id "apK9QjAh5Y1i2tUxg4H90AAABeU"] [Sat Aug 29 05:06:42.754808 2026] [security2:error] [pid 1017536:tid 1017667] [client 185.104.184.230:36252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9QiJcY4fy7tP-rU0N6QAAAhU"] [Sat Aug 29 05:06:42.785286 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.104.49.130:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/kerang.php"] [unique_id "apK9QiJcY4fy7tP-rU0N6wAAAjE"] [Sat Aug 29 05:06:42.785855 2026] [security2:error] [pid 1017536:tid 1017698] [client 20.151.200.44:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/999.php"] [unique_id "apK9QiJcY4fy7tP-rU0N7AAAAjQ"] [Sat Aug 29 05:06:42.799294 2026] [security2:error] [pid 1017536:tid 1017713] [client 45.61.187.50:63344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "succulentideas.com"] [uri "/"] [unique_id "apK9QiJcY4fy7tP-rU0N7gAAAkM"] [Sat Aug 29 05:06:42.806850 2026] [security2:error] [pid 1017536:tid 1017752] [client 68.155.159.216:18242] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.cisagency.com"] [uri "/1.php"] [unique_id "apK9QiJcY4fy7tP-rU0N7wAAAmo"] [Sat Aug 29 05:06:42.806967 2026] [security2:error] [pid 1017536:tid 1017752] [client 68.155.159.216:18242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/1.php"] [unique_id "apK9QiJcY4fy7tP-rU0N7wAAAmo"] [Sat Aug 29 05:06:42.836651 2026] [security2:error] [pid 1017536:tid 1017669] [client 158.23.147.79:35730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9QiJcY4fy7tP-rU0N8QAAAhc"] [Sat Aug 29 05:06:42.856170 2026] [security2:error] [pid 1017536:tid 1017770] [client 20.48.250.41:25353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/h02ugyh.php"] [unique_id "apK9QiJcY4fy7tP-rU0N8gAAAnw"] [Sat Aug 29 05:06:42.884800 2026] [security2:error] [pid 1017536:tid 1017711] [client 20.63.81.20:41940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-activate.php"] [unique_id "apK9QiJcY4fy7tP-rU0N8wAAAkE"] [Sat Aug 29 05:06:42.885892 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:33616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9QiJcY4fy7tP-rU0N9AAAAks"] [Sat Aug 29 05:06:42.899350 2026] [security2:error] [pid 1018003:tid 1018163] [client 4.205.62.107:22300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/god.php"] [unique_id "apK9QjAh5Y1i2tUxg4H90wAABcQ"] [Sat Aug 29 05:06:42.910837 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.220.204.93:59115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/inege.php"] [unique_id "apK9QjAh5Y1i2tUxg4H91QAABd0"] [Sat Aug 29 05:06:42.927300 2026] [security2:error] [pid 1018003:tid 1018255] [client 4.205.62.107:22457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/mga.php"] [unique_id "apK9QjAh5Y1i2tUxg4H91gAABh8"] [Sat Aug 29 05:06:42.929646 2026] [security2:error] [pid 1017536:tid 1017761] [client 4.205.62.107:26630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/mga.php"] [unique_id "apK9QiJcY4fy7tP-rU0N-gAAAnM"] [Sat Aug 29 05:06:42.929708 2026] [security2:error] [pid 1017536:tid 1017731] [client 57.141.14.89:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/"] [unique_id "apK9QiJcY4fy7tP-rU0N-QAAAlU"] [Sat Aug 29 05:06:42.950008 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.151.200.44:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/Zeiss.php"] [unique_id "apK9QiJcY4fy7tP-rU0N_AAAAlM"] [Sat Aug 29 05:06:42.969963 2026] [security2:error] [pid 1017536:tid 1017745] [client 158.23.147.79:30490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9QiJcY4fy7tP-rU0N_wAAAmM"] [Sat Aug 29 05:06:43.006763 2026] [security2:error] [pid 1017536:tid 1017698] [client 168.107.94.195:54244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9QyJcY4fy7tP-rU0OBQAAAjQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:43.012208 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.48.250.41:25462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/xxw.php"] [unique_id "apK9QyJcY4fy7tP-rU0OBwAAAk4"] [Sat Aug 29 05:06:43.014041 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.63.81.20:46948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-trackback.php"] [unique_id "apK9QyJcY4fy7tP-rU0OCAAAAos"] [Sat Aug 29 05:06:43.036288 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.147.79:48336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/images/about.php"] [unique_id "apK9QzAh5Y1i2tUxg4H92QAABcg"] [Sat Aug 29 05:06:43.036423 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.52.41.200:1159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/file2.php"] [unique_id "apK9QyJcY4fy7tP-rU0OCgAAAoc"] [Sat Aug 29 05:06:43.050147 2026] [security2:error] [pid 1017536:tid 1017712] [client 20.220.204.93:59095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wp-link10.php"] [unique_id "apK9QyJcY4fy7tP-rU0ODAAAAkI"] [Sat Aug 29 05:06:43.065941 2026] [security2:error] [pid 1017536:tid 1017721] [client 68.155.159.216:16350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-login.php"] [unique_id "apK9QyJcY4fy7tP-rU0ODQAAAks"] [Sat Aug 29 05:06:43.068239 2026] [core:error] [pid 1018003:tid 1018230] [client 158.158.54.35:15206] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:43.068258 2026] [core:error] [pid 1018003:tid 1018230] [client 158.158.54.35:15206] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:43.101941 2026] [security2:error] [pid 1017536:tid 1017678] [client 40.83.93.50:1770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/core.php"] [unique_id "apK9QyJcY4fy7tP-rU0ODgAAAiA"] [Sat Aug 29 05:06:43.119286 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.197.61.180:8913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/blog.php"] [unique_id "apK9QyJcY4fy7tP-rU0ODwAAAhs"] [Sat Aug 29 05:06:43.123258 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.104.49.130:20620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apK9QyJcY4fy7tP-rU0OEAAAAjI"] [Sat Aug 29 05:06:43.130796 2026] [security2:error] [pid 1017536:tid 1017732] [client 45.61.187.50:63554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "succulentideas.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apK9QyJcY4fy7tP-rU0OEQAAAlY"] [Sat Aug 29 05:06:43.141818 2026] [security2:error] [pid 1017536:tid 1017637] [remote 74.7.227.189:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pinnacleforms.com"] [uri "/ist4isp.php"] [unique_id "apK9QyJcY4fy7tP-rU0OEgACHGQ"], referer: https://mail.pinnacleforms.com/ [Sat Aug 29 05:06:43.145753 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.63.81.20:46957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/pri.php"] [unique_id "apK9QyJcY4fy7tP-rU0OEwAAAh0"] [Sat Aug 29 05:06:43.151191 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.196.209.81:4130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/csv.php"] [unique_id "apK9QyJcY4fy7tP-rU0OFAAAApM"] [Sat Aug 29 05:06:43.163482 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.48.250.41:25403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/bolt.php"] [unique_id "apK9QyJcY4fy7tP-rU0OFQAAApI"] [Sat Aug 29 05:06:43.170138 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.23.147.79:32589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/login.php"] [unique_id "apK9QyJcY4fy7tP-rU0OFwAAAkc"] [Sat Aug 29 05:06:43.179209 2026] [security2:error] [pid 1017536:tid 1017705] [client 158.23.147.79:30564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9QyJcY4fy7tP-rU0OGAAAAjs"] [Sat Aug 29 05:06:43.191912 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.220.204.93:50761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ww.php"] [unique_id "apK9QzAh5Y1i2tUxg4H92wAABgI"] [Sat Aug 29 05:06:43.277062 2026] [security2:error] [pid 1018003:tid 1018231] [client 68.155.159.216:65089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9QzAh5Y1i2tUxg4H93AAABgc"] [Sat Aug 29 05:06:43.278460 2026] [security2:error] [pid 1017536:tid 1017709] [client 20.151.200.44:64334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/ww2.php"] [unique_id "apK9QyJcY4fy7tP-rU0OIgAAAj8"] [Sat Aug 29 05:06:43.278891 2026] [security2:error] [pid 1017536:tid 1017673] [client 68.155.159.216:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/simple.php"] [unique_id "apK9QyJcY4fy7tP-rU0OIwAAAhs"] [Sat Aug 29 05:06:43.285133 2026] [core:error] [pid 1018003:tid 1018239] [client 45.148.10.62:38840] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:43.285147 2026] [core:error] [pid 1018003:tid 1018239] [client 45.148.10.62:38840] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:43.301692 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.250.41:25375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/rtx.php"] [unique_id "apK9QzAh5Y1i2tUxg4H93gAABgM"] [Sat Aug 29 05:06:43.302440 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.63.81.20:46911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp_blog_footer.php"] [unique_id "apK9QzAh5Y1i2tUxg4H93wAABiA"] [Sat Aug 29 05:06:43.349997 2026] [security2:error] [pid 1017536:tid 1017711] [client 185.104.184.230:36262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9QyJcY4fy7tP-rU0OJQAAAkE"] [Sat Aug 29 05:06:43.355398 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.220.204.93:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/w1px.php"] [unique_id "apK9QzAh5Y1i2tUxg4H94gAABc0"] [Sat Aug 29 05:06:43.356047 2026] [security2:error] [pid 1017536:tid 1017705] [client 68.155.159.216:50289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9QyJcY4fy7tP-rU0OJgAAAjs"] [Sat Aug 29 05:06:43.374058 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:51433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9QzAh5Y1i2tUxg4H94wAABbw"] [Sat Aug 29 05:06:43.374436 2026] [security2:error] [pid 1017536:tid 1017753] [client 4.205.62.107:55949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/gnmlc.php"] [unique_id "apK9QyJcY4fy7tP-rU0OJwAAAms"] [Sat Aug 29 05:06:43.385144 2026] [security2:error] [pid 1018003:tid 1018190] [client 168.107.94.195:54592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9QzAh5Y1i2tUxg4H95AAABd8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:43.406678 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.151.200.44:65005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/anz.php"] [unique_id "apK9QzAh5Y1i2tUxg4H95QAABiU"] [Sat Aug 29 05:06:43.448117 2026] [security2:error] [pid 1017536:tid 1017776] [client 20.151.200.44:64837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/sef.php"] [unique_id "apK9QyJcY4fy7tP-rU0OLAAAAoI"] [Sat Aug 29 05:06:43.451857 2026] [security2:error] [pid 1017536:tid 1017767] [client 20.63.81.20:44495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/sushi.php"] [unique_id "apK9QyJcY4fy7tP-rU0OLQAAAnk"] [Sat Aug 29 05:06:43.459749 2026] [security2:error] [pid 1017536:tid 1017765] [client 20.48.250.41:25371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/ckk.php"] [unique_id "apK9QyJcY4fy7tP-rU0OMQAAAnc"] [Sat Aug 29 05:06:43.461265 2026] [security2:error] [pid 1017536:tid 1017780] [client 4.205.62.107:53416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/routes.php"] [unique_id "apK9QyJcY4fy7tP-rU0OMgAAAoY"] [Sat Aug 29 05:06:43.478018 2026] [security2:error] [pid 1017536:tid 1017695] [client 158.23.147.79:25426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9QyJcY4fy7tP-rU0ONQAAAjE"] [Sat Aug 29 05:06:43.492631 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.52.41.200:1423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK9QzAh5Y1i2tUxg4H96gAABec"] [Sat Aug 29 05:06:43.512753 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.158.54.35:4871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/lite.php"] [unique_id "apK9QyJcY4fy7tP-rU0OOQAAApA"] [Sat Aug 29 05:06:43.519901 2026] [security2:error] [pid 1017536:tid 1017713] [client 68.155.159.216:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9QyJcY4fy7tP-rU0OOgAAAkM"] [Sat Aug 29 05:06:43.531779 2026] [security2:error] [pid 1017536:tid 1017784] [client 197.219.150.206:60297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9QyJcY4fy7tP-rU0OPAAAAoo"] [Sat Aug 29 05:06:43.531894 2026] [security2:error] [pid 1017536:tid 1017784] [client 197.219.150.206:60297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9QyJcY4fy7tP-rU0OPAAAAoo"] [Sat Aug 29 05:06:43.565020 2026] [security2:error] [pid 1017536:tid 1017778] [client 136.107.231.130:29358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alanmossman.mossmanphoto.com"] [uri "/docker-compose.yml"] [unique_id "apK9QyJcY4fy7tP-rU0OPwAAAoQ"] [Sat Aug 29 05:06:43.570871 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.220.204.93:52345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/to.php"] [unique_id "apK9QyJcY4fy7tP-rU0OQgAAAlY"] [Sat Aug 29 05:06:43.583504 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.63.81.20:44522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/manga.php"] [unique_id "apK9QzAh5Y1i2tUxg4H97wAABeA"] [Sat Aug 29 05:06:43.584671 2026] [security2:error] [pid 1017536:tid 1017737] [client 40.83.93.50:1601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/db-status.php"] [unique_id "apK9QyJcY4fy7tP-rU0ORQAAAls"] [Sat Aug 29 05:06:43.601601 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.151.200.44:64393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/bge.php"] [unique_id "apK9QzAh5Y1i2tUxg4H98AAABfo"] [Sat Aug 29 05:06:43.604766 2026] [security2:error] [pid 1017536:tid 1017761] [client 20.48.250.41:25368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.oncesocial.com"] [uri "/R57.php"] [unique_id "apK9QyJcY4fy7tP-rU0ORgAAAnM"] [Sat Aug 29 05:06:43.614937 2026] [security2:error] [pid 1017536:tid 1017792] [client 68.155.159.216:30593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/chosen.php"] [unique_id "apK9QyJcY4fy7tP-rU0OSQAAApI"] [Sat Aug 29 05:06:43.621632 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.196.209.81:4142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/fox.php"] [unique_id "apK9QzAh5Y1i2tUxg4H98wAABdA"] [Sat Aug 29 05:06:43.674505 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.147.79:61616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9QyJcY4fy7tP-rU0OUAAAApA"] [Sat Aug 29 05:06:43.688641 2026] [security2:error] [pid 1017536:tid 1017752] [client 136.107.231.130:29364] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.anthropic/config.json"] [unique_id "apK9QyJcY4fy7tP-rU0OUQAAAmo"] [Sat Aug 29 05:06:43.701765 2026] [security2:error] [pid 1017536:tid 1017731] [client 103.171.189.88:55805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9QyJcY4fy7tP-rU0OUgAAAlU"] [Sat Aug 29 05:06:43.701886 2026] [security2:error] [pid 1017536:tid 1017731] [client 103.171.189.88:55805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9QyJcY4fy7tP-rU0OUgAAAlU"] [Sat Aug 29 05:06:43.712524 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.220.204.93:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/thui.php"] [unique_id "apK9QzAh5Y1i2tUxg4H99QAABeU"] [Sat Aug 29 05:06:43.725546 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.151.200.44:64298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/admin123.php"] [unique_id "apK9QzAh5Y1i2tUxg4H99gAABio"] [Sat Aug 29 05:06:43.730413 2026] [security2:error] [pid 1017536:tid 1017743] [client 136.107.231.130:29384] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.codex/config.toml"] [unique_id "apK9QyJcY4fy7tP-rU0OVAAAAmE"] [Sat Aug 29 05:06:43.731385 2026] [security2:error] [pid 1017536:tid 1017778] [client 20.63.81.20:44446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/asdfghj.php"] [unique_id "apK9QyJcY4fy7tP-rU0OVQAAAoQ"] [Sat Aug 29 05:06:43.746478 2026] [security2:error] [pid 1017536:tid 1017709] [client 136.107.231.130:29364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.hermes/.env"] [unique_id "apK9QyJcY4fy7tP-rU0OVgAAAj8"] [Sat Aug 29 05:06:43.765613 2026] [security2:error] [pid 1017536:tid 1017737] [client 168.107.94.195:54955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9QyJcY4fy7tP-rU0OVwAAAls"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:43.766785 2026] [security2:error] [pid 1017536:tid 1017674] [client 4.205.62.107:22225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/xa.php"] [unique_id "apK9QyJcY4fy7tP-rU0OWAAAAhw"] [Sat Aug 29 05:06:43.770047 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.147.79:50060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9QzAh5Y1i2tUxg4H9-AAABd0"] [Sat Aug 29 05:06:43.783176 2026] [security2:error] [pid 1017536:tid 1017740] [client 136.107.231.130:29384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.hermes/config.yaml"] [unique_id "apK9QyJcY4fy7tP-rU0OWQAAAl4"] [Sat Aug 29 05:06:43.787638 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.23.147.79:26559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9QzAh5Y1i2tUxg4H9-wAABh8"] [Sat Aug 29 05:06:43.803999 2026] [security2:error] [pid 1017536:tid 1017761] [client 136.107.231.130:29364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.openclaw/.env"] [unique_id "apK9QyJcY4fy7tP-rU0OXQAAAnM"] [Sat Aug 29 05:06:43.804113 2026] [security2:error] [pid 1017536:tid 1017761] [client 136.107.231.130:29364] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alanmossman.mossmanphoto.com"] [uri "/.openclaw/.env"] [unique_id "apK9QyJcY4fy7tP-rU0OXQAAAnM"] [Sat Aug 29 05:06:43.828564 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.197.61.180:7220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/bypass.php"] [unique_id "apK9QyJcY4fy7tP-rU0OYwAAAh0"] [Sat Aug 29 05:06:43.835899 2026] [security2:error] [pid 1017536:tid 1017770] [client 68.155.159.216:52816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9QyJcY4fy7tP-rU0OZAAAAnw"] [Sat Aug 29 05:06:43.840579 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.151.200.44:65015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/wp-ana.php"] [unique_id "apK9QzAh5Y1i2tUxg4H9_QAABfs"] [Sat Aug 29 05:06:43.861991 2026] [security2:error] [pid 1017536:tid 1017695] [client 20.63.81.20:44529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/dragonshell.php"] [unique_id "apK9QyJcY4fy7tP-rU0OZgAAAjE"] [Sat Aug 29 05:06:43.862197 2026] [security2:error] [pid 1017536:tid 1017733] [client 20.220.204.93:52351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/Jcrop.php"] [unique_id "apK9QyJcY4fy7tP-rU0OZwAAAlc"] [Sat Aug 29 05:06:43.868346 2026] [security2:error] [pid 1017536:tid 1017710] [client 158.23.147.79:17490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9QyJcY4fy7tP-rU0OagAAAkA"] [Sat Aug 29 05:06:43.887784 2026] [security2:error] [pid 1017536:tid 1017696] [client 20.151.200.44:46595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9QyJcY4fy7tP-rU0ObAAAAjI"] [Sat Aug 29 05:06:43.923589 2026] [security2:error] [pid 1017536:tid 1017683] [client 68.155.159.216:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/ws.php"] [unique_id "apK9QyJcY4fy7tP-rU0ObwAAAiU"] [Sat Aug 29 05:06:43.943441 2026] [security2:error] [pid 1017536:tid 1017765] [client 185.104.184.230:36270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9QyJcY4fy7tP-rU0OcQAAAnc"] [Sat Aug 29 05:06:43.945823 2026] [core:error] [pid 1018003:tid 1018222] [client 45.148.10.62:49700] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:43.945844 2026] [core:error] [pid 1018003:tid 1018222] [client 45.148.10.62:49700] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:43.947415 2026] [security2:error] [pid 1017536:tid 1017678] [client 158.23.147.79:35823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9QyJcY4fy7tP-rU0OcgAAAiA"] [Sat Aug 29 05:06:43.951246 2026] [security2:error] [pid 1018003:tid 1018180] [client 136.107.231.130:29380] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/awsConfig.js"] [unique_id "apK9QzAh5Y1i2tUxg4H-AQAABdU"] [Sat Aug 29 05:06:43.955669 2026] [security2:error] [pid 1017536:tid 1017694] [client 20.52.41.200:1766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/xda.php"] [unique_id "apK9QyJcY4fy7tP-rU0OdQAAAjA"] [Sat Aug 29 05:06:43.960122 2026] [security2:error] [pid 1017536:tid 1017717] [client 158.158.54.35:20300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/term.php"] [unique_id "apK9QyJcY4fy7tP-rU0OdwAAAkc"] [Sat Aug 29 05:06:43.989273 2026] [security2:error] [pid 1017536:tid 1017724] [client 68.155.159.216:33746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/admin.php"] [unique_id "apK9QyJcY4fy7tP-rU0OegAAAk4"] [Sat Aug 29 05:06:43.990869 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.63.81.20:44516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-safe.php"] [unique_id "apK9QzAh5Y1i2tUxg4H-AgAABeM"] [Sat Aug 29 05:06:44.028386 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.196.209.81:9458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/disagraeosc.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-BQAABcc"] [Sat Aug 29 05:06:44.035644 2026] [security2:error] [pid 1017536:tid 1017675] [client 4.205.62.107:22354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/fleen.php"] [unique_id "apK9RCJcY4fy7tP-rU0OfQAAAh0"] [Sat Aug 29 05:06:44.051013 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.220.204.93:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ws58.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-BgAABfk"] [Sat Aug 29 05:06:44.060296 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.151.200.44:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/secret.php"] [unique_id "apK9RCJcY4fy7tP-rU0OfwAAAho"] [Sat Aug 29 05:06:44.065661 2026] [security2:error] [pid 1017536:tid 1017770] [client 4.205.62.107:21844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/konfig.php"] [unique_id "apK9RCJcY4fy7tP-rU0OgQAAAnw"] [Sat Aug 29 05:06:44.065678 2026] [security2:error] [pid 1017536:tid 1017745] [client 4.205.62.107:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ccou.php"] [unique_id "apK9RCJcY4fy7tP-rU0OggAAAmM"] [Sat Aug 29 05:06:44.090652 2026] [security2:error] [pid 1017536:tid 1017713] [client 40.83.93.50:1645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK9RCJcY4fy7tP-rU0OgwAAAkM"] [Sat Aug 29 05:06:44.096388 2026] [security2:error] [pid 1018003:tid 1018189] [client 149.34.210.141:59355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-BwAABd4"] [Sat Aug 29 05:06:44.096509 2026] [security2:error] [pid 1018003:tid 1018189] [client 149.34.210.141:59355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-BwAABd4"] [Sat Aug 29 05:06:44.144614 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.147.79:48185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9RCJcY4fy7tP-rU0OhAAAApA"] [Sat Aug 29 05:06:44.146015 2026] [security2:error] [pid 1017536:tid 1017698] [client 168.107.94.195:55319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9RCJcY4fy7tP-rU0OhgAAAjQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:44.148103 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.63.81.20:44503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/gjewuagf.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-CQAABds"] [Sat Aug 29 05:06:44.157659 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.49.130:36362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/ms-edit.php"] [unique_id "apK9RCJcY4fy7tP-rU0OigAAAiA"] [Sat Aug 29 05:06:44.169759 2026] [security2:error] [pid 1018003:tid 1018231] [client 68.155.159.216:16227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-CwAABgc"] [Sat Aug 29 05:06:44.177045 2026] [security2:error] [pid 1017536:tid 1017785] [client 20.151.200.44:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/7h.php"] [unique_id "apK9RCJcY4fy7tP-rU0OjAAAAos"] [Sat Aug 29 05:06:44.205977 2026] [security2:error] [pid 1018003:tid 1018256] [client 68.155.159.216:51201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/cgi-bin/index.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-DAAABiA"] [Sat Aug 29 05:06:44.211212 2026] [security2:error] [pid 1018003:tid 1018244] [client 136.107.231.130:29380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alanmossman.mossmanphoto.com"] [uri "/metrics"] [unique_id "apK9RDAh5Y1i2tUxg4H-DQAABhQ"] [Sat Aug 29 05:06:44.235337 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.151.200.44:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/pro.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-DgAABc0"] [Sat Aug 29 05:06:44.267605 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.220.204.93:52308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/xs.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-DwAABiU"] [Sat Aug 29 05:06:44.288848 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.63.81.20:46941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/tnglzqmv.php"] [unique_id "apK9RCJcY4fy7tP-rU0OjgAAAk0"] [Sat Aug 29 05:06:44.292510 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.147.79:32656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/hehehehe.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-EQAABdc"] [Sat Aug 29 05:06:44.327732 2026] [security2:error] [pid 1017536:tid 1017674] [client 158.23.147.79:30533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/goat1.php"] [unique_id "apK9RCJcY4fy7tP-rU0OkAAAAhw"] [Sat Aug 29 05:06:44.347852 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.18.15:36681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/atomlib.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-EgAABdA"] [Sat Aug 29 05:06:44.366163 2026] [security2:error] [pid 1017536:tid 1017705] [client 20.151.200.44:46652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9RCJcY4fy7tP-rU0OlwAAAjs"] [Sat Aug 29 05:06:44.382316 2026] [security2:error] [pid 1017536:tid 1017751] [client 68.155.159.216:38544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-admin/about.php"] [unique_id "apK9RCJcY4fy7tP-rU0OmQAAAmk"] [Sat Aug 29 05:06:44.382948 2026] [security2:error] [pid 1017536:tid 1017793] [client 68.155.159.216:65025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9RCJcY4fy7tP-rU0OmgAAApM"] [Sat Aug 29 05:06:44.385112 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.18.15:36761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/gjewuagf.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-FQAABfA"] [Sat Aug 29 05:06:44.392089 2026] [security2:error] [pid 1017536:tid 1017673] [client 20.151.200.44:64985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/999.php"] [unique_id "apK9RCJcY4fy7tP-rU0OmwAAAhs"] [Sat Aug 29 05:06:44.400702 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.220.204.93:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/zu.php"] [unique_id "apK9RCJcY4fy7tP-rU0OngAAAlM"] [Sat Aug 29 05:06:44.410842 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.52.41.200:1733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/theme.php"] [unique_id "apK9RCJcY4fy7tP-rU0OoAAAAlY"] [Sat Aug 29 05:06:44.423511 2026] [security2:error] [pid 1017536:tid 1017752] [client 158.158.54.35:11358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/config.php"] [unique_id "apK9RCJcY4fy7tP-rU0OoQAAAmo"] [Sat Aug 29 05:06:44.427618 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.196.209.81:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/about.php525"] [unique_id "apK9RDAh5Y1i2tUxg4H-GAAABb0"] [Sat Aug 29 05:06:44.429165 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.63.81.20:46958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wefile.php"] [unique_id "apK9RCJcY4fy7tP-rU0OowAAAm8"] [Sat Aug 29 05:06:44.442485 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.18.15:23462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/revo.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-GQAABeU"] [Sat Aug 29 05:06:44.445569 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.104.18.15:7001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/dragonshell.php"] [unique_id "apK9RCJcY4fy7tP-rU0OrAAAAiA"] [Sat Aug 29 05:06:44.457599 2026] [security2:error] [pid 1017536:tid 1017694] [client 68.155.159.216:50181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9RCJcY4fy7tP-rU0OrQAAAjA"] [Sat Aug 29 05:06:44.463520 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.151.200.44:64298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/wp-gzone.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-GwAABcQ"] [Sat Aug 29 05:06:44.478272 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.104.18.15:36855] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.horseweblog.com"] [uri "/1.php"] [unique_id "apK9RCJcY4fy7tP-rU0OrwAAAoo"] [Sat Aug 29 05:06:44.478349 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.104.18.15:36855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/1.php"] [unique_id "apK9RCJcY4fy7tP-rU0OrwAAAoo"] [Sat Aug 29 05:06:44.486879 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.18.15:8011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/os.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-HAAABb4"] [Sat Aug 29 05:06:44.489344 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.18.15:13246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-HQAABik"] [Sat Aug 29 05:06:44.521242 2026] [security2:error] [pid 1017536:tid 1017793] [client 4.205.62.107:55988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/koiy.php"] [unique_id "apK9RCJcY4fy7tP-rU0OsgAAApM"] [Sat Aug 29 05:06:44.527407 2026] [security2:error] [pid 1018003:tid 1018222] [client 168.107.94.195:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-HwAABf8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:44.536136 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.220.204.93:59128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/lanka.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-IAAABc8"] [Sat Aug 29 05:06:44.538190 2026] [security2:error] [pid 1018003:tid 1018192] [client 185.104.184.230:36274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9RDAh5Y1i2tUxg4H-IQAABeE"] [Sat Aug 29 05:06:44.540090 2026] [security2:error] [pid 1017536:tid 1017672] [client 20.151.200.44:64433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/sef.php"] [unique_id "apK9RCJcY4fy7tP-rU0OswAAAho"] [Sat Aug 29 05:06:44.546824 2026] [security2:error] [pid 1017536:tid 1017724] [client 20.197.61.180:8915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/extractable-loader-head.php"] [unique_id "apK9RCJcY4fy7tP-rU0OtgAAAk4"] [Sat Aug 29 05:06:44.555575 2026] [security2:error] [pid 1017536:tid 1017732] [client 20.63.81.20:41969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/blog.php"] [unique_id "apK9RCJcY4fy7tP-rU0OuAAAAlY"] [Sat Aug 29 05:06:44.556138 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.18.15:36653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/tnglzqmv.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-IgAABcg"] [Sat Aug 29 05:06:44.568343 2026] [security2:error] [pid 1017536:tid 1017778] [client 61.9.8.103:5904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9RCJcY4fy7tP-rU0OtwAAAoQ"] [Sat Aug 29 05:06:44.568467 2026] [security2:error] [pid 1017536:tid 1017778] [client 61.9.8.103:5904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9RCJcY4fy7tP-rU0OtwAAAoQ"] [Sat Aug 29 05:06:44.575740 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.18.15:6983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-safe.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-JAAABis"] [Sat Aug 29 05:06:44.583542 2026] [security2:error] [pid 1017536:tid 1017695] [client 40.83.93.50:23994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/f35.php"] [unique_id "apK9RCJcY4fy7tP-rU0OugAAAjE"] [Sat Aug 29 05:06:44.584902 2026] [security2:error] [pid 1017536:tid 1017790] [client 158.23.147.79:25489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/lock.php"] [unique_id "apK9RCJcY4fy7tP-rU0OuwAAApA"] [Sat Aug 29 05:06:44.600556 2026] [security2:error] [pid 1017536:tid 1017696] [client 68.155.159.216:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/makeasmtp.php"] [unique_id "apK9RCJcY4fy7tP-rU0OvAAAAjI"] [Sat Aug 29 05:06:44.603491 2026] [security2:error] [pid 1017536:tid 1017683] [client 20.104.18.15:23400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/birrs.php"] [unique_id "apK9RCJcY4fy7tP-rU0OvQAAAiU"] [Sat Aug 29 05:06:44.604408 2026] [security2:error] [pid 1017536:tid 1017792] [client 4.205.62.107:9004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/fm.php"] [unique_id "apK9RCJcY4fy7tP-rU0OvgAAApI"] [Sat Aug 29 05:06:44.604574 2026] [security2:error] [pid 1017536:tid 1017678] [client 20.151.200.44:64234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/str.php"] [unique_id "apK9RCJcY4fy7tP-rU0OvwAAAiA"] [Sat Aug 29 05:06:44.620144 2026] [security2:error] [pid 1017536:tid 1017785] [client 158.23.147.79:24461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/packed.php"] [unique_id "apK9RCJcY4fy7tP-rU0OwQAAAos"] [Sat Aug 29 05:06:44.620517 2026] [security2:error] [pid 1017536:tid 1017781] [client 20.104.18.15:8134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/htio.php"] [unique_id "apK9RCJcY4fy7tP-rU0OwgAAAoc"] [Sat Aug 29 05:06:44.621366 2026] [security2:error] [pid 1017536:tid 1017706] [client 20.104.49.130:36062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/tool.php"] [unique_id "apK9RCJcY4fy7tP-rU0OwwAAAjw"] [Sat Aug 29 05:06:44.675144 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.18.15:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/samll.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-JQAABc0"] [Sat Aug 29 05:06:44.678593 2026] [security2:error] [pid 1017536:tid 1017675] [client 20.104.18.15:13171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/xmini4.php"] [unique_id "apK9RCJcY4fy7tP-rU0OygAAAh0"] [Sat Aug 29 05:06:44.680184 2026] [security2:error] [pid 1017536:tid 1017793] [client 20.63.81.20:46851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apK9RCJcY4fy7tP-rU0OywAAApM"] [Sat Aug 29 05:06:44.681315 2026] [security2:error] [pid 1017536:tid 1017669] [client 20.220.204.93:59080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/gettest.php"] [unique_id "apK9RCJcY4fy7tP-rU0OzAAAAhc"] [Sat Aug 29 05:06:44.708970 2026] [core:error] [pid 1018003:tid 1018271] [client 45.148.10.62:49712] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:44.708988 2026] [core:error] [pid 1018003:tid 1018271] [client 45.148.10.62:49712] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:44.723064 2026] [security2:error] [pid 1017536:tid 1017673] [client 68.155.159.216:30659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/goods.php"] [unique_id "apK9RCJcY4fy7tP-rU0O0AAAAhs"] [Sat Aug 29 05:06:44.724683 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:7042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/gjewuagf.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-KAAABec"] [Sat Aug 29 05:06:44.725254 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.151.200.44:47369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/baee.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-KQAABiI"] [Sat Aug 29 05:06:44.742778 2026] [security2:error] [pid 1017536:tid 1017757] [client 20.104.18.15:23414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/sss.php"] [unique_id "apK9RCJcY4fy7tP-rU0O0QAAAm8"] [Sat Aug 29 05:06:44.756337 2026] [security2:error] [pid 1017536:tid 1017721] [client 20.104.18.15:8095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/dev.php"] [unique_id "apK9RCJcY4fy7tP-rU0O0gAAAks"] [Sat Aug 29 05:06:44.757646 2026] [security2:error] [pid 1017536:tid 1017784] [client 20.151.200.44:65084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/admin123.php"] [unique_id "apK9RCJcY4fy7tP-rU0O0wAAAoo"] [Sat Aug 29 05:06:44.758976 2026] [security2:error] [pid 1017536:tid 1017598] [remote 52.167.144.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9RCJcY4fy7tP-rU0O1QACQz0"] [Sat Aug 29 05:06:44.772099 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.18.15:36683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wefile.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-KgAABfw"] [Sat Aug 29 05:06:44.802050 2026] [security2:error] [pid 1018003:tid 1018179] [client 171.61.160.196:2734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-KwAABdQ"] [Sat Aug 29 05:06:44.802128 2026] [security2:error] [pid 1018003:tid 1018179] [client 171.61.160.196:2734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-KwAABdQ"] [Sat Aug 29 05:06:44.803711 2026] [security2:error] [pid 1017536:tid 1017723] [client 20.63.81.20:44452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/robot.php"] [unique_id "apK9RCJcY4fy7tP-rU0O2QAAAk0"] [Sat Aug 29 05:06:44.807505 2026] [security2:error] [pid 1017536:tid 1017753] [client 20.104.18.15:36672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/she11.php"] [unique_id "apK9RCJcY4fy7tP-rU0O2gAAAms"] [Sat Aug 29 05:06:44.814250 2026] [security2:error] [pid 1017536:tid 1017731] [client 20.220.204.93:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/35.php"] [unique_id "apK9RCJcY4fy7tP-rU0O2wAAAlU"] [Sat Aug 29 05:06:44.815398 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.18.15:13161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/gulu.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-LAAABdA"] [Sat Aug 29 05:06:44.823150 2026] [autoindex:error] [pid 1017536:tid 1017743] [client 147.185.132.79:65006] AH01276: Cannot serve directory /home3/aknsvwmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:44.823403 2026] [security2:error] [pid 1018003:tid 1018239] [client 158.23.147.79:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/asd.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-LQAABg8"] [Sat Aug 29 05:06:44.856256 2026] [security2:error] [pid 1017536:tid 1017778] [client 158.158.54.35:8731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9RCJcY4fy7tP-rU0O3gAAAoQ"] [Sat Aug 29 05:06:44.864478 2026] [security2:error] [pid 1017536:tid 1017729] [client 20.52.41.200:1781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/classwithtostring.php"] [unique_id "apK9RCJcY4fy7tP-rU0O3wAAAlM"] [Sat Aug 29 05:06:44.866383 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.151.200.44:64954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/mega.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-LgAABbk"] [Sat Aug 29 05:06:44.878318 2026] [security2:error] [pid 1017536:tid 1017792] [client 20.196.209.81:9433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/spip.php"] [unique_id "apK9RCJcY4fy7tP-rU0O4AAAApI"] [Sat Aug 29 05:06:44.878337 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.104.18.15:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/tnglzqmv.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-LwAABhw"] [Sat Aug 29 05:06:44.892010 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.104.18.15:8057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/gos.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-MAAABgQ"] [Sat Aug 29 05:06:44.916772 2026] [security2:error] [pid 1018003:tid 1018188] [client 168.107.94.195:56032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-MgAABd0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:44.920006 2026] [security2:error] [pid 1018003:tid 1018255] [client 4.205.62.107:22315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/ws61.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-MwAABh8"] [Sat Aug 29 05:06:44.922864 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:26579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/languages/about.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-NAAABb4"] [Sat Aug 29 05:06:44.923227 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.18.15:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/blog.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-NQAABe8"] [Sat Aug 29 05:06:44.931010 2026] [security2:error] [pid 1018003:tid 1018185] [client 158.23.147.79:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-NgAABdo"] [Sat Aug 29 05:06:44.932740 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.48.250.41:21461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-NwAABfs"] [Sat Aug 29 05:06:44.933187 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.63.81.20:46933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/revo.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-OAAABfY"] [Sat Aug 29 05:06:44.941606 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.151.200.44:64385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/7h.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-OgAABgE"] [Sat Aug 29 05:06:44.942845 2026] [security2:error] [pid 1018003:tid 1018222] [client 68.155.159.216:52831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-OwAABf8"] [Sat Aug 29 05:06:44.942995 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.220.204.93:52325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/maraz.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-PAAABeM"] [Sat Aug 29 05:06:44.969257 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.18.15:36849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/kerang.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-PwAABcg"] [Sat Aug 29 05:06:44.976732 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.147.79:17428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-QAAABis"] [Sat Aug 29 05:06:44.977276 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.104.18.15:13217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/replace.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-QQAABfk"] [Sat Aug 29 05:06:44.980298 2026] [security2:error] [pid 1018003:tid 1018156] [client 45.61.187.50:63982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "succulentideas.com"] [uri "/wp-content/plugins/wp_gljbkwx/wp_gljbkwx.php"] [unique_id "apK9RDAh5Y1i2tUxg4H-QgAABb0"] [Sat Aug 29 05:06:45.011492 2026] [security2:error] [pid 1018003:tid 1018111] [remote 74.7.227.154:41662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9RTAh5Y1i2tUxg4H-QwAGLlo"], referer: https://goodtogo.store/sitemap_index.xml?p=%2Fhome4%2Fsortthru%2Fpublic_html%2Fgoodtogo%2Fwebapp%2Fwp-content%2Fplugins%2Fwp-easycart%2Fadmin%2Felementor [Sat Aug 29 05:06:45.012399 2026] [http2:warn] [pid 1017536:tid 1017739] [client 57.141.14.32:63142] h2_stream(1017536-172-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:06:45.017489 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.18.15:7015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wefile.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-RAAABhY"] [Sat Aug 29 05:06:45.034743 2026] [security2:error] [pid 1018003:tid 1018160] [client 68.155.159.216:18322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-RgAABcE"] [Sat Aug 29 05:06:45.043558 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.18.15:8106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/132.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-SQAABiY"] [Sat Aug 29 05:06:45.054875 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.151.200.44:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/ww3.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-SgAABd8"] [Sat Aug 29 05:06:45.061476 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.63.81.20:46922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/birrs.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-TAAABi8"] [Sat Aug 29 05:06:45.063390 2026] [security2:error] [pid 1018003:tid 1018233] [client 40.83.93.50:1649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/index.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-TQAABgk"] [Sat Aug 29 05:06:45.079011 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.220.204.93:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/kbfr.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-TwAABdI"] [Sat Aug 29 05:06:45.087161 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.104.18.15:36818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-UQAABiI"] [Sat Aug 29 05:06:45.094072 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.48.250.41:21447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-UgAABdw"] [Sat Aug 29 05:06:45.107091 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.18.15:13130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/c4.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-VAAABeA"] [Sat Aug 29 05:06:45.127326 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.151.200.44:65075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/wp-gzone.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-VQAABdk"] [Sat Aug 29 05:06:45.132897 2026] [security2:error] [pid 1018003:tid 1018153] [client 185.104.184.230:36280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9RTAh5Y1i2tUxg4H-VgAABbo"] [Sat Aug 29 05:06:45.135637 2026] [security2:error] [pid 1018003:tid 1018230] [client 68.155.159.216:33724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/xmlrpc.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-VwAABgY"] [Sat Aug 29 05:06:45.150643 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.23.147.79:30649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-WAAABcM"] [Sat Aug 29 05:06:45.157126 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.23.147.79:35760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/radio.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-WwAABg4"] [Sat Aug 29 05:06:45.171375 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.18.15:36794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/m.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-XAAABe8"] [Sat Aug 29 05:06:45.174030 2026] [security2:error] [pid 1018003:tid 1018185] [client 4.205.62.107:22242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/phpinfo01.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-XQAABdo"] [Sat Aug 29 05:06:45.195969 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.18.15:8155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/v22.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-XwAABf8"] [Sat Aug 29 05:06:45.200670 2026] [security2:error] [pid 1018003:tid 1018194] [client 4.205.62.107:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/rum.or.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-YAAABeM"] [Sat Aug 29 05:06:45.204261 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:7122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/blog.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-YgAABeE"] [Sat Aug 29 05:06:45.204294 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.63.81.20:44495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/sss.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-YQAABjE"] [Sat Aug 29 05:06:45.209584 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.220.204.93:59130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wp-act.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-YwAABcc"] [Sat Aug 29 05:06:45.217117 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.18.15:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/robot.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-ZAAABcg"] [Sat Aug 29 05:06:45.226196 2026] [core:error] [pid 1018003:tid 1018175] [client 20.104.18.15:23524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.226211 2026] [core:error] [pid 1018003:tid 1018175] [client 20.104.18.15:23524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.234904 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.250.41:21496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ff1.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-ZgAABis"] [Sat Aug 29 05:06:45.237335 2026] [security2:error] [pid 1018003:tid 1018275] [client 4.205.62.107:22392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/nw.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-aAAABjM"] [Sat Aug 29 05:06:45.248088 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.147.79:48409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-aQAABd4"] [Sat Aug 29 05:06:45.250090 2026] [security2:error] [pid 1018003:tid 1018259] [client 20.104.18.15:13067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/rxr.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-agAABiM"] [Sat Aug 29 05:06:45.260331 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.151.200.44:47327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/d12.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-awAABds"] [Sat Aug 29 05:06:45.262709 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.151.200.44:64266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/sko.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-bAAABcs"] [Sat Aug 29 05:06:45.263709 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.151.200.44:64984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/str.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-bQAABgc"] [Sat Aug 29 05:06:45.272977 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.197.61.180:7888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/defaults.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-bgAABhQ"] [Sat Aug 29 05:06:45.277241 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-admin/images/about.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-bwAABbw"] [Sat Aug 29 05:06:45.279716 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.196.209.81:17913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/backup.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-cAAABdg"] [Sat Aug 29 05:06:45.298093 2026] [security2:error] [pid 1018003:tid 1018198] [client 168.107.94.195:56470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-cQAABec"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:45.302243 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.158.54.35:15218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-good.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-cgAABcI"] [Sat Aug 29 05:06:45.308175 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:23362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-cwAABcA"] [Sat Aug 29 05:06:45.321167 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.52.41.200:1171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/news.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-dAAABik"] [Sat Aug 29 05:06:45.335012 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.18.15:36640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/fling.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-dQAABiw"] [Sat Aug 29 05:06:45.339239 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.104.18.15:6966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-dwAABhM"] [Sat Aug 29 05:06:45.342488 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.18.15:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-activate.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-eAAABcU"] [Sat Aug 29 05:06:45.350495 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.220.204.93:59051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/24.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-eQAABfA"] [Sat Aug 29 05:06:45.374443 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.250.41:21385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/t.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-egAABcM"] [Sat Aug 29 05:06:45.378815 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.18.15:36719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/revo.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-ewAABf4"] [Sat Aug 29 05:06:45.394281 2026] [security2:error] [pid 1018003:tid 1018227] [client 20.151.200.44:64855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/zoz.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-fAAABgQ"] [Sat Aug 29 05:06:45.406263 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.147.79:32588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-fQAABeE"] [Sat Aug 29 05:06:45.408694 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.18.15:13162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.doozytrack.com"] [uri "/reviall.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-fgAABcc"] [Sat Aug 29 05:06:45.418998 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.63.81.20:44523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-fwAABis"] [Sat Aug 29 05:06:45.425528 2026] [security2:error] [pid 1018003:tid 1018069] [remote 74.7.227.154:41662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9RTAh5Y1i2tUxg4H-gAAFvTA"], referer: https://goodtogo.store/sitemap_index.xml?p=%2Fhome4%2Fsortthru%2Fpublic_html%2Fgoodtogo%2Fwebapp%2Fwp-content%2Fplugins%2Fwp-easycart%2Fadmin%2Felementor [Sat Aug 29 05:06:45.431535 2026] [security2:error] [pid 1018003:tid 1018256] [client 45.148.10.62:49726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninaanddon.strangeworx.com"] [uri "/wp-config.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-gQAABiA"] [Sat Aug 29 05:06:45.457386 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.18.15:23368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/xmini4.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-ggAABds"] [Sat Aug 29 05:06:45.460094 2026] [security2:error] [pid 1018003:tid 1018270] [client 158.23.147.79:30566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/classwithtostring.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-gwAABi4"] [Sat Aug 29 05:06:45.470949 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.18.15:6989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/robot.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-hQAABhQ"] [Sat Aug 29 05:06:45.472043 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.151.200.44:65040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/mega.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-hgAABiU"] [Sat Aug 29 05:06:45.478704 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.151.200.44:47420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/yyy.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-hwAABi8"] [Sat Aug 29 05:06:45.497663 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.18.15:36793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/btyuio.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-iQAABeQ"] [Sat Aug 29 05:06:45.522953 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.48.250.41:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/erty.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-kAAABeA"] [Sat Aug 29 05:06:45.537529 2026] [security2:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9RTAh5Y1i2tUxg4H-kgAGHGk"] [Sat Aug 29 05:06:45.538275 2026] [security2:error] [pid 1018003:tid 1018152] [client 40.83.93.50:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/install.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-kwAABbk"] [Sat Aug 29 05:06:45.545237 2026] [security2:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9RTAh5Y1i2tUxg4H-lQAGHHU"] [Sat Aug 29 05:06:45.547239 2026] [core:error] [pid 1018003:tid 1018119] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.547253 2026] [core:error] [pid 1018003:tid 1018119] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.549797 2026] [security2:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9RTAh5Y1i2tUxg4H-mgAGHGo"] [Sat Aug 29 05:06:45.549912 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.104.18.15:36683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/birrs.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-ngAABhM"] [Sat Aug 29 05:06:45.555444 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.63.81.20:46970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/xmini4.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-nwAABc8"] [Sat Aug 29 05:06:45.557414 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:8175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-trackback.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-oAAABes"] [Sat Aug 29 05:06:45.568208 2026] [security2:error] [pid 1018003:tid 1018162] [client 68.155.159.216:50297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-pQAABcM"] [Sat Aug 29 05:06:45.569216 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.569231 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.569246 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.569248 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.569255 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.569260 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.569748 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.569762 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.588236 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.18.15:23382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/gulu.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-pgAABis"] [Sat Aug 29 05:06:45.595471 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.151.200.44:64925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/mmm.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-qAAABds"] [Sat Aug 29 05:06:45.622492 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.18.15:7088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/revo.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-qQAABiU"] [Sat Aug 29 05:06:45.637179 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.18.15:36680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/dehnl.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-qgAABdg"] [Sat Aug 29 05:06:45.656878 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.220.204.93:50813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/155.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-qwAABgk"] [Sat Aug 29 05:06:45.658692 2026] [security2:error] [pid 1018003:tid 1018198] [client 4.205.62.107:55986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/w.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-rAAABec"] [Sat Aug 29 05:06:45.673756 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.49.130:47962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/log.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-rQAABdw"] [Sat Aug 29 05:06:45.676449 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.196.209.81:4113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/haiterus.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-rgAABew"] [Sat Aug 29 05:06:45.677244 2026] [security2:error] [pid 1018003:tid 1018161] [client 168.107.94.195:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-rwAABcI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:45.686528 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.63.81.20:44421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/gulu.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-wAAABg4"] [Sat Aug 29 05:06:45.689597 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.48.250.41:21497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/0x.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-wQAABho"] [Sat Aug 29 05:06:45.695144 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.151.200.44:65037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/ww3.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-xAAABhI"] [Sat Aug 29 05:06:45.695557 2026] [security2:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9RTAh5Y1i2tUxg4H-wwAFwDQ"] [Sat Aug 29 05:06:45.695942 2026] [security2:error] [pid 1018003:tid 1018180] [client 158.23.147.79:25485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/index/function.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-xQAABdU"] [Sat Aug 29 05:06:45.702902 2026] [core:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.702920 2026] [core:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.703371 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.703383 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.704212 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.704223 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.705242 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.705253 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.705310 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.705318 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.705633 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.705646 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.709461 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.18.15:36733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/sss.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-zwAABf4"] [Sat Aug 29 05:06:45.709617 2026] [security2:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9RTAh5Y1i2tUxg4H-zgAFwHs"] [Sat Aug 29 05:06:45.709910 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.709919 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.710402 2026] [security2:error] [pid 1018003:tid 1018218] [client 111.235.68.106:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-0QAABfs"] [Sat Aug 29 05:06:45.711548 2026] [core:error] [pid 1018003:tid 1018207] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.712561 2026] [core:error] [pid 1018003:tid 1018207] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.712635 2026] [security2:error] [pid 1018003:tid 1018218] [client 111.235.68.106:60249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-0QAABfs"] [Sat Aug 29 05:06:45.713115 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.713122 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.716703 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.716714 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.717154 2026] [core:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.717162 2026] [core:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.722785 2026] [security2:error] [pid 1018003:tid 1018275] [client 185.104.184.230:36292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9RTAh5Y1i2tUxg4H-1wAABjM"] [Sat Aug 29 05:06:45.744541 2026] [security2:error] [pid 1018003:tid 1018270] [client 4.205.62.107:53327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/pinfo.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-2AAABi4"] [Sat Aug 29 05:06:45.745306 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.104.18.15:23374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/replace.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-2QAABcE"] [Sat Aug 29 05:06:45.749327 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.18.15:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/pri.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-2gAABiY"] [Sat Aug 29 05:06:45.764809 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.18.15:6917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/birrs.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-2wAABbw"] [Sat Aug 29 05:06:45.769159 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.769175 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.773823 2026] [security2:error] [pid 1018003:tid 1018170] [client 158.158.54.35:8761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-3QAABcs"] [Sat Aug 29 05:06:45.779176 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.52.41.200:1232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/about/function.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-3gAABd8"] [Sat Aug 29 05:06:45.790845 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.151.200.44:46647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/bgymj.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-5AAABcI"] [Sat Aug 29 05:06:45.807582 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.220.204.93:52277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/file.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-5wAABhM"] [Sat Aug 29 05:06:45.813562 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.63.81.20:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/replace.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-6AAABc8"] [Sat Aug 29 05:06:45.820838 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.104.18.15:36715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/zoo2.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-6QAABcM"] [Sat Aug 29 05:06:45.825300 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:38737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wzy.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-6gAABb4"] [Sat Aug 29 05:06:45.827391 2026] [security2:error] [pid 1018003:tid 1018194] [client 68.155.159.216:30694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-6wAABeM"] [Sat Aug 29 05:06:45.841212 2026] [security2:error] [pid 1018003:tid 1018115] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9RTAh5Y1i2tUxg4H-7AAF6V4"] [Sat Aug 29 05:06:45.848134 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.151.200.44:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/advanced.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-8QAABgM"] [Sat Aug 29 05:06:45.848300 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.151.200.44:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/sko.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-8gAABeA"] [Sat Aug 29 05:06:45.854597 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.48.250.41:21379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/66.php"] [unique_id "apK9RTAh5Y1i2tUxg4H-9QAABfo"] [Sat Aug 29 05:06:45.861576 2026] [security2:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9RTAh5Y1i2tUxg4H-9wAF6Q8"] [Sat Aug 29 05:06:45.861587 2026] [security2:error] [pid 1018003:tid 1018031] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9RTAh5Y1i2tUxg4H-9gAF6Qo"] [Sat Aug 29 05:06:45.868809 2026] [core:error] [pid 1018003:tid 1018255] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.868823 2026] [core:error] [pid 1018003:tid 1018255] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.870501 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.870514 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.870665 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.870674 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.876955 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.104.18.15:23319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/c4.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_BgAABbo"] [Sat Aug 29 05:06:45.881938 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.18.15:8046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp_blog_footer.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_DgAABgw"] [Sat Aug 29 05:06:45.884067 2026] [security2:error] [pid 1018003:tid 1018212] [client 68.155.159.216:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_EAAABfU"] [Sat Aug 29 05:06:45.885883 2026] [security2:error] [pid 1018003:tid 1018160] [client 158.23.147.79:24424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-l0gin.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_EQAABcE"] [Sat Aug 29 05:06:45.890719 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.890732 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.891316 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.891324 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.918864 2026] [security2:error] [pid 1018003:tid 1018169] [client 103.162.125.59:54658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_FQAABco"] [Sat Aug 29 05:06:45.918995 2026] [security2:error] [pid 1018003:tid 1018169] [client 103.162.125.59:54658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_FQAABco"] [Sat Aug 29 05:06:45.933467 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.933493 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.936086 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.936105 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.937100 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.147.79:61586] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/1.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_GQAABfY"] [Sat Aug 29 05:06:45.937227 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.147.79:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/1.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_GQAABfY"] [Sat Aug 29 05:06:45.939533 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.18.15:7050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/sss.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_GgAABiU"] [Sat Aug 29 05:06:45.943691 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.943706 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.944646 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.63.81.20:46909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/c4.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_HAAABdA"] [Sat Aug 29 05:06:45.949701 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.220.204.93:52320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_HQAABjE"] [Sat Aug 29 05:06:45.960402 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.960414 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.960415 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.960435 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.960760 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.960768 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.980913 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.980925 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.983289 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.151.200.44:65078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/zoz.php"] [unique_id "apK9RTAh5Y1i2tUxg4H_IgAABcU"] [Sat Aug 29 05:06:45.985278 2026] [security2:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9RTAh5Y1i2tUxg4H_IwAF6RY"] [Sat Aug 29 05:06:45.996408 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:45.996416 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.006361 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.18.15:23363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/rxr.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_JQAABcQ"] [Sat Aug 29 05:06:46.027272 2026] [security2:error] [pid 1018003:tid 1018236] [client 158.23.147.79:26489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/banners/about.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_JgAABgw"] [Sat Aug 29 05:06:46.030230 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:36736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/zoo1.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_KQAABi4"] [Sat Aug 29 05:06:46.037810 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.250.41:21396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/f35.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_MwAABco"] [Sat Aug 29 05:06:46.048720 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.18.15:8032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/sushi.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_NAAABb0"] [Sat Aug 29 05:06:46.055972 2026] [security2:error] [pid 1018003:tid 1018233] [client 168.107.94.195:57232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_NQAABgk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:46.058249 2026] [security2:error] [pid 1018003:tid 1018196] [client 158.23.147.79:49990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/simple.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_OQAABeU"] [Sat Aug 29 05:06:46.058499 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.197.61.180:8917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/post.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_OgAABgI"] [Sat Aug 29 05:06:46.060075 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.060086 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.060274 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.060286 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.060377 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.060397 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.060575 2026] [security2:error] [pid 1018003:tid 1018258] [client 4.205.62.107:22415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/xza.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_OwAABiI"] [Sat Aug 29 05:06:46.066101 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.066114 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.067478 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.067491 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.076242 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.63.81.20:44431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/rxr.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_PwAABgo"] [Sat Aug 29 05:06:46.080158 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.196.209.81:9428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/go.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_QAAABc8"] [Sat Aug 29 05:06:46.085550 2026] [core:error] [pid 1018003:tid 1018267] [client 20.104.18.15:36861] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.085569 2026] [core:error] [pid 1018003:tid 1018267] [client 20.104.18.15:36861] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.086068 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.220.204.93:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/06.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_RAAABgc"] [Sat Aug 29 05:06:46.095337 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.147.79:17451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/chosen.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_RwAABfs"] [Sat Aug 29 05:06:46.102592 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.102606 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.112029 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.151.200.44:65063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/mmm.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_SQAABf4"] [Sat Aug 29 05:06:46.113694 2026] [security2:error] [pid 1018003:tid 1018230] [client 45.61.187.50:64241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "succulentideas.com"] [uri "/wp-content/plugins/wp_gljbkwx/wp_gljbkwx.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_SgAABgY"] [Sat Aug 29 05:06:46.122777 2026] [security2:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9RjAh5Y1i2tUxg4H_SwAGAxc"] [Sat Aug 29 05:06:46.127640 2026] [security2:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9RjAh5Y1i2tUxg4H_TwAGAxI"] [Sat Aug 29 05:06:46.139870 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:18402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_VwAABdc"] [Sat Aug 29 05:06:46.146709 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.151.200.44:64284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/blox.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_XAAABbo"] [Sat Aug 29 05:06:46.151767 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.18.15:23320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "louiseandkane.strangeworx.com"] [uri "/reviall.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_XgAABgw"] [Sat Aug 29 05:06:46.155111 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.155132 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.155528 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.155541 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.155949 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.151.200.44:46624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/fh26.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_YQAABco"] [Sat Aug 29 05:06:46.159998 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.160020 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.160297 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.160308 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.160451 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.160464 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.162259 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.162278 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.164329 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.164344 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.166506 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.166520 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.173163 2026] [security2:error] [pid 1018003:tid 1018180] [client 20.104.18.15:36714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_aQAABdU"] [Sat Aug 29 05:06:46.191713 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.48.250.41:21484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wen.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_agAABd4"] [Sat Aug 29 05:06:46.200416 2026] [security2:error] [pid 1018003:tid 1018157] [client 40.83.93.50:1648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/languages/about.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_awAABb4"] [Sat Aug 29 05:06:46.203164 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.18.15:8109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/manga.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_bAAABdk"] [Sat Aug 29 05:06:46.203803 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.63.81.20:44469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alabamaracingrealtor.com"] [uri "/reviall.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_bQAABiY"] [Sat Aug 29 05:06:46.230274 2026] [security2:error] [pid 1018003:tid 1018273] [client 158.158.54.35:11335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/abcd.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_dgAABjE"] [Sat Aug 29 05:06:46.241497 2026] [cgid:error] [pid 1018003:tid 1018191] [client 20.52.41.200:1153] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:46.252343 2026] [security2:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9RjAh5Y1i2tUxg4H_fgAFwS4"] [Sat Aug 29 05:06:46.255526 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.255539 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.262434 2026] [security2:error] [pid 1018003:tid 1018250] [client 68.155.159.216:33661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/atomlib.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_gQAABho"] [Sat Aug 29 05:06:46.274304 2026] [security2:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9RjAh5Y1i2tUxg4H_gwAFwSg"] [Sat Aug 29 05:06:46.275565 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.275579 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.288003 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.220.204.93:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/class.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_hAAABgE"] [Sat Aug 29 05:06:46.294863 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.151.200.44:61920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/kcs.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_hQAABcQ"] [Sat Aug 29 05:06:46.311626 2026] [security2:error] [pid 1018003:tid 1018233] [client 4.205.62.107:22357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wp-info.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_jgAABgk"] [Sat Aug 29 05:06:46.315007 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.151.200.44:62720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/advanced.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_kAAABeU"] [Sat Aug 29 05:06:46.317028 2026] [security2:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9RjAh5Y1i2tUxg4H_kQAFwTk"] [Sat Aug 29 05:06:46.318347 2026] [security2:error] [pid 1018003:tid 1018256] [client 185.104.184.230:36300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.xvo.oau.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK9RjAh5Y1i2tUxg4H_kgAABiA"] [Sat Aug 29 05:06:46.335166 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.23.184.117:18481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/admin.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_mgAABfk"] [Sat Aug 29 05:06:46.337546 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.18.15:36716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/xmini4.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_nAAABe8"] [Sat Aug 29 05:06:46.339659 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.339671 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.341839 2026] [security2:error] [pid 1018003:tid 1018265] [client 4.205.62.107:65437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/xmy.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_nQAABik"] [Sat Aug 29 05:06:46.348125 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.348138 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.349854 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.48.250.41:21448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/inc.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_nwAABiU"] [Sat Aug 29 05:06:46.355256 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.147.79:48283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_oAAABgI"] [Sat Aug 29 05:06:46.360273 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.18.15:36717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/radio.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_oQAABeQ"] [Sat Aug 29 05:06:46.373916 2026] [security2:error] [pid 1018003:tid 1018170] [client 4.205.62.107:22294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/myfile.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_pAAABcs"] [Sat Aug 29 05:06:46.385083 2026] [core:error] [pid 1018003:tid 1018227] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.385095 2026] [core:error] [pid 1018003:tid 1018227] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.385963 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.385978 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.388134 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.388148 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.389402 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:16132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_qwAABd8"] [Sat Aug 29 05:06:46.390087 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.390096 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.390127 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.390135 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.391311 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.391323 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.392147 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.52.41.200:1153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/admin.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_rgAABdg"] [Sat Aug 29 05:06:46.393485 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.393498 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.393870 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.393879 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.399664 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.399675 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.412201 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:7043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_sgAABi4"] [Sat Aug 29 05:06:46.414854 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.18.15:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/asdfghj.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_swAABcI"] [Sat Aug 29 05:06:46.434489 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.434505 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.435833 2026] [security2:error] [pid 1018003:tid 1018252] [client 168.107.94.195:57590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_tQAABhw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:46.446196 2026] [security2:error] [pid 1018003:tid 1018233] [client 158.23.184.117:34515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/elp.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_uAAABgk"] [Sat Aug 29 05:06:46.461514 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.461537 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.461890 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:35263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_uwAABdA"] [Sat Aug 29 05:06:46.462626 2026] [security2:error] [pid 1018003:tid 1018224] [client 52.139.37.240:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/aged.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_vAAABgE"] [Sat Aug 29 05:06:46.469569 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.18.15:36609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/gulu.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_vgAABd0"] [Sat Aug 29 05:06:46.479937 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.184.117:19347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/api.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_wQAABf8"] [Sat Aug 29 05:06:46.489380 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.489401 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.492573 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.196.209.81:17860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/gecko-new.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_wwAABhI"] [Sat Aug 29 05:06:46.508044 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.104.18.15:36788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/one.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_zQAABgY"] [Sat Aug 29 05:06:46.513623 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.151.200.44:64361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/blox.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_zgAABec"] [Sat Aug 29 05:06:46.522124 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.48.250.41:21475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/6bcwiqwj.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_0QAABho"] [Sat Aug 29 05:06:46.523012 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.523026 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.525836 2026] [core:error] [pid 1018003:tid 1018167] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.525852 2026] [core:error] [pid 1018003:tid 1018167] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.526611 2026] [security2:error] [pid 1018003:tid 1018243] [client 45.148.10.62:49738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ninaanddon.strangeworx.com"] [uri "/wp-config.php.old"] [unique_id "apK9RjAh5Y1i2tUxg4H_0wAABhM"] [Sat Aug 29 05:06:46.528603 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.528617 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.541498 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.220.204.93:52295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/8.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_1QAABeU"] [Sat Aug 29 05:06:46.542121 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.49.130:60939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/berlin.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_1gAABiA"] [Sat Aug 29 05:06:46.546751 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.49.130:57505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/sta.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_1wAABio"] [Sat Aug 29 05:06:46.555075 2026] [security2:error] [pid 1018003:tid 1018185] [client 68.155.159.216:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_3wAABdo"] [Sat Aug 29 05:06:46.557937 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_4gAABbw"] [Sat Aug 29 05:06:46.562086 2026] [security2:error] [pid 1018003:tid 1018206] [client 158.23.147.79:32733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/admin.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_6AAABe8"] [Sat Aug 29 05:06:46.566175 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.18.15:7979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/dragonshell.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_7gAABgk"] [Sat Aug 29 05:06:46.567925 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.18.15:7018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/xmini4.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_7wAABcU"] [Sat Aug 29 05:06:46.572055 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:30548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4H_8QAABdA"] [Sat Aug 29 05:06:46.576494 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.576510 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.577914 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.577930 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.579403 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.579425 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.580207 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.580217 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.584027 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.584041 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.585185 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.585202 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.585701 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.585710 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.586691 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.586705 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.588577 2026] [core:error] [pid 1018003:tid 1018166] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.588600 2026] [core:error] [pid 1018003:tid 1018166] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.589722 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.589733 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.592272 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.184.117:34521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/Exception-class.php"] [unique_id "apK9RjAh5Y1i2tUxg4H__AAABb0"] [Sat Aug 29 05:06:46.594320 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.151.200.44:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/wsz.php"] [unique_id "apK9RjAh5Y1i2tUxg4H__QAABfU"] [Sat Aug 29 05:06:46.614004 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.18.15:36663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/replace.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAAQAABbw"] [Sat Aug 29 05:06:46.620524 2026] [security2:error] [pid 1018003:tid 1018172] [client 158.23.184.117:19310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/chosen.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAAgAABc0"] [Sat Aug 29 05:06:46.630723 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.630739 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.632010 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.151.200.44:46636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/fgd.php"] [unique_id "apK9RjAh5Y1i2tUxg4EABgAABiY"] [Sat Aug 29 05:06:46.665971 2026] [security2:error] [pid 1018003:tid 1018169] [client 52.139.37.240:61672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/essexec.php"] [unique_id "apK9RjAh5Y1i2tUxg4EACQAABco"] [Sat Aug 29 05:06:46.669764 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.151.200.44:64415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/kcs.php"] [unique_id "apK9RjAh5Y1i2tUxg4EACgAABik"] [Sat Aug 29 05:06:46.670405 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.18.15:36784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/503.php"] [unique_id "apK9RjAh5Y1i2tUxg4EACwAABfo"] [Sat Aug 29 05:06:46.671675 2026] [security2:error] [pid 1018003:tid 1018213] [client 68.155.159.216:50411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/images/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4EADAAABfY"] [Sat Aug 29 05:06:46.682486 2026] [security2:error] [pid 1018003:tid 1018255] [client 40.83.93.50:23974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAEgAABh8"] [Sat Aug 29 05:06:46.685012 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.685028 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.685549 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.220.204.93:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/0x0x.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAFQAABcs"] [Sat Aug 29 05:06:46.687164 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.687179 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.695379 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.250.41:21451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/easy.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAGQAABf4"] [Sat Aug 29 05:06:46.695802 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.158.54.35:28370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-access.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAGAAABg4"] [Sat Aug 29 05:06:46.697242 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.104.18.15:8111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-safe.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAGgAABg8"] [Sat Aug 29 05:06:46.697479 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.18.15:7039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/gulu.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAGwAABfs"] [Sat Aug 29 05:06:46.725732 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.725745 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.728308 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.728320 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.728962 2026] [core:error] [pid 1018003:tid 1018153] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.728974 2026] [core:error] [pid 1018003:tid 1018153] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.737835 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.184.117:33942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/ee.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAIQAABgo"] [Sat Aug 29 05:06:46.757364 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:49160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAMQAABgk"] [Sat Aug 29 05:06:46.772044 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.18.15:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/c4.php"] [unique_id "apK9RjAh5Y1i2tUxg4EANgAABdA"] [Sat Aug 29 05:06:46.777568 2026] [security2:error] [pid 1018003:tid 1018186] [client 158.23.147.79:30638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4EANwAABds"] [Sat Aug 29 05:06:46.777896 2026] [security2:error] [pid 1018003:tid 1018185] [client 68.155.159.216:51887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/images/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAOAAABdo"] [Sat Aug 29 05:06:46.781095 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.184.117:19274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/config.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAOgAABb4"] [Sat Aug 29 05:06:46.784094 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.784106 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.786029 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.786043 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.790523 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.790523 2026] [core:error] [pid 1018003:tid 1018216] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.790537 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.790545 2026] [core:error] [pid 1018003:tid 1018216] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.791666 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.791677 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.798180 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.197.61.180:7780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/csv.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAQgAABcE"] [Sat Aug 29 05:06:46.799297 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.799306 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.801277 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.801287 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.803438 2026] [core:error] [pid 1018003:tid 1018255] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.803453 2026] [core:error] [pid 1018003:tid 1018255] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.806016 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.806027 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.806134 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.806141 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.809172 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.809181 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.809748 2026] [security2:error] [pid 1018003:tid 1018271] [client 4.205.62.107:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/btx25.php"] [unique_id "apK9RjAh5Y1i2tUxg4EASAAABi8"] [Sat Aug 29 05:06:46.812922 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.151.200.44:64336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/wsz.php"] [unique_id "apK9RjAh5Y1i2tUxg4EASQAABbo"] [Sat Aug 29 05:06:46.815227 2026] [security2:error] [pid 1018003:tid 1018163] [client 168.107.94.195:58035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4EASgAABcQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:46.828478 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.18.15:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/gjewuagf.php"] [unique_id "apK9RjAh5Y1i2tUxg4EASwAABjM"] [Sat Aug 29 05:06:46.838779 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.220.204.93:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/166.php"] [unique_id "apK9RjAh5Y1i2tUxg4EATAAABi4"] [Sat Aug 29 05:06:46.845472 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.250.41:21389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/fresh3.php"] [unique_id "apK9RjAh5Y1i2tUxg4EATQAABcU"] [Sat Aug 29 05:06:46.847137 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:25528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/.well-known/content.php"] [unique_id "apK9RjAh5Y1i2tUxg4EATwAABdA"] [Sat Aug 29 05:06:46.848210 2026] [cgid:error] [pid 1018003:tid 1018250] [client 20.52.41.200:1243] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:46.854949 2026] [core:error] [pid 1018003:tid 1018111] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.854960 2026] [core:error] [pid 1018003:tid 1018111] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.856636 2026] [security2:error] [pid 1018003:tid 1018226] [client 52.139.37.240:2595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/fw.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAUQAABgM"] [Sat Aug 29 05:06:46.860332 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.151.200.44:47371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/inject.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAUwAABc0"] [Sat Aug 29 05:06:46.868919 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.104.18.15:36781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/504.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAVQAABfk"] [Sat Aug 29 05:06:46.886883 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.886899 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.896122 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.896134 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.922617 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.922656 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.922894 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.196.209.81:17884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/wp-admin.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAYAAABd8"] [Sat Aug 29 05:06:46.925623 2026] [security2:error] [pid 1018003:tid 1018221] [client 68.155.159.216:6035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAYQAABf4"] [Sat Aug 29 05:06:46.926900 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.23.184.117:34742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/edit.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAYwAABgE"] [Sat Aug 29 05:06:46.929538 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.18.15:36675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/rxr.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAZAAABfs"] [Sat Aug 29 05:06:46.929928 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.184.117:19283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/core.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAZQAABco"] [Sat Aug 29 05:06:46.934169 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.934189 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.947211 2026] [security2:error] [pid 1018003:tid 1018243] [client 4.205.62.107:53374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/admin-ajax.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAZgAABhM"] [Sat Aug 29 05:06:46.947593 2026] [security2:error] [pid 1018003:tid 1018188] [client 68.155.159.216:30667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAaAAABd0"] [Sat Aug 29 05:06:46.950814 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.18.15:6976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/replace.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAaQAABcc"] [Sat Aug 29 05:06:46.956022 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.151.200.44:64396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/msy.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAawAABiI"] [Sat Aug 29 05:06:46.958775 2026] [security2:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.wp-config.php.swp"] [unique_id "apK9RjAh5Y1i2tUxg4EAbQAFz18"] [Sat Aug 29 05:06:46.963695 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.18.15:8150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/tnglzqmv.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAcQAABi8"] [Sat Aug 29 05:06:46.974281 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.151.200.44:64316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/msy.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAdwAABcI"] [Sat Aug 29 05:06:46.974617 2026] [security2:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9RjAh5Y1i2tUxg4EAdQAFz2k"] [Sat Aug 29 05:06:46.976991 2026] [security2:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9RjAh5Y1i2tUxg4EAegAFz2o"] [Sat Aug 29 05:06:46.977093 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.977105 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.979009 2026] [core:error] [pid 1018003:tid 1018132] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.979022 2026] [core:error] [pid 1018003:tid 1018132] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.987777 2026] [core:error] [pid 1018003:tid 1018163] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.987789 2026] [core:error] [pid 1018003:tid 1018163] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.992143 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.992154 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:46.997493 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.52.41.200:1243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/lock360.php"] [unique_id "apK9RjAh5Y1i2tUxg4EAgQAABgk"] [Sat Aug 29 05:06:47.010158 2026] [cgid:error] [pid 1018003:tid 1018217] [client 45.156.129.121:40300] AH01264: stderr from /home1/acovibco/public_html/metlane/cgi-bin/authLogin.cgi: script not found or unable to stat, referer: http://metlane.com/cgi-bin/authLogin.cgi [Sat Aug 29 05:06:47.015251 2026] [security2:error] [pid 1018003:tid 1018194] [client 52.139.37.240:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/zwso.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAgwAABeM"] [Sat Aug 29 05:06:47.017484 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.18.15:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/admin.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAhAAABgc"] [Sat Aug 29 05:06:47.022064 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.220.204.93:59042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/h2a2ck.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAiAAABfY"] [Sat Aug 29 05:06:47.023928 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.023940 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.024205 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.024215 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.024214 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.024226 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.026602 2026] [core:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.026614 2026] [core:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.028929 2026] [security2:error] [pid 1018003:tid 1018177] [client 68.155.159.216:51798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/content.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAigAABdI"] [Sat Aug 29 05:06:47.036611 2026] [security2:error] [pid 1018003:tid 1018198] [client 52.139.37.240:32753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/up.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAjAAABec"] [Sat Aug 29 05:06:47.039287 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.039305 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.059615 2026] [security2:error] [pid 1018003:tid 1018270] [client 52.139.37.240:2607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/zwso.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAjQAABi4"] [Sat Aug 29 05:06:47.072015 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.147.79:24509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAkAAABco"] [Sat Aug 29 05:06:47.072299 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.184.117:34735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/f35.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAkQAABb4"] [Sat Aug 29 05:06:47.072970 2026] [core:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.072983 2026] [core:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.073139 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.184.117:19305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/data.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAkgAABhY"] [Sat Aug 29 05:06:47.073337 2026] [security2:error] [pid 1018003:tid 1018226] [client 52.139.37.240:21384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/breads1.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAkwAABgM"] [Sat Aug 29 05:06:47.073961 2026] [core:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.073972 2026] [core:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.078893 2026] [core:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.078907 2026] [core:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.087555 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.48.250.41:21495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/bgymj.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAlQAABhM"] [Sat Aug 29 05:06:47.092896 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.18.15:36669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amandaandandrew.strangeworx.com"] [uri "/reviall.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAlgAABgw"] [Sat Aug 29 05:06:47.105960 2026] [security2:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EAmQAGBm0"] [Sat Aug 29 05:06:47.110353 2026] [security2:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EAmgAF3HY"] [Sat Aug 29 05:06:47.120448 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.18.15:7086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/c4.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAnAAABcQ"] [Sat Aug 29 05:06:47.120669 2026] [security2:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EAmwAGCms"] [Sat Aug 29 05:06:47.125317 2026] [security2:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EAngAGCXs"] [Sat Aug 29 05:06:47.125341 2026] [security2:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EAnQAGCXk"] [Sat Aug 29 05:06:47.126972 2026] [core:error] [pid 1018003:tid 1018137] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.126985 2026] [core:error] [pid 1018003:tid 1018137] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.139947 2026] [security2:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EAoQAGB2g"] [Sat Aug 29 05:06:47.140176 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.147.79:58093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAowAABeM"] [Sat Aug 29 05:06:47.140197 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.158.54.35:35205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAogAABhA"] [Sat Aug 29 05:06:47.141455 2026] [security2:error] [pid 1018003:tid 1018225] [client 52.139.37.240:30807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9RzAh5Y1i2tUxg4EApAAABgI"] [Sat Aug 29 05:06:47.142246 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.18.15:8118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wefile.php"] [unique_id "apK9RzAh5Y1i2tUxg4EApQAABik"] [Sat Aug 29 05:06:47.147560 2026] [security2:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EApgAGIGw"] [Sat Aug 29 05:06:47.158969 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.220.204.93:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/error_log.php"] [unique_id "apK9RzAh5Y1i2tUxg4EApwAABis"] [Sat Aug 29 05:06:47.177103 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:36674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ws85.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAqQAABcA"] [Sat Aug 29 05:06:47.181148 2026] [security2:error] [pid 1018003:tid 1018172] [client 40.83.93.50:23959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/languages/index.php"] [unique_id "apK9RzAh5Y1i2tUxg4EArAAABc0"] [Sat Aug 29 05:06:47.186980 2026] [security2:error] [pid 1018003:tid 1018161] [client 52.139.37.240:8456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/upfile.php"] [unique_id "apK9RzAh5Y1i2tUxg4EArgAABcI"] [Sat Aug 29 05:06:47.196006 2026] [security2:error] [pid 1018003:tid 1018275] [client 4.205.62.107:21571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/ms-edit.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAtAAABjM"] [Sat Aug 29 05:06:47.196013 2026] [security2:error] [pid 1018003:tid 1018255] [client 168.107.94.195:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAswAABh8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:47.205382 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.147.79:17424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/goods.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAtwAABdQ"] [Sat Aug 29 05:06:47.209074 2026] [security2:error] [pid 1018003:tid 1018189] [client 52.139.37.240:33587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/admin/function.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAuQAABd4"] [Sat Aug 29 05:06:47.211343 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:26488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAuwAABc8"] [Sat Aug 29 05:06:47.216802 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.184.117:19276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/db-status.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAvgAABdc"] [Sat Aug 29 05:06:47.220121 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.23.184.117:34699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/fff.php"] [unique_id "apK9RzAh5Y1i2tUxg4EAwQAABiw"] [Sat Aug 29 05:06:47.220747 2026] [core:error] [pid 1018003:tid 1018167] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.220759 2026] [core:error] [pid 1018003:tid 1018167] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.224746 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.224763 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.224904 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.224919 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.224981 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.224994 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.226533 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.226544 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.247703 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.247720 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.255389 2026] [security2:error] [pid 1018003:tid 1018250] [client 68.155.159.216:18182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/cong.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA0AAABho"] [Sat Aug 29 05:06:47.258246 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.18.15:7016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/rxr.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA0gAABfo"] [Sat Aug 29 05:06:47.268634 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.268658 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.271598 2026] [security2:error] [pid 1018003:tid 1018184] [client 52.139.37.240:61669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/admin/function.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA2gAABdk"] [Sat Aug 29 05:06:47.273106 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.48.250.41:21482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ws69.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA2wAABdk"] [Sat Aug 29 05:06:47.274173 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.274190 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.284267 2026] [security2:error] [pid 1018003:tid 1018212] [client 52.139.37.240:20771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/must.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA4AAABfU"] [Sat Aug 29 05:06:47.286459 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.286477 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.286810 2026] [security2:error] [pid 1018003:tid 1018153] [client 45.148.10.62:49748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninaanddon.strangeworx.com"] [uri "/config.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA4gAABbo"] [Sat Aug 29 05:06:47.294643 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.220.204.93:59118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/403.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA6wAABek"] [Sat Aug 29 05:06:47.294750 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.294765 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.295315 2026] [security2:error] [pid 1018003:tid 1018170] [client 52.139.37.240:32748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-content/155.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA7AAABcs"] [Sat Aug 29 05:06:47.296725 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.18.15:8027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/blog.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA7QAABfs"] [Sat Aug 29 05:06:47.301819 2026] [security2:error] [pid 1018003:tid 1018252] [client 45.61.187.50:64523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "succulentideas.com"] [uri "/wp-content/plugins/wp_gljbkwx/wp_gljbkwx.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA7wAABhw"] [Sat Aug 29 05:06:47.314758 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.314778 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.316075 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.316088 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.316238 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.316249 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.318620 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.23.147.79:50072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-admin/about.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA9QAABdw"] [Sat Aug 29 05:06:47.334233 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.334246 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.335684 2026] [core:error] [pid 1018003:tid 1018166] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.335707 2026] [core:error] [pid 1018003:tid 1018166] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.339523 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.339535 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.346307 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.196.209.81:17903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/wp-configs.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA-wAABf8"] [Sat Aug 29 05:06:47.358883 2026] [security2:error] [pid 1018003:tid 1018258] [client 158.23.184.117:19345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/f35.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA_QAABiI"] [Sat Aug 29 05:06:47.365176 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.184.117:34734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/ff1.php"] [unique_id "apK9RzAh5Y1i2tUxg4EA_wAABiU"] [Sat Aug 29 05:06:47.371979 2026] [http2:info] [pid 1028675:tid 1028675] h2_workers: created with min=128 max=192 idle_ms=600000 [Sat Aug 29 05:06:47.375555 2026] [security2:error] [pid 1018003:tid 1018239] [client 68.155.159.216:33614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/lv.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBAQAABg8"] [Sat Aug 29 05:06:47.377093 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.18.15:36773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ffs.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBAwAABek"] [Sat Aug 29 05:06:47.377335 2026] [security2:error] [pid 1018003:tid 1018195] [client 52.139.37.240:8473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/form.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBBAAABeQ"] [Sat Aug 29 05:06:47.384655 2026] [autoindex:error] [pid 1018003:tid 1018196] [client 52.139.37.240:0] AH01276: Cannot serve directory /home4/swumccom/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:47.402600 2026] [core:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.402789 2026] [core:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.405221 2026] [security2:error] [pid 1018003:tid 1018217] [client 52.139.37.240:33571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/zoom1.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBDAAABfo"] [Sat Aug 29 05:06:47.407124 2026] [core:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.407140 2026] [core:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.422521 2026] [core:error] [pid 1018003:tid 1018047] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.422541 2026] [core:error] [pid 1018003:tid 1018047] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.442872 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.18.15:8094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBEQAABbw"] [Sat Aug 29 05:06:47.445883 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.445902 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.456271 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.52.41.200:1238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-conflg.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBFAAABhY"] [Sat Aug 29 05:06:47.457932 2026] [security2:error] [pid 1018003:tid 1018202] [client 213.202.253.4:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/wp-content/txets.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBFQAABes"], referer: www.google.com [Sat Aug 29 05:06:47.461239 2026] [security2:error] [pid 1018003:tid 1018164] [client 4.205.62.107:22269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/infos.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBFgAABcU"] [Sat Aug 29 05:06:47.470777 2026] [security2:error] [pid 1018003:tid 1018186] [client 4.205.62.107:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ms-edit.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBGAAABds"] [Sat Aug 29 05:06:47.470830 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.470841 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.473037 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.473054 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.474438 2026] [security2:error] [pid 1018003:tid 1018250] [client 52.139.37.240:31493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/z.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBGQAABho"] [Sat Aug 29 05:06:47.474583 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.48.250.41:21391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ccs.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBGgAABgI"] [Sat Aug 29 05:06:47.476827 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.18.15:7064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moderntechservices.com"] [uri "/reviall.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBHAAABis"] [Sat Aug 29 05:06:47.477506 2026] [security2:error] [pid 1018003:tid 1018252] [client 52.139.37.240:2587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/zoom1.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBHQAABhw"] [Sat Aug 29 05:06:47.482136 2026] [security2:error] [pid 1018003:tid 1018243] [client 52.139.37.240:20741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/up.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBIAAABhM"] [Sat Aug 29 05:06:47.490436 2026] [security2:error] [pid 1018003:tid 1018242] [client 52.139.37.240:52217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-update.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBJgAABhI"] [Sat Aug 29 05:06:47.500034 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.500049 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.501388 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.184.117:19351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBKQAABcg"] [Sat Aug 29 05:06:47.509264 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.184.117:34703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/flower.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBLAAABgM"] [Sat Aug 29 05:06:47.515880 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.515901 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.524345 2026] [core:error] [pid 1028675:tid 1028825] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.524377 2026] [core:error] [pid 1028675:tid 1028825] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.524998 2026] [security2:error] [pid 1018003:tid 1018189] [client 4.205.62.107:22327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/thui.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBMwAABd4"] [Sat Aug 29 05:06:47.526872 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.526889 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.527219 2026] [core:error] [pid 1028675:tid 1028828] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.527232 2026] [core:error] [pid 1028675:tid 1028828] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.527597 2026] [core:error] [pid 1018003:tid 1018227] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.527621 2026] [core:error] [pid 1018003:tid 1018227] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.527642 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.527653 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.528561 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.528576 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.531233 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.531246 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.531826 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.531841 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.550968 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.104.18.15:36726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/nano.php"] [unique_id "apK9R9dHPfW2QFvhmL7LsAAAABs"] [Sat Aug 29 05:06:47.551233 2026] [security2:error] [pid 1028675:tid 1028836] [client 20.220.204.93:59096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/cytyr.php"] [unique_id "apK9R9dHPfW2QFvhmL7LsQAAABo"] [Sat Aug 29 05:06:47.553682 2026] [security2:error] [pid 1018003:tid 1018040] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EBOQAGLBM"] [Sat Aug 29 05:06:47.571801 2026] [security2:error] [pid 1028675:tid 1028834] [client 57.141.14.89:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/"] [unique_id "apK9R9dHPfW2QFvhmL7LsgAAABg"] [Sat Aug 29 05:06:47.576009 2026] [security2:error] [pid 1028675:tid 1028847] [client 168.107.94.195:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9R9dHPfW2QFvhmL7LtQAAACU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:47.579273 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.579294 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.583398 2026] [security2:error] [pid 1028675:tid 1028826] [client 52.139.37.240:8468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/wp-sigunq.php"] [unique_id "apK9R9dHPfW2QFvhmL7LtgAAABA"] [Sat Aug 29 05:06:47.591462 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.158.54.35:11336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBPQAABdQ"] [Sat Aug 29 05:06:47.600320 2026] [core:error] [pid 1028675:tid 1028850] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.600337 2026] [core:error] [pid 1028675:tid 1028850] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.601446 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.18.15:8112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/robot.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBPgAABgk"] [Sat Aug 29 05:06:47.602010 2026] [security2:error] [pid 1028675:tid 1028852] [client 158.23.147.79:35758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/login.php"] [unique_id "apK9R9dHPfW2QFvhmL7LuAAAACo"] [Sat Aug 29 05:06:47.627123 2026] [security2:error] [pid 1028675:tid 1028838] [client 52.139.37.240:32836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/about.php7"] [unique_id "apK9R9dHPfW2QFvhmL7LuQAAABw"] [Sat Aug 29 05:06:47.641919 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.48.250.41:21439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/mar.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBQgAABhM"] [Sat Aug 29 05:06:47.642280 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.197.61.180:11597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/fox.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBQwAABcs"] [Sat Aug 29 05:06:47.643288 2026] [core:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.643308 2026] [core:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.645073 2026] [security2:error] [pid 1028675:tid 1028851] [client 158.23.184.117:19329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/home.php"] [unique_id "apK9R9dHPfW2QFvhmL7LugAAACk"] [Sat Aug 29 05:06:47.649330 2026] [security2:error] [pid 1028675:tid 1028821] [client 40.83.93.50:1790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/languages/min.php"] [unique_id "apK9R9dHPfW2QFvhmL7LvAAAAAs"] [Sat Aug 29 05:06:47.661864 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:9227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/radio.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBRQAABdc"] [Sat Aug 29 05:06:47.668775 2026] [security2:error] [pid 1028675:tid 1028868] [client 158.23.147.79:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/xmlrpc.php"] [unique_id "apK9R9dHPfW2QFvhmL7LvQAAADo"] [Sat Aug 29 05:06:47.668992 2026] [core:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.669173 2026] [core:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.670719 2026] [security2:error] [pid 1028675:tid 1028867] [client 20.104.49.130:39054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/pfm.php"] [unique_id "apK9R9dHPfW2QFvhmL7LvgAAADk"] [Sat Aug 29 05:06:47.671796 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.671812 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.673221 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.184.117:33933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/file.php"] [unique_id "apK9R9dHPfW2QFvhmL7LwAAAADA"] [Sat Aug 29 05:06:47.673851 2026] [security2:error] [pid 1028675:tid 1028869] [client 68.155.159.216:56519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9R9dHPfW2QFvhmL7LwQAAADs"] [Sat Aug 29 05:06:47.673915 2026] [security2:error] [pid 1028675:tid 1028853] [client 52.139.37.240:2598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/about.php7"] [unique_id "apK9R9dHPfW2QFvhmL7LwgAAACs"] [Sat Aug 29 05:06:47.675166 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.675184 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.675901 2026] [security2:error] [pid 1028675:tid 1028855] [client 52.139.37.240:31506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/f35.php"] [unique_id "apK9R9dHPfW2QFvhmL7LwwAAAC0"] [Sat Aug 29 05:06:47.676115 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.676128 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.676756 2026] [core:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.676767 2026] [core:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.680696 2026] [core:error] [pid 1028675:tid 1028856] [client 52.139.37.240:21438] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.680708 2026] [core:error] [pid 1028675:tid 1028856] [client 52.139.37.240:21438] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.690906 2026] [security2:error] [pid 1028675:tid 1028870] [client 158.23.147.79:30570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9R9dHPfW2QFvhmL7LxQAAADw"] [Sat Aug 29 05:06:47.691557 2026] [security2:error] [pid 1018003:tid 1018267] [client 52.139.37.240:32020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/xmrlpc.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBTAAABis"] [Sat Aug 29 05:06:47.695353 2026] [core:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.695374 2026] [core:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.707610 2026] [core:error] [pid 1028675:tid 1028877] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.707629 2026] [core:error] [pid 1028675:tid 1028877] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.712089 2026] [security2:error] [pid 1028675:tid 1028879] [client 20.220.204.93:50801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/galer.php"] [unique_id "apK9R9dHPfW2QFvhmL7LyAAAAEU"] [Sat Aug 29 05:06:47.719794 2026] [security2:error] [pid 1018003:tid 1018075] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EBUgAGHDY"] [Sat Aug 29 05:06:47.721035 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.721051 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.721067 2026] [core:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.721074 2026] [core:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.721767 2026] [core:error] [pid 1018003:tid 1018083] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.721780 2026] [core:error] [pid 1018003:tid 1018083] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.723215 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.104.18.15:36645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ano.php"] [unique_id "apK9R9dHPfW2QFvhmL7LyQAAAEo"] [Sat Aug 29 05:06:47.730814 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.730829 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.734551 2026] [security2:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EBVQAGHEA"] [Sat Aug 29 05:06:47.747000 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.49.130:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBVgAABf4"] [Sat Aug 29 05:06:47.758404 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.758427 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.759305 2026] [security2:error] [pid 1028675:tid 1028893] [client 20.104.18.15:8062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/revo.php"] [unique_id "apK9R9dHPfW2QFvhmL7LzAAAAFM"] [Sat Aug 29 05:06:47.764856 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.196.209.81:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/essexec.php"] [unique_id "apK9R9dHPfW2QFvhmL7LzQAAADI"] [Sat Aug 29 05:06:47.775511 2026] [security2:error] [pid 1028675:tid 1028897] [client 68.155.159.216:50310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9R9dHPfW2QFvhmL7LzgAAAFc"] [Sat Aug 29 05:06:47.777523 2026] [security2:error] [pid 1018003:tid 1018275] [client 52.139.37.240:8624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drjrae.com"] [uri "/07.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBWAAABjM"] [Sat Aug 29 05:06:47.783180 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.48.250.41:21490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ccu.php"] [unique_id "apK9R9dHPfW2QFvhmL7LzwAAAFk"] [Sat Aug 29 05:06:47.788394 2026] [security2:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EBWQAGLkc"] [Sat Aug 29 05:06:47.790097 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.184.117:19350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/index.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBWwAABew"] [Sat Aug 29 05:06:47.818280 2026] [security2:error] [pid 1028675:tid 1028895] [client 158.23.184.117:34537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/goods.php"] [unique_id "apK9R9dHPfW2QFvhmL7L0QAAAFU"] [Sat Aug 29 05:06:47.821569 2026] [security2:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9RzAh5Y1i2tUxg4EBXAAF2iU"] [Sat Aug 29 05:06:47.826203 2026] [security2:error] [pid 1018003:tid 1018239] [client 52.139.37.240:33584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/cron.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBXgAABg8"] [Sat Aug 29 05:06:47.829198 2026] [core:error] [pid 1018003:tid 1018089] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.829213 2026] [core:error] [pid 1018003:tid 1018089] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.840875 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.840887 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.843811 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.843826 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.844349 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.844371 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.849836 2026] [core:error] [pid 1018003:tid 1018097] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.849851 2026] [core:error] [pid 1018003:tid 1018097] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.851978 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.851990 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.856768 2026] [core:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.856782 2026] [core:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.867344 2026] [core:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.867365 2026] [core:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.869711 2026] [security2:error] [pid 1028675:tid 1028904] [client 52.139.37.240:2906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/cron.php"] [unique_id "apK9R9dHPfW2QFvhmL7L1QAAAF4"] [Sat Aug 29 05:06:47.873518 2026] [security2:error] [pid 1028675:tid 1028905] [client 52.139.37.240:30792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/file61.php"] [unique_id "apK9R9dHPfW2QFvhmL7L1gAAAF8"] [Sat Aug 29 05:06:47.878842 2026] [security2:error] [pid 1018003:tid 1018256] [client 68.155.159.216:49171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBaAAABiA"] [Sat Aug 29 05:06:47.881484 2026] [core:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.881495 2026] [core:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.883522 2026] [security2:error] [pid 1028675:tid 1028907] [client 52.139.37.240:32743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/about/function.php"] [unique_id "apK9R9dHPfW2QFvhmL7L2AAAAGE"] [Sat Aug 29 05:06:47.887066 2026] [security2:error] [pid 1028675:tid 1028927] [client 158.23.147.79:30543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9R9dHPfW2QFvhmL7L2wAAAHU"] [Sat Aug 29 05:06:47.896871 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:8133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/birrs.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBbQAABeE"] [Sat Aug 29 05:06:47.900012 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.900027 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.900811 2026] [core:error] [pid 1028675:tid 1028928] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.900826 2026] [core:error] [pid 1028675:tid 1028928] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.900953 2026] [security2:error] [pid 1028675:tid 1028906] [client 52.139.37.240:21415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-content/155.php"] [unique_id "apK9R9dHPfW2QFvhmL7L3QAAAGA"] [Sat Aug 29 05:06:47.911529 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.52.41.200:1788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/123.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBbgAABfY"] [Sat Aug 29 05:06:47.914061 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.220.204.93:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/baixy.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBbwAABio"] [Sat Aug 29 05:06:47.921668 2026] [core:error] [pid 1028675:tid 1028932] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.922927 2026] [core:error] [pid 1028675:tid 1028932] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.927740 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.927761 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.936820 2026] [security2:error] [pid 1028675:tid 1028924] [client 158.23.184.117:19335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/login.php"] [unique_id "apK9R9dHPfW2QFvhmL7L4AAAAHI"] [Sat Aug 29 05:06:47.947731 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.250.41:21476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ak.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBcQAABcE"] [Sat Aug 29 05:06:47.948569 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.18.15:36732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/mgrr.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBcgAABgk"] [Sat Aug 29 05:06:47.950246 2026] [core:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.950265 2026] [core:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.951785 2026] [security2:error] [pid 1018003:tid 1018190] [client 4.205.62.107:56019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/app_dev.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBcwAABd8"] [Sat Aug 29 05:06:47.952101 2026] [security2:error] [pid 1028675:tid 1028831] [client 158.23.147.79:25413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/cong.php"] [unique_id "apK9R9dHPfW2QFvhmL7L4QAAABU"] [Sat Aug 29 05:06:47.955381 2026] [security2:error] [pid 1028675:tid 1028832] [client 168.107.94.195:58947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9R9dHPfW2QFvhmL7L4gAAABY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:47.956915 2026] [core:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.956931 2026] [core:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.966350 2026] [security2:error] [pid 1028675:tid 1028818] [client 158.23.147.79:48365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/lock.php"] [unique_id "apK9R9dHPfW2QFvhmL7L4wAAAAg"] [Sat Aug 29 05:06:47.967161 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.184.117:33926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/g.php"] [unique_id "apK9RzAh5Y1i2tUxg4EBdQAABbw"] [Sat Aug 29 05:06:47.977660 2026] [security2:error] [pid 1028675:tid 1028933] [client 52.139.37.240:8502] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.drjrae.com"] [uri "/c99.php"] [unique_id "apK9R9dHPfW2QFvhmL7L5AAAAHs"] [Sat Aug 29 05:06:47.978757 2026] [security2:error] [pid 1028675:tid 1028903] [client 87.219.197.128:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9R9dHPfW2QFvhmL7L5QAAAF0"] [Sat Aug 29 05:06:47.978869 2026] [security2:error] [pid 1028675:tid 1028903] [client 87.219.197.128:54881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9R9dHPfW2QFvhmL7L5QAAAF0"] [Sat Aug 29 05:06:47.982304 2026] [core:error] [pid 1018003:tid 1018091] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.982318 2026] [core:error] [pid 1018003:tid 1018091] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.982736 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.982751 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.990806 2026] [core:error] [pid 1018003:tid 1018074] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:47.990820 2026] [core:error] [pid 1018003:tid 1018074] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.025374 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.025398 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.026044 2026] [security2:error] [pid 1018003:tid 1018189] [client 68.155.159.216:6023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBggAABd4"] [Sat Aug 29 05:06:48.026592 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.026617 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.029701 2026] [security2:error] [pid 1028675:tid 1028839] [client 52.139.37.240:33586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/wp-2019.php"] [unique_id "apK9SNdHPfW2QFvhmL7L7AAAAB0"] [Sat Aug 29 05:06:48.031019 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.031034 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.033619 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.033640 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.040043 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.104.18.15:8055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/sss.php"] [unique_id "apK9SNdHPfW2QFvhmL7L7gAAACw"] [Sat Aug 29 05:06:48.044078 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.18.15:13652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBgwAABeQ"] [Sat Aug 29 05:06:48.060152 2026] [security2:error] [pid 1028675:tid 1028929] [client 158.158.54.35:11367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/bthil.php"] [unique_id "apK9SNdHPfW2QFvhmL7L8AAAAHc"] [Sat Aug 29 05:06:48.073037 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.220.204.93:52348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ava.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBhgAABek"] [Sat Aug 29 05:06:48.076881 2026] [core:error] [pid 1028675:tid 1028817] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.076902 2026] [core:error] [pid 1028675:tid 1028817] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.080880 2026] [security2:error] [pid 1028675:tid 1028864] [client 68.155.159.216:24544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9SNdHPfW2QFvhmL7L8wAAADY"] [Sat Aug 29 05:06:48.081197 2026] [security2:error] [pid 1028675:tid 1028852] [client 158.23.184.117:19359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/logs233/index.php"] [unique_id "apK9SNdHPfW2QFvhmL7L9AAAACo"] [Sat Aug 29 05:06:48.086794 2026] [cgid:error] [pid 1028675:tid 1028813] [client 34.7.40.70:4982] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.087316 2026] [security2:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9SDAh5Y1i2tUxg4EBiwAGNV0"] [Sat Aug 29 05:06:48.093003 2026] [cgid:error] [pid 1028675:tid 1028815] [client 34.7.40.70:5032] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.093454 2026] [cgid:error] [pid 1018003:tid 1018202] [client 34.7.40.70:4984] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.093548 2026] [security2:error] [pid 1018003:tid 1018202] [client 34.7.40.70:4984] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9SDAh5Y1i2tUxg4EBjAAABes"] [Sat Aug 29 05:06:48.093655 2026] [cgid:error] [pid 1018003:tid 1018206] [client 34.7.40.70:4972] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.096288 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.096302 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.096651 2026] [cgid:error] [pid 1018003:tid 1018164] [client 34.7.40.70:5054] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.096762 2026] [security2:error] [pid 1018003:tid 1018164] [client 34.7.40.70:5054] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9SDAh5Y1i2tUxg4EBjgAABcU"] [Sat Aug 29 05:06:48.097415 2026] [core:error] [pid 1028675:tid 1028868] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.097430 2026] [core:error] [pid 1028675:tid 1028868] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.099338 2026] [cgid:error] [pid 1018003:tid 1018262] [client 34.7.40.70:5016] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.101876 2026] [cgid:error] [pid 1018003:tid 1018265] [client 34.7.40.70:4994] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.102126 2026] [cgid:error] [pid 1018003:tid 1018186] [client 34.7.40.70:5078] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.102126 2026] [cgid:error] [pid 1018003:tid 1018166] [client 34.7.40.70:5062] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.103273 2026] [cgid:error] [pid 1028675:tid 1028820] [client 34.7.40.70:5100] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.103320 2026] [cgid:error] [pid 1028675:tid 1028825] [client 34.7.40.70:5082] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.103545 2026] [security2:error] [pid 1028675:tid 1028825] [client 34.7.40.70:5082] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9SNdHPfW2QFvhmL7L-wAAAA8"] [Sat Aug 29 05:06:48.103776 2026] [cgid:error] [pid 1018003:tid 1018250] [client 34.7.40.70:5116] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.103911 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.104.18.15:36767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/mac.php"] [unique_id "apK9SNdHPfW2QFvhmL7L_QAAAD4"] [Sat Aug 29 05:06:48.105330 2026] [security2:error] [pid 1018003:tid 1018246] [client 34.7.40.70:5136] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/config/storage.yml"] [unique_id "apK9SDAh5Y1i2tUxg4EBlgAABhY"] [Sat Aug 29 05:06:48.105583 2026] [cgid:error] [pid 1028675:tid 1028833] [client 34.7.40.70:5086] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.105851 2026] [security2:error] [pid 1018003:tid 1018161] [client 34.7.40.70:5000] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/backend/aws.json"] [unique_id "apK9SDAh5Y1i2tUxg4EBmAAABcI"] [Sat Aug 29 05:06:48.105991 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.105999 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.107275 2026] [core:error] [pid 1018003:tid 1018094] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.107289 2026] [core:error] [pid 1018003:tid 1018094] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.107620 2026] [cgid:error] [pid 1028675:tid 1028828] [client 34.7.40.70:5104] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.108269 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.108276 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.108303 2026] [cgid:error] [pid 1028675:tid 1028835] [client 34.7.40.70:5122] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.109408 2026] [cgid:error] [pid 1018003:tid 1018172] [client 34.7.40.70:5146] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.109864 2026] [cgid:error] [pid 1018003:tid 1018268] [client 34.7.40.70:5192] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.111971 2026] [cgid:error] [pid 1018003:tid 1018273] [client 34.7.40.70:5046] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.113085 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.113100 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.113808 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.113827 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.114910 2026] [cgid:error] [pid 1028675:tid 1028837] [client 34.7.40.70:5162] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.115050 2026] [security2:error] [pid 1028675:tid 1028837] [client 34.7.40.70:5162] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9SNdHPfW2QFvhmL7MAgAAABs"] [Sat Aug 29 05:06:48.115511 2026] [cgid:error] [pid 1018003:tid 1018242] [client 34.7.40.70:5220] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.118725 2026] [cgid:error] [pid 1028675:tid 1028836] [client 34.7.40.70:5176] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.119161 2026] [cgid:error] [pid 1018003:tid 1018184] [client 34.7.40.70:5182] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.119528 2026] [cgid:error] [pid 1018003:tid 1018182] [client 34.7.40.70:5252] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.119597 2026] [cgid:error] [pid 1028675:tid 1028810] [client 34.7.40.70:5242] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.121528 2026] [security2:error] [pid 1028675:tid 1028879] [client 4.205.62.107:53420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wdf.php"] [unique_id "apK9SNdHPfW2QFvhmL7MBgAAAEU"] [Sat Aug 29 05:06:48.123042 2026] [cgid:error] [pid 1028675:tid 1028841] [client 34.7.40.70:5258] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.123156 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.48.250.41:21411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/lib.php"] [unique_id "apK9SNdHPfW2QFvhmL7MBwAAAEY"] [Sat Aug 29 05:06:48.127077 2026] [cgid:error] [pid 1018003:tid 1018231] [client 34.7.40.70:5230] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.128351 2026] [cgid:error] [pid 1018003:tid 1018170] [client 34.7.40.70:5240] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.128628 2026] [cgid:error] [pid 1028675:tid 1028822] [client 34.7.40.70:5250] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.130836 2026] [security2:error] [pid 1028675:tid 1028840] [client 40.83.93.50:1767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/languages/pk.php"] [unique_id "apK9SNdHPfW2QFvhmL7MCgAAAB4"] [Sat Aug 29 05:06:48.131044 2026] [cgid:error] [pid 1018003:tid 1018159] [client 34.7.40.70:5206] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.131392 2026] [cgid:error] [pid 1018003:tid 1018243] [client 34.7.40.70:5194] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:48.137130 2026] [security2:error] [pid 1018003:tid 1018271] [client 158.23.184.117:33971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/hplfuns.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBpgAABi8"] [Sat Aug 29 05:06:48.139222 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.151.200.44:64267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/siln.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBqAAABgY"] [Sat Aug 29 05:06:48.143810 2026] [security2:error] [pid 1028675:tid 1028886] [client 20.151.200.44:47332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/mga.php"] [unique_id "apK9SNdHPfW2QFvhmL7MDAAAAEw"] [Sat Aug 29 05:06:48.147273 2026] [security2:error] [pid 1028675:tid 1028887] [client 68.155.159.216:51520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK9SNdHPfW2QFvhmL7MDQAAAE0"] [Sat Aug 29 05:06:48.152926 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.152940 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.159435 2026] [security2:error] [pid 1028675:tid 1028873] [client 158.23.147.79:65489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/ws.php"] [unique_id "apK9SNdHPfW2QFvhmL7MDgAAAD8"] [Sat Aug 29 05:06:48.164567 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.164587 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.171318 2026] [security2:error] [pid 1018003:tid 1018188] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBhQAF3Ts"] [Sat Aug 29 05:06:48.180659 2026] [security2:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9SDAh5Y1i2tUxg4EBqwAF2lc"] [Sat Aug 29 05:06:48.183119 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.18.15:13735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBrgAABdA"] [Sat Aug 29 05:06:48.198515 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.198544 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.210179 2026] [core:error] [pid 1028675:tid 1028910] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.210200 2026] [core:error] [pid 1028675:tid 1028910] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.212742 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.220.204.93:52288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/gdn.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBsgAABbw"] [Sat Aug 29 05:06:48.227840 2026] [security2:error] [pid 1028675:tid 1028897] [client 158.23.184.117:19361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/maintenance.php"] [unique_id "apK9SNdHPfW2QFvhmL7MGgAAAFc"] [Sat Aug 29 05:06:48.248854 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.48.250.41:21487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wp-style.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBtgAABeM"] [Sat Aug 29 05:06:48.250851 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.250870 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.251903 2026] [core:error] [pid 1018003:tid 1018163] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.251920 2026] [core:error] [pid 1018003:tid 1018163] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.271900 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.196.209.81:4151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/hello.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBwgAABhA"] [Sat Aug 29 05:06:48.274934 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.274955 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.275876 2026] [core:error] [pid 1028675:tid 1028926] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.275895 2026] [core:error] [pid 1028675:tid 1028926] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.279596 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.104.18.15:36720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/simple.php"] [unique_id "apK9SNdHPfW2QFvhmL7MIAAAAHE"] [Sat Aug 29 05:06:48.282545 2026] [core:error] [pid 1028675:tid 1028928] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.282564 2026] [core:error] [pid 1028675:tid 1028928] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.284477 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.184.117:34740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/ioxi-o.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBxgAABco"] [Sat Aug 29 05:06:48.284961 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.284973 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.285392 2026] [core:error] [pid 1028675:tid 1028934] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.285406 2026] [core:error] [pid 1028675:tid 1028934] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.287982 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.287996 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.294680 2026] [core:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.294699 2026] [core:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.301082 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.301098 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.303520 2026] [security2:error] [pid 1028675:tid 1028937] [client 158.23.147.79:38778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9SNdHPfW2QFvhmL7MIwAAAH8"] [Sat Aug 29 05:06:48.311554 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.23.147.79:17481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBzQAABcI"] [Sat Aug 29 05:06:48.316997 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.147.79:26573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/asd.php"] [unique_id "apK9SDAh5Y1i2tUxg4EBzgAABew"] [Sat Aug 29 05:06:48.329620 2026] [core:error] [pid 1018003:tid 1018140] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.329637 2026] [core:error] [pid 1018003:tid 1018140] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.330297 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.330318 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.335187 2026] [security2:error] [pid 1018003:tid 1018268] [client 4.205.62.107:22423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/lmfi2.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB0QAABiw"] [Sat Aug 29 05:06:48.335495 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.335513 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.336273 2026] [security2:error] [pid 1028675:tid 1028829] [client 168.107.94.195:59354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9SNdHPfW2QFvhmL7MJgAAABM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:48.337735 2026] [core:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.337747 2026] [core:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.344664 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.104.62:29213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/term.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB0wAABdk"] [Sat Aug 29 05:06:48.353939 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.220.204.93:52326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/f2.php"] [unique_id "apK9SNdHPfW2QFvhmL7MKAAAAAQ"] [Sat Aug 29 05:06:48.363684 2026] [security2:error] [pid 1018003:tid 1018236] [client 68.155.159.216:18200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB1wAABgw"] [Sat Aug 29 05:06:48.365492 2026] [security2:error] [pid 1028675:tid 1028818] [client 158.23.147.79:24493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK9SNdHPfW2QFvhmL7MKQAAAAg"] [Sat Aug 29 05:06:48.367432 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.104.18.15:13707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/ap.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB2AAABgY"] [Sat Aug 29 05:06:48.371850 2026] [security2:error] [pid 1028675:tid 1028824] [client 158.23.184.117:19323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/min.php"] [unique_id "apK9SNdHPfW2QFvhmL7MKwAAAA4"] [Sat Aug 29 05:06:48.372448 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.372460 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.378549 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.52.41.200:1262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/yanz.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB2QAABis"] [Sat Aug 29 05:06:48.387598 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.48.250.41:21467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/browse.php"] [unique_id "apK9SNdHPfW2QFvhmL7MLAAAACY"] [Sat Aug 29 05:06:48.390003 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.197.61.180:16583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/disagraeosc.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB2gAABgE"] [Sat Aug 29 05:06:48.390943 2026] [core:error] [pid 1028675:tid 1028933] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.390956 2026] [core:error] [pid 1028675:tid 1028933] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.393783 2026] [security2:error] [pid 1028675:tid 1028844] [client 68.155.159.216:60765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9SNdHPfW2QFvhmL7MLgAAACI"] [Sat Aug 29 05:06:48.410288 2026] [core:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.410304 2026] [core:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.427555 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.18.15:36723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/xty.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB4AAABiA"] [Sat Aug 29 05:06:48.433076 2026] [security2:error] [pid 1028675:tid 1028857] [client 158.23.147.79:49802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9SNdHPfW2QFvhmL7MLwAAAC8"] [Sat Aug 29 05:06:48.435999 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.23.184.117:34714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/in.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB4wAABfo"] [Sat Aug 29 05:06:48.436521 2026] [security2:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9SDAh5Y1i2tUxg4EB4QAGB20"] [Sat Aug 29 05:06:48.436523 2026] [security2:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9SDAh5Y1i2tUxg4EB4gAGB3g"] [Sat Aug 29 05:06:48.443328 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.443347 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.448408 2026] [core:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.448426 2026] [core:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.449843 2026] [core:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.449857 2026] [core:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.450656 2026] [core:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.450665 2026] [core:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.452379 2026] [core:error] [pid 1018003:tid 1018137] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.452394 2026] [core:error] [pid 1018003:tid 1018137] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.453026 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.453036 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.454971 2026] [security2:error] [pid 1018003:tid 1018243] [client 45.61.187.50:64764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "succulentideas.com"] [uri "/wp-content/plugins/wp_gljbkwx/wp_gljbkwx.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB6gAABhM"] [Sat Aug 29 05:06:48.456658 2026] [core:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.456676 2026] [core:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.478425 2026] [core:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.478446 2026] [core:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.485377 2026] [security2:error] [pid 1018003:tid 1018156] [client 68.155.159.216:33667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB8AAABb0"] [Sat Aug 29 05:06:48.487177 2026] [security2:error] [pid 1028675:tid 1028869] [client 20.220.204.93:50815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/grsiuk.php"] [unique_id "apK9SNdHPfW2QFvhmL7MMgAAADs"] [Sat Aug 29 05:06:48.488267 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.151.200.44:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/f-401.php"] [unique_id "apK9SNdHPfW2QFvhmL7MMwAAAAU"] [Sat Aug 29 05:06:48.519614 2026] [security2:error] [pid 1028675:tid 1028864] [client 158.23.184.117:19340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/module.php"] [unique_id "apK9SNdHPfW2QFvhmL7MNQAAADY"] [Sat Aug 29 05:06:48.523901 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.523920 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.527642 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.48.250.41:21390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/zoo.php"] [unique_id "apK9SNdHPfW2QFvhmL7MNwAAADg"] [Sat Aug 29 05:06:48.529906 2026] [core:error] [pid 1018003:tid 1018170] [client 158.158.54.35:15176] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.529929 2026] [core:error] [pid 1018003:tid 1018170] [client 158.158.54.35:15176] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.532609 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.49.130:42197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/worksec.php"] [unique_id "apK9SNdHPfW2QFvhmL7MOAAAAD0"] [Sat Aug 29 05:06:48.538103 2026] [security2:error] [pid 1028675:tid 1028852] [client 20.104.104.62:28818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/ms-edit.php"] [unique_id "apK9SNdHPfW2QFvhmL7MOQAAACo"] [Sat Aug 29 05:06:48.542851 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.104.18.15:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/media.php"] [unique_id "apK9SNdHPfW2QFvhmL7MOgAAAA8"] [Sat Aug 29 05:06:48.543224 2026] [security2:error] [pid 1018003:tid 1018174] [client 68.155.159.216:16327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-admin.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB9AAABc8"] [Sat Aug 29 05:06:48.551076 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.551090 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.553570 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.151.200.44:65070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/siln.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB9gAABes"] [Sat Aug 29 05:06:48.569475 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.569489 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.581653 2026] [security2:error] [pid 1028675:tid 1028820] [client 158.23.184.117:54171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/info.php"] [unique_id "apK9SNdHPfW2QFvhmL7MPQAAAAo"] [Sat Aug 29 05:06:48.589426 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.104.18.15:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/sallu.php"] [unique_id "apK9SNdHPfW2QFvhmL7MPwAAADU"] [Sat Aug 29 05:06:48.590897 2026] [core:error] [pid 1028675:tid 1028875] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.590914 2026] [core:error] [pid 1028675:tid 1028875] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.595583 2026] [security2:error] [pid 1018003:tid 1018191] [client 103.185.242.143:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB-QAABeA"] [Sat Aug 29 05:06:48.595667 2026] [security2:error] [pid 1018003:tid 1018191] [client 103.185.242.143:63584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9SDAh5Y1i2tUxg4EB-QAABeA"] [Sat Aug 29 05:06:48.600382 2026] [security2:error] [pid 1028675:tid 1028879] [client 4.205.62.107:26651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/sys.php"] [unique_id "apK9SNdHPfW2QFvhmL7MQAAAAEU"] [Sat Aug 29 05:06:48.604071 2026] [security2:error] [pid 1028675:tid 1028881] [client 4.205.62.107:22444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/vx.php"] [unique_id "apK9SNdHPfW2QFvhmL7MQQAAAEc"] [Sat Aug 29 05:06:48.610303 2026] [security2:error] [pid 1028675:tid 1028861] [client 40.83.93.50:1656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.leedscastlepunting.co.uk"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK9SNdHPfW2QFvhmL7MQgAAADM"] [Sat Aug 29 05:06:48.616584 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.616609 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.625093 2026] [core:error] [pid 1018003:tid 1018115] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.625103 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.625111 2026] [core:error] [pid 1018003:tid 1018115] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.625112 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.630307 2026] [security2:error] [pid 1028675:tid 1028888] [client 68.155.159.216:30691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/file.php"] [unique_id "apK9SNdHPfW2QFvhmL7MRQAAAE4"] [Sat Aug 29 05:06:48.632730 2026] [core:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.632752 2026] [core:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.646053 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.646071 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.649846 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.649859 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.651540 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.651560 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.652595 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.220.204.93:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wp-scr1pts.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECEQAABjU"] [Sat Aug 29 05:06:48.653581 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.48.250.41:21386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/elp.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECEgAABdo"] [Sat Aug 29 05:06:48.654032 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.654045 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.654733 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.654744 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.656260 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.656271 2026] [core:error] [pid 1018003:tid 1018242] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.661967 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.661979 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.663711 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.23.184.117:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/options.php"] [unique_id "apK9SNdHPfW2QFvhmL7MSQAAAEo"] [Sat Aug 29 05:06:48.666936 2026] [security2:error] [pid 1028675:tid 1028914] [client 4.205.62.107:22463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/public/bnn_.php.php"] [unique_id "apK9SNdHPfW2QFvhmL7MSgAAAGg"] [Sat Aug 29 05:06:48.669091 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.196.209.81:14609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/fi2.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECFQAABiI"] [Sat Aug 29 05:06:48.669683 2026] [core:error] [pid 1028675:tid 1028913] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.669696 2026] [core:error] [pid 1028675:tid 1028913] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.673631 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.104.18.15:13744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/adminfuns.php"] [unique_id "apK9SNdHPfW2QFvhmL7MTAAAAG0"] [Sat Aug 29 05:06:48.687864 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.104.18.15:8182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apK9SNdHPfW2QFvhmL7MTQAAAHU"] [Sat Aug 29 05:06:48.717489 2026] [security2:error] [pid 1028675:tid 1028934] [client 168.107.94.195:59717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9SNdHPfW2QFvhmL7MTwAAAHw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:48.727219 2026] [security2:error] [pid 1028675:tid 1028911] [client 158.23.184.117:34728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/inputs.php"] [unique_id "apK9SNdHPfW2QFvhmL7MUAAAAGU"] [Sat Aug 29 05:06:48.731763 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.104.62:28809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/admin.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECGgAABcA"] [Sat Aug 29 05:06:48.733217 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.151.200.44:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/inwp.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECGwAABco"] [Sat Aug 29 05:06:48.737462 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.737478 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.743416 2026] [security2:error] [pid 1018003:tid 1018240] [client 45.148.10.62:49756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninaanddon.strangeworx.com"] [uri "/config.php.bak"] [unique_id "apK9SDAh5Y1i2tUxg4ECHgAABhA"] [Sat Aug 29 05:06:48.747892 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.747908 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.753476 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.104.18.15:36613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/codex.php"] [unique_id "apK9SNdHPfW2QFvhmL7MVQAAAHI"] [Sat Aug 29 05:06:48.754818 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.754829 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.756546 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.756558 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.770450 2026] [security2:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9SDAh5Y1i2tUxg4ECIwAF0B8"] [Sat Aug 29 05:06:48.770639 2026] [security2:error] [pid 1018003:tid 1018038] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9SDAh5Y1i2tUxg4ECJAAF0BE"] [Sat Aug 29 05:06:48.771725 2026] [core:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.771737 2026] [core:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.779575 2026] [security2:error] [pid 1028675:tid 1028824] [client 68.155.159.216:38581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/chosen.php"] [unique_id "apK9SNdHPfW2QFvhmL7MVwAAAA4"] [Sat Aug 29 05:06:48.784092 2026] [security2:error] [pid 1018003:tid 1018037] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9SDAh5Y1i2tUxg4ECJQAF4BA"] [Sat Aug 29 05:06:48.784735 2026] [security2:error] [pid 1018003:tid 1018206] [client 68.155.159.216:9295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECJgAABe8"] [Sat Aug 29 05:06:48.790588 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.147.79:32648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/atomlib.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECJwAABiY"] [Sat Aug 29 05:06:48.796881 2026] [security2:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9SDAh5Y1i2tUxg4ECKAAFzVE"] [Sat Aug 29 05:06:48.799325 2026] [security2:error] [pid 1028675:tid 1028842] [client 20.220.204.93:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/num.php"] [unique_id "apK9SNdHPfW2QFvhmL7MWQAAACA"] [Sat Aug 29 05:06:48.806385 2026] [security2:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9SDAh5Y1i2tUxg4ECKQAGDxc"] [Sat Aug 29 05:06:48.806987 2026] [security2:error] [pid 1028675:tid 1028827] [client 158.23.184.117:19346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/panel.php"] [unique_id "apK9SNdHPfW2QFvhmL7MWgAAABE"] [Sat Aug 29 05:06:48.809697 2026] [core:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.809710 2026] [core:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.810202 2026] [security2:error] [pid 1028675:tid 1028860] [client 47.128.36.27:27970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jmdental.com.au"] [uri "/robots.txt"] [unique_id "apK9SNdHPfW2QFvhmL7MWwAAADI"] [Sat Aug 29 05:06:48.810228 2026] [core:error] [pid 1018003:tid 1018040] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.810234 2026] [core:error] [pid 1018003:tid 1018040] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.810507 2026] [core:error] [pid 1018003:tid 1018131] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.810517 2026] [core:error] [pid 1018003:tid 1018131] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.812180 2026] [core:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.812195 2026] [core:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.813670 2026] [security2:error] [pid 1028675:tid 1028831] [client 20.48.250.41:21376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/666.php"] [unique_id "apK9SNdHPfW2QFvhmL7MXAAAABU"] [Sat Aug 29 05:06:48.817077 2026] [core:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.817088 2026] [core:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.819789 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.18.15:13725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/classwithtostring.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECLwAABdc"] [Sat Aug 29 05:06:48.833027 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.52.41.200:1165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/autoload_classmap.php"] [unique_id "apK9SNdHPfW2QFvhmL7MXQAAAGs"] [Sat Aug 29 05:06:48.843944 2026] [core:error] [pid 1018003:tid 1018048] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.843966 2026] [core:error] [pid 1018003:tid 1018048] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.858390 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.104.18.15:8124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/xmini4.php"] [unique_id "apK9SNdHPfW2QFvhmL7MXwAAACc"] [Sat Aug 29 05:06:48.871411 2026] [security2:error] [pid 1028675:tid 1028819] [client 158.23.184.117:34512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/item.php"] [unique_id "apK9SNdHPfW2QFvhmL7MYAAAAAk"] [Sat Aug 29 05:06:48.888566 2026] [security2:error] [pid 1028675:tid 1028902] [client 68.155.159.216:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9SNdHPfW2QFvhmL7MYQAAAFw"] [Sat Aug 29 05:06:48.918895 2026] [core:error] [pid 1018003:tid 1018054] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.918918 2026] [core:error] [pid 1018003:tid 1018054] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.923671 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.923693 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.923737 2026] [core:error] [pid 1018003:tid 1018054] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.923747 2026] [core:error] [pid 1018003:tid 1018054] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.928177 2026] [security2:error] [pid 1028675:tid 1028865] [client 20.104.104.62:27018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/admin.php"] [unique_id "apK9SNdHPfW2QFvhmL7MYwAAADc"] [Sat Aug 29 05:06:48.930388 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.930412 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.932180 2026] [core:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.932200 2026] [core:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.940224 2026] [security2:error] [pid 1028675:tid 1028869] [client 20.104.18.15:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/5656.php"] [unique_id "apK9SNdHPfW2QFvhmL7MZAAAADs"] [Sat Aug 29 05:06:48.940997 2026] [security2:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9SDAh5Y1i2tUxg4ECNwAGLi4"] [Sat Aug 29 05:06:48.941320 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.220.204.93:52334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/a4.php"] [unique_id "apK9SNdHPfW2QFvhmL7MZQAAAAU"] [Sat Aug 29 05:06:48.942610 2026] [security2:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9SDAh5Y1i2tUxg4ECOAAGLig"] [Sat Aug 29 05:06:48.943176 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.104.62:29204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/index.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECOgAABgo"] [Sat Aug 29 05:06:48.943753 2026] [security2:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9SDAh5Y1i2tUxg4ECOQAGLjk"] [Sat Aug 29 05:06:48.950589 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.18.15:13753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECPAAABhQ"] [Sat Aug 29 05:06:48.955967 2026] [security2:error] [pid 1028675:tid 1028929] [client 158.23.184.117:19324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "apK9SNdHPfW2QFvhmL7MZwAAAHc"] [Sat Aug 29 05:06:48.963164 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.48.250.41:21474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/knmt.php"] [unique_id "apK9SNdHPfW2QFvhmL7MaAAAAC4"] [Sat Aug 29 05:06:48.978628 2026] [security2:error] [pid 1028675:tid 1028871] [client 68.155.159.216:49181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9SNdHPfW2QFvhmL7MagAAAD0"] [Sat Aug 29 05:06:48.982644 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.151.200.44:46639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/ad1.php"] [unique_id "apK9SDAh5Y1i2tUxg4ECRAAABiA"] [Sat Aug 29 05:06:48.992011 2026] [core:error] [pid 1028675:tid 1028909] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.992028 2026] [core:error] [pid 1028675:tid 1028909] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.997717 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.997732 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.997862 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:48.997872 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.009146 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.009162 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.015594 2026] [security2:error] [pid 1028675:tid 1028838] [client 158.158.54.35:11371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/cv.php"] [unique_id "apK9SddHPfW2QFvhmL7MbwAAABw"] [Sat Aug 29 05:06:49.016417 2026] [security2:error] [pid 1028675:tid 1028859] [client 158.23.184.117:34513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/k.php"] [unique_id "apK9SddHPfW2QFvhmL7McAAAADE"] [Sat Aug 29 05:06:49.020431 2026] [cgid:error] [pid 1018003:tid 1018213] [client 158.23.184.117:46967] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/dontbenicemovie/404.shtml [Sat Aug 29 05:06:49.023916 2026] [security2:error] [pid 1028675:tid 1028821] [client 158.23.147.79:30634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9SddHPfW2QFvhmL7McQAAAAs"] [Sat Aug 29 05:06:49.030053 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.18.15:8030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/gulu.php"] [unique_id "apK9STAh5Y1i2tUxg4ECSwAABgM"] [Sat Aug 29 05:06:49.049874 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.049893 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.049922 2026] [security2:error] [pid 1028675:tid 1028836] [client 195.178.110.101:1816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/index.php"] [unique_id "apK9SddHPfW2QFvhmL7McwAAABo"] [Sat Aug 29 05:06:49.066071 2026] [core:error] [pid 1028675:tid 1028810] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.066094 2026] [core:error] [pid 1028675:tid 1028810] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.067286 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.184.117:46967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/wk/admin.php"] [unique_id "apK9STAh5Y1i2tUxg4ECUwAABfU"] [Sat Aug 29 05:06:49.067396 2026] [core:error] [pid 1028675:tid 1028841] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.067409 2026] [core:error] [pid 1028675:tid 1028841] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.068541 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.068557 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.072475 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.196.209.81:17858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/1p.php"] [unique_id "apK9SddHPfW2QFvhmL7MdgAAAFg"] [Sat Aug 29 05:06:49.084061 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.18.15:13646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK9STAh5Y1i2tUxg4ECVAAABco"] [Sat Aug 29 05:06:49.087543 2026] [security2:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9STAh5Y1i2tUxg4ECVQAGJT8"] [Sat Aug 29 05:06:49.088452 2026] [security2:error] [pid 1018003:tid 1018240] [client 4.205.62.107:55985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/php-info.php"] [unique_id "apK9STAh5Y1i2tUxg4ECVgAABhA"] [Sat Aug 29 05:06:49.092100 2026] [security2:error] [pid 1018003:tid 1018088] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9STAh5Y1i2tUxg4ECWQAF6UM"] [Sat Aug 29 05:06:49.093620 2026] [core:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.093639 2026] [core:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.096194 2026] [security2:error] [pid 1018003:tid 1018191] [client 168.107.94.195:60173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9STAh5Y1i2tUxg4ECXQAABeA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:49.100513 2026] [security2:error] [pid 1028675:tid 1028891] [client 20.220.204.93:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/tfm.php"] [unique_id "apK9SddHPfW2QFvhmL7MegAAAFE"] [Sat Aug 29 05:06:49.100892 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.184.117:19349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/pki-validation/pl.php"] [unique_id "apK9STAh5Y1i2tUxg4ECYAAABcQ"] [Sat Aug 29 05:06:49.103295 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.103309 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.103974 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.48.250.41:21463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/sbhu.php"] [unique_id "apK9STAh5Y1i2tUxg4ECYQAABe8"] [Sat Aug 29 05:06:49.109237 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.197.61.180:8922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/about.php525"] [unique_id "apK9SddHPfW2QFvhmL7MfAAAAC8"] [Sat Aug 29 05:06:49.112931 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.112946 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.118743 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.118757 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.123257 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.104.18.15:36771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/w3lls.php"] [unique_id "apK9SddHPfW2QFvhmL7MgAAAAFo"] [Sat Aug 29 05:06:49.123534 2026] [core:error] [pid 1028675:tid 1028896] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.123545 2026] [core:error] [pid 1028675:tid 1028896] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.123999 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.104.104.62:27530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/lite.php"] [unique_id "apK9SddHPfW2QFvhmL7MgQAAABk"] [Sat Aug 29 05:06:49.124882 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.124900 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.132957 2026] [security2:error] [pid 1028675:tid 1028899] [client 68.155.159.216:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/simple.php"] [unique_id "apK9SddHPfW2QFvhmL7MggAAAFk"] [Sat Aug 29 05:06:49.137586 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.104.104.62:29241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/about.php"] [unique_id "apK9SddHPfW2QFvhmL7MgwAAAEY"] [Sat Aug 29 05:06:49.151555 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.151570 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.161828 2026] [security2:error] [pid 1028675:tid 1028883] [client 158.23.184.117:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/license.php"] [unique_id "apK9SddHPfW2QFvhmL7MiAAAAEk"] [Sat Aug 29 05:06:49.168878 2026] [security2:error] [pid 1028675:tid 1028897] [client 40.83.93.50:7739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/post.php"] [unique_id "apK9SddHPfW2QFvhmL7MiQAAAFc"] [Sat Aug 29 05:06:49.181822 2026] [security2:error] [pid 1018003:tid 1018236] [client 68.155.159.216:24411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/admin.php"] [unique_id "apK9STAh5Y1i2tUxg4ECZgAABgw"] [Sat Aug 29 05:06:49.182498 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.104.18.15:8058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/replace.php"] [unique_id "apK9SddHPfW2QFvhmL7MigAAAG8"] [Sat Aug 29 05:06:49.186360 2026] [core:error] [pid 1018003:tid 1018207] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.186379 2026] [core:error] [pid 1018003:tid 1018207] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.212113 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.151.200.44:64384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/f-401.php"] [unique_id "apK9STAh5Y1i2tUxg4ECagAABcc"] [Sat Aug 29 05:06:49.215615 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.18.15:13734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK9STAh5Y1i2tUxg4ECbAAABeQ"] [Sat Aug 29 05:06:49.216676 2026] [security2:error] [pid 1028675:tid 1028919] [client 158.23.184.117:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/admin.php"] [unique_id "apK9SddHPfW2QFvhmL7MjQAAAG0"] [Sat Aug 29 05:06:49.230391 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.220.204.93:52303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/Geforce.php"] [unique_id "apK9STAh5Y1i2tUxg4ECbwAABcM"] [Sat Aug 29 05:06:49.244982 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.184.117:19313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/pki-validation/x.php"] [unique_id "apK9STAh5Y1i2tUxg4ECcQAABgo"] [Sat Aug 29 05:06:49.251433 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.49.130:58107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/Jcrop.php"] [unique_id "apK9STAh5Y1i2tUxg4ECcwAABfo"] [Sat Aug 29 05:06:49.253012 2026] [security2:error] [pid 1028675:tid 1028905] [client 20.48.250.41:21469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/a332.php"] [unique_id "apK9SddHPfW2QFvhmL7MjwAAAF8"] [Sat Aug 29 05:06:49.271485 2026] [security2:error] [pid 1018003:tid 1018059] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9STAh5Y1i2tUxg4ECdgAGLiY"] [Sat Aug 29 05:06:49.271630 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.271643 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.274165 2026] [core:error] [pid 1018003:tid 1018079] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.274179 2026] [core:error] [pid 1018003:tid 1018079] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.276489 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.52.41.200:1237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/bi.php"] [unique_id "apK9STAh5Y1i2tUxg4ECfgAABcI"] [Sat Aug 29 05:06:49.280115 2026] [core:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.280135 2026] [core:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.292124 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.292141 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.292157 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.292166 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.303591 2026] [core:error] [pid 1028675:tid 1028934] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.303608 2026] [core:error] [pid 1028675:tid 1028934] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.304983 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.304994 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.306336 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.306360 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.307708 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.307720 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.309075 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.309089 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.313831 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.313845 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.318629 2026] [security2:error] [pid 1028675:tid 1028814] [client 4.205.62.107:8964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/snq.php"] [unique_id "apK9SddHPfW2QFvhmL7MlwAAAAQ"] [Sat Aug 29 05:06:49.320922 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.104.62:27052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/about.php"] [unique_id "apK9SddHPfW2QFvhmL7MmAAAAHo"] [Sat Aug 29 05:06:49.321276 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.151.200.44:61969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/hq.php"] [unique_id "apK9SddHPfW2QFvhmL7MmQAAACg"] [Sat Aug 29 05:06:49.331736 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.104.18.15:36631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/fpwch.php"] [unique_id "apK9SddHPfW2QFvhmL7MmgAAACw"] [Sat Aug 29 05:06:49.332332 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.104.104.62:29247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/vx.php"] [unique_id "apK9SddHPfW2QFvhmL7MmwAAAHI"] [Sat Aug 29 05:06:49.334595 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.334606 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.340022 2026] [core:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.340033 2026] [core:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.344496 2026] [core:error] [pid 1018003:tid 1018066] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.344508 2026] [core:error] [pid 1018003:tid 1018066] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.346473 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.18.15:13732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/wsd.php"] [unique_id "apK9SddHPfW2QFvhmL7MnQAAAFw"] [Sat Aug 29 05:06:49.357842 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.220.204.93:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/click.php"] [unique_id "apK9SddHPfW2QFvhmL7MngAAAF0"] [Sat Aug 29 05:06:49.360836 2026] [security2:error] [pid 1028675:tid 1028834] [client 20.151.200.44:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/1vbqo.php"] [unique_id "apK9SddHPfW2QFvhmL7MnwAAABg"] [Sat Aug 29 05:06:49.361293 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.18.15:8163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/c4.php"] [unique_id "apK9SddHPfW2QFvhmL7MoAAAACk"] [Sat Aug 29 05:06:49.364078 2026] [security2:error] [pid 1028675:tid 1028813] [client 20.104.49.130:60789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/gecko-new.php"] [unique_id "apK9SddHPfW2QFvhmL7MoQAAAAM"] [Sat Aug 29 05:06:49.370644 2026] [core:error] [pid 1028675:tid 1028865] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.370656 2026] [core:error] [pid 1028675:tid 1028865] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.411488 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.48.250.41:21493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ws66.php"] [unique_id "apK9SddHPfW2QFvhmL7MpAAAADQ"] [Sat Aug 29 05:06:49.437327 2026] [security2:error] [pid 1028675:tid 1028870] [client 158.23.147.79:17461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9SddHPfW2QFvhmL7MpQAAADw"] [Sat Aug 29 05:06:49.439697 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.147.79:26468] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.olker.us"] [uri "/1.php"] [unique_id "apK9STAh5Y1i2tUxg4ECiwAABf8"] [Sat Aug 29 05:06:49.439772 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.147.79:26468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/1.php"] [unique_id "apK9STAh5Y1i2tUxg4ECiwAABf8"] [Sat Aug 29 05:06:49.440618 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.104.49.130:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/abc.php"] [unique_id "apK9SddHPfW2QFvhmL7MpgAAACs"] [Sat Aug 29 05:06:49.444381 2026] [core:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.444403 2026] [core:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.444493 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.444503 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.445066 2026] [core:error] [pid 1018003:tid 1018105] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.445074 2026] [core:error] [pid 1018003:tid 1018105] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.451908 2026] [core:error] [pid 1018003:tid 1018099] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.451922 2026] [core:error] [pid 1018003:tid 1018099] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.455620 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.455631 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.461578 2026] [security2:error] [pid 1028675:tid 1028820] [client 68.155.159.216:18365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9SddHPfW2QFvhmL7MqgAAAAo"] [Sat Aug 29 05:06:49.464210 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.464221 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.469233 2026] [core:error] [pid 1028675:tid 1028925] [client 45.148.10.62:49768] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.471177 2026] [security2:error] [pid 1028675:tid 1028810] [client 4.205.62.107:22456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/wpver.php"] [unique_id "apK9SddHPfW2QFvhmL7MsAAAAAA"] [Sat Aug 29 05:06:49.474625 2026] [security2:error] [pid 1018003:tid 1018186] [client 158.23.147.79:24510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ans.php"] [unique_id "apK9STAh5Y1i2tUxg4EClgAABds"] [Sat Aug 29 05:06:49.474658 2026] [security2:error] [pid 1028675:tid 1028898] [client 168.107.94.195:60418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9SddHPfW2QFvhmL7MsQAAAFg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:49.481456 2026] [core:error] [pid 1018003:tid 1018029] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.481469 2026] [core:error] [pid 1018003:tid 1018029] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.483838 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.483851 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.485438 2026] [security2:error] [pid 1028675:tid 1028882] [client 20.104.18.15:13699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/bulet.php"] [unique_id "apK9SddHPfW2QFvhmL7MswAAAEg"] [Sat Aug 29 05:06:49.491160 2026] [core:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.491170 2026] [core:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.493160 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.220.204.93:52335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ms.php"] [unique_id "apK9STAh5Y1i2tUxg4ECoAAABfs"] [Sat Aug 29 05:06:49.493528 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.18.15:7960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/rxr.php"] [unique_id "apK9STAh5Y1i2tUxg4ECoQAABdA"] [Sat Aug 29 05:06:49.495094 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.104.18.15:36616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/domvf.php"] [unique_id "apK9SddHPfW2QFvhmL7MtAAAADM"] [Sat Aug 29 05:06:49.500703 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.158.54.35:29634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/packed.php"] [unique_id "apK9STAh5Y1i2tUxg4ECpAAABiU"] [Sat Aug 29 05:06:49.509398 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.509413 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.509609 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.509619 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.513733 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.513744 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.513895 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.513903 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.515869 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.515879 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.518504 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.518514 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.519778 2026] [security2:error] [pid 1028675:tid 1028838] [client 20.104.104.62:27054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/inputs.php"] [unique_id "apK9SddHPfW2QFvhmL7MtgAAABw"] [Sat Aug 29 05:06:49.520730 2026] [security2:error] [pid 1018003:tid 1018256] [client 68.155.159.216:65105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/file.php"] [unique_id "apK9STAh5Y1i2tUxg4ECrQAABiA"] [Sat Aug 29 05:06:49.525707 2026] [security2:error] [pid 1028675:tid 1028877] [client 20.104.104.62:29242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9SddHPfW2QFvhmL7MtwAAAEM"] [Sat Aug 29 05:06:49.545985 2026] [security2:error] [pid 1028675:tid 1028909] [client 20.196.209.81:13311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/Njima.php"] [unique_id "apK9SddHPfW2QFvhmL7MuAAAAGM"] [Sat Aug 29 05:06:49.548639 2026] [security2:error] [pid 1028675:tid 1028892] [client 158.23.147.79:25539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9SddHPfW2QFvhmL7MuQAAAFI"] [Sat Aug 29 05:06:49.554931 2026] [core:error] [pid 1018003:tid 1018161] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.554950 2026] [core:error] [pid 1018003:tid 1018161] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.556335 2026] [security2:error] [pid 1028675:tid 1028889] [client 158.23.147.79:50126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9SddHPfW2QFvhmL7MugAAAE8"] [Sat Aug 29 05:06:49.563731 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.48.250.41:21494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ws68.php"] [unique_id "apK9SddHPfW2QFvhmL7MuwAAAFA"] [Sat Aug 29 05:06:49.572444 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.147.79:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9STAh5Y1i2tUxg4ECsQAABd4"] [Sat Aug 29 05:06:49.586697 2026] [security2:error] [pid 1028675:tid 1028896] [client 68.155.159.216:33727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/content.php"] [unique_id "apK9SddHPfW2QFvhmL7MvAAAAFY"] [Sat Aug 29 05:06:49.591027 2026] [core:error] [pid 1018003:tid 1018106] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.591045 2026] [core:error] [pid 1018003:tid 1018106] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.595773 2026] [core:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.595785 2026] [core:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.601082 2026] [core:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.601094 2026] [core:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.613370 2026] [security2:error] [pid 1018003:tid 1018166] [client 45.61.187.50:65028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "succulentideas.com"] [uri "/wp-content/plugins/wp_gljbkwx/wp_gljbkwx.php"] [unique_id "apK9STAh5Y1i2tUxg4ECuAAABcc"] [Sat Aug 29 05:06:49.614719 2026] [core:error] [pid 1028675:tid 1028894] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.614732 2026] [core:error] [pid 1028675:tid 1028894] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.618500 2026] [security2:error] [pid 1028675:tid 1028901] [client 20.104.18.15:13709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/av.php"] [unique_id "apK9SddHPfW2QFvhmL7MwQAAAFs"] [Sat Aug 29 05:06:49.622558 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.622574 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.632993 2026] [core:error] [pid 1028675:tid 1028847] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.633005 2026] [core:error] [pid 1028675:tid 1028847] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.633187 2026] [core:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.633197 2026] [core:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.636165 2026] [core:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.636174 2026] [core:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.643766 2026] [security2:error] [pid 1028675:tid 1028928] [client 20.104.18.15:36770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/biufile.php"] [unique_id "apK9SddHPfW2QFvhmL7MxAAAAHY"] [Sat Aug 29 05:06:49.647191 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.220.204.93:50790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/zxekqlxb.php"] [unique_id "apK9SddHPfW2QFvhmL7MxQAAAG0"] [Sat Aug 29 05:06:49.648000 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.104.18.15:8010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canistermachine.com"] [uri "/reviall.php"] [unique_id "apK9STAh5Y1i2tUxg4ECuwAABiI"] [Sat Aug 29 05:06:49.652099 2026] [security2:error] [pid 1028675:tid 1028905] [client 20.151.200.44:47304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/h02ugyh.php"] [unique_id "apK9SddHPfW2QFvhmL7MxgAAAF8"] [Sat Aug 29 05:06:49.663019 2026] [core:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.663041 2026] [core:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.679408 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.679427 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.684411 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.684430 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.686016 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.686029 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.686062 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.686079 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.691090 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.691101 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.693707 2026] [core:error] [pid 1028675:tid 1028827] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.693718 2026] [core:error] [pid 1028675:tid 1028827] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.699125 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.48.250.41:21435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/users.php"] [unique_id "apK9SddHPfW2QFvhmL7MzgAAACY"] [Sat Aug 29 05:06:49.714638 2026] [security2:error] [pid 1028675:tid 1028895] [client 20.52.41.200:1789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/cc.php"] [unique_id "apK9SddHPfW2QFvhmL7MzwAAAFU"] [Sat Aug 29 05:06:49.714666 2026] [security2:error] [pid 1028675:tid 1028935] [client 20.104.104.62:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/adminfuns.php"] [unique_id "apK9SddHPfW2QFvhmL7M0AAAAH0"] [Sat Aug 29 05:06:49.718113 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.104.104.62:29246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/goods.php"] [unique_id "apK9STAh5Y1i2tUxg4ECywAABhw"] [Sat Aug 29 05:06:49.718216 2026] [security2:error] [pid 1018003:tid 1018196] [client 40.83.93.50:7871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/flower.php"] [unique_id "apK9STAh5Y1i2tUxg4ECzAAABeU"] [Sat Aug 29 05:06:49.733273 2026] [security2:error] [pid 1018003:tid 1018180] [client 68.155.159.216:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/file17.php"] [unique_id "apK9STAh5Y1i2tUxg4ECzQAABdU"] [Sat Aug 29 05:06:49.741562 2026] [security2:error] [pid 1028675:tid 1028814] [client 4.205.62.107:22366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/radio.php"] [unique_id "apK9SddHPfW2QFvhmL7M0QAAAAQ"] [Sat Aug 29 05:06:49.747482 2026] [security2:error] [pid 1018003:tid 1018117] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9STAh5Y1i2tUxg4ECzgAF_mA"] [Sat Aug 29 05:06:49.749514 2026] [security2:error] [pid 1018003:tid 1018174] [client 4.205.62.107:65522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/phpsysinfo.php"] [unique_id "apK9STAh5Y1i2tUxg4EC0AAABc8"] [Sat Aug 29 05:06:49.750986 2026] [core:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.750997 2026] [core:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.751175 2026] [core:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.751183 2026] [core:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.761392 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.104.18.15:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/images.php"] [unique_id "apK9SddHPfW2QFvhmL7M0wAAACg"] [Sat Aug 29 05:06:49.762439 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.147.79:35838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/hehehehe.php"] [unique_id "apK9STAh5Y1i2tUxg4EC0gAABhA"] [Sat Aug 29 05:06:49.769618 2026] [security2:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9STAh5Y1i2tUxg4EC0wAF_nY"] [Sat Aug 29 05:06:49.772347 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.772397 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.776927 2026] [security2:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9STAh5Y1i2tUxg4EC1QAF_ns"] [Sat Aug 29 05:06:49.778767 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.220.204.93:59087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/init.php"] [unique_id "apK9SddHPfW2QFvhmL7M1AAAACc"] [Sat Aug 29 05:06:49.782982 2026] [security2:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9STAh5Y1i2tUxg4EC1wAF_3k"] [Sat Aug 29 05:06:49.803800 2026] [security2:error] [pid 1018003:tid 1018182] [client 4.205.62.107:22297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/php_info.php"] [unique_id "apK9STAh5Y1i2tUxg4EC2gAABdc"] [Sat Aug 29 05:06:49.804649 2026] [core:error] [pid 1018003:tid 1018261] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.804672 2026] [core:error] [pid 1018003:tid 1018261] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.811545 2026] [security2:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9STAh5Y1i2tUxg4EC2wAF_2g"] [Sat Aug 29 05:06:49.814152 2026] [core:error] [pid 1028675:tid 1028846] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.814169 2026] [core:error] [pid 1028675:tid 1028846] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.816989 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.18.15:36796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/blacks.php"] [unique_id "apK9STAh5Y1i2tUxg4EC3AAABi8"] [Sat Aug 29 05:06:49.820859 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.151.200.44:47336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/shelp.php"] [unique_id "apK9STAh5Y1i2tUxg4EC3QAABgE"] [Sat Aug 29 05:06:49.833478 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.48.250.41:21395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/bzjdlofz.php"] [unique_id "apK9STAh5Y1i2tUxg4EC3gAABdk"] [Sat Aug 29 05:06:49.836077 2026] [security2:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9STAh5Y1i2tUxg4EC4AAFumw"] [Sat Aug 29 05:06:49.837088 2026] [security2:error] [pid 1018003:tid 1018133] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9STAh5Y1i2tUxg4EC4gAFunA"] [Sat Aug 29 05:06:49.837183 2026] [security2:error] [pid 1018003:tid 1018111] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9STAh5Y1i2tUxg4EC4QAFulo"] [Sat Aug 29 05:06:49.837599 2026] [core:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.837612 2026] [core:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.840287 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.197.61.180:8924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/spip.php"] [unique_id "apK9STAh5Y1i2tUxg4EC5gAABhQ"] [Sat Aug 29 05:06:49.854677 2026] [security2:error] [pid 1028675:tid 1028871] [client 168.107.94.195:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9SddHPfW2QFvhmL7M2wAAAD0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:49.878289 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.878306 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.886778 2026] [security2:error] [pid 1028675:tid 1028870] [client 68.155.159.216:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/goods.php"] [unique_id "apK9SddHPfW2QFvhmL7M4AAAADw"] [Sat Aug 29 05:06:49.888239 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.104.18.15:13661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/ops.php"] [unique_id "apK9SddHPfW2QFvhmL7M4QAAACs"] [Sat Aug 29 05:06:49.897821 2026] [security2:error] [pid 1028675:tid 1028821] [client 158.23.147.79:32767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/lv.php"] [unique_id "apK9SddHPfW2QFvhmL7M4gAAAAs"] [Sat Aug 29 05:06:49.900560 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.900574 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.916257 2026] [security2:error] [pid 1018003:tid 1018242] [client 20.104.104.62:28931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-access.php"] [unique_id "apK9STAh5Y1i2tUxg4EC7gAABhI"] [Sat Aug 29 05:06:49.921091 2026] [security2:error] [pid 1018003:tid 1018226] [client 68.155.159.216:51546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9STAh5Y1i2tUxg4EC7wAABgM"] [Sat Aug 29 05:06:49.925895 2026] [security2:error] [pid 1018003:tid 1018192] [client 68.155.159.216:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/login.php"] [unique_id "apK9STAh5Y1i2tUxg4EC8wAABeE"] [Sat Aug 29 05:06:49.937044 2026] [core:error] [pid 1018003:tid 1018161] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.937070 2026] [core:error] [pid 1018003:tid 1018161] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.954181 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.220.204.93:52339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/term.php"] [unique_id "apK9SddHPfW2QFvhmL7M6QAAAEQ"] [Sat Aug 29 05:06:49.954949 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.954966 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.970443 2026] [security2:error] [pid 1028675:tid 1028886] [client 20.104.18.15:36625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/beck.php"] [unique_id "apK9SddHPfW2QFvhmL7M6gAAAEw"] [Sat Aug 29 05:06:49.971464 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.196.209.81:9448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/configs.php"] [unique_id "apK9STAh5Y1i2tUxg4EC-AAABdo"] [Sat Aug 29 05:06:49.987211 2026] [core:error] [pid 1028675:tid 1028861] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.987212 2026] [core:error] [pid 1028675:tid 1028810] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.987227 2026] [core:error] [pid 1028675:tid 1028861] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.987231 2026] [core:error] [pid 1028675:tid 1028810] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.990506 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.990518 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.990948 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.991063 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.997442 2026] [cgid:error] [pid 1028675:tid 1028843] [client 20.104.104.62:27060] AH01264: stderr from /home3/nlvnnet/public_html/ngoiloi/cgi-bin: script not found or unable to stat [Sat Aug 29 05:06:49.998574 2026] [core:error] [pid 1028675:tid 1028888] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.998602 2026] [core:error] [pid 1028675:tid 1028888] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.999463 2026] [core:error] [pid 1018003:tid 1018035] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:49.999569 2026] [core:error] [pid 1018003:tid 1018035] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.018172 2026] [security2:error] [pid 1028675:tid 1028865] [client 158.158.54.35:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-admin/js/index.php"] [unique_id "apK9StdHPfW2QFvhmL7M8QAAADc"] [Sat Aug 29 05:06:50.021347 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.104.18.15:13752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/coffexium.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDBAAABiI"] [Sat Aug 29 05:06:50.023321 2026] [core:error] [pid 1018003:tid 1018145] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.023336 2026] [core:error] [pid 1018003:tid 1018145] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.038332 2026] [security2:error] [pid 1018003:tid 1018047] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDBwAFuho"] [Sat Aug 29 05:06:50.045753 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.045769 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.046714 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.046748 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.048454 2026] [core:error] [pid 1028675:tid 1028857] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.048469 2026] [core:error] [pid 1028675:tid 1028857] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.048730 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.048739 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.049351 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.049373 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.063492 2026] [security2:error] [pid 1028675:tid 1028896] [client 20.104.104.62:27060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/edit.php"] [unique_id "apK9StdHPfW2QFvhmL7M9gAAAFY"] [Sat Aug 29 05:06:50.075269 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.151.200.44:61967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/mh.php"] [unique_id "apK9StdHPfW2QFvhmL7M-AAAAGQ"] [Sat Aug 29 05:06:50.075764 2026] [core:error] [pid 1028675:tid 1028835] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.075779 2026] [core:error] [pid 1028675:tid 1028835] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.077183 2026] [security2:error] [pid 1028675:tid 1028899] [client 68.155.159.216:49156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9StdHPfW2QFvhmL7M-QAAAFk"] [Sat Aug 29 05:06:50.081327 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.48.250.41:21445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/selesai.php"] [unique_id "apK9StdHPfW2QFvhmL7M-gAAAEY"] [Sat Aug 29 05:06:50.106777 2026] [security2:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9SjAh5Y1i2tUxg4EDDAAFzx8"] [Sat Aug 29 05:06:50.108943 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.220.204.93:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/aaa.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDDQAABhA"] [Sat Aug 29 05:06:50.115724 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.104.62:28817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/autoload_classmap/function.php"] [unique_id "apK9StdHPfW2QFvhmL7M-wAAAE8"] [Sat Aug 29 05:06:50.127753 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.104.18.15:36670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/t3.php"] [unique_id "apK9StdHPfW2QFvhmL7M_AAAACU"] [Sat Aug 29 05:06:50.130398 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.104.49.130:47810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/sta.php"] [unique_id "apK9StdHPfW2QFvhmL7M_QAAAG8"] [Sat Aug 29 05:06:50.133180 2026] [security2:error] [pid 1018003:tid 1018038] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9SjAh5Y1i2tUxg4EDDgAFxBE"] [Sat Aug 29 05:06:50.134697 2026] [security2:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDDwAFxBY"] [Sat Aug 29 05:06:50.141621 2026] [security2:error] [pid 1018003:tid 1018206] [client 68.155.159.216:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDEgAABe8"] [Sat Aug 29 05:06:50.143116 2026] [security2:error] [pid 1028675:tid 1028914] [client 158.23.147.79:48324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/index/function.php"] [unique_id "apK9StdHPfW2QFvhmL7M_gAAAGg"] [Sat Aug 29 05:06:50.157444 2026] [security2:error] [pid 1028675:tid 1028926] [client 20.104.18.15:13741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/BDKR28WP.php"] [unique_id "apK9StdHPfW2QFvhmL7NAAAAAHQ"] [Sat Aug 29 05:06:50.161607 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.52.41.200:1169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/files/index.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDFQAABfo"] [Sat Aug 29 05:06:50.169765 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.151.200.44:46620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/13ede.php"] [unique_id "apK9StdHPfW2QFvhmL7NAwAAAH8"] [Sat Aug 29 05:06:50.171558 2026] [security2:error] [pid 1018003:tid 1018186] [client 158.23.147.79:30561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/images/index.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDGAAABds"] [Sat Aug 29 05:06:50.173169 2026] [core:error] [pid 1028675:tid 1028905] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.173183 2026] [core:error] [pid 1028675:tid 1028905] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.180384 2026] [security2:error] [pid 1018003:tid 1018131] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDGQAFxG4"] [Sat Aug 29 05:06:50.181866 2026] [security2:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDGgAFxHI"] [Sat Aug 29 05:06:50.188176 2026] [core:error] [pid 1028675:tid 1028852] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.188193 2026] [core:error] [pid 1028675:tid 1028852] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.216720 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.216736 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.218399 2026] [core:error] [pid 1028675:tid 1028827] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.218429 2026] [core:error] [pid 1028675:tid 1028827] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.222053 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.222076 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.224472 2026] [security2:error] [pid 1028675:tid 1028935] [client 4.205.62.107:55964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/infos.php"] [unique_id "apK9StdHPfW2QFvhmL7NDwAAAH0"] [Sat Aug 29 05:06:50.235682 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.235700 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.236439 2026] [security2:error] [pid 1028675:tid 1028839] [client 168.107.94.195:60973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9StdHPfW2QFvhmL7NEAAAAB0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:50.238241 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.48.250.41:21333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/shlo.php"] [unique_id "apK9StdHPfW2QFvhmL7NEgAAACw"] [Sat Aug 29 05:06:50.239330 2026] [security2:error] [pid 1028675:tid 1028903] [client 68.155.159.216:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-admin/about.php"] [unique_id "apK9StdHPfW2QFvhmL7NEwAAAF0"] [Sat Aug 29 05:06:50.239382 2026] [core:error] [pid 1028675:tid 1028902] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.239395 2026] [core:error] [pid 1028675:tid 1028902] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.246932 2026] [core:error] [pid 1028675:tid 1028834] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.246946 2026] [core:error] [pid 1028675:tid 1028834] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.248303 2026] [core:error] [pid 1028675:tid 1028851] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.248317 2026] [core:error] [pid 1028675:tid 1028851] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.251522 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.251541 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.254230 2026] [security2:error] [pid 1028675:tid 1028909] [client 40.83.93.50:13765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/meta.php"] [unique_id "apK9StdHPfW2QFvhmL7NFwAAAGM"] [Sat Aug 29 05:06:50.260103 2026] [core:error] [pid 1028675:tid 1028884] [client 45.148.10.62:49776] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.265930 2026] [security2:error] [pid 1028675:tid 1028816] [client 20.104.104.62:27039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/term.php"] [unique_id "apK9StdHPfW2QFvhmL7NGgAAAAY"] [Sat Aug 29 05:06:50.280190 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.104.18.15:36546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDJgAABg4"] [Sat Aug 29 05:06:50.283059 2026] [security2:error] [pid 1028675:tid 1028867] [client 20.220.204.93:52267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/xsox.php"] [unique_id "apK9StdHPfW2QFvhmL7NHAAAADk"] [Sat Aug 29 05:06:50.293738 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.18.15:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/sf.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDKAAABi8"] [Sat Aug 29 05:06:50.302757 2026] [security2:error] [pid 1018003:tid 1018061] [remote 66.116.199.98:36060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.jarritosmexicanos.mx"] [uri "/wp-login.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDJwAFuSg"] [Sat Aug 29 05:06:50.305280 2026] [core:error] [pid 1028675:tid 1028898] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.305295 2026] [core:error] [pid 1028675:tid 1028898] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.307705 2026] [core:error] [pid 1018003:tid 1018222] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.307719 2026] [core:error] [pid 1018003:tid 1018222] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.311762 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.49.130:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/ioxi-o.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDKgAABdk"] [Sat Aug 29 05:06:50.313309 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.104.62:28800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/ms.php"] [unique_id "apK9StdHPfW2QFvhmL7NHwAAAD0"] [Sat Aug 29 05:06:50.314224 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.314237 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.318034 2026] [security2:error] [pid 1028675:tid 1028870] [client 158.23.184.117:34510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/load.php"] [unique_id "apK9StdHPfW2QFvhmL7NIQAAADw"] [Sat Aug 29 05:06:50.336195 2026] [security2:error] [pid 1018003:tid 1018057] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDLwAFxCQ"] [Sat Aug 29 05:06:50.356625 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.356644 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.356819 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.356826 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.375000 2026] [security2:error] [pid 1018003:tid 1018050] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDMgAFxB0"] [Sat Aug 29 05:06:50.377403 2026] [security2:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDNAAFxDM"] [Sat Aug 29 05:06:50.384919 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.196.209.81:9435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/disagraeed.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDNgAABgw"] [Sat Aug 29 05:06:50.388472 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.250.41:21491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/asax.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDNwAABfY"] [Sat Aug 29 05:06:50.392673 2026] [core:error] [pid 1028675:tid 1028873] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.392690 2026] [core:error] [pid 1028675:tid 1028873] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.394406 2026] [security2:error] [pid 1028675:tid 1028930] [client 158.23.184.117:19354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "apK9StdHPfW2QFvhmL7NKAAAAHg"] [Sat Aug 29 05:06:50.395286 2026] [security2:error] [pid 1028675:tid 1028810] [client 158.23.184.117:47005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/goods.php"] [unique_id "apK9StdHPfW2QFvhmL7NKQAAAAA"] [Sat Aug 29 05:06:50.402334 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.402350 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.403177 2026] [security2:error] [pid 1028675:tid 1028908] [client 158.23.147.79:61590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9StdHPfW2QFvhmL7NKwAAAGI"] [Sat Aug 29 05:06:50.409151 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.409169 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.416593 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.416608 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.420967 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.420980 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.426046 2026] [security2:error] [pid 1018003:tid 1018088] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDPgAFwUM"] [Sat Aug 29 05:06:50.430649 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.18.15:36856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/abcd.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDPwAABgo"] [Sat Aug 29 05:06:50.434160 2026] [security2:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDQAAF9UA"] [Sat Aug 29 05:06:50.445076 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.104.104.62:64647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/Contrller.php"] [unique_id "apK9StdHPfW2QFvhmL7NLgAAAEk"] [Sat Aug 29 05:06:50.455586 2026] [autoindex:error] [pid 1018003:tid 1018192] [client 147.185.132.39:60412] AH01276: Cannot serve directory /home3/rwnbzvmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:50.462893 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.104.62:27022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/wp.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDRAAABgM"] [Sat Aug 29 05:06:50.467545 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.220.204.93:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/lkui.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDRQAABes"] [Sat Aug 29 05:06:50.479932 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.104.104.62:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/meiwei.php"] [unique_id "apK9StdHPfW2QFvhmL7NMQAAAHE"] [Sat Aug 29 05:06:50.481091 2026] [security2:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDRgAGIhw"] [Sat Aug 29 05:06:50.485501 2026] [core:error] [pid 1028675:tid 1028926] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.485517 2026] [core:error] [pid 1028675:tid 1028926] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.494636 2026] [security2:error] [pid 1028675:tid 1028812] [client 20.104.104.62:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/sao.php"] [unique_id "apK9StdHPfW2QFvhmL7NNQAAAAI"] [Sat Aug 29 05:06:50.506748 2026] [security2:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDTQAGIiI"] [Sat Aug 29 05:06:50.514621 2026] [security2:error] [pid 1018003:tid 1018190] [client 4.205.62.107:53356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/aws_credentials.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDTwAABd8"] [Sat Aug 29 05:06:50.515103 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.515113 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.515145 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.515154 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.524010 2026] [security2:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDUAAGIjE"] [Sat Aug 29 05:06:50.525578 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.525593 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.538216 2026] [security2:error] [pid 1028675:tid 1028914] [client 158.23.184.117:33930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/manager.php"] [unique_id "apK9StdHPfW2QFvhmL7NOAAAAGg"] [Sat Aug 29 05:06:50.541005 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.184.117:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/w.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDUwAABcg"] [Sat Aug 29 05:06:50.541298 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.184.117:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/security.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDVAAABjM"] [Sat Aug 29 05:06:50.542706 2026] [security2:error] [pid 1018003:tid 1018196] [client 158.23.147.79:17456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/file.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDVgAABeU"] [Sat Aug 29 05:06:50.542926 2026] [security2:error] [pid 1018003:tid 1018059] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDVQAFyCY"] [Sat Aug 29 05:06:50.543649 2026] [security2:error] [pid 1018003:tid 1018079] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDVwAFyDo"] [Sat Aug 29 05:06:50.552703 2026] [security2:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDWAAF71s"] [Sat Aug 29 05:06:50.558378 2026] [security2:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDWQAF-iA"] [Sat Aug 29 05:06:50.558776 2026] [security2:error] [pid 1028675:tid 1028922] [client 20.197.61.180:7872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/backup.php"] [unique_id "apK9StdHPfW2QFvhmL7NOQAAAHA"] [Sat Aug 29 05:06:50.563379 2026] [security2:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDWgAF2yo"] [Sat Aug 29 05:06:50.567932 2026] [security2:error] [pid 1028675:tid 1028927] [client 68.155.159.216:18431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9StdHPfW2QFvhmL7NOwAAAHU"] [Sat Aug 29 05:06:50.571188 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.48.250.41:21388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/fetch.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDXQAABjE"] [Sat Aug 29 05:06:50.577741 2026] [security2:error] [pid 1018003:tid 1018091] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDYQAGLkY"] [Sat Aug 29 05:06:50.577810 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.104.104.62:28819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/adminfuns.php"] [unique_id "apK9StdHPfW2QFvhmL7NPQAAAAg"] [Sat Aug 29 05:06:50.582552 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.104.104.62:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/Zeiss.php"] [unique_id "apK9StdHPfW2QFvhmL7NPwAAAA4"] [Sat Aug 29 05:06:50.582573 2026] [security2:error] [pid 1028675:tid 1028827] [client 158.23.147.79:24434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/worksec.php"] [unique_id "apK9StdHPfW2QFvhmL7NPgAAABE"] [Sat Aug 29 05:06:50.592306 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.151.200.44:47415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/k8.php"] [unique_id "apK9StdHPfW2QFvhmL7NQAAAADI"] [Sat Aug 29 05:06:50.599917 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.599932 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.600277 2026] [core:error] [pid 1018003:tid 1018216] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.600289 2026] [core:error] [pid 1018003:tid 1018216] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.601642 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.601654 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.605651 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.52.41.200:1783] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpsl-ggc.org"] [uri "/1.php7"] [unique_id "apK9StdHPfW2QFvhmL7NQQAAACU"] [Sat Aug 29 05:06:50.605733 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.52.41.200:1783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/1.php7"] [unique_id "apK9StdHPfW2QFvhmL7NQQAAACU"] [Sat Aug 29 05:06:50.607002 2026] [security2:error] [pid 1018003:tid 1018188] [client 4.205.62.107:22337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/ah25.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDZQAABd0"] [Sat Aug 29 05:06:50.617373 2026] [security2:error] [pid 1028675:tid 1028920] [client 158.158.54.35:29674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/core.php"] [unique_id "apK9StdHPfW2QFvhmL7NQgAAAG4"] [Sat Aug 29 05:06:50.629835 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.104.62:42673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/uuu.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDZgAABeQ"] [Sat Aug 29 05:06:50.632384 2026] [security2:error] [pid 1018003:tid 1018162] [client 68.155.159.216:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/file17.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDZwAABcM"] [Sat Aug 29 05:06:50.645417 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.220.204.93:50794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDaAAABis"] [Sat Aug 29 05:06:50.655205 2026] [security2:error] [pid 1028675:tid 1028849] [client 158.23.147.79:26531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/ws.php"] [unique_id "apK9StdHPfW2QFvhmL7NQwAAACc"] [Sat Aug 29 05:06:50.656113 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.104.104.62:27034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/ioxi-o.php"] [unique_id "apK9StdHPfW2QFvhmL7NRAAAACI"] [Sat Aug 29 05:06:50.662206 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.147.79:50048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/chosen.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDaQAABiA"] [Sat Aug 29 05:06:50.668633 2026] [security2:error] [pid 1018003:tid 1018233] [client 168.107.94.195:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDagAABgk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:50.670574 2026] [security2:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDawAF2Es"] [Sat Aug 29 05:06:50.687096 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.184.117:62290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/new.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDcwAABiY"] [Sat Aug 29 05:06:50.689543 2026] [security2:error] [pid 1028675:tid 1028917] [client 158.23.184.117:19348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/system.php"] [unique_id "apK9StdHPfW2QFvhmL7NRgAAAGs"] [Sat Aug 29 05:06:50.697034 2026] [core:error] [pid 1028675:tid 1028934] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.697052 2026] [core:error] [pid 1028675:tid 1028934] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.699818 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.699837 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.700051 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.700073 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.700600 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.700608 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.705486 2026] [security2:error] [pid 1028675:tid 1028839] [client 158.23.184.117:33937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/media.php"] [unique_id "apK9StdHPfW2QFvhmL7NSwAAAB0"] [Sat Aug 29 05:06:50.717274 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.717296 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.717805 2026] [security2:error] [pid 1028675:tid 1028834] [client 20.104.104.62:4135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/ww2.php"] [unique_id "apK9StdHPfW2QFvhmL7NTgAAABg"] [Sat Aug 29 05:06:50.720372 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.23.147.79:59200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9StdHPfW2QFvhmL7NUAAAAEo"] [Sat Aug 29 05:06:50.722726 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.722739 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.723948 2026] [security2:error] [pid 1028675:tid 1028828] [client 68.155.159.216:33665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9StdHPfW2QFvhmL7NUQAAABI"] [Sat Aug 29 05:06:50.732794 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.732812 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.733165 2026] [security2:error] [pid 1028675:tid 1028895] [client 20.48.250.41:21437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/vx.php"] [unique_id "apK9StdHPfW2QFvhmL7NVQAAAFU"] [Sat Aug 29 05:06:50.735029 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.735044 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.738735 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.738750 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.741281 2026] [core:error] [pid 1028675:tid 1028867] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.741300 2026] [core:error] [pid 1028675:tid 1028867] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.744657 2026] [core:error] [pid 1028675:tid 1028868] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.744674 2026] [core:error] [pid 1028675:tid 1028868] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.770961 2026] [security2:error] [pid 1028675:tid 1028813] [client 20.104.104.62:29199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-content/about.php"] [unique_id "apK9StdHPfW2QFvhmL7NWQAAAAM"] [Sat Aug 29 05:06:50.780581 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.780599 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.790348 2026] [security2:error] [pid 1028675:tid 1028832] [client 40.83.93.50:7693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/randkeyword.php"] [unique_id "apK9StdHPfW2QFvhmL7NXAAAABY"] [Sat Aug 29 05:06:50.803616 2026] [security2:error] [pid 1028675:tid 1028810] [client 20.220.204.93:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/motu.php"] [unique_id "apK9StdHPfW2QFvhmL7NXwAAAAA"] [Sat Aug 29 05:06:50.812777 2026] [security2:error] [pid 1028675:tid 1028840] [client 158.23.147.79:30558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9StdHPfW2QFvhmL7NYQAAAB4"] [Sat Aug 29 05:06:50.815139 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.815154 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.815964 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.815979 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.819255 2026] [core:error] [pid 1028675:tid 1028908] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.819271 2026] [core:error] [pid 1028675:tid 1028908] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.829191 2026] [security2:error] [pid 1018003:tid 1018206] [client 20.104.104.62:40202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/fonts/priv8.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDiwAABe8"] [Sat Aug 29 05:06:50.833170 2026] [security2:error] [pid 1028675:tid 1028843] [client 158.23.184.117:57107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/php8.php"] [unique_id "apK9StdHPfW2QFvhmL7NZgAAACE"] [Sat Aug 29 05:06:50.833605 2026] [security2:error] [pid 1028675:tid 1028886] [client 158.23.184.117:19380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/users.php"] [unique_id "apK9StdHPfW2QFvhmL7NZwAAAEw"] [Sat Aug 29 05:06:50.839801 2026] [security2:error] [pid 1028675:tid 1028894] [client 68.155.159.216:30604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/file5.php"] [unique_id "apK9StdHPfW2QFvhmL7NaAAAAFQ"] [Sat Aug 29 05:06:50.849268 2026] [core:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.849281 2026] [core:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.849288 2026] [security2:error] [pid 1028675:tid 1028877] [client 158.23.184.117:33943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/mar.php"] [unique_id "apK9StdHPfW2QFvhmL7NagAAAEM"] [Sat Aug 29 05:06:50.850753 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.104.104.62:23408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/private.php"] [unique_id "apK9StdHPfW2QFvhmL7NbAAAAFI"] [Sat Aug 29 05:06:50.857441 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.104.104.62:43031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/anz.php"] [unique_id "apK9StdHPfW2QFvhmL7NbwAAAD4"] [Sat Aug 29 05:06:50.876129 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.48.250.41:21503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/global.php"] [unique_id "apK9StdHPfW2QFvhmL7NcAAAAEk"] [Sat Aug 29 05:06:50.878677 2026] [security2:error] [pid 1018003:tid 1018218] [client 4.205.62.107:22236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/BDKR28WP.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDkgAABfs"] [Sat Aug 29 05:06:50.885627 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.885645 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.886624 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.886639 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.892004 2026] [core:error] [pid 1018003:tid 1018106] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.892018 2026] [core:error] [pid 1018003:tid 1018106] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.892645 2026] [security2:error] [pid 1018003:tid 1018175] [client 4.205.62.107:65435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/sgd.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDmgAABdA"] [Sat Aug 29 05:06:50.893292 2026] [core:error] [pid 1028675:tid 1028921] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.893302 2026] [core:error] [pid 1028675:tid 1028921] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.913439 2026] [core:error] [pid 1028675:tid 1028914] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.913468 2026] [core:error] [pid 1028675:tid 1028914] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.922076 2026] [security2:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDoAAFul8"] [Sat Aug 29 05:06:50.922467 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.922487 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.922779 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.922792 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.925933 2026] [security2:error] [pid 1028675:tid 1028829] [client 20.104.104.62:27062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/system_core.php"] [unique_id "apK9StdHPfW2QFvhmL7NdgAAABM"] [Sat Aug 29 05:06:50.929462 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.929479 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.936072 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.196.209.81:9522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/add_actualites.php"] [unique_id "apK9StdHPfW2QFvhmL7NdwAAAEQ"] [Sat Aug 29 05:06:50.944267 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.944288 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.946155 2026] [security2:error] [pid 1028675:tid 1028831] [client 20.220.204.93:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/Ov-Simple1.php"] [unique_id "apK9StdHPfW2QFvhmL7NegAAABU"] [Sat Aug 29 05:06:50.946193 2026] [security2:error] [pid 1018003:tid 1018177] [client 4.205.62.107:22490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/broadcasting.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDowAABdI"] [Sat Aug 29 05:06:50.965742 2026] [security2:error] [pid 1028675:tid 1028852] [client 20.104.104.62:29200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/66.php"] [unique_id "apK9StdHPfW2QFvhmL7NgQAAACo"] [Sat Aug 29 05:06:50.965785 2026] [security2:error] [pid 1028675:tid 1028684] [remote 31.13.127.112:64462] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.jobindjibouti.com"] [uri "/wp-content/uploads/2017/08/Logo-couleur-e1596529147682.png"] [unique_id "apK9StdHPfW2QFvhmL7NfwAABQQ"] [Sat Aug 29 05:06:50.969684 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.969698 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.973147 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.973159 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.975144 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.975156 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:50.975711 2026] [security2:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDqgAFumk"] [Sat Aug 29 05:06:50.984274 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.184.117:19378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/wp-blog-header.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDqwAABiA"] [Sat Aug 29 05:06:50.987199 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.184.117:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9SjAh5Y1i2tUxg4EDrAAABgY"] [Sat Aug 29 05:06:50.994383 2026] [security2:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9SjAh5Y1i2tUxg4EDrQAFwWQ"] [Sat Aug 29 05:06:50.995832 2026] [security2:error] [pid 1028675:tid 1028911] [client 158.23.184.117:34736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/my1.php"] [unique_id "apK9StdHPfW2QFvhmL7NhAAAAGU"] [Sat Aug 29 05:06:51.013951 2026] [security2:error] [pid 1028675:tid 1028828] [client 158.23.184.117:46920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/wk/admin.php"] [unique_id "apK9S9dHPfW2QFvhmL7NhQAAABI"] [Sat Aug 29 05:06:51.015262 2026] [security2:error] [pid 1028675:tid 1028876] [client 158.23.147.79:32760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7NhgAAAEI"] [Sat Aug 29 05:06:51.023884 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.104.62:64696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/bge.php"] [unique_id "apK9SzAh5Y1i2tUxg4EDrwAABb4"] [Sat Aug 29 05:06:51.033268 2026] [security2:error] [pid 1028675:tid 1028819] [client 20.48.250.41:21377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/fs.php"] [unique_id "apK9S9dHPfW2QFvhmL7NiQAAAAk"] [Sat Aug 29 05:06:51.037902 2026] [security2:error] [pid 1018003:tid 1018132] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EDsAAGKW8"] [Sat Aug 29 05:06:51.038265 2026] [security2:error] [pid 1028675:tid 1028817] [client 68.155.159.216:50195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7NigAAAAc"] [Sat Aug 29 05:06:51.047838 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.52.41.200:1255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/disagraeosc.php"] [unique_id "apK9S9dHPfW2QFvhmL7NiwAAAEY"] [Sat Aug 29 05:06:51.048885 2026] [security2:error] [pid 1028675:tid 1028851] [client 168.107.94.195:61618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9S9dHPfW2QFvhmL7NjQAAACk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:51.053101 2026] [core:error] [pid 1018003:tid 1018217] [client 45.148.10.62:49786] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.054860 2026] [security2:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EDtAAF3wY"] [Sat Aug 29 05:06:51.062582 2026] [security2:error] [pid 1028675:tid 1028882] [client 68.155.159.216:52821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/hehehehe.php"] [unique_id "apK9S9dHPfW2QFvhmL7NjgAAAEg"] [Sat Aug 29 05:06:51.068793 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.104.104.62:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/lfi.php"] [unique_id "apK9S9dHPfW2QFvhmL7NjwAAAHc"] [Sat Aug 29 05:06:51.071706 2026] [security2:error] [pid 1028675:tid 1028902] [client 52.139.37.240:61659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/wp-2019.php"] [unique_id "apK9S9dHPfW2QFvhmL7NkQAAAFw"] [Sat Aug 29 05:06:51.074536 2026] [security2:error] [pid 1018003:tid 1018117] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EDuAAF32A"] [Sat Aug 29 05:06:51.078795 2026] [security2:error] [pid 1028675:tid 1028913] [client 68.155.159.216:51303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7NkgAAAGc"] [Sat Aug 29 05:06:51.085586 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.085604 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.086669 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.086685 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.087542 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.087557 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.089016 2026] [security2:error] [pid 1018003:tid 1018244] [client 158.158.54.35:8734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/admin/function.php"] [unique_id "apK9SzAh5Y1i2tUxg4EDvQAABhQ"] [Sat Aug 29 05:06:51.092318 2026] [security2:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EDvgAF3zQ"] [Sat Aug 29 05:06:51.092949 2026] [security2:error] [pid 1018003:tid 1018226] [client 52.139.37.240:31123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/mah.php"] [unique_id "apK9SzAh5Y1i2tUxg4EDvwAABgM"] [Sat Aug 29 05:06:51.102111 2026] [security2:error] [pid 1028675:tid 1028856] [client 52.139.37.240:32731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/an.php"] [unique_id "apK9S9dHPfW2QFvhmL7NlwAAAC4"] [Sat Aug 29 05:06:51.103302 2026] [security2:error] [pid 1028675:tid 1028833] [client 52.139.37.240:20767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-update.php"] [unique_id "apK9S9dHPfW2QFvhmL7NmAAAABc"] [Sat Aug 29 05:06:51.113817 2026] [security2:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EDwQAF33s"] [Sat Aug 29 05:06:51.114683 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.114695 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.124329 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.124345 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.127348 2026] [security2:error] [pid 1028675:tid 1028862] [client 158.23.184.117:19372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/wp-links-opml.php"] [unique_id "apK9S9dHPfW2QFvhmL7NmgAAADQ"] [Sat Aug 29 05:06:51.130087 2026] [security2:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EDxQAF31Y"] [Sat Aug 29 05:06:51.133295 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.184.117:46984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/txets.php"] [unique_id "apK9SzAh5Y1i2tUxg4EDyQAABco"] [Sat Aug 29 05:06:51.156770 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.104.104.62:43019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/wp-ana.php"] [unique_id "apK9S9dHPfW2QFvhmL7NoQAAAAE"] [Sat Aug 29 05:06:51.158821 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.104.104.62:29207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/elp.php"] [unique_id "apK9S9dHPfW2QFvhmL7NogAAAA8"] [Sat Aug 29 05:06:51.159370 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.159390 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.159453 2026] [core:error] [pid 1028675:tid 1028899] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.159464 2026] [core:error] [pid 1028675:tid 1028899] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.159806 2026] [security2:error] [pid 1028675:tid 1028810] [client 158.23.184.117:33924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/mm.php"] [unique_id "apK9S9dHPfW2QFvhmL7NowAAAAA"] [Sat Aug 29 05:06:51.161158 2026] [security2:error] [pid 1018003:tid 1018196] [client 158.23.184.117:46359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/admin.php"] [unique_id "apK9SzAh5Y1i2tUxg4EDywAABeU"] [Sat Aug 29 05:06:51.166005 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.104.104.62:20724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/vendor/priv8.php"] [unique_id "apK9S9dHPfW2QFvhmL7NpQAAAEk"] [Sat Aug 29 05:06:51.166231 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.220.204.93:52338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/wp-blogs.php"] [unique_id "apK9SzAh5Y1i2tUxg4EDzQAABjM"] [Sat Aug 29 05:06:51.171510 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.171529 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.171574 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.171583 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.171630 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.171639 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.173752 2026] [security2:error] [pid 1028675:tid 1028905] [client 158.23.147.79:25548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7NpgAAAF8"] [Sat Aug 29 05:06:51.174730 2026] [security2:error] [pid 1028675:tid 1028932] [client 68.155.159.216:49278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9S9dHPfW2QFvhmL7NpwAAAHo"] [Sat Aug 29 05:06:51.179310 2026] [security2:error] [pid 1028675:tid 1028936] [client 20.151.200.44:47363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/alog.php"] [unique_id "apK9S9dHPfW2QFvhmL7NqAAAAH4"] [Sat Aug 29 05:06:51.187479 2026] [security2:error] [pid 1028675:tid 1028908] [client 52.139.37.240:9114] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.drjrae.com"] [uri "/c99.php"] [unique_id "apK9S9dHPfW2QFvhmL7NqgAAAGI"] [Sat Aug 29 05:06:51.191382 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.104.62:27045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/goods.php"] [unique_id "apK9SzAh5Y1i2tUxg4ED0gAABdk"] [Sat Aug 29 05:06:51.196664 2026] [security2:error] [pid 1028675:tid 1028916] [client 20.48.250.41:21479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ioxi.php"] [unique_id "apK9S9dHPfW2QFvhmL7NrAAAAGo"] [Sat Aug 29 05:06:51.240182 2026] [security2:error] [pid 1028675:tid 1028921] [client 52.139.37.240:32838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/gecko-new.php"] [unique_id "apK9S9dHPfW2QFvhmL7NsAAAAG8"] [Sat Aug 29 05:06:51.243016 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.243033 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.251892 2026] [core:error] [pid 1028675:tid 1028850] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.251912 2026] [core:error] [pid 1028675:tid 1028850] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.256908 2026] [security2:error] [pid 1028675:tid 1028846] [client 158.23.147.79:48406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/.well-known/content.php"] [unique_id "apK9S9dHPfW2QFvhmL7NtQAAACQ"] [Sat Aug 29 05:06:51.266152 2026] [security2:error] [pid 1028675:tid 1028845] [client 52.139.37.240:2907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/gecko-new.php"] [unique_id "apK9S9dHPfW2QFvhmL7NtgAAACM"] [Sat Aug 29 05:06:51.269155 2026] [security2:error] [pid 1028675:tid 1028827] [client 158.23.184.117:19266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/wp-load.php"] [unique_id "apK9S9dHPfW2QFvhmL7NuQAAABE"] [Sat Aug 29 05:06:51.269258 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.269270 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.271785 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.271798 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.275761 2026] [security2:error] [pid 1028675:tid 1028840] [client 40.83.93.50:7572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/goods.php"] [unique_id "apK9S9dHPfW2QFvhmL7NuwAAAB4"] [Sat Aug 29 05:06:51.278825 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.278840 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.284518 2026] [security2:error] [pid 1028675:tid 1028896] [client 158.23.147.79:30579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7NvQAAAFY"] [Sat Aug 29 05:06:51.291580 2026] [security2:error] [pid 1028675:tid 1028860] [client 158.23.184.117:46999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/adminfuns.php"] [unique_id "apK9S9dHPfW2QFvhmL7NvgAAADI"] [Sat Aug 29 05:06:51.293600 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.104.104.62:56357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/secret.php"] [unique_id "apK9S9dHPfW2QFvhmL7NvwAAAEA"] [Sat Aug 29 05:06:51.298743 2026] [security2:error] [pid 1028675:tid 1028824] [client 52.139.37.240:32109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/asw.php"] [unique_id "apK9S9dHPfW2QFvhmL7NwAAAAA4"] [Sat Aug 29 05:06:51.301051 2026] [security2:error] [pid 1028675:tid 1028814] [client 52.139.37.240:31041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/mini.php"] [unique_id "apK9S9dHPfW2QFvhmL7NwQAAAAQ"] [Sat Aug 29 05:06:51.302129 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.302146 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.302971 2026] [security2:error] [pid 1028675:tid 1028815] [client 158.23.184.117:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/network.php"] [unique_id "apK9S9dHPfW2QFvhmL7NwgAAAAU"] [Sat Aug 29 05:06:51.303024 2026] [security2:error] [pid 1018003:tid 1018234] [client 68.155.159.216:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9SzAh5Y1i2tUxg4ED6AAABgo"] [Sat Aug 29 05:06:51.303821 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.104.104.62:42665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/quoys.php"] [unique_id "apK9S9dHPfW2QFvhmL7NwwAAAB8"] [Sat Aug 29 05:06:51.304810 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.23.184.117:47029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/goods.php"] [unique_id "apK9SzAh5Y1i2tUxg4ED6QAABdw"] [Sat Aug 29 05:06:51.305441 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.220.204.93:50781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/mini.php"] [unique_id "apK9S9dHPfW2QFvhmL7NxAAAAEY"] [Sat Aug 29 05:06:51.308691 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.308708 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.310543 2026] [security2:error] [pid 1028675:tid 1028878] [client 52.139.37.240:20766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/xmrlpc.php"] [unique_id "apK9S9dHPfW2QFvhmL7NxQAAAEQ"] [Sat Aug 29 05:06:51.312555 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.312568 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.321086 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.321105 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.322782 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.322796 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.330434 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.151.200.44:61913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/f2r4.php"] [unique_id "apK9SzAh5Y1i2tUxg4ED9AAABhQ"] [Sat Aug 29 05:06:51.330592 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.330605 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.343975 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.343990 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.346215 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.48.250.41:21501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/bootstrap.php"] [unique_id "apK9SzAh5Y1i2tUxg4ED-AAABhM"] [Sat Aug 29 05:06:51.347630 2026] [security2:error] [pid 1018003:tid 1018156] [client 68.155.159.216:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9SzAh5Y1i2tUxg4ED-gAABb0"] [Sat Aug 29 05:06:51.349681 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.349696 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.359649 2026] [security2:error] [pid 1028675:tid 1028895] [client 20.104.104.62:28815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/ioxi-o.php"] [unique_id "apK9S9dHPfW2QFvhmL7NzQAAAFU"] [Sat Aug 29 05:06:51.359681 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.196.209.81:9446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/alfanew.php7"] [unique_id "apK9S9dHPfW2QFvhmL7NzAAAAGg"] [Sat Aug 29 05:06:51.369520 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.369540 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.370129 2026] [security2:error] [pid 1028675:tid 1028933] [client 4.205.62.107:56025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/env.php"] [unique_id "apK9S9dHPfW2QFvhmL7NzgAAAHs"] [Sat Aug 29 05:06:51.382491 2026] [security2:error] [pid 1028675:tid 1028882] [client 52.139.37.240:8619] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.drjrae.com"] [uri "/c99.php"] [unique_id "apK9S9dHPfW2QFvhmL7NzwAAAEg"] [Sat Aug 29 05:06:51.387081 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.387094 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.387451 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.387467 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.389397 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.104.62:27040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/bolt.php"] [unique_id "apK9S9dHPfW2QFvhmL7N0gAAAFw"] [Sat Aug 29 05:06:51.397718 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.197.61.180:15952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/haiterus.php"] [unique_id "apK9SzAh5Y1i2tUxg4ED_gAABc8"] [Sat Aug 29 05:06:51.414093 2026] [security2:error] [pid 1028675:tid 1028832] [client 158.23.184.117:19365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/wp-mail.php"] [unique_id "apK9S9dHPfW2QFvhmL7N1QAAABY"] [Sat Aug 29 05:06:51.422006 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.422028 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.424556 2026] [core:error] [pid 1028675:tid 1028889] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.424577 2026] [core:error] [pid 1028675:tid 1028889] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.425073 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.104.104.62:4856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/pro.php"] [unique_id "apK9S9dHPfW2QFvhmL7N2QAAABs"] [Sat Aug 29 05:06:51.429169 2026] [security2:error] [pid 1028675:tid 1028855] [client 168.107.94.195:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7N2wAAAC0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:51.436854 2026] [security2:error] [pid 1028675:tid 1028866] [client 158.23.184.117:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/403.php"] [unique_id "apK9S9dHPfW2QFvhmL7N3AAAADg"] [Sat Aug 29 05:06:51.446063 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.151.200.44:64357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/hq.php"] [unique_id "apK9S9dHPfW2QFvhmL7N3QAAABk"] [Sat Aug 29 05:06:51.447388 2026] [security2:error] [pid 1028675:tid 1028825] [client 158.23.184.117:33936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/new.php"] [unique_id "apK9S9dHPfW2QFvhmL7N3gAAAA8"] [Sat Aug 29 05:06:51.448992 2026] [security2:error] [pid 1028675:tid 1028821] [client 52.139.37.240:33570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/add_actualites.php"] [unique_id "apK9S9dHPfW2QFvhmL7N3wAAAAs"] [Sat Aug 29 05:06:51.452407 2026] [security2:error] [pid 1028675:tid 1028810] [client 158.23.184.117:46982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/w.php"] [unique_id "apK9S9dHPfW2QFvhmL7N4QAAAAA"] [Sat Aug 29 05:06:51.453243 2026] [core:error] [pid 1028675:tid 1028936] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.453256 2026] [core:error] [pid 1028675:tid 1028936] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.460586 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.460603 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.481833 2026] [security2:error] [pid 1028675:tid 1028899] [client 52.139.37.240:2883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/add_actualites.php"] [unique_id "apK9S9dHPfW2QFvhmL7N6QAAAFk"] [Sat Aug 29 05:06:51.483239 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.220.204.93:52290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/amp.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEEAAABgI"] [Sat Aug 29 05:06:51.484116 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.484133 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.492673 2026] [security2:error] [pid 1028675:tid 1028863] [client 52.139.37.240:32127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/item.php"] [unique_id "apK9S9dHPfW2QFvhmL7N6gAAADU"] [Sat Aug 29 05:06:51.498588 2026] [security2:error] [pid 1028675:tid 1028865] [client 52.139.37.240:31015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/v.php"] [unique_id "apK9S9dHPfW2QFvhmL7N6wAAADc"] [Sat Aug 29 05:06:51.500215 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.18.15:13719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/k.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEEQAABiY"] [Sat Aug 29 05:06:51.502970 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.250.41:21315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/export.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEEgAABis"] [Sat Aug 29 05:06:51.504125 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.52.41.200:1152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-logs.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEEwAABeM"] [Sat Aug 29 05:06:51.504633 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.104.62:60465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/vbbn.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEFAAABcI"] [Sat Aug 29 05:06:51.506770 2026] [security2:error] [pid 1028675:tid 1028867] [client 52.139.37.240:21411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/about/function.php"] [unique_id "apK9S9dHPfW2QFvhmL7N7AAAADk"] [Sat Aug 29 05:06:51.511667 2026] [security2:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9SzAh5Y1i2tUxg4EEFQAF3xQ"] [Sat Aug 29 05:06:51.512456 2026] [security2:error] [pid 1018003:tid 1018160] [client 158.23.147.79:59843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEFgAABcE"] [Sat Aug 29 05:06:51.522663 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.522679 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.522860 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.522886 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.523055 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.104.62:64725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/css/priv8.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEGQAABfA"] [Sat Aug 29 05:06:51.523060 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.523070 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.524805 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.524820 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.525627 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.525642 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.529141 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.529151 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.559170 2026] [security2:error] [pid 1028675:tid 1028854] [client 158.23.184.117:19379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/wp-settings.php"] [unique_id "apK9S9dHPfW2QFvhmL7N9AAAACw"] [Sat Aug 29 05:06:51.560398 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.560426 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.565065 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.104.62:4820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/999.php"] [unique_id "apK9S9dHPfW2QFvhmL7N9gAAAD0"] [Sat Aug 29 05:06:51.565641 2026] [core:error] [pid 1028675:tid 1028878] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.565652 2026] [core:error] [pid 1028675:tid 1028878] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.576786 2026] [security2:error] [pid 1018003:tid 1018277] [client 52.139.37.240:8508] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webdisk.drjrae.com"] [uri "/c99.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEJAAABjU"] [Sat Aug 29 05:06:51.585759 2026] [security2:error] [pid 1028675:tid 1028901] [client 158.158.54.35:20594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/admin/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7N-gAAAFs"] [Sat Aug 29 05:06:51.587025 2026] [cgid:error] [pid 1018003:tid 1018157] [client 158.23.184.117:62303] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/dontbenicemovie/404.shtml [Sat Aug 29 05:06:51.587638 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.104.104.62:27028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/file.php"] [unique_id "apK9S9dHPfW2QFvhmL7N-wAAAB0"] [Sat Aug 29 05:06:51.587747 2026] [core:error] [pid 1028675:tid 1028891] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.587754 2026] [core:error] [pid 1028675:tid 1028891] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.589478 2026] [core:error] [pid 1028675:tid 1028856] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.589489 2026] [core:error] [pid 1028675:tid 1028856] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.590238 2026] [security2:error] [pid 1028675:tid 1028814] [client 158.23.184.117:33921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/0x.php"] [unique_id "apK9S9dHPfW2QFvhmL7N_QAAAAQ"] [Sat Aug 29 05:06:51.596879 2026] [security2:error] [pid 1028675:tid 1028815] [client 158.23.184.117:46385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/new.php"] [unique_id "apK9S9dHPfW2QFvhmL7N_gAAAAU"] [Sat Aug 29 05:06:51.597782 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:36548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/nofile.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEJgAABeE"] [Sat Aug 29 05:06:51.625530 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.104.62:28806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-links-opml.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEKAAABcc"] [Sat Aug 29 05:06:51.627660 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.627674 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.632836 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.632850 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.634179 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.184.117:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/.trash7206/index.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEKgAABb0"] [Sat Aug 29 05:06:51.636718 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.104.18.15:13633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/82.php"] [unique_id "apK9S9dHPfW2QFvhmL7OAgAAAC8"] [Sat Aug 29 05:06:51.644239 2026] [security2:error] [pid 1028675:tid 1028931] [client 52.139.37.240:33575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/browse.php"] [unique_id "apK9S9dHPfW2QFvhmL7OBAAAAHk"] [Sat Aug 29 05:06:51.651403 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.147.79:17492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/file17.php"] [unique_id "apK9SzAh5Y1i2tUxg4EELAAABjM"] [Sat Aug 29 05:06:51.652954 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.250.41:21455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/gk.php"] [unique_id "apK9SzAh5Y1i2tUxg4EELQAABcg"] [Sat Aug 29 05:06:51.656729 2026] [core:error] [pid 1028675:tid 1028898] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.656747 2026] [core:error] [pid 1028675:tid 1028898] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.668611 2026] [security2:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EEMQAGHy4"] [Sat Aug 29 05:06:51.669938 2026] [core:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.669952 2026] [core:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.679616 2026] [security2:error] [pid 1028675:tid 1028929] [client 52.139.37.240:2890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/browse.php"] [unique_id "apK9S9dHPfW2QFvhmL7OBgAAAHc"] [Sat Aug 29 05:06:51.687914 2026] [security2:error] [pid 1018003:tid 1018153] [client 52.139.37.240:32062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/jga.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEMwAABbo"] [Sat Aug 29 05:06:51.688774 2026] [security2:error] [pid 1018003:tid 1018172] [client 68.155.159.216:18329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/radio.php"] [unique_id "apK9SzAh5Y1i2tUxg4EENAAABc0"] [Sat Aug 29 05:06:51.693514 2026] [security2:error] [pid 1028675:tid 1028925] [client 52.139.37.240:31064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9S9dHPfW2QFvhmL7OBwAAAHM"] [Sat Aug 29 05:06:51.696021 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.696041 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.706239 2026] [security2:error] [pid 1028675:tid 1028831] [client 52.139.37.240:21175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/an.php"] [unique_id "apK9S9dHPfW2QFvhmL7OCAAAABU"] [Sat Aug 29 05:06:51.706521 2026] [security2:error] [pid 1018003:tid 1018273] [client 158.23.184.117:19278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/.well-known/wp-signup.php"] [unique_id "apK9SzAh5Y1i2tUxg4EENgAABjE"] [Sat Aug 29 05:06:51.709875 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.104.62:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/sef.php"] [unique_id "apK9SzAh5Y1i2tUxg4EENwAABdI"] [Sat Aug 29 05:06:51.717578 2026] [security2:error] [pid 1018003:tid 1018250] [client 4.205.62.107:53408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/v1.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEOAAABho"] [Sat Aug 29 05:06:51.718743 2026] [security2:error] [pid 1028675:tid 1028926] [client 20.104.104.62:52045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/rfi.php"] [unique_id "apK9S9dHPfW2QFvhmL7OCQAAAHQ"] [Sat Aug 29 05:06:51.721062 2026] [security2:error] [pid 1028675:tid 1028886] [client 20.220.204.93:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/cc13.php"] [unique_id "apK9S9dHPfW2QFvhmL7OCgAAAEw"] [Sat Aug 29 05:06:51.721701 2026] [security2:error] [pid 1018003:tid 1018057] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EEOQAF7CQ"] [Sat Aug 29 05:06:51.723954 2026] [security2:error] [pid 1018003:tid 1018050] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EEOwAF7B0"] [Sat Aug 29 05:06:51.724841 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.724856 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.727338 2026] [core:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.727363 2026] [core:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.730051 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.730067 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.731039 2026] [core:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.731059 2026] [core:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.733222 2026] [security2:error] [pid 1028675:tid 1028812] [client 68.155.159.216:65111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/file5.php"] [unique_id "apK9S9dHPfW2QFvhmL7OCwAAAAI"] [Sat Aug 29 05:06:51.733962 2026] [core:error] [pid 1018003:tid 1018075] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.733977 2026] [core:error] [pid 1018003:tid 1018075] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.740872 2026] [core:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.740887 2026] [core:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.742499 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.184.117:46925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/php8.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEQQAABc8"] [Sat Aug 29 05:06:51.749321 2026] [security2:error] [pid 1028675:tid 1028932] [client 4.205.62.107:22351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/groceries/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7ODQAAAHo"] [Sat Aug 29 05:06:51.753315 2026] [security2:error] [pid 1028675:tid 1028825] [client 68.155.159.216:16314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/lock.php"] [unique_id "apK9S9dHPfW2QFvhmL7ODgAAAA8"] [Sat Aug 29 05:06:51.753547 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.104.18.15:36614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/run.php"] [unique_id "apK9S9dHPfW2QFvhmL7ODwAAAAs"] [Sat Aug 29 05:06:51.754160 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.196.209.81:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/xmlrpc.php0"] [unique_id "apK9S9dHPfW2QFvhmL7OEAAAAE0"] [Sat Aug 29 05:06:51.769153 2026] [security2:error] [pid 1028675:tid 1028820] [client 158.23.147.79:24498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/x.php"] [unique_id "apK9S9dHPfW2QFvhmL7OEQAAAAo"] [Sat Aug 29 05:06:51.776297 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.18.15:13644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/dex.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEQgAABdw"] [Sat Aug 29 05:06:51.782210 2026] [security2:error] [pid 1028675:tid 1028879] [client 40.83.93.50:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/hehe.php"] [unique_id "apK9S9dHPfW2QFvhmL7OEgAAAEU"] [Sat Aug 29 05:06:51.783767 2026] [security2:error] [pid 1028675:tid 1028837] [client 158.23.184.117:46989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/.trash7206/admin.php"] [unique_id "apK9S9dHPfW2QFvhmL7OEwAAABs"] [Sat Aug 29 05:06:51.783995 2026] [security2:error] [pid 1028675:tid 1028930] [client 45.148.10.62:49790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninaanddon.strangeworx.com"] [uri "/phpinfo.php"] [unique_id "apK9S9dHPfW2QFvhmL7OFAAAAHg"] [Sat Aug 29 05:06:51.784591 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.104.62:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/404.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEQwAABiY"] [Sat Aug 29 05:06:51.798119 2026] [security2:error] [pid 1028675:tid 1028919] [client 158.23.184.117:34746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/0.php"] [unique_id "apK9S9dHPfW2QFvhmL7OFQAAAG0"] [Sat Aug 29 05:06:51.803756 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.48.250.41:21404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/logs1.php"] [unique_id "apK9S9dHPfW2QFvhmL7OFgAAAFk"] [Sat Aug 29 05:06:51.805287 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.805303 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.808593 2026] [security2:error] [pid 1028675:tid 1028849] [client 158.158.54.35:17855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/.trash7206/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7OGAAAACc"] [Sat Aug 29 05:06:51.810092 2026] [security2:error] [pid 1028675:tid 1028863] [client 168.107.94.195:62376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9S9dHPfW2QFvhmL7OGQAAADU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:51.817243 2026] [security2:error] [pid 1028675:tid 1028847] [client 158.23.147.79:50155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/goods.php"] [unique_id "apK9S9dHPfW2QFvhmL7OGwAAACU"] [Sat Aug 29 05:06:51.823176 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.104.62:28838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/feokc.php"] [unique_id "apK9SzAh5Y1i2tUxg4EESwAABeQ"] [Sat Aug 29 05:06:51.840212 2026] [security2:error] [pid 1028675:tid 1028830] [client 52.139.37.240:32843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/contentloader1.php"] [unique_id "apK9S9dHPfW2QFvhmL7OHAAAABQ"] [Sat Aug 29 05:06:51.840553 2026] [security2:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EETQAF-hw"] [Sat Aug 29 05:06:51.840552 2026] [security2:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EETAAF-nE"] [Sat Aug 29 05:06:51.844024 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.151.200.44:47391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/adin.php"] [unique_id "apK9SzAh5Y1i2tUxg4EETwAABiw"] [Sat Aug 29 05:06:51.848538 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.104.62:37196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/admin123.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEUAAABb4"] [Sat Aug 29 05:06:51.850466 2026] [security2:error] [pid 1028675:tid 1028928] [client 158.23.184.117:19330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/002.php"] [unique_id "apK9S9dHPfW2QFvhmL7OHgAAAHY"] [Sat Aug 29 05:06:51.853762 2026] [security2:error] [pid 1028675:tid 1028828] [client 68.155.159.216:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/goat.php"] [unique_id "apK9S9dHPfW2QFvhmL7OHwAAABI"] [Sat Aug 29 05:06:51.859673 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.859690 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.859738 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.859747 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.862048 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.862064 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.862066 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.862077 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.862713 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.862728 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.869246 2026] [security2:error] [pid 1028675:tid 1028922] [client 52.139.37.240:2583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/contentloader1.php"] [unique_id "apK9S9dHPfW2QFvhmL7OIgAAAHA"] [Sat Aug 29 05:06:51.870211 2026] [core:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.870227 2026] [core:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.881751 2026] [security2:error] [pid 1028675:tid 1028924] [client 52.139.37.240:32064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/mac.php"] [unique_id "apK9S9dHPfW2QFvhmL7OJQAAAHI"] [Sat Aug 29 05:06:51.888556 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.184.117:46383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEWQAABcQ"] [Sat Aug 29 05:06:51.891567 2026] [security2:error] [pid 1018003:tid 1018079] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EEWgAGAzo"] [Sat Aug 29 05:06:51.894045 2026] [security2:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9SzAh5Y1i2tUxg4EEWwAGA1s"] [Sat Aug 29 05:06:51.897457 2026] [security2:error] [pid 1028675:tid 1028842] [client 52.139.37.240:31540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apK9S9dHPfW2QFvhmL7OKAAAACA"] [Sat Aug 29 05:06:51.905707 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.18.15:13745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/inso.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEXQAABjM"] [Sat Aug 29 05:06:51.908032 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.104.104.62:40233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/assets/priv8.php"] [unique_id "apK9S9dHPfW2QFvhmL7OKgAAAB0"] [Sat Aug 29 05:06:51.919535 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.104.62:42631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/tajj.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEYAAABc0"] [Sat Aug 29 05:06:51.927229 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.927258 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.927314 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.927397 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.927983 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.928005 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.928577 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.928591 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.932224 2026] [security2:error] [pid 1028675:tid 1028814] [client 158.23.147.79:30628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7OKwAAAAQ"] [Sat Aug 29 05:06:51.932312 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.151.200.44:64869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/sadis.php"] [unique_id "apK9S9dHPfW2QFvhmL7OLAAAAC4"] [Sat Aug 29 05:06:51.934616 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.18.15:36728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/new.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEZQAABh8"] [Sat Aug 29 05:06:51.937253 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.147.79:35789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEZgAABgI"] [Sat Aug 29 05:06:51.937806 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.937820 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.940444 2026] [security2:error] [pid 1018003:tid 1018196] [client 158.23.184.117:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/oxshell.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEZwAABeU"] [Sat Aug 29 05:06:51.945549 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.184.117:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/wp-content/admin.php"] [unique_id "apK9S9dHPfW2QFvhmL7OLQAAADA"] [Sat Aug 29 05:06:51.949120 2026] [security2:error] [pid 1018003:tid 1018185] [client 68.155.159.216:30685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/file88.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEaQAABdo"] [Sat Aug 29 05:06:51.956377 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.220.204.93:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/aa.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEbQAABc8"] [Sat Aug 29 05:06:51.962241 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.52.41.200:1751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/css/about.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEbwAABgc"] [Sat Aug 29 05:06:51.962944 2026] [security2:error] [pid 1028675:tid 1028934] [client 20.48.250.41:21323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/inege.php"] [unique_id "apK9S9dHPfW2QFvhmL7OLwAAAHw"] [Sat Aug 29 05:06:51.964885 2026] [security2:error] [pid 1028675:tid 1028867] [client 158.158.54.35:18144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wk/index.php"] [unique_id "apK9S9dHPfW2QFvhmL7OMAAAADk"] [Sat Aug 29 05:06:51.990835 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.104.62:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/wk/index.php"] [unique_id "apK9SzAh5Y1i2tUxg4EEcQAABcU"] [Sat Aug 29 05:06:51.994413 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:51.994435 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.001565 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.184.117:19267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/0x.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEcgAABis"] [Sat Aug 29 05:06:52.013972 2026] [security2:error] [pid 1028675:tid 1028832] [client 4.205.62.107:22226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/_js.jpg..bk.php"] [unique_id "apK9TNdHPfW2QFvhmL7OMwAAABY"] [Sat Aug 29 05:06:52.025854 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.104.104.62:29224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/k.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEdgAABcE"] [Sat Aug 29 05:06:52.026627 2026] [security2:error] [pid 1028675:tid 1028929] [client 4.205.62.107:58458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9TNdHPfW2QFvhmL7ONQAAAHc"] [Sat Aug 29 05:06:52.028697 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.184.117:62330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/txets.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEdwAABgY"] [Sat Aug 29 05:06:52.032268 2026] [security2:error] [pid 1028675:tid 1028831] [client 4.205.62.107:65469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/fleen.php"] [unique_id "apK9TNdHPfW2QFvhmL7OOAAAABU"] [Sat Aug 29 05:06:52.037480 2026] [security2:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEeQAGJkU"] [Sat Aug 29 05:06:52.038798 2026] [core:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.038810 2026] [core:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.039485 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.039505 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.039765 2026] [core:error] [pid 1018003:tid 1018104] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.039772 2026] [core:error] [pid 1018003:tid 1018104] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.039772 2026] [core:error] [pid 1018003:tid 1018081] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.039782 2026] [core:error] [pid 1018003:tid 1018081] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.039873 2026] [core:error] [pid 1018003:tid 1018066] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.039878 2026] [core:error] [pid 1018003:tid 1018066] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.043677 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.043687 2026] [core:error] [pid 1018003:tid 1018218] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.055660 2026] [core:error] [pid 1018003:tid 1018074] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.055672 2026] [core:error] [pid 1018003:tid 1018074] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.057910 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.057925 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.063598 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.063615 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.082854 2026] [security2:error] [pid 1028675:tid 1028810] [client 4.205.62.107:22026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/v4.php"] [unique_id "apK9TNdHPfW2QFvhmL7OPAAAAAA"] [Sat Aug 29 05:06:52.083598 2026] [security2:error] [pid 1028675:tid 1028907] [client 158.23.184.117:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/php8.php"] [unique_id "apK9TNdHPfW2QFvhmL7OPQAAAGE"] [Sat Aug 29 05:06:52.091971 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.250.41:21472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wp-link10.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEgwAABcs"] [Sat Aug 29 05:06:52.093330 2026] [security2:error] [pid 1028675:tid 1028908] [client 20.220.204.93:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/s1.php"] [unique_id "apK9TNdHPfW2QFvhmL7OPgAAAGI"] [Sat Aug 29 05:06:52.096561 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.096574 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.109101 2026] [core:error] [pid 1018003:tid 1018099] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.109112 2026] [core:error] [pid 1018003:tid 1018099] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.110470 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.104.62:52039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/grsiuk.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEiQAABcc"] [Sat Aug 29 05:06:52.111031 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.111040 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.113605 2026] [security2:error] [pid 1018003:tid 1018172] [client 158.158.54.35:20552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/storage/rip.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEigAABc0"] [Sat Aug 29 05:06:52.115856 2026] [security2:error] [pid 1028675:tid 1028829] [client 158.23.147.79:62669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9TNdHPfW2QFvhmL7OPwAAABM"] [Sat Aug 29 05:06:52.116309 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.104.62:56373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/7h.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEiwAABdg"] [Sat Aug 29 05:06:52.130333 2026] [security2:error] [pid 1028675:tid 1028910] [client 158.23.147.79:32615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/content.php"] [unique_id "apK9TNdHPfW2QFvhmL7OQAAAAGQ"] [Sat Aug 29 05:06:52.133745 2026] [core:error] [pid 1028675:tid 1028927] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.133758 2026] [core:error] [pid 1028675:tid 1028927] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.136235 2026] [security2:error] [pid 1028675:tid 1028817] [client 20.197.61.180:8924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/go.php"] [unique_id "apK9TNdHPfW2QFvhmL7OQgAAAAc"] [Sat Aug 29 05:06:52.141672 2026] [security2:error] [pid 1028675:tid 1028900] [client 68.155.159.216:50177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9TNdHPfW2QFvhmL7OQwAAAFo"] [Sat Aug 29 05:06:52.161453 2026] [core:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.161469 2026] [core:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.166521 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.104.49.130:60774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/makeasmtp.php"] [unique_id "apK9TNdHPfW2QFvhmL7ORAAAACc"] [Sat Aug 29 05:06:52.184289 2026] [security2:error] [pid 1028675:tid 1028853] [client 68.155.159.216:52751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9TNdHPfW2QFvhmL7ORQAAACs"] [Sat Aug 29 05:06:52.196162 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.104.62:27064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/wp-content/admin.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEjgAABec"] [Sat Aug 29 05:06:52.203073 2026] [core:error] [pid 1018003:tid 1018118] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.203090 2026] [core:error] [pid 1018003:tid 1018118] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.205774 2026] [security2:error] [pid 1028675:tid 1028917] [client 168.107.94.195:62717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9TNdHPfW2QFvhmL7OSAAAAGs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:52.207072 2026] [security2:error] [pid 1018003:tid 1018029] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEkAAGIgg"] [Sat Aug 29 05:06:52.207108 2026] [security2:error] [pid 1018003:tid 1018045] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEkQAGIhg"] [Sat Aug 29 05:06:52.212828 2026] [core:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.212838 2026] [core:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.217321 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.104.104.62:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/js/priv8.php"] [unique_id "apK9TNdHPfW2QFvhmL7OSQAAACM"] [Sat Aug 29 05:06:52.220910 2026] [security2:error] [pid 1028675:tid 1028876] [client 20.151.200.44:64895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/xcre1.php"] [unique_id "apK9TNdHPfW2QFvhmL7OSgAAAEI"] [Sat Aug 29 05:06:52.222988 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.104.104.62:29205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/tx78.php"] [unique_id "apK9TNdHPfW2QFvhmL7OSwAAAG0"] [Sat Aug 29 05:06:52.231749 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.220.204.93:50777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/0byte.php"] [unique_id "apK9TNdHPfW2QFvhmL7OTQAAADM"] [Sat Aug 29 05:06:52.240275 2026] [security2:error] [pid 1018003:tid 1018106] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEkwAF0FU"] [Sat Aug 29 05:06:52.240382 2026] [security2:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EElAAF0H8"] [Sat Aug 29 05:06:52.242410 2026] [core:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.242427 2026] [core:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.246239 2026] [core:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.246251 2026] [core:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.247676 2026] [core:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.247691 2026] [core:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.248294 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.248304 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.248685 2026] [core:error] [pid 1018003:tid 1018113] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.248699 2026] [core:error] [pid 1018003:tid 1018113] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.261577 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.151.200.44:47379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/sf9.php"] [unique_id "apK9TNdHPfW2QFvhmL7OUgAAADI"] [Sat Aug 29 05:06:52.269132 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.250.41:21325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ww.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEnQAABh8"] [Sat Aug 29 05:06:52.272279 2026] [security2:error] [pid 1028675:tid 1028923] [client 40.83.93.50:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK9TNdHPfW2QFvhmL7OUwAAAHE"] [Sat Aug 29 05:06:52.278449 2026] [core:error] [pid 1018003:tid 1018098] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.278466 2026] [core:error] [pid 1018003:tid 1018098] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.280793 2026] [security2:error] [pid 1028675:tid 1028926] [client 20.196.209.81:13278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/content.php"] [unique_id "apK9TNdHPfW2QFvhmL7OVQAAAHQ"] [Sat Aug 29 05:06:52.282280 2026] [security2:error] [pid 1018003:tid 1018068] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEoQAF-S8"] [Sat Aug 29 05:06:52.283520 2026] [security2:error] [pid 1028675:tid 1028851] [client 158.23.147.79:25502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/about/function.php"] [unique_id "apK9TNdHPfW2QFvhmL7OVgAAACk"] [Sat Aug 29 05:06:52.284187 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.104.104.62:23361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/ahy66.php"] [unique_id "apK9TNdHPfW2QFvhmL7OVwAAAHI"] [Sat Aug 29 05:06:52.290156 2026] [security2:error] [pid 1028675:tid 1028854] [client 68.155.159.216:49294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/asd.php"] [unique_id "apK9TNdHPfW2QFvhmL7OWAAAACw"] [Sat Aug 29 05:06:52.302003 2026] [security2:error] [pid 1028675:tid 1028813] [client 68.155.159.216:24571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/xmlrpc.php"] [unique_id "apK9TNdHPfW2QFvhmL7OWQAAAAM"] [Sat Aug 29 05:06:52.324009 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.324023 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.325125 2026] [security2:error] [pid 1018003:tid 1018239] [client 216.244.66.243:45856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scottportfolio.com"] [uri "/userfiles/5300-kakoi-sort-bolgarskogo-pertsa-luchshe-posadit.xml"] [unique_id "apK9TDAh5Y1i2tUxg4EEowAABg8"] [Sat Aug 29 05:06:52.325245 2026] [security2:error] [pid 1018003:tid 1018239] [client 216.244.66.243:45856] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scottportfolio.com"] [uri "/userfiles/5300-kakoi-sort-bolgarskogo-pertsa-luchshe-posadit.xml"] [unique_id "apK9TDAh5Y1i2tUxg4EEowAABg8"] [Sat Aug 29 05:06:52.325688 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.325700 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.327316 2026] [security2:error] [pid 1028675:tid 1028873] [client 20.104.104.62:56359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/wp-gzone.php"] [unique_id "apK9TNdHPfW2QFvhmL7OXAAAAD8"] [Sat Aug 29 05:06:52.356123 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.356141 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.363092 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.147.79:48204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/cong.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEpAAABgI"] [Sat Aug 29 05:06:52.367129 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.151.200.44:64845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/motu.php"] [unique_id "apK9TNdHPfW2QFvhmL7OYAAAAHs"] [Sat Aug 29 05:06:52.376929 2026] [security2:error] [pid 1028675:tid 1028906] [client 68.155.159.216:51213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9TNdHPfW2QFvhmL7OZAAAAGA"] [Sat Aug 29 05:06:52.390466 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.147.79:30544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEqwAABfA"] [Sat Aug 29 05:06:52.390794 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.390806 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.391153 2026] [security2:error] [pid 1028675:tid 1028868] [client 20.104.104.62:27050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9TNdHPfW2QFvhmL7OaAAAADo"] [Sat Aug 29 05:06:52.391155 2026] [core:error] [pid 1028675:tid 1028859] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.391166 2026] [core:error] [pid 1028675:tid 1028859] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.392505 2026] [core:error] [pid 1028675:tid 1028857] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.392517 2026] [core:error] [pid 1028675:tid 1028857] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.394309 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.394336 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.404940 2026] [security2:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9TDAh5Y1i2tUxg4EErgAF_gY"] [Sat Aug 29 05:06:52.413959 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.413979 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.414002 2026] [security2:error] [pid 1028675:tid 1028865] [client 158.158.54.35:17818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/admin.php"] [unique_id "apK9TNdHPfW2QFvhmL7ObQAAADc"] [Sat Aug 29 05:06:52.416290 2026] [security2:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEswAF_jQ"] [Sat Aug 29 05:06:52.417411 2026] [security2:error] [pid 1028675:tid 1028911] [client 20.52.41.200:1242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/system_log.php"] [unique_id "apK9TNdHPfW2QFvhmL7ObwAAAGU"] [Sat Aug 29 05:06:52.420427 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.104.62:29206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEtQAABdI"] [Sat Aug 29 05:06:52.426874 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.220.204.93:52305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/xr.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEtgAABcI"] [Sat Aug 29 05:06:52.436088 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.436103 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.440715 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.104.104.62:40220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/images/priv8.php"] [unique_id "apK9TNdHPfW2QFvhmL7OcgAAAD4"] [Sat Aug 29 05:06:52.453859 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.453875 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.454326 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.454335 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.457269 2026] [core:error] [pid 1028675:tid 1028820] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.457282 2026] [core:error] [pid 1028675:tid 1028820] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.459205 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.459219 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.459505 2026] [security2:error] [pid 1028675:tid 1028829] [client 20.104.104.62:4861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/str.php"] [unique_id "apK9TNdHPfW2QFvhmL7OdQAAABM"] [Sat Aug 29 05:06:52.460677 2026] [security2:error] [pid 1028675:tid 1028879] [client 20.48.250.41:21421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/w1px.php"] [unique_id "apK9TNdHPfW2QFvhmL7OdgAAAEU"] [Sat Aug 29 05:06:52.462980 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.104.62:60456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/gaje.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEvwAABeQ"] [Sat Aug 29 05:06:52.473449 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.473465 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.478988 2026] [security2:error] [pid 1018003:tid 1018130] [remote 74.7.227.154:41662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9TDAh5Y1i2tUxg4EEwAAGLG0"], referer: https://goodtogo.store/sitemap_index.xml?p=%2Fhome4%2Fsortthru%2Fpublic_html%2Fgoodtogo%2Fwebapp%2Fwp-content%2Fplugins%2Fwp-easycart%2Fadmin%2Felementor [Sat Aug 29 05:06:52.514912 2026] [security2:error] [pid 1028675:tid 1028899] [client 4.205.62.107:55975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/xve22.php"] [unique_id "apK9TNdHPfW2QFvhmL7OfAAAAFk"] [Sat Aug 29 05:06:52.517896 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.151.200.44:61327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/wefile.php"] [unique_id "apK9TNdHPfW2QFvhmL7OfQAAACc"] [Sat Aug 29 05:06:52.541907 2026] [security2:error] [pid 1028675:tid 1028917] [client 68.155.159.216:51208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/index.php"] [unique_id "apK9TNdHPfW2QFvhmL7OfwAAAGs"] [Sat Aug 29 05:06:52.545695 2026] [autoindex:error] [pid 1028675:tid 1028853] [client 20.63.219.114:0] AH01276: Cannot serve directory /home2/davidsea/public_html/travelcrazed/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:52.547310 2026] [core:error] [pid 1028675:tid 1028853] [client 20.63.219.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.564130 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.220.204.93:50789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/h02ugyh.php"] [unique_id "apK9TNdHPfW2QFvhmL7OgQAAAG0"] [Sat Aug 29 05:06:52.564593 2026] [security2:error] [pid 1018003:tid 1018206] [client 158.158.54.35:15192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/zoom1.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEwwAABe8"] [Sat Aug 29 05:06:52.568290 2026] [security2:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EExQAGEGs"] [Sat Aug 29 05:06:52.581047 2026] [security2:error] [pid 1018003:tid 1018137] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEyQAGEHQ"] [Sat Aug 29 05:06:52.583614 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.104.62:27522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/.well-known/logs233/index.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEygAABjU"] [Sat Aug 29 05:06:52.584021 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.151.200.44:47322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/lte7.php"] [unique_id "apK9TNdHPfW2QFvhmL7OggAAADI"] [Sat Aug 29 05:06:52.584554 2026] [security2:error] [pid 1028675:tid 1028887] [client 168.107.94.195:63247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9TNdHPfW2QFvhmL7OgwAAAE0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:52.585646 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.104.62:64676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/mega.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEywAABdg"] [Sat Aug 29 05:06:52.603679 2026] [security2:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEzAAGEGU"] [Sat Aug 29 05:06:52.610094 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.49.130:52496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/menu.php"] [unique_id "apK9TDAh5Y1i2tUxg4EEzgAABdQ"] [Sat Aug 29 05:06:52.615342 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.104.104.62:29244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-content/sallu.php"] [unique_id "apK9TNdHPfW2QFvhmL7OiQAAABI"] [Sat Aug 29 05:06:52.616483 2026] [security2:error] [pid 1018003:tid 1018133] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EEzwAGEHA"] [Sat Aug 29 05:06:52.617161 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.104.62:42702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/wp-admin/zwso.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE0AAABfo"] [Sat Aug 29 05:06:52.621275 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.621289 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.624191 2026] [core:error] [pid 1028675:tid 1028871] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.624204 2026] [core:error] [pid 1028675:tid 1028871] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.635976 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.147.79:53823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/cong.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE0wAABco"] [Sat Aug 29 05:06:52.637609 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.637622 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.645644 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.48.250.41:21488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/to.php"] [unique_id "apK9TNdHPfW2QFvhmL7OjgAAAB0"] [Sat Aug 29 05:06:52.673497 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.673517 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.684233 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.151.200.44:64197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/EM.php"] [unique_id "apK9TNdHPfW2QFvhmL7OkQAAAC4"] [Sat Aug 29 05:06:52.695054 2026] [core:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.695069 2026] [core:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.698340 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.698479 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.706319 2026] [security2:error] [pid 1028675:tid 1028916] [client 103.240.76.112:42589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9TNdHPfW2QFvhmL7OlAAAAGo"] [Sat Aug 29 05:06:52.706432 2026] [security2:error] [pid 1028675:tid 1028916] [client 103.240.76.112:42589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9TNdHPfW2QFvhmL7OlAAAAGo"] [Sat Aug 29 05:06:52.707640 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.220.204.93:52251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/xxw.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE4gAABdk"] [Sat Aug 29 05:06:52.717810 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.104.62:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/ww3.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE5QAABeU"] [Sat Aug 29 05:06:52.718014 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.196.209.81:17888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/wxo.php"] [unique_id "apK9TNdHPfW2QFvhmL7OlgAAADM"] [Sat Aug 29 05:06:52.731428 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.731447 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.733537 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.733556 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.734129 2026] [core:error] [pid 1028675:tid 1028933] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.734151 2026] [core:error] [pid 1028675:tid 1028933] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.736178 2026] [core:error] [pid 1018003:tid 1018047] [remote 45.148.10.62:49802] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.736651 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.736663 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.739203 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.739214 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.747944 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.104.62:20695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/Xploit.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE7QAABbw"] [Sat Aug 29 05:06:52.760212 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.147.79:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/css/index.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE7wAABis"] [Sat Aug 29 05:06:52.764245 2026] [security2:error] [pid 1018003:tid 1018224] [client 40.83.93.50:7743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/wp-contentt.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE8AAABgE"] [Sat Aug 29 05:06:52.765737 2026] [security2:error] [pid 1018003:tid 1018221] [client 158.23.147.79:17439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/file5.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE8QAABf4"] [Sat Aug 29 05:06:52.768810 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.104.62:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/Contrller.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE8gAABiw"] [Sat Aug 29 05:06:52.776342 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.104.104.62:27015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/as.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE9QAABeM"] [Sat Aug 29 05:06:52.779049 2026] [core:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.779063 2026] [core:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.779504 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.779515 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.780981 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.780993 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.787308 2026] [security2:error] [pid 1028675:tid 1028889] [client 213.202.253.4:64638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/wp-content/txets.php"] [unique_id "apK9TNdHPfW2QFvhmL7OmQAAAE8"], referer: www.google.com [Sat Aug 29 05:06:52.799130 2026] [security2:error] [pid 1028675:tid 1028868] [client 20.48.250.41:21499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/thui.php"] [unique_id "apK9TNdHPfW2QFvhmL7OmgAAADo"] [Sat Aug 29 05:06:52.800210 2026] [core:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.800223 2026] [core:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.811574 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.104.104.62:28959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/0.php"] [unique_id "apK9TDAh5Y1i2tUxg4EE_wAABd4"] [Sat Aug 29 05:06:52.817758 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.817772 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.836820 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.197.61.180:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/gecko-new.php"] [unique_id "apK9TNdHPfW2QFvhmL7OnQAAAHI"] [Sat Aug 29 05:06:52.838094 2026] [security2:error] [pid 1018003:tid 1018246] [client 68.155.159.216:18343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9TDAh5Y1i2tUxg4EFAQAABhY"] [Sat Aug 29 05:06:52.846220 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.104.62:43024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/sko.php"] [unique_id "apK9TDAh5Y1i2tUxg4EFAgAABes"] [Sat Aug 29 05:06:52.854099 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.854115 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.855900 2026] [security2:error] [pid 1028675:tid 1028935] [client 20.151.200.44:65503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/ca4.php"] [unique_id "apK9TNdHPfW2QFvhmL7OngAAAH0"] [Sat Aug 29 05:06:52.857219 2026] [security2:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EFBAAGKQ0"] [Sat Aug 29 05:06:52.860218 2026] [security2:error] [pid 1028675:tid 1028832] [client 4.205.62.107:9176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/olfclass.php"] [unique_id "apK9TNdHPfW2QFvhmL7OoAAAABY"] [Sat Aug 29 05:06:52.860846 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.860846 2026] [security2:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EFBQAGKRQ"] [Sat Aug 29 05:06:52.860860 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.860864 2026] [security2:error] [pid 1028675:tid 1028843] [client 68.155.159.216:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/file88.php"] [unique_id "apK9TNdHPfW2QFvhmL7OoQAAACE"] [Sat Aug 29 05:06:52.862627 2026] [security2:error] [pid 1018003:tid 1018153] [client 68.155.159.216:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/index/function.php"] [unique_id "apK9TDAh5Y1i2tUxg4EFBgAABbo"] [Sat Aug 29 05:06:52.863265 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.220.204.93:50758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/bolt.php"] [unique_id "apK9TDAh5Y1i2tUxg4EFBwAABbk"] [Sat Aug 29 05:06:52.866856 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.158.54.35:10358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/php8.php"] [unique_id "apK9TDAh5Y1i2tUxg4EFCQAABc8"] [Sat Aug 29 05:06:52.868666 2026] [security2:error] [pid 1028675:tid 1028827] [client 20.52.41.200:1773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/24.php"] [unique_id "apK9TNdHPfW2QFvhmL7OowAAABE"] [Sat Aug 29 05:06:52.881831 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.881845 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.886898 2026] [security2:error] [pid 1028675:tid 1028884] [client 4.205.62.107:22373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/konfig.php"] [unique_id "apK9TNdHPfW2QFvhmL7OqAAAAEo"] [Sat Aug 29 05:06:52.890233 2026] [security2:error] [pid 1018003:tid 1018037] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9TDAh5Y1i2tUxg4EFDAAGKRA"] [Sat Aug 29 05:06:52.891016 2026] [core:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.891030 2026] [core:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.891779 2026] [core:error] [pid 1018003:tid 1018131] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.891793 2026] [core:error] [pid 1018003:tid 1018131] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.892798 2026] [core:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.892810 2026] [core:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.897683 2026] [security2:error] [pid 1028675:tid 1028831] [client 158.23.147.79:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/x.php"] [unique_id "apK9TNdHPfW2QFvhmL7OqgAAABU"] [Sat Aug 29 05:06:52.917882 2026] [core:error] [pid 1018003:tid 1018039] [remote 45.148.10.62:49802] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.917909 2026] [core:error] [pid 1018003:tid 1018039] [remote 45.148.10.62:49802] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.920345 2026] [core:error] [pid 1018003:tid 1018025] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.920377 2026] [core:error] [pid 1018003:tid 1018025] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.940452 2026] [security2:error] [pid 1028675:tid 1028812] [client 158.23.147.79:50174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9TNdHPfW2QFvhmL7OrQAAAAI"] [Sat Aug 29 05:06:52.943180 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.151.200.44:46653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/tanjiro.php"] [unique_id "apK9TDAh5Y1i2tUxg4EFEgAABcI"] [Sat Aug 29 05:06:52.963105 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.963124 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.963885 2026] [security2:error] [pid 1028675:tid 1028899] [client 168.107.94.195:63556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9TNdHPfW2QFvhmL7OrwAAAFk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:52.974535 2026] [security2:error] [pid 1018003:tid 1018188] [client 68.155.159.216:33705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9TDAh5Y1i2tUxg4EFFAAABd0"] [Sat Aug 29 05:06:52.980589 2026] [security2:error] [pid 1028675:tid 1028848] [client 68.155.159.216:6063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9TNdHPfW2QFvhmL7OtgAAACY"] [Sat Aug 29 05:06:52.989671 2026] [core:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.989689 2026] [core:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.990141 2026] [core:error] [pid 1018003:tid 1018054] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.990155 2026] [core:error] [pid 1018003:tid 1018054] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.990205 2026] [core:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.990215 2026] [core:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:52.996379 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.104.62:4830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/zoz.php"] [unique_id "apK9TDAh5Y1i2tUxg4EFGgAABek"] [Sat Aug 29 05:06:53.004426 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.220.204.93:41804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/rtx.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFGwAABg8"] [Sat Aug 29 05:06:53.004427 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.104.104.62:29234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/aa.php"] [unique_id "apK9TddHPfW2QFvhmL7OuQAAABs"] [Sat Aug 29 05:06:53.006121 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.48.250.41:21468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/Jcrop.php"] [unique_id "apK9TddHPfW2QFvhmL7OugAAABs"] [Sat Aug 29 05:06:53.008787 2026] [security2:error] [pid 1018003:tid 1018175] [client 34.7.40.70:44734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/web.config"] [unique_id "apK9TTAh5Y1i2tUxg4EFHAAABdA"] [Sat Aug 29 05:06:53.010363 2026] [cgid:error] [pid 1028675:tid 1028858] [client 34.7.40.70:44740] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.011793 2026] [security2:error] [pid 1018003:tid 1018218] [client 20.104.104.62:23405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/Zeiss.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFHQAABfs"] [Sat Aug 29 05:06:53.017397 2026] [cgid:error] [pid 1018003:tid 1018275] [client 34.7.40.70:44738] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.018111 2026] [cgid:error] [pid 1028675:tid 1028865] [client 34.7.40.70:44756] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.018282 2026] [cgid:error] [pid 1028675:tid 1028886] [client 34.7.40.70:44754] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.018381 2026] [security2:error] [pid 1028675:tid 1028886] [client 34.7.40.70:44754] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9TddHPfW2QFvhmL7OvQAAAEw"] [Sat Aug 29 05:06:53.020973 2026] [cgid:error] [pid 1028675:tid 1028932] [client 34.7.40.70:44784] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.022082 2026] [security2:error] [pid 1028675:tid 1028905] [client 158.158.54.35:20333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/txets.php"] [unique_id "apK9TddHPfW2QFvhmL7OwAAAAF8"] [Sat Aug 29 05:06:53.022451 2026] [cgid:error] [pid 1028675:tid 1028911] [client 34.7.40.70:44766] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.022900 2026] [cgid:error] [pid 1018003:tid 1018184] [client 34.7.40.70:44774] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.024566 2026] [cgid:error] [pid 1028675:tid 1028835] [client 34.7.40.70:44778] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.026103 2026] [cgid:error] [pid 1028675:tid 1028855] [client 34.7.40.70:44794] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.039286 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.147.79:30542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFIwAABbw"] [Sat Aug 29 05:06:53.039610 2026] [security2:error] [pid 1018003:tid 1018277] [client 60.243.207.176:61313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFIQAABjU"] [Sat Aug 29 05:06:53.039686 2026] [security2:error] [pid 1018003:tid 1018277] [client 60.243.207.176:61313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFIQAABjU"] [Sat Aug 29 05:06:53.040855 2026] [security2:error] [pid 1018003:tid 1018231] [client 34.7.40.70:44800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.40.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/configuration.php.bak"] [unique_id "apK9TTAh5Y1i2tUxg4EFJQAABgc"] [Sat Aug 29 05:06:53.041067 2026] [cgid:error] [pid 1028675:tid 1028825] [client 34.7.40.70:44796] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.041088 2026] [cgid:error] [pid 1018003:tid 1018196] [client 34.7.40.70:44820] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.046568 2026] [cgid:error] [pid 1028675:tid 1028897] [client 34.7.40.70:44816] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.048563 2026] [cgid:error] [pid 1018003:tid 1018207] [client 34.7.40.70:44832] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.054706 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.054720 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.057847 2026] [cgid:error] [pid 1028675:tid 1028842] [client 34.7.40.70:44834] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:53.062748 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.062770 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.065301 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.065323 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.067457 2026] [security2:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fastnetus.com"] [uri "/wp-config.php.bak"] [unique_id "apK9TTAh5Y1i2tUxg4EFLwAGHzM"] [Sat Aug 29 05:06:53.068899 2026] [security2:error] [pid 1018003:tid 1018050] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9TTAh5Y1i2tUxg4EFLgAGHx0"] [Sat Aug 29 05:06:53.076367 2026] [security2:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fastnetus.com"] [uri "/wp-config.php.new"] [unique_id "apK9TTAh5Y1i2tUxg4EFMQAGHyc"] [Sat Aug 29 05:06:53.077611 2026] [security2:error] [pid 1028675:tid 1028890] [client 158.23.147.79:35729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/admin.php"] [unique_id "apK9TddHPfW2QFvhmL7OzwAAAFA"] [Sat Aug 29 05:06:53.085262 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.151.200.44:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/x0x.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFMwAABcs"] [Sat Aug 29 05:06:53.085624 2026] [security2:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fastnetus.com"] [uri "/wp-config.php.old"] [unique_id "apK9TTAh5Y1i2tUxg4EFNAAGHwM"] [Sat Aug 29 05:06:53.101519 2026] [security2:error] [pid 1028675:tid 1028877] [client 158.23.184.117:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/wp-mail.php"] [unique_id "apK9TddHPfW2QFvhmL7O0AAAAEM"] [Sat Aug 29 05:06:53.119442 2026] [security2:error] [pid 1028675:tid 1028891] [client 20.104.104.62:27033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9TddHPfW2QFvhmL7O0QAAAFE"] [Sat Aug 29 05:06:53.121914 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.121930 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.135133 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.196.209.81:9447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/as.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFOAAABgY"] [Sat Aug 29 05:06:53.138316 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.104.62:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/mmm.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFPQAABco"] [Sat Aug 29 05:06:53.138512 2026] [security2:error] [pid 1018003:tid 1018088] [remote 93.123.109.228:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9TTAh5Y1i2tUxg4EFPAAGH0M"] [Sat Aug 29 05:06:53.139170 2026] [core:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.139180 2026] [core:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.139922 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.139938 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:43512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.139943 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.139960 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.141285 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.141301 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.145574 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.145575 2026] [core:error] [pid 1028675:tid 1028894] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.145586 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.145592 2026] [core:error] [pid 1028675:tid 1028894] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.152829 2026] [security2:error] [pid 1018003:tid 1018038] [remote 45.148.10.62:49802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninaanddon.strangeworx.com"] [uri "/wp-login.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFNgAF3hE"] [Sat Aug 29 05:06:53.155021 2026] [security2:error] [pid 1018003:tid 1018213] [client 4.205.62.107:22417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/setup-config.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFPwAABfY"] [Sat Aug 29 05:06:53.162878 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.23.184.117:19282] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "yeselespinoza.andresortega.org"] [uri "/1.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFQQAABhM"] [Sat Aug 29 05:06:53.162969 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.23.184.117:19282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/1.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFQQAABhM"] [Sat Aug 29 05:06:53.162979 2026] [core:error] [pid 1018003:tid 1018167] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.162997 2026] [core:error] [pid 1018003:tid 1018167] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.164501 2026] [security2:error] [pid 1018003:tid 1018240] [client 4.205.62.107:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFQgAABhA"] [Sat Aug 29 05:06:53.168324 2026] [security2:error] [pid 1018003:tid 1018186] [client 4.205.62.107:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/upload.form.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFQwAABds"] [Sat Aug 29 05:06:53.183971 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.23.184.117:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/adminfuns.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFRAAABfo"] [Sat Aug 29 05:06:53.183995 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.220.204.93:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/ckk.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFRQAABbk"] [Sat Aug 29 05:06:53.210698 2026] [cgid:error] [pid 1018003:tid 1018252] [client 20.104.104.62:28829] AH01265: stderr from /home1/allgoodd/public_html/watercolorsbylola/cgi-bin/: attempt to invoke directory as script [Sat Aug 29 05:06:53.217582 2026] [security2:error] [pid 1028675:tid 1028851] [client 4.205.62.107:22438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/debuggen.php"] [unique_id "apK9TddHPfW2QFvhmL7O2AAAACk"] [Sat Aug 29 05:06:53.227687 2026] [security2:error] [pid 1018003:tid 1018153] [client 158.23.184.117:33941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/p.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFSAAABbo"] [Sat Aug 29 05:06:53.231994 2026] [security2:error] [pid 1028675:tid 1028906] [client 158.23.147.79:38722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/packed.php"] [unique_id "apK9TddHPfW2QFvhmL7O2gAAAGA"] [Sat Aug 29 05:06:53.233248 2026] [security2:error] [pid 1028675:tid 1028881] [client 158.23.147.79:32754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9TddHPfW2QFvhmL7O2wAAAEc"] [Sat Aug 29 05:06:53.236681 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.48.250.41:21324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ws58.php"] [unique_id "apK9TddHPfW2QFvhmL7O3AAAAEA"] [Sat Aug 29 05:06:53.239277 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.104.104.62:36959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/ww2.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFSwAABho"] [Sat Aug 29 05:06:53.247224 2026] [cgid:error] [pid 1018003:tid 1018180] [client 158.23.184.117:46914] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/dontbenicemovie/404.shtml [Sat Aug 29 05:06:53.257463 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.151.200.44:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/Rk41.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFTQAABcI"] [Sat Aug 29 05:06:53.263772 2026] [security2:error] [pid 1028675:tid 1028868] [client 68.155.159.216:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/nf_tracking.php"] [unique_id "apK9TddHPfW2QFvhmL7O3QAAADo"] [Sat Aug 29 05:06:53.268164 2026] [security2:error] [pid 1028675:tid 1028859] [client 20.104.49.130:46580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/bdroot.php"] [unique_id "apK9TddHPfW2QFvhmL7O3wAAADE"] [Sat Aug 29 05:06:53.269297 2026] [core:error] [pid 1028675:tid 1028902] [client 20.52.41.200:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.269313 2026] [core:error] [pid 1028675:tid 1028902] [client 20.52.41.200:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.274907 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.104.62:28829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/file.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFTgAABdA"] [Sat Aug 29 05:06:53.275262 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.104.104.62:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/advanced.php"] [unique_id "apK9TddHPfW2QFvhmL7O4QAAAHI"] [Sat Aug 29 05:06:53.276175 2026] [core:error] [pid 1028675:tid 1028857] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.276191 2026] [core:error] [pid 1028675:tid 1028857] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.294120 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.23.184.117:46914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/3.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFUAAABdk"] [Sat Aug 29 05:06:53.306381 2026] [security2:error] [pid 1018003:tid 1018273] [client 158.23.184.117:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/10.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFUQAABjE"] [Sat Aug 29 05:06:53.308063 2026] [fcgid:warn] [pid 1018003:tid 1018277] (70014)End of file found: [client 66.132.186.197:8382] mod_fcgid: can't get data from http client [Sat Aug 29 05:06:53.310083 2026] [security2:error] [pid 1018003:tid 1018166] [client 40.83.93.50:7716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/theme.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFUwAABcc"] [Sat Aug 29 05:06:53.313907 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.220.204.93:52317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aztecalimpieza.com"] [uri "/R57.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFVQAABgc"] [Sat Aug 29 05:06:53.314180 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.151.200.44:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "livingthecode.org"] [uri "/fesa.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFVgAABeU"] [Sat Aug 29 05:06:53.314327 2026] [cgid:error] [pid 1018003:tid 1018159] [client 20.52.41.200:1191] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:53.329386 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.184.117:62273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/403.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFWAAABfs"] [Sat Aug 29 05:06:53.342803 2026] [security2:error] [pid 1028675:tid 1028917] [client 168.107.94.195:63801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9TddHPfW2QFvhmL7O4wAAAGs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:53.360599 2026] [security2:error] [pid 1028675:tid 1028848] [client 93.123.109.228:52412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9TddHPfW2QFvhmL7O5AAAACY"] [Sat Aug 29 05:06:53.367919 2026] [security2:error] [pid 1028675:tid 1028915] [client 158.23.184.117:34553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/php.php"] [unique_id "apK9TddHPfW2QFvhmL7O5gAAAGk"] [Sat Aug 29 05:06:53.381069 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.48.250.41:21394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/xs.php"] [unique_id "apK9TddHPfW2QFvhmL7O6QAAAB4"] [Sat Aug 29 05:06:53.392799 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.104.104.62:27031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/abcd.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFWwAABf4"] [Sat Aug 29 05:06:53.403150 2026] [security2:error] [pid 1028675:tid 1028837] [client 103.168.67.159:53248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9TddHPfW2QFvhmL7O6gAAABs"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:06:53.403780 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.104.62:43034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/blox.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFXAAABes"] [Sat Aug 29 05:06:53.420777 2026] [security2:error] [pid 1018003:tid 1018213] [client 68.155.159.216:49243] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/1.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFXQAABfY"] [Sat Aug 29 05:06:53.420868 2026] [security2:error] [pid 1018003:tid 1018213] [client 68.155.159.216:49243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/1.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFXQAABfY"] [Sat Aug 29 05:06:53.433066 2026] [security2:error] [pid 1018003:tid 1018243] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9TTAh5Y1i2tUxg4EFXgAABhM"] [Sat Aug 29 05:06:53.439499 2026] [security2:error] [pid 1028675:tid 1028853] [client 158.23.184.117:62272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK9TddHPfW2QFvhmL7O6wAAACs"] [Sat Aug 29 05:06:53.448655 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.184.117:19268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/100.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFXwAABb0"] [Sat Aug 29 05:06:53.457737 2026] [security2:error] [pid 1018003:tid 1018225] [client 93.123.109.228:52476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9TTAh5Y1i2tUxg4EFYAAABgI"] [Sat Aug 29 05:06:53.460619 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.52.41.200:1191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFYQAABec"] [Sat Aug 29 05:06:53.472194 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.23.147.79:48354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/js/index.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFYwAABfo"] [Sat Aug 29 05:06:53.473727 2026] [core:error] [pid 1028675:tid 1028878] [client 158.158.54.35:15211] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.473749 2026] [core:error] [pid 1028675:tid 1028878] [client 158.158.54.35:15211] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.474418 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.104.104.62:29190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/sc.php"] [unique_id "apK9TddHPfW2QFvhmL7O8AAAADA"] [Sat Aug 29 05:06:53.487162 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.158.54.35:10343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/install.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFcQAABcI"] [Sat Aug 29 05:06:53.497203 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.23.147.79:30541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-login.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFdgAABek"] [Sat Aug 29 05:06:53.512589 2026] [security2:error] [pid 1028675:tid 1028825] [client 158.23.184.117:33932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/past.php"] [unique_id "apK9TddHPfW2QFvhmL7O_QAAAA8"] [Sat Aug 29 05:06:53.517837 2026] [security2:error] [pid 1028675:tid 1028842] [client 20.48.250.41:21412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/zu.php"] [unique_id "apK9TddHPfW2QFvhmL7O_wAAACA"] [Sat Aug 29 05:06:53.527291 2026] [security2:error] [pid 1028675:tid 1028862] [client 158.23.184.117:46952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/.trash7206/index.php"] [unique_id "apK9TddHPfW2QFvhmL7PAQAAADQ"] [Sat Aug 29 05:06:53.535498 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.104.104.62:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/kcs.php"] [unique_id "apK9TddHPfW2QFvhmL7PAgAAABI"] [Sat Aug 29 05:06:53.539768 2026] [security2:error] [pid 1028675:tid 1028893] [client 93.123.109.228:52440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9TddHPfW2QFvhmL7PAwAAAFM"] [Sat Aug 29 05:06:53.554800 2026] [security2:error] [pid 1028675:tid 1028925] [client 93.123.109.228:52428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9TddHPfW2QFvhmL7PBAAAAHM"] [Sat Aug 29 05:06:53.570067 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.196.209.81:17872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/room.php"] [unique_id "apK9TddHPfW2QFvhmL7PBQAAAG4"] [Sat Aug 29 05:06:53.574237 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.151.200.44:46655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/7logs.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFeQAABio"] [Sat Aug 29 05:06:53.582587 2026] [security2:error] [pid 1028675:tid 1028908] [client 20.197.61.180:7584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/wp-admin.php"] [unique_id "apK9TddHPfW2QFvhmL7PBgAAAGI"] [Sat Aug 29 05:06:53.585558 2026] [cgid:error] [pid 1018003:tid 1018236] [client 158.23.184.117:46930] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/wanderl1/public_html/dontbenicemovie/404.shtml [Sat Aug 29 05:06:53.588254 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.104.62:27058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/index/function.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFfQAABew"] [Sat Aug 29 05:06:53.590444 2026] [security2:error] [pid 1018003:tid 1018273] [client 93.123.109.228:52516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9TTAh5Y1i2tUxg4EFfgAABjE"] [Sat Aug 29 05:06:53.593185 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.184.117:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/2.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFfwAABjM"] [Sat Aug 29 05:06:53.612938 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.104.104.62:23406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/anz.php"] [unique_id "apK9TddHPfW2QFvhmL7PBwAAAA4"] [Sat Aug 29 05:06:53.616027 2026] [security2:error] [pid 1028675:tid 1028830] [client 20.104.104.62:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wso2.5.1.php"] [unique_id "apK9TddHPfW2QFvhmL7PCAAAABQ"] [Sat Aug 29 05:06:53.632128 2026] [security2:error] [pid 1018003:tid 1018195] [client 158.23.184.117:46930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/wp-admin/css/admin.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFgQAABeQ"] [Sat Aug 29 05:06:53.649469 2026] [security2:error] [pid 1018003:tid 1018170] [client 93.123.109.228:52492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9TTAh5Y1i2tUxg4EFggAABcs"] [Sat Aug 29 05:06:53.658347 2026] [security2:error] [pid 1028675:tid 1028871] [client 4.205.62.107:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/06.php"] [unique_id "apK9TddHPfW2QFvhmL7PDAAAAD0"] [Sat Aug 29 05:06:53.659388 2026] [security2:error] [pid 1028675:tid 1028866] [client 158.23.184.117:33945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/root.php"] [unique_id "apK9TddHPfW2QFvhmL7PDQAAADg"] [Sat Aug 29 05:06:53.664154 2026] [security2:error] [pid 1018003:tid 1018246] [client 93.123.109.228:52506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9TTAh5Y1i2tUxg4EFgwAABhY"] [Sat Aug 29 05:06:53.673783 2026] [security2:error] [pid 1018003:tid 1018218] [client 158.23.184.117:47032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/.trash7206/admin.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFhgAABfs"] [Sat Aug 29 05:06:53.675567 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.104.104.62:29223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/tinyfilemanager.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFhwAABcc"] [Sat Aug 29 05:06:53.680004 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.104.104.62:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/wsz.php"] [unique_id "apK9TddHPfW2QFvhmL7PDgAAAH8"] [Sat Aug 29 05:06:53.696803 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.250.41:21450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/lanka.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFiwAABds"] [Sat Aug 29 05:06:53.724733 2026] [security2:error] [pid 1018003:tid 1018191] [client 168.107.94.195:64100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFjQAABeA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:53.743894 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.184.117:19381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/222.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFkAAABb0"] [Sat Aug 29 05:06:53.747119 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.49.130:54806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/talkxkej.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFkgAABcI"] [Sat Aug 29 05:06:53.768353 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.104.49.130:57496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/wp-css.php"] [unique_id "apK9TddHPfW2QFvhmL7PFgAAACE"] [Sat Aug 29 05:06:53.773857 2026] [security2:error] [pid 1028675:tid 1028826] [client 158.23.147.79:54343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9TddHPfW2QFvhmL7PFwAAABA"] [Sat Aug 29 05:06:53.778767 2026] [security2:error] [pid 1028675:tid 1028912] [client 20.151.200.44:46645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/sf.php"] [unique_id "apK9TddHPfW2QFvhmL7PGgAAAGY"] [Sat Aug 29 05:06:53.780018 2026] [security2:error] [pid 1028675:tid 1028811] [client 93.123.109.228:52468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9TddHPfW2QFvhmL7PGQAAAAE"] [Sat Aug 29 05:06:53.780232 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.184.117:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/bthil.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFkwAABbk"] [Sat Aug 29 05:06:53.786605 2026] [security2:error] [pid 1028675:tid 1028859] [client 20.104.104.62:27008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/rip.php"] [unique_id "apK9TddHPfW2QFvhmL7PGwAAADE"] [Sat Aug 29 05:06:53.804017 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.23.184.117:34507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/r.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFmAAABek"] [Sat Aug 29 05:06:53.818941 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.104.104.62:43071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/msy.php"] [unique_id "apK9TddHPfW2QFvhmL7PHQAAAD4"] [Sat Aug 29 05:06:53.827846 2026] [security2:error] [pid 1028675:tid 1028827] [client 158.23.184.117:46970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/wp-content/admin.php"] [unique_id "apK9TddHPfW2QFvhmL7PHgAAABE"] [Sat Aug 29 05:06:53.840758 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.104.62:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wibu.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFmwAABio"] [Sat Aug 29 05:06:53.868605 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.147.79:26568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFngAABfU"] [Sat Aug 29 05:06:53.869531 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.48.250.41:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/gettest.php"] [unique_id "apK9TddHPfW2QFvhmL7PIAAAAHo"] [Sat Aug 29 05:06:53.876593 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.23.147.79:17409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/file88.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFoAAABgE"] [Sat Aug 29 05:06:53.880882 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.104.104.62:28824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/upload.php"] [unique_id "apK9TddHPfW2QFvhmL7PJAAAACc"] [Sat Aug 29 05:06:53.882040 2026] [security2:error] [pid 1028675:tid 1028845] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9TddHPfW2QFvhmL7PIwAAACM"] [Sat Aug 29 05:06:53.888699 2026] [security2:error] [pid 1028675:tid 1028840] [client 158.23.184.117:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/24.php"] [unique_id "apK9TddHPfW2QFvhmL7PJgAAAB4"] [Sat Aug 29 05:06:53.892527 2026] [security2:error] [pid 1018003:tid 1018059] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/.env.php.bak"] [unique_id "apK9TTAh5Y1i2tUxg4EFpAAF8CY"] [Sat Aug 29 05:06:53.892775 2026] [security2:error] [pid 1018003:tid 1018070] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/config/.env.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFpgAF8DE"] [Sat Aug 29 05:06:53.892845 2026] [security2:error] [pid 1018003:tid 1018092] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/laravel/.env"] [unique_id "apK9TTAh5Y1i2tUxg4EFpQAF8Ec"] [Sat Aug 29 05:06:53.902159 2026] [security2:error] [pid 1028675:tid 1028817] [client 93.123.109.228:52412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9TddHPfW2QFvhmL7PJwAAAAc"] [Sat Aug 29 05:06:53.916324 2026] [security2:error] [pid 1018003:tid 1018089] [remote 40.77.167.35:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFqQAF_0Q"] [Sat Aug 29 05:06:53.925811 2026] [cgid:error] [pid 1028675:tid 1028857] [client 20.52.41.200:1266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:53.929694 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.184.117:46396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/file.php"] [unique_id "apK9TddHPfW2QFvhmL7PKgAAADA"] [Sat Aug 29 05:06:53.945726 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.104.104.62:23381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/bge.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFtAAABhM"] [Sat Aug 29 05:06:53.947269 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.184.117:34726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.miketowery.net"] [uri "/sid3.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFtQAABeM"] [Sat Aug 29 05:06:53.949633 2026] [security2:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9TTAh5Y1i2tUxg4EFsAAFvEU"] [Sat Aug 29 05:06:53.950853 2026] [security2:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9TTAh5Y1i2tUxg4EFrgAFvCA"] [Sat Aug 29 05:06:53.955402 2026] [core:error] [pid 1028675:tid 1028832] [client 158.158.54.35:24931] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.955419 2026] [core:error] [pid 1028675:tid 1028832] [client 158.158.54.35:24931] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.957456 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.104.62:42778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/siln.php"] [unique_id "apK9TTAh5Y1i2tUxg4EFvgAABgI"] [Sat Aug 29 05:06:53.958204 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.958217 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.974166 2026] [core:error] [pid 1028675:tid 1028908] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.974193 2026] [core:error] [pid 1028675:tid 1028908] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.975164 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.975188 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.975582 2026] [core:error] [pid 1028675:tid 1028854] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.975596 2026] [core:error] [pid 1028675:tid 1028854] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.976840 2026] [security2:error] [pid 1028675:tid 1028844] [client 158.23.184.117:46949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diamondswindowtinting.enproftp.com"] [uri "/wp-mail.php"] [unique_id "apK9TddHPfW2QFvhmL7PNwAAACI"] [Sat Aug 29 05:06:53.978616 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.978632 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.981482 2026] [security2:error] [pid 1028675:tid 1028824] [client 68.155.159.216:16165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/.well-known/content.php"] [unique_id "apK9TddHPfW2QFvhmL7POAAAAA4"] [Sat Aug 29 05:06:53.985279 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.158.54.35:32905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/ioxi-o.php"] [unique_id "apK9TddHPfW2QFvhmL7POgAAAEo"] [Sat Aug 29 05:06:53.991892 2026] [core:error] [pid 1018003:tid 1018074] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.991907 2026] [core:error] [pid 1018003:tid 1018074] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.991935 2026] [security2:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9TTAh5Y1i2tUxg4EFywAFvDg"] [Sat Aug 29 05:06:53.992551 2026] [security2:error] [pid 1028675:tid 1028910] [client 68.155.159.216:65116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/NewFile.php/"] [unique_id "apK9TddHPfW2QFvhmL7PPgAAAGQ"] [Sat Aug 29 05:06:53.994887 2026] [core:error] [pid 1028675:tid 1028904] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.994901 2026] [core:error] [pid 1028675:tid 1028904] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:53.996671 2026] [security2:error] [pid 1028675:tid 1028913] [client 57.141.14.103:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/"] [unique_id "apK9TddHPfW2QFvhmL7PPQAAAGc"] [Sat Aug 29 05:06:54.017005 2026] [security2:error] [pid 1028675:tid 1028903] [client 158.23.147.79:24550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9TtdHPfW2QFvhmL7PRAAAAF0"] [Sat Aug 29 05:06:54.018268 2026] [security2:error] [pid 1028675:tid 1028870] [client 68.155.159.216:18374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/login.php"] [unique_id "apK9TtdHPfW2QFvhmL7PRgAAADw"] [Sat Aug 29 05:06:54.021378 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.151.200.44:47299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/super.php"] [unique_id "apK9TtdHPfW2QFvhmL7PSAAAACk"] [Sat Aug 29 05:06:54.022633 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.022650 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.023347 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.023375 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.023638 2026] [core:error] [pid 1028675:tid 1028885] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.023647 2026] [core:error] [pid 1028675:tid 1028885] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.024631 2026] [security2:error] [pid 1018003:tid 1018240] [client 4.205.62.107:21625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/paths.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF1AAABhA"] [Sat Aug 29 05:06:54.024970 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.024983 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.025074 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.025083 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.026708 2026] [core:error] [pid 1028675:tid 1028874] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.026722 2026] [core:error] [pid 1028675:tid 1028874] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.030406 2026] [security2:error] [pid 1028675:tid 1028882] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9TtdHPfW2QFvhmL7PTQAAAEg"] [Sat Aug 29 05:06:54.034041 2026] [security2:error] [pid 1018003:tid 1018189] [client 93.123.109.228:52512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9TjAh5Y1i2tUxg4EF1gAABd4"] [Sat Aug 29 05:06:54.034362 2026] [security2:error] [pid 1018003:tid 1018180] [client 158.23.184.117:19292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yeselespinoza.andresortega.org"] [uri "/3pjcpmfsd8b.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF1wAABdU"] [Sat Aug 29 05:06:54.036563 2026] [security2:error] [pid 1028675:tid 1028843] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9TtdHPfW2QFvhmL7PTwAAACE"] [Sat Aug 29 05:06:54.044738 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.147.79:49984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF2QAABjM"] [Sat Aug 29 05:06:54.045469 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.196.209.81:17916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/class-wp-cmd.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF2wAABb4"] [Sat Aug 29 05:06:54.049599 2026] [security2:error] [pid 1018003:tid 1018058] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/config.php.bak"] [unique_id "apK9TjAh5Y1i2tUxg4EF3AAF9iU"] [Sat Aug 29 05:06:54.052061 2026] [security2:error] [pid 1018003:tid 1018118] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/core/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EF3QAF9mE"] [Sat Aug 29 05:06:54.062520 2026] [security2:error] [pid 1018003:tid 1018267] [client 40.83.93.50:17339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/alumni_reg.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF4QAABis"] [Sat Aug 29 05:06:54.067440 2026] [security2:error] [pid 1028675:tid 1028838] [client 103.168.67.159:53254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9TtdHPfW2QFvhmL7PVAAAABw"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:06:54.067713 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.104.62:27071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/wp-content.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF4gAABjU"] [Sat Aug 29 05:06:54.073579 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.48.250.41:21252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/35.php"] [unique_id "apK9TtdHPfW2QFvhmL7PVQAAACg"] [Sat Aug 29 05:06:54.075492 2026] [security2:error] [pid 1018003:tid 1018236] [client 158.23.184.117:46369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dontbenicemovie.wanderlustpictures.com"] [uri "/lock360.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF4wAABgw"] [Sat Aug 29 05:06:54.081705 2026] [cgid:error] [pid 1028675:tid 1028917] [client 20.52.41.200:1266] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:54.081974 2026] [security2:error] [pid 1018003:tid 1018273] [client 68.155.159.216:6025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/chosen.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF5gAABjE"] [Sat Aug 29 05:06:54.084523 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.104.62:29208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-act.php"] [unique_id "apK9TtdHPfW2QFvhmL7PVwAAAE8"] [Sat Aug 29 05:06:54.088034 2026] [security2:error] [pid 1018003:tid 1018262] [client 197.219.150.206:60835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF6gAABiY"] [Sat Aug 29 05:06:54.088279 2026] [security2:error] [pid 1018003:tid 1018262] [client 197.219.150.206:60835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF6gAABiY"] [Sat Aug 29 05:06:54.102804 2026] [security2:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EF7QAFy38"] [Sat Aug 29 05:06:54.104528 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.104.104.62:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/f-401.php"] [unique_id "apK9TtdHPfW2QFvhmL7PWQAAAGE"] [Sat Aug 29 05:06:54.105398 2026] [security2:error] [pid 1018003:tid 1018218] [client 168.107.94.195:64526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF7gAABfs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:54.112731 2026] [core:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.112754 2026] [core:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.133479 2026] [security2:error] [pid 1028675:tid 1028933] [client 4.205.62.107:9002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/abcd.php"] [unique_id "apK9TtdHPfW2QFvhmL7PXgAAAHs"] [Sat Aug 29 05:06:54.136914 2026] [security2:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EF9AAFy18"] [Sat Aug 29 05:06:54.138054 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.104.62:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/wp-ana.php"] [unique_id "apK9TjAh5Y1i2tUxg4EF-QAABcI"] [Sat Aug 29 05:06:54.138975 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.138994 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.139297 2026] [security2:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EF-gAFy18"] [Sat Aug 29 05:06:54.141734 2026] [core:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.141763 2026] [core:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.146739 2026] [security2:error] [pid 1028675:tid 1028878] [client 158.23.147.79:30714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9TtdHPfW2QFvhmL7PYgAAAEQ"] [Sat Aug 29 05:06:54.166785 2026] [security2:error] [pid 1018003:tid 1018159] [client 103.171.189.88:56377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGAwAABcA"] [Sat Aug 29 05:06:54.166915 2026] [security2:error] [pid 1018003:tid 1018159] [client 103.171.189.88:56377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGAwAABcA"] [Sat Aug 29 05:06:54.173812 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.173830 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.178059 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.178079 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.178549 2026] [security2:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9TjAh5Y1i2tUxg4EGCAAFy2k"] [Sat Aug 29 05:06:54.179614 2026] [security2:error] [pid 1018003:tid 1018121] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/configuration.php.bak"] [unique_id "apK9TjAh5Y1i2tUxg4EGCgAF0GQ"] [Sat Aug 29 05:06:54.180132 2026] [security2:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9TjAh5Y1i2tUxg4EGCQAFy2k"] [Sat Aug 29 05:06:54.191750 2026] [security2:error] [pid 1018003:tid 1018139] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/public/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGDgAFvXY"] [Sat Aug 29 05:06:54.198834 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.198853 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.203073 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.49.130:53813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/wp-login.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGEgAABcg"] [Sat Aug 29 05:06:54.207048 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.207063 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.221084 2026] [core:error] [pid 1028675:tid 1028835] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.221106 2026] [core:error] [pid 1028675:tid 1028835] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.226845 2026] [security2:error] [pid 1028675:tid 1028833] [client 20.151.200.44:47417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/lufix1.php"] [unique_id "apK9TtdHPfW2QFvhmL7PcAAAABc"] [Sat Aug 29 05:06:54.230809 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.52.41.200:1266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/images/index.php"] [unique_id "apK9TtdHPfW2QFvhmL7PcQAAAA4"] [Sat Aug 29 05:06:54.231573 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:21492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/maraz.php"] [unique_id "apK9TtdHPfW2QFvhmL7PcgAAAHM"] [Sat Aug 29 05:06:54.237036 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.237055 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.238352 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.238379 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.241840 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.241858 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.254693 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.104.62:37187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/hq.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGHQAABgc"] [Sat Aug 29 05:06:54.265204 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.104.62:40201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/Wop.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGHgAABcU"] [Sat Aug 29 05:06:54.281645 2026] [core:error] [pid 1028675:tid 1028836] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.281668 2026] [core:error] [pid 1028675:tid 1028836] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.282467 2026] [security2:error] [pid 1028675:tid 1028877] [client 20.104.104.62:29185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-admin/user/index.php"] [unique_id "apK9TtdHPfW2QFvhmL7PdwAAAEM"] [Sat Aug 29 05:06:54.300433 2026] [security2:error] [pid 1018003:tid 1018128] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/.env.swp"] [unique_id "apK9TjAh5Y1i2tUxg4EGJgAF_2s"] [Sat Aug 29 05:06:54.301175 2026] [security2:error] [pid 1018003:tid 1018137] [remote 74.7.227.154:41662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo.store"] [uri "/sitemap_index.xml"] [unique_id "apK9TjAh5Y1i2tUxg4EGKAAF_3Q"], referer: https://goodtogo.store/sitemap_index.xml?p=%2Fhome4%2Fsortthru%2Fpublic_html%2Fgoodtogo%2Fwebapp%2Fwp-content%2Fplugins%2Fwp-easycart%2Fadmin%2Felementor [Sat Aug 29 05:06:54.304469 2026] [core:error] [pid 1028675:tid 1028851] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.304486 2026] [core:error] [pid 1028675:tid 1028851] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.304976 2026] [security2:error] [pid 1028675:tid 1028885] [client 4.205.62.107:22379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/phpversion.php"] [unique_id "apK9TtdHPfW2QFvhmL7PfgAAAEs"] [Sat Aug 29 05:06:54.308716 2026] [security2:error] [pid 1018003:tid 1018161] [client 4.205.62.107:65470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/aws_auth.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGKgAABcI"] [Sat Aug 29 05:06:54.309134 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.309145 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.316401 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.316428 2026] [core:error] [pid 1018003:tid 1018225] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.317401 2026] [security2:error] [pid 1018003:tid 1018174] [client 4.205.62.107:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/goods.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGLQAABc8"] [Sat Aug 29 05:06:54.317908 2026] [security2:error] [pid 1028675:tid 1028906] [client 68.155.159.216:9268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/admin.php"] [unique_id "apK9TtdHPfW2QFvhmL7PgwAAAGA"] [Sat Aug 29 05:06:54.318731 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.318744 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.319276 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.319289 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.320570 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.197.61.180:11633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/wp-configs.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGLwAABeU"] [Sat Aug 29 05:06:54.332213 2026] [security2:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9TjAh5Y1i2tUxg4EGMQAF2mU"] [Sat Aug 29 05:06:54.365202 2026] [security2:error] [pid 1018003:tid 1018133] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/.env.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGNAAFvXA"] [Sat Aug 29 05:06:54.367074 2026] [security2:error] [pid 1028675:tid 1028863] [client 68.155.159.216:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wzy.php"] [unique_id "apK9TtdHPfW2QFvhmL7PhwAAADU"] [Sat Aug 29 05:06:54.370161 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.104.62:42680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/secret.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGNQAABeA"] [Sat Aug 29 05:06:54.371970 2026] [security2:error] [pid 1018003:tid 1018271] [client 4.205.62.107:22265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wp-admin/sc.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGNgAABi8"] [Sat Aug 29 05:06:54.372642 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.147.79:32765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/goat.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGNwAABec"] [Sat Aug 29 05:06:54.384384 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.104.62:43036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/mh.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGQAAABes"] [Sat Aug 29 05:06:54.392767 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.250.41:21384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/kbfr.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGQwAABgY"] [Sat Aug 29 05:06:54.403584 2026] [core:error] [pid 1028675:tid 1028924] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.403609 2026] [core:error] [pid 1028675:tid 1028924] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.408388 2026] [core:error] [pid 1028675:tid 1028883] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.408404 2026] [core:error] [pid 1028675:tid 1028883] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.409561 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.409576 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.410298 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.410308 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.416925 2026] [core:error] [pid 1028675:tid 1028933] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.416939 2026] [core:error] [pid 1028675:tid 1028933] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.427881 2026] [security2:error] [pid 1028675:tid 1028871] [client 158.158.54.35:28355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/themes/about.php"] [unique_id "apK9TtdHPfW2QFvhmL7PkAAAAD0"] [Sat Aug 29 05:06:54.429261 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.429277 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.430241 2026] [security2:error] [pid 1028675:tid 1028931] [client 68.155.159.216:24562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/atomlib.php"] [unique_id "apK9TtdHPfW2QFvhmL7PkQAAAHk"] [Sat Aug 29 05:06:54.434506 2026] [security2:error] [pid 1018003:tid 1018206] [client 158.23.147.79:25538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGTAAABe8"] [Sat Aug 29 05:06:54.456941 2026] [security2:error] [pid 1018003:tid 1018147] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9TjAh5Y1i2tUxg4EGTQAF2H4"] [Sat Aug 29 05:06:54.469304 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.151.200.44:47300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/hack.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGUAAABcE"] [Sat Aug 29 05:06:54.470112 2026] [security2:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9TjAh5Y1i2tUxg4EGUQAF-wA"] [Sat Aug 29 05:06:54.474807 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.104.62:27041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/ws.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGVAAABcI"] [Sat Aug 29 05:06:54.477465 2026] [security2:error] [pid 1028675:tid 1028810] [client 20.104.104.62:29193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-content/index.php"] [unique_id "apK9TtdHPfW2QFvhmL7PlQAAAAA"] [Sat Aug 29 05:06:54.484167 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.196.209.81:9751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/disagreed.php"] [unique_id "apK9TtdHPfW2QFvhmL7PmAAAACg"] [Sat Aug 29 05:06:54.484427 2026] [core:error] [pid 1028675:tid 1028842] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.484439 2026] [core:error] [pid 1028675:tid 1028842] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.486017 2026] [security2:error] [pid 1018003:tid 1018174] [client 168.107.94.195:65013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGVgAABc8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:54.488218 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.104.49.130:46532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/run.php"] [unique_id "apK9TtdHPfW2QFvhmL7PmQAAAE0"] [Sat Aug 29 05:06:54.489268 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.489278 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.505300 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.158.54.35:18123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/xmlrpc.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGWwAABfk"] [Sat Aug 29 05:06:54.505387 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.505400 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.521569 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.104.49.130:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/coffexium.php"] [unique_id "apK9TtdHPfW2QFvhmL7PoAAAABk"] [Sat Aug 29 05:06:54.527276 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.104.104.62:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/f2r4.php"] [unique_id "apK9TtdHPfW2QFvhmL7PogAAAB0"] [Sat Aug 29 05:06:54.528794 2026] [security2:error] [pid 1018003:tid 1018207] [client 68.155.159.216:49219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/ws.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGYgAABfA"] [Sat Aug 29 05:06:54.536878 2026] [core:error] [pid 1028675:tid 1028854] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.536894 2026] [core:error] [pid 1028675:tid 1028854] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.540188 2026] [core:error] [pid 1028675:tid 1028919] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.540206 2026] [core:error] [pid 1028675:tid 1028919] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.540510 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.540521 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.540800 2026] [security2:error] [pid 1028675:tid 1028820] [client 20.104.104.62:36938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/pro.php"] [unique_id "apK9TtdHPfW2QFvhmL7PpQAAAAo"] [Sat Aug 29 05:06:54.543886 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.543898 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.555651 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.48.250.41:21343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wp-act.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGZwAABgo"] [Sat Aug 29 05:06:54.563284 2026] [security2:error] [pid 1018003:tid 1018186] [client 40.83.93.50:7561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/colors.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGbQAABds"] [Sat Aug 29 05:06:54.566915 2026] [security2:error] [pid 1018003:tid 1018145] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9TjAh5Y1i2tUxg4EGbwAF-3w"] [Sat Aug 29 05:06:54.568292 2026] [core:error] [pid 1028675:tid 1028815] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.568312 2026] [core:error] [pid 1028675:tid 1028815] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.579446 2026] [security2:error] [pid 1028675:tid 1028836] [client 20.104.104.62:40207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/pah.php"] [unique_id "apK9TtdHPfW2QFvhmL7PrAAAABo"] [Sat Aug 29 05:06:54.579931 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.147.79:48384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/index.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGcQAABec"] [Sat Aug 29 05:06:54.582269 2026] [core:error] [pid 1028675:tid 1028811] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.582280 2026] [core:error] [pid 1028675:tid 1028811] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.587009 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.151.200.44:65041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/mh.php"] [unique_id "apK9TtdHPfW2QFvhmL7PrgAAADM"] [Sat Aug 29 05:06:54.594505 2026] [security2:error] [pid 1018003:tid 1018032] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9TjAh5Y1i2tUxg4EGcwAF-ws"] [Sat Aug 29 05:06:54.601512 2026] [security2:error] [pid 1018003:tid 1018277] [client 93.123.109.228:52492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/.wp-config.php.swp"] [unique_id "apK9TjAh5Y1i2tUxg4EGdQAABjU"] [Sat Aug 29 05:06:54.606993 2026] [security2:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9TjAh5Y1i2tUxg4EGdgAF-w0"] [Sat Aug 29 05:06:54.612126 2026] [security2:error] [pid 1028675:tid 1028813] [client 20.151.200.44:47423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/155.php"] [unique_id "apK9TtdHPfW2QFvhmL7PrwAAAAM"] [Sat Aug 29 05:06:54.625613 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.625626 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.625924 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.625932 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.629599 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.629611 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.636522 2026] [security2:error] [pid 1028675:tid 1028819] [client 149.34.210.141:7599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9TtdHPfW2QFvhmL7PsQAAAAk"] [Sat Aug 29 05:06:54.636607 2026] [security2:error] [pid 1028675:tid 1028819] [client 149.34.210.141:7599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9TtdHPfW2QFvhmL7PsQAAAAk"] [Sat Aug 29 05:06:54.642110 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.642123 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.650904 2026] [security2:error] [pid 1028675:tid 1028852] [client 93.123.109.228:52428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9TtdHPfW2QFvhmL7PtAAAACo"] [Sat Aug 29 05:06:54.661847 2026] [security2:error] [pid 1018003:tid 1018189] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGfAAABd4"] [Sat Aug 29 05:06:54.670587 2026] [security2:error] [pid 1028675:tid 1028831] [client 20.52.41.200:1729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/num.php"] [unique_id "apK9TtdHPfW2QFvhmL7PtwAAABU"] [Sat Aug 29 05:06:54.670632 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.104.104.62:29191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/wp-content/uploads/wpr-addons/forms/b1ack.php"] [unique_id "apK9TtdHPfW2QFvhmL7PtgAAAAs"] [Sat Aug 29 05:06:54.673882 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.104.104.62:27055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/0x.php"] [unique_id "apK9TtdHPfW2QFvhmL7PuAAAAH8"] [Sat Aug 29 05:06:54.678142 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.104.104.62:43056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/sadis.php"] [unique_id "apK9TtdHPfW2QFvhmL7PugAAAEA"] [Sat Aug 29 05:06:54.705195 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.250.41:21462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/24.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGggAABcs"] [Sat Aug 29 05:06:54.712704 2026] [core:error] [pid 1028675:tid 1028882] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.712724 2026] [core:error] [pid 1028675:tid 1028882] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.720236 2026] [security2:error] [pid 1028675:tid 1028843] [client 93.123.109.228:52412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9TtdHPfW2QFvhmL7PwQAAACE"] [Sat Aug 29 05:06:54.726434 2026] [security2:error] [pid 1028675:tid 1028838] [client 20.104.104.62:23411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/999.php"] [unique_id "apK9TtdHPfW2QFvhmL7PxQAAABw"] [Sat Aug 29 05:06:54.727131 2026] [security2:error] [pid 1028675:tid 1028872] [client 68.155.159.216:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9TtdHPfW2QFvhmL7PxgAAAD4"] [Sat Aug 29 05:06:54.732821 2026] [security2:error] [pid 1018003:tid 1018071] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/storage/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGjQAGDjI"] [Sat Aug 29 05:06:54.734388 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.734406 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.734575 2026] [core:error] [pid 1028675:tid 1028823] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.734587 2026] [core:error] [pid 1028675:tid 1028823] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.740327 2026] [security2:error] [pid 1018003:tid 1018275] [client 93.123.109.228:52476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGjgAABjM"] [Sat Aug 29 05:06:54.742185 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.742201 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.745211 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.745227 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.745275 2026] [core:error] [pid 1028675:tid 1028896] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.745285 2026] [core:error] [pid 1028675:tid 1028896] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.745644 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.745653 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.746155 2026] [security2:error] [pid 1028675:tid 1028909] [client 68.155.159.216:51827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/mah.php"] [unique_id "apK9TtdHPfW2QFvhmL7PzwAAAGM"] [Sat Aug 29 05:06:54.748233 2026] [security2:error] [pid 1028675:tid 1028837] [client 158.23.147.79:63809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/packed.php"] [unique_id "apK9TtdHPfW2QFvhmL7P0AAAABs"] [Sat Aug 29 05:06:54.749685 2026] [security2:error] [pid 1018003:tid 1018155] [client 93.123.109.228:52492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGkQAABbw"] [Sat Aug 29 05:06:54.752172 2026] [security2:error] [pid 1018003:tid 1018233] [client 93.123.109.228:52512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGkgAABgk"] [Sat Aug 29 05:06:54.757183 2026] [security2:error] [pid 1018003:tid 1018054] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/wp/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGlAAGICE"] [Sat Aug 29 05:06:54.758614 2026] [security2:error] [pid 1018003:tid 1018167] [client 93.123.109.228:52498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGlQAABcg"] [Sat Aug 29 05:06:54.761750 2026] [security2:error] [pid 1028675:tid 1028911] [client 20.104.49.130:52288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/666.php"] [unique_id "apK9TtdHPfW2QFvhmL7P0QAAAGU"] [Sat Aug 29 05:06:54.767875 2026] [security2:error] [pid 1018003:tid 1018100] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/web/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGmQAF2E8"] [Sat Aug 29 05:06:54.768579 2026] [security2:error] [pid 1018003:tid 1018061] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tgd6.com"] [uri "/wp-config.php~"] [unique_id "apK9TjAh5Y1i2tUxg4EGnAAF2Cg"] [Sat Aug 29 05:06:54.768708 2026] [core:error] [pid 1028675:tid 1028905] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.768807 2026] [core:error] [pid 1028675:tid 1028905] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.769101 2026] [core:error] [pid 1028675:tid 1028914] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.769109 2026] [core:error] [pid 1028675:tid 1028914] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.770412 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.770430 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.782667 2026] [security2:error] [pid 1028675:tid 1028810] [client 20.104.104.62:20801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/webshell.php"] [unique_id "apK9TtdHPfW2QFvhmL7P1QAAAAA"] [Sat Aug 29 05:06:54.788020 2026] [security2:error] [pid 1018003:tid 1018050] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/wp-config.old"] [unique_id "apK9TjAh5Y1i2tUxg4EGnwAGAh0"] [Sat Aug 29 05:06:54.790155 2026] [security2:error] [pid 1028675:tid 1028850] [client 4.205.62.107:56010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/xin1.php"] [unique_id "apK9TtdHPfW2QFvhmL7P1gAAACg"] [Sat Aug 29 05:06:54.800984 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.800997 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.803162 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.803175 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.810265 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.104.104.62:64694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/xcre1.php"] [unique_id "apK9TtdHPfW2QFvhmL7P2wAAAC4"] [Sat Aug 29 05:06:54.812795 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.812807 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.816170 2026] [core:error] [pid 1018003:tid 1018166] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.816188 2026] [core:error] [pid 1018003:tid 1018166] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.816612 2026] [core:error] [pid 1028675:tid 1028830] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.816623 2026] [core:error] [pid 1028675:tid 1028830] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.821081 2026] [security2:error] [pid 1018003:tid 1018195] [client 93.123.109.228:52420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9TjAh5Y1i2tUxg4EGowAABeQ"] [Sat Aug 29 05:06:54.821343 2026] [security2:error] [pid 1028675:tid 1028846] [client 93.123.109.228:52470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9TtdHPfW2QFvhmL7P4AAAACQ"] [Sat Aug 29 05:06:54.846700 2026] [security2:error] [pid 1028675:tid 1028901] [client 20.196.209.81:17156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK9TtdHPfW2QFvhmL7P4gAAAFs"] [Sat Aug 29 05:06:54.849505 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.48.250.41:21502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/155.php"] [unique_id "apK9TtdHPfW2QFvhmL7P4wAAAB8"] [Sat Aug 29 05:06:54.867877 2026] [security2:error] [pid 1018003:tid 1018219] [client 168.107.94.195:65345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGqAAABfw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:54.869036 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.104.62:28851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.watercolorsbylola.allgooddays.org"] [uri "/.well-known/s1.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGqQAABco"] [Sat Aug 29 05:06:54.869061 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.104.62:27026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ngoiloi.nlvn.net"] [uri "/an.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGqgAABc8"] [Sat Aug 29 05:06:54.883982 2026] [security2:error] [pid 1028675:tid 1028848] [client 158.158.54.35:20573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9TtdHPfW2QFvhmL7P5QAAACY"] [Sat Aug 29 05:06:54.889176 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.196.209.81:9465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/class_api.php"] [unique_id "apK9TtdHPfW2QFvhmL7P5gAAACs"] [Sat Aug 29 05:06:54.917539 2026] [security2:error] [pid 1028675:tid 1028891] [client 52.139.37.240:20795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/asw.php"] [unique_id "apK9TtdHPfW2QFvhmL7P6AAAAFE"] [Sat Aug 29 05:06:54.922864 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.147.79:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGswAABew"] [Sat Aug 29 05:06:54.941519 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.941543 2026] [core:error] [pid 1018003:tid 1018198] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.950789 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.158.54.35:23567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/filemanager.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGtwAABhY"] [Sat Aug 29 05:06:54.975228 2026] [security2:error] [pid 1028675:tid 1028836] [client 158.23.147.79:26618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/cong.php"] [unique_id "apK9TtdHPfW2QFvhmL7P6wAAABo"] [Sat Aug 29 05:06:54.983032 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.147.79:17473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/NewFile.php/"] [unique_id "apK9TtdHPfW2QFvhmL7P7AAAADA"] [Sat Aug 29 05:06:54.986693 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.48.250.41:21464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/file.php"] [unique_id "apK9TjAh5Y1i2tUxg4EGvQAABg8"] [Sat Aug 29 05:06:54.988059 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.988075 2026] [core:error] [pid 1018003:tid 1018179] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.988308 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:54.988318 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.007051 2026] [security2:error] [pid 1018003:tid 1018189] [client 68.155.159.216:38528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9TzAh5Y1i2tUxg4EGwQAABd4"] [Sat Aug 29 05:06:55.022474 2026] [core:error] [pid 1028675:tid 1028921] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.022495 2026] [core:error] [pid 1028675:tid 1028921] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.039016 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.197.61.180:11591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/essexec.php"] [unique_id "apK9TzAh5Y1i2tUxg4EGygAABbk"] [Sat Aug 29 05:06:55.044543 2026] [security2:error] [pid 1028675:tid 1028904] [client 52.139.37.240:33549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/upfile.php"] [unique_id "apK9T9dHPfW2QFvhmL7P-AAAAF4"] [Sat Aug 29 05:06:55.049316 2026] [security2:error] [pid 1018003:tid 1018075] [remote 34.139.66.91:54766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tgd6.com"] [uri "/wp-config.php.swp"] [unique_id "apK9TzAh5Y1i2tUxg4EGywAFyzY"] [Sat Aug 29 05:06:55.058504 2026] [core:error] [pid 1028675:tid 1028882] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.058523 2026] [core:error] [pid 1028675:tid 1028882] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.063572 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.063633 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.065514 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.065539 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.069293 2026] [security2:error] [pid 1028675:tid 1028920] [client 52.139.37.240:2900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/upfile.php"] [unique_id "apK9T9dHPfW2QFvhmL7QAwAAAG4"] [Sat Aug 29 05:06:55.075321 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.075337 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.076174 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.076187 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.091980 2026] [core:error] [pid 1028675:tid 1028928] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.091996 2026] [core:error] [pid 1028675:tid 1028928] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.093373 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.093389 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.094663 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.094676 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.095774 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.095792 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.096166 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.096178 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.101108 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.49.130:46539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/srontol.php"] [unique_id "apK9TzAh5Y1i2tUxg4EG3AAABis"] [Sat Aug 29 05:06:55.109048 2026] [security2:error] [pid 1028675:tid 1028818] [client 52.139.37.240:31497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QCwAAAAg"] [Sat Aug 29 05:06:55.110625 2026] [security2:error] [pid 1028675:tid 1028916] [client 52.139.37.240:32033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QDQAAAGo"] [Sat Aug 29 05:06:55.110828 2026] [core:error] [pid 1028675:tid 1028934] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.110837 2026] [core:error] [pid 1028675:tid 1028934] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.119979 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.119993 2026] [core:error] [pid 1018003:tid 1018206] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.128163 2026] [cgid:error] [pid 1028675:tid 1028877] [client 20.52.41.200:1749] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:55.128503 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.128524 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.130127 2026] [security2:error] [pid 1028675:tid 1028859] [client 52.139.37.240:20865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/item.php"] [unique_id "apK9T9dHPfW2QFvhmL7QEAAAADE"] [Sat Aug 29 05:06:55.141987 2026] [security2:error] [pid 1018003:tid 1018160] [client 158.23.147.79:24458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/log-mama/function.php"] [unique_id "apK9TzAh5Y1i2tUxg4EG5AAABcE"] [Sat Aug 29 05:06:55.152689 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.48.250.41:21340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9T9dHPfW2QFvhmL7QEwAAAHc"] [Sat Aug 29 05:06:55.156332 2026] [security2:error] [pid 1028675:tid 1028850] [client 68.155.159.216:65098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/dropdown.php"] [unique_id "apK9T9dHPfW2QFvhmL7QFQAAACg"] [Sat Aug 29 05:06:55.161444 2026] [security2:error] [pid 1028675:tid 1028855] [client 4.205.62.107:22063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/olfclass.php"] [unique_id "apK9T9dHPfW2QFvhmL7QFwAAAC0"] [Sat Aug 29 05:06:55.167076 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.167095 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.170966 2026] [security2:error] [pid 1028675:tid 1028887] [client 158.23.147.79:50145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/file.php"] [unique_id "apK9T9dHPfW2QFvhmL7QGAAAAE0"] [Sat Aug 29 05:06:55.179766 2026] [core:error] [pid 1028675:tid 1028817] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.179790 2026] [core:error] [pid 1028675:tid 1028817] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.180333 2026] [security2:error] [pid 1028675:tid 1028932] [client 68.155.159.216:18289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/hehehehe.php"] [unique_id "apK9T9dHPfW2QFvhmL7QGgAAAHo"] [Sat Aug 29 05:06:55.206043 2026] [security2:error] [pid 1018003:tid 1018194] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EG8gAABeM"] [Sat Aug 29 05:06:55.238673 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.238691 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.244545 2026] [security2:error] [pid 1018003:tid 1018156] [client 61.9.8.151:60029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9TzAh5Y1i2tUxg4EG_AAABb0"] [Sat Aug 29 05:06:55.244630 2026] [security2:error] [pid 1018003:tid 1018156] [client 61.9.8.151:60029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9TzAh5Y1i2tUxg4EG_AAABb0"] [Sat Aug 29 05:06:55.247142 2026] [security2:error] [pid 1028675:tid 1028905] [client 20.196.209.81:5815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/options-general.php"] [unique_id "apK9T9dHPfW2QFvhmL7QJQAAAF8"] [Sat Aug 29 05:06:55.248297 2026] [security2:error] [pid 1028675:tid 1028832] [client 168.107.94.195:49340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QJgAAABY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:55.250113 2026] [core:error] [pid 1018003:tid 1018105] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.250134 2026] [core:error] [pid 1018003:tid 1018105] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.257917 2026] [security2:error] [pid 1028675:tid 1028836] [client 158.23.147.79:30534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9T9dHPfW2QFvhmL7QKQAAABo"] [Sat Aug 29 05:06:55.258213 2026] [security2:error] [pid 1018003:tid 1018261] [client 52.139.37.240:32859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/form.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHAgAABiU"] [Sat Aug 29 05:06:55.262145 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.147.79:35743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/xmlrpc.php"] [unique_id "apK9T9dHPfW2QFvhmL7QLAAAADA"] [Sat Aug 29 05:06:55.264152 2026] [security2:error] [pid 1028675:tid 1028828] [client 40.83.93.50:7699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/Js.php"] [unique_id "apK9T9dHPfW2QFvhmL7QLQAAABI"] [Sat Aug 29 05:06:55.270846 2026] [security2:error] [pid 1018003:tid 1018169] [client 52.139.37.240:2893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/form.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHBgAABco"] [Sat Aug 29 05:06:55.274431 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.274445 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.278770 2026] [core:error] [pid 1028675:tid 1028921] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.278787 2026] [core:error] [pid 1028675:tid 1028921] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.282064 2026] [cgid:error] [pid 1028675:tid 1028819] [client 20.52.41.200:1749] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:55.287387 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.151.200.44:62725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/f2r4.php"] [unique_id "apK9T9dHPfW2QFvhmL7QNgAAAH8"] [Sat Aug 29 05:06:55.291317 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.48.250.41:21425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/06.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHDgAABi8"] [Sat Aug 29 05:06:55.293656 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.293675 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.295126 2026] [core:error] [pid 1028675:tid 1028838] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.295139 2026] [core:error] [pid 1028675:tid 1028838] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.296726 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.296740 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.300527 2026] [security2:error] [pid 1028675:tid 1028935] [client 52.139.37.240:32103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QOgAAAH0"] [Sat Aug 29 05:06:55.300713 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.300721 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.313073 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.313092 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.315991 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.316002 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.324377 2026] [security2:error] [pid 1018003:tid 1018106] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/.wp-config.php.swp"] [unique_id "apK9TzAh5Y1i2tUxg4EHEwAF_1U"] [Sat Aug 29 05:06:55.328750 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.328771 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.329657 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.329668 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.332187 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.332204 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.335143 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.104.49.130:43044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/ohct.php"] [unique_id "apK9T9dHPfW2QFvhmL7QQwAAAEE"] [Sat Aug 29 05:06:55.336590 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.336610 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.339756 2026] [security2:error] [pid 1028675:tid 1028916] [client 20.151.200.44:47328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/mcd.php"] [unique_id "apK9T9dHPfW2QFvhmL7QRQAAAGo"] [Sat Aug 29 05:06:55.341406 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.196.209.81:9767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/aksinet.php"] [unique_id "apK9T9dHPfW2QFvhmL7QRgAAAC4"] [Sat Aug 29 05:06:55.346212 2026] [security2:error] [pid 1028675:tid 1028888] [client 52.139.37.240:20871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/jga.php"] [unique_id "apK9T9dHPfW2QFvhmL7QSAAAAE4"] [Sat Aug 29 05:06:55.354118 2026] [security2:error] [pid 1028675:tid 1028820] [client 158.158.54.35:20342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-admin/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QSQAAAAo"] [Sat Aug 29 05:06:55.359055 2026] [autoindex:error] [pid 1018003:tid 1018172] [client 52.139.37.240:0] AH01276: Cannot serve directory /home4/swumccom/public_html/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:06:55.371105 2026] [security2:error] [pid 1018003:tid 1018152] [client 93.123.109.228:52548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHGAAABbk"] [Sat Aug 29 05:06:55.372790 2026] [security2:error] [pid 1018003:tid 1018162] [client 4.205.62.107:9199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/userfuns.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHGQAABcM"] [Sat Aug 29 05:06:55.395147 2026] [security2:error] [pid 1018003:tid 1018170] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHGgAABcs"] [Sat Aug 29 05:06:55.395251 2026] [security2:error] [pid 1028675:tid 1028815] [client 158.158.54.35:17808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9T9dHPfW2QFvhmL7QTgAAAAU"] [Sat Aug 29 05:06:55.399790 2026] [security2:error] [pid 1028675:tid 1028883] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9T9dHPfW2QFvhmL7QUAAAAEk"] [Sat Aug 29 05:06:55.416649 2026] [security2:error] [pid 1028675:tid 1028850] [client 93.123.109.228:52470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9T9dHPfW2QFvhmL7QUQAAACg"] [Sat Aug 29 05:06:55.424875 2026] [security2:error] [pid 1028675:tid 1028922] [client 52.139.37.240:31141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/wp-index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QUwAAAHA"] [Sat Aug 29 05:06:55.426716 2026] [security2:error] [pid 1028675:tid 1028892] [client 68.155.159.216:9218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9T9dHPfW2QFvhmL7QVAAAAFI"] [Sat Aug 29 05:06:55.432342 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.52.41.200:1749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/upgrade/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QVQAAADU"] [Sat Aug 29 05:06:55.448241 2026] [security2:error] [pid 1018003:tid 1018155] [client 4.205.62.107:26660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/hiquido.com/index.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHHAAABbw"] [Sat Aug 29 05:06:55.449491 2026] [security2:error] [pid 1028675:tid 1028933] [client 52.139.37.240:32834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/wp-sigunq.php"] [unique_id "apK9T9dHPfW2QFvhmL7QVwAAAHs"] [Sat Aug 29 05:06:55.459644 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.48.250.41:21481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/class.php"] [unique_id "apK9T9dHPfW2QFvhmL7QWAAAAFA"] [Sat Aug 29 05:06:55.462817 2026] [security2:error] [pid 1018003:tid 1018213] [client 4.205.62.107:21611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/hiquido.com/index.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHIQAABfY"] [Sat Aug 29 05:06:55.468614 2026] [security2:error] [pid 1028675:tid 1028822] [client 52.139.37.240:2576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/wp-sigunq.php"] [unique_id "apK9T9dHPfW2QFvhmL7QWQAAAAw"] [Sat Aug 29 05:06:55.478152 2026] [security2:error] [pid 1018003:tid 1018184] [client 4.205.62.107:51482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/asa.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHIgAABdk"] [Sat Aug 29 05:06:55.482901 2026] [security2:error] [pid 1018003:tid 1018258] [client 68.155.159.216:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHIwAABiI"] [Sat Aug 29 05:06:55.490088 2026] [security2:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHJgAFwTs"] [Sat Aug 29 05:06:55.490389 2026] [security2:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHJQAFwXU"] [Sat Aug 29 05:06:55.490451 2026] [security2:error] [pid 1018003:tid 1018094] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHJwAFwUk"] [Sat Aug 29 05:06:55.495085 2026] [security2:error] [pid 1028675:tid 1028925] [client 52.139.37.240:32718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/zafir1.php"] [unique_id "apK9T9dHPfW2QFvhmL7QWwAAAHM"] [Sat Aug 29 05:06:55.503136 2026] [security2:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHLAAF4WQ"] [Sat Aug 29 05:06:55.503148 2026] [security2:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHLQAF4TA"] [Sat Aug 29 05:06:55.509452 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.147.79:32677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHLwAABfA"] [Sat Aug 29 05:06:55.511796 2026] [security2:error] [pid 1028675:tid 1028910] [client 4.205.62.107:22229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/application.config.php"] [unique_id "apK9T9dHPfW2QFvhmL7QXQAAAGQ"] [Sat Aug 29 05:06:55.532940 2026] [core:error] [pid 1028675:tid 1028919] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.532955 2026] [core:error] [pid 1028675:tid 1028919] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.535319 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.535335 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.535537 2026] [core:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.535550 2026] [core:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.536042 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.536051 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.536289 2026] [core:error] [pid 1028675:tid 1028897] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.536300 2026] [core:error] [pid 1028675:tid 1028897] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.536931 2026] [core:error] [pid 1018003:tid 1018098] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.536939 2026] [core:error] [pid 1018003:tid 1018098] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.539007 2026] [security2:error] [pid 1028675:tid 1028908] [client 52.139.37.240:21130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/mac.php"] [unique_id "apK9T9dHPfW2QFvhmL7QYAAAAGI"] [Sat Aug 29 05:06:55.539129 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.147.79:25555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QYQAAADA"] [Sat Aug 29 05:06:55.543081 2026] [security2:error] [pid 1028675:tid 1028828] [client 68.155.159.216:24396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/lv.php"] [unique_id "apK9T9dHPfW2QFvhmL7QYgAAABI"] [Sat Aug 29 05:06:55.558138 2026] [security2:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHPAAF7DQ"] [Sat Aug 29 05:06:55.558253 2026] [core:error] [pid 1018003:tid 1018091] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.558264 2026] [core:error] [pid 1018003:tid 1018091] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.559537 2026] [core:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.559557 2026] [core:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.561922 2026] [security2:error] [pid 1018003:tid 1018109] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHPQAFylg"] [Sat Aug 29 05:06:55.620466 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.48.250.41:21354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/8.php"] [unique_id "apK9T9dHPfW2QFvhmL7QaQAAAHU"] [Sat Aug 29 05:06:55.622375 2026] [security2:error] [pid 1028675:tid 1028854] [client 52.139.37.240:31654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/ww2.php"] [unique_id "apK9T9dHPfW2QFvhmL7QawAAACw"] [Sat Aug 29 05:06:55.629445 2026] [security2:error] [pid 1028675:tid 1028920] [client 168.107.94.195:49649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9T9dHPfW2QFvhmL7QbgAAAG4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:55.635816 2026] [security2:error] [pid 1028675:tid 1028867] [client 68.155.159.216:49227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QbwAAADk"] [Sat Aug 29 05:06:55.644107 2026] [security2:error] [pid 1018003:tid 1018188] [client 52.139.37.240:33547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superresources.com"] [uri "/07.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHRQAABd0"] [Sat Aug 29 05:06:55.645601 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.645614 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.655974 2026] [security2:error] [pid 1018003:tid 1018239] [client 20.104.49.130:47847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/static.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHUAAABg8"] [Sat Aug 29 05:06:55.659109 2026] [security2:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHUgAGH2U"] [Sat Aug 29 05:06:55.659491 2026] [security2:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHUwAGH1Y"] [Sat Aug 29 05:06:55.659928 2026] [security2:error] [pid 1028675:tid 1028837] [client 158.23.147.79:30590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QdQAAABs"] [Sat Aug 29 05:06:55.664536 2026] [security2:error] [pid 1028675:tid 1028935] [client 52.139.37.240:2580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fairfaxbible.org"] [uri "/07.php"] [unique_id "apK9T9dHPfW2QFvhmL7QeAAAAH0"] [Sat Aug 29 05:06:55.668064 2026] [security2:error] [pid 1028675:tid 1028832] [client 20.196.209.81:5777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/options.php"] [unique_id "apK9T9dHPfW2QFvhmL7QeQAAABY"] [Sat Aug 29 05:06:55.672975 2026] [core:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.672992 2026] [core:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.684569 2026] [security2:error] [pid 1018003:tid 1018243] [client 158.23.147.79:48191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/about/function.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHVwAABhM"] [Sat Aug 29 05:06:55.689273 2026] [security2:error] [pid 1028675:tid 1028847] [client 52.139.37.240:32746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/abc.php"] [unique_id "apK9T9dHPfW2QFvhmL7QewAAACU"] [Sat Aug 29 05:06:55.690321 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.690339 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.694857 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.694885 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.716979 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.717001 2026] [core:error] [pid 1028675:tid 1028829] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.717810 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.717826 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.719442 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.719458 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.725623 2026] [security2:error] [pid 1028675:tid 1028818] [client 93.123.109.228:52468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9T9dHPfW2QFvhmL7QgQAAAAg"] [Sat Aug 29 05:06:55.729168 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.729183 2026] [core:error] [pid 1018003:tid 1018162] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.729200 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.729207 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.739567 2026] [core:error] [pid 1028675:tid 1028820] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.739587 2026] [core:error] [pid 1028675:tid 1028820] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.760060 2026] [security2:error] [pid 1028675:tid 1028852] [client 52.139.37.240:21388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QiQAAACo"] [Sat Aug 29 05:06:55.764053 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.196.209.81:14654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/alfa-rex1.php"] [unique_id "apK9T9dHPfW2QFvhmL7QigAAAF0"] [Sat Aug 29 05:06:55.765610 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.104.49.130:57615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/bdroot.php"] [unique_id "apK9T9dHPfW2QFvhmL7QjAAAACc"] [Sat Aug 29 05:06:55.770188 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.48.250.41:21489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/0x0x.php"] [unique_id "apK9T9dHPfW2QFvhmL7QjQAAAC8"] [Sat Aug 29 05:06:55.770258 2026] [core:error] [pid 1028675:tid 1028931] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.770270 2026] [core:error] [pid 1028675:tid 1028931] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.772668 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.197.61.180:9715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/hello.php"] [unique_id "apK9T9dHPfW2QFvhmL7QjgAAAB8"] [Sat Aug 29 05:06:55.779547 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.779562 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.779591 2026] [core:error] [pid 1028675:tid 1028850] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.779601 2026] [core:error] [pid 1028675:tid 1028850] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.780897 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.780916 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.791111 2026] [security2:error] [pid 1018003:tid 1018240] [client 93.123.109.228:52506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9TzAh5Y1i2tUxg4EHcAAABhA"] [Sat Aug 29 05:06:55.816820 2026] [security2:error] [pid 1018003:tid 1018277] [client 40.83.93.50:7717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/access.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHdwAABjU"] [Sat Aug 29 05:06:55.820079 2026] [security2:error] [pid 1028675:tid 1028871] [client 52.139.37.240:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/7logs.php"] [unique_id "apK9T9dHPfW2QFvhmL7QlgAAAD0"] [Sat Aug 29 05:06:55.824526 2026] [security2:error] [pid 1018003:tid 1018161] [client 68.155.159.216:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHeAAABcI"] [Sat Aug 29 05:06:55.830858 2026] [security2:error] [pid 1018003:tid 1018180] [client 158.158.54.35:16129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/radio.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHegAABdU"] [Sat Aug 29 05:06:55.834381 2026] [security2:error] [pid 1018003:tid 1018268] [client 68.155.159.216:2007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHewAABiw"] [Sat Aug 29 05:06:55.843762 2026] [core:error] [pid 1028675:tid 1028865] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.843780 2026] [core:error] [pid 1028675:tid 1028865] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.844085 2026] [core:error] [pid 1028675:tid 1028846] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.844099 2026] [core:error] [pid 1028675:tid 1028846] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.847608 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.158.54.35:38402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-admin/css/admin.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHfAAABdQ"] [Sat Aug 29 05:06:55.850570 2026] [core:error] [pid 1018003:tid 1018207] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.850584 2026] [core:error] [pid 1018003:tid 1018207] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.861863 2026] [security2:error] [pid 1018003:tid 1018236] [client 52.139.37.240:33566] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "superresources.com"] [uri "/c99.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHggAABgw"] [Sat Aug 29 05:06:55.861863 2026] [security2:error] [pid 1028675:tid 1028932] [client 52.139.37.240:2880] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "fairfaxbible.org"] [uri "/c99.php"] [unique_id "apK9T9dHPfW2QFvhmL7QmwAAAHo"] [Sat Aug 29 05:06:55.881145 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.151.200.44:47373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/waw.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHigAABec"] [Sat Aug 29 05:06:55.887279 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.52.41.200:1261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "apK9T9dHPfW2QFvhmL7QogAAACM"] [Sat Aug 29 05:06:55.887400 2026] [core:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.887416 2026] [core:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.908438 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.908460 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.924347 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.924380 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.924996 2026] [security2:error] [pid 1018003:tid 1018156] [client 4.205.62.107:53266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/sadd.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHkQAABb0"] [Sat Aug 29 05:06:55.927950 2026] [core:error] [pid 1028675:tid 1028879] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.927971 2026] [core:error] [pid 1028675:tid 1028879] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.930467 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.48.250.41:21473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/166.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHlAAABdA"] [Sat Aug 29 05:06:55.932392 2026] [security2:error] [pid 1018003:tid 1018032] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9TzAh5Y1i2tUxg4EHlQAGLgs"] [Sat Aug 29 05:06:55.937743 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.937764 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.942018 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.942032 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.946861 2026] [core:error] [pid 1028675:tid 1028874] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.946876 2026] [core:error] [pid 1028675:tid 1028874] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.951120 2026] [core:error] [pid 1028675:tid 1028904] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.951139 2026] [core:error] [pid 1028675:tid 1028904] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.960791 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.960808 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.967084 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.967098 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.972683 2026] [core:error] [pid 1028675:tid 1028907] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.972702 2026] [core:error] [pid 1028675:tid 1028907] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.974570 2026] [core:error] [pid 1018003:tid 1018163] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:55.974587 2026] [core:error] [pid 1018003:tid 1018163] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.004163 2026] [security2:error] [pid 1028675:tid 1028814] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9UNdHPfW2QFvhmL7QrwAAAAQ"] [Sat Aug 29 05:06:56.004657 2026] [security2:error] [pid 1018003:tid 1018131] [remote 34.139.66.91:54766] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "tgd6.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9UDAh5Y1i2tUxg4EHqAAFy24"] [Sat Aug 29 05:06:56.008292 2026] [security2:error] [pid 1028675:tid 1028889] [client 93.123.109.228:52428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9UNdHPfW2QFvhmL7QsAAAAE8"] [Sat Aug 29 05:06:56.009430 2026] [security2:error] [pid 1028675:tid 1028885] [client 168.107.94.195:49920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9UNdHPfW2QFvhmL7QsQAAAEs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:56.044384 2026] [security2:error] [pid 1028675:tid 1028895] [client 20.151.200.44:64399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/sadis.php"] [unique_id "apK9UNdHPfW2QFvhmL7QsgAAAFU"] [Sat Aug 29 05:06:56.055789 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.48.160.90:51688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9UNdHPfW2QFvhmL7QswAAADQ"] [Sat Aug 29 05:06:56.067712 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.48.250.41:21381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/h2a2ck.php"] [unique_id "apK9UNdHPfW2QFvhmL7QtgAAADM"] [Sat Aug 29 05:06:56.069293 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.196.209.81:22428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/panel.php"] [unique_id "apK9UDAh5Y1i2tUxg4EHrAAABcc"] [Sat Aug 29 05:06:56.101643 2026] [security2:error] [pid 1018003:tid 1018258] [client 158.23.147.79:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9UDAh5Y1i2tUxg4EHtgAABiI"] [Sat Aug 29 05:06:56.114646 2026] [security2:error] [pid 1018003:tid 1018161] [client 68.155.159.216:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9UDAh5Y1i2tUxg4EHtwAABcI"] [Sat Aug 29 05:06:56.121074 2026] [security2:error] [pid 1028675:tid 1028924] [client 68.155.159.216:33773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9UNdHPfW2QFvhmL7QuwAAAHI"] [Sat Aug 29 05:06:56.121239 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.121250 2026] [core:error] [pid 1018003:tid 1018180] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.123784 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.123799 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.128222 2026] [core:error] [pid 1028675:tid 1028823] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.128242 2026] [core:error] [pid 1028675:tid 1028823] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.128891 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.128907 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.129626 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.129645 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.149596 2026] [security2:error] [pid 1018003:tid 1018255] [client 127.0.0.1:28372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "apK9UDAh5Y1i2tUxg4EHrQAABh8"] [Sat Aug 29 05:06:56.149884 2026] [security2:error] [pid 1028675:tid 1028847] [client 74.7.228.38:39154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.thehsubox.com"] [uri "/robots.txt"] [unique_id "apK9UNdHPfW2QFvhmL7QtAAAJRk"] [Sat Aug 29 05:06:56.161066 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.196.209.81:17889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/headerg.php"] [unique_id "apK9UDAh5Y1i2tUxg4EHwgAABfY"] [Sat Aug 29 05:06:56.161526 2026] [security2:error] [pid 1028675:tid 1028896] [client 158.23.147.79:26604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9UNdHPfW2QFvhmL7QwgAAAFY"] [Sat Aug 29 05:06:56.184190 2026] [security2:error] [pid 1018003:tid 1018057] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EHywAF3CQ"] [Sat Aug 29 05:06:56.186571 2026] [core:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.186586 2026] [core:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.192016 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.192031 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.197985 2026] [core:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.197998 2026] [core:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.200465 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.200478 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.201161 2026] [core:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.201171 2026] [core:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.205589 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.205603 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.209164 2026] [core:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.209175 2026] [core:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.212091 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.212103 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.223119 2026] [security2:error] [pid 1028675:tid 1028843] [client 68.155.159.216:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/goods.php"] [unique_id "apK9UNdHPfW2QFvhmL7QzAAAACE"] [Sat Aug 29 05:06:56.231002 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.250.41:21446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/error_log.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH1QAABgY"] [Sat Aug 29 05:06:56.245183 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.245198 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.251644 2026] [security2:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/admin/phpinfo.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH2QAF3B4"] [Sat Aug 29 05:06:56.254448 2026] [security2:error] [pid 1028675:tid 1028890] [client 68.155.159.216:65139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/.well-known/index.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q0AAAAFA"] [Sat Aug 29 05:06:56.268304 2026] [security2:error] [pid 1018003:tid 1018152] [client 111.235.68.106:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH2wAABbk"] [Sat Aug 29 05:06:56.268410 2026] [security2:error] [pid 1018003:tid 1018152] [client 111.235.68.106:62087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH2wAABbk"] [Sat Aug 29 05:06:56.273895 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.23.147.79:50107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/file17.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH3QAABio"] [Sat Aug 29 05:06:56.275343 2026] [core:error] [pid 1018003:tid 1018038] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.275363 2026] [core:error] [pid 1018003:tid 1018038] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.277411 2026] [security2:error] [pid 1028675:tid 1028891] [client 158.23.147.79:24441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/bk/index.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q0gAAAFE"] [Sat Aug 29 05:06:56.280353 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.280382 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.282851 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.158.54.35:20604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/item.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH3wAABgI"] [Sat Aug 29 05:06:56.285257 2026] [security2:error] [pid 1018003:tid 1018075] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/admin_phpinfo.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH4QAF2zY"] [Sat Aug 29 05:06:56.289827 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.158.54.35:17793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/adminfuns.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH4wAABdg"] [Sat Aug 29 05:06:56.301317 2026] [security2:error] [pid 1028675:tid 1028894] [client 4.205.62.107:21596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/gnmlc.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q1gAAAFQ"] [Sat Aug 29 05:06:56.302632 2026] [security2:error] [pid 1028675:tid 1028931] [client 40.83.93.50:17313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/classsmtps.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q1wAAAHk"] [Sat Aug 29 05:06:56.310014 2026] [security2:error] [pid 1018003:tid 1018190] [client 158.23.147.79:62659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-l0gin.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH5gAABd8"] [Sat Aug 29 05:06:56.311081 2026] [security2:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EH5QAFukA"] [Sat Aug 29 05:06:56.318069 2026] [security2:error] [pid 1028675:tid 1028846] [client 74.7.175.137:47346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "scentsofmagic.store"] [uri "/robots.txt"] [unique_id "apK9UNdHPfW2QFvhmL7Q2AAAACQ"] [Sat Aug 29 05:06:56.319055 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.48.160.90:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH6AAABjM"] [Sat Aug 29 05:06:56.320619 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.320634 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.341158 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.52.41.200:1277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/gifclass.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH6wAABeM"] [Sat Aug 29 05:06:56.343642 2026] [security2:error] [pid 1018003:tid 1018238] [client 93.123.109.228:52512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EH7AAABg4"] [Sat Aug 29 05:06:56.349611 2026] [security2:error] [pid 1018003:tid 1018172] [client 93.123.109.228:52498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EH7QAABc0"] [Sat Aug 29 05:06:56.362547 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.48.250.41:21326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/403.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH7gAABcc"] [Sat Aug 29 05:06:56.364968 2026] [security2:error] [pid 1018003:tid 1018256] [client 93.123.109.228:52492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EH7wAABiA"] [Sat Aug 29 05:06:56.365559 2026] [security2:error] [pid 1028675:tid 1028910] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9UNdHPfW2QFvhmL7Q2gAAAGQ"] [Sat Aug 29 05:06:56.370566 2026] [security2:error] [pid 1028675:tid 1028905] [client 158.23.147.79:35721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/atomlib.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q2wAAAF8"] [Sat Aug 29 05:06:56.381096 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.147.79:30558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin.php"] [unique_id "apK9UDAh5Y1i2tUxg4EH8wAABhA"] [Sat Aug 29 05:06:56.381646 2026] [security2:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EH8gAF2i4"] [Sat Aug 29 05:06:56.382910 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.382921 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.382973 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.382983 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.384906 2026] [security2:error] [pid 1018003:tid 1018115] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EH9gAF2l4"] [Sat Aug 29 05:06:56.385001 2026] [security2:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EH9AAF2iM"] [Sat Aug 29 05:06:56.389000 2026] [security2:error] [pid 1018003:tid 1018160] [client 93.123.109.228:52456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EH-QAABcE"] [Sat Aug 29 05:06:56.389944 2026] [security2:error] [pid 1028675:tid 1028845] [client 168.107.94.195:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q3AAAACM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:56.391134 2026] [core:error] [pid 1018003:tid 1018089] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.391146 2026] [core:error] [pid 1018003:tid 1018089] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.412094 2026] [security2:error] [pid 1028675:tid 1028908] [client 20.151.200.44:64391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/xcre1.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q3QAAAGI"] [Sat Aug 29 05:06:56.446554 2026] [core:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.446572 2026] [core:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.448304 2026] [core:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.448315 2026] [core:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.449034 2026] [security2:error] [pid 1028675:tid 1028858] [client 74.7.175.137:47086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "scentsofmagic.store"] [uri "/robots.txt"] [unique_id "apK9UNdHPfW2QFvhmL7Q4QAAMBw"], referer: http://scentsofmagic.store/robots.txt [Sat Aug 29 05:06:56.452005 2026] [security2:error] [pid 1018003:tid 1018053] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/web.config"] [unique_id "apK9UDAh5Y1i2tUxg4EIBAAGNSA"] [Sat Aug 29 05:06:56.454650 2026] [security2:error] [pid 1018003:tid 1018236] [client 114.119.132.57:40249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_reviews_write.php/products_id/880/osCsid/98540975880f445559b164a4ef4b8d85"] [unique_id "apK9UDAh5Y1i2tUxg4EIBwAABgw"], referer: http://www.classiclightingusa.com/catalog/product_info.php/products_id/880/osCsid/98540975880f445559b164a4ef4b8d85 [Sat Aug 29 05:06:56.455916 2026] [core:error] [pid 1018003:tid 1018079] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.455929 2026] [core:error] [pid 1018003:tid 1018079] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.461689 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.461705 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.466476 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.196.209.81:22418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/pk.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q5AAAAA4"] [Sat Aug 29 05:06:56.474793 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.474808 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.500772 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.500791 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.511019 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.197.61.180:11600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/fi2.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIEAAABgE"] [Sat Aug 29 05:06:56.513973 2026] [security2:error] [pid 1028675:tid 1028811] [client 103.162.125.59:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q6AAAAAE"] [Sat Aug 29 05:06:56.514106 2026] [security2:error] [pid 1028675:tid 1028811] [client 103.162.125.59:55207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q6AAAAAE"] [Sat Aug 29 05:06:56.514237 2026] [security2:error] [pid 1018003:tid 1018099] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/api/info.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIEgAF2k4"] [Sat Aug 29 05:06:56.515257 2026] [security2:error] [pid 1028675:tid 1028930] [client 20.48.160.90:51273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/ser.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q6QAAAHg"] [Sat Aug 29 05:06:56.535173 2026] [security2:error] [pid 1018003:tid 1018156] [client 68.155.159.216:9310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/atomlib.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIFgAABb0"] [Sat Aug 29 05:06:56.540806 2026] [security2:error] [pid 1028675:tid 1028826] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9UNdHPfW2QFvhmL7Q7AAAABA"] [Sat Aug 29 05:06:56.541598 2026] [security2:error] [pid 1028675:tid 1028816] [client 20.48.250.41:21444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/cytyr.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q7QAAAAY"] [Sat Aug 29 05:06:56.543494 2026] [core:error] [pid 1018003:tid 1018105] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.543507 2026] [core:error] [pid 1018003:tid 1018105] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.548729 2026] [security2:error] [pid 1018003:tid 1018169] [client 93.123.109.228:52456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EIGQAABco"] [Sat Aug 29 05:06:56.548978 2026] [security2:error] [pid 1028675:tid 1028882] [client 74.7.175.137:47360] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "scentsofmagic.store"] [uri "/robots.txt"] [unique_id "apK9UNdHPfW2QFvhmL7Q7gAAAEg"] [Sat Aug 29 05:06:56.553628 2026] [security2:error] [pid 1018003:tid 1018191] [client 68.155.159.216:51679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-blog-header.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIGgAABeA"] [Sat Aug 29 05:06:56.559547 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.559563 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.560703 2026] [security2:error] [pid 1028675:tid 1028935] [client 93.123.109.228:52470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9UNdHPfW2QFvhmL7Q8QAAAH0"] [Sat Aug 29 05:06:56.561051 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.196.209.81:9769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/meta.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q8gAAAEY"] [Sat Aug 29 05:06:56.562393 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.562407 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.570756 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.570776 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.579989 2026] [security2:error] [pid 1018003:tid 1018243] [client 20.151.200.44:64387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/motu.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIHwAABhM"] [Sat Aug 29 05:06:56.582904 2026] [core:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.582920 2026] [core:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.587050 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.587066 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.588742 2026] [security2:error] [pid 1018003:tid 1018187] [client 68.155.159.216:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIIAAABdw"] [Sat Aug 29 05:06:56.594745 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.49.130:56226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/bthil.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q9QAAAEQ"] [Sat Aug 29 05:06:56.600119 2026] [security2:error] [pid 1018003:tid 1018152] [client 4.205.62.107:22147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/app_local.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIIQAABbk"] [Sat Aug 29 05:06:56.609140 2026] [core:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.609155 2026] [core:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.610376 2026] [security2:error] [pid 1028675:tid 1028861] [client 4.205.62.107:24976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ws79.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q-AAAADM"] [Sat Aug 29 05:06:56.613393 2026] [core:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.613408 2026] [core:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.614579 2026] [security2:error] [pid 1028675:tid 1028856] [client 158.23.147.79:32579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q-gAAAC4"] [Sat Aug 29 05:06:56.616366 2026] [security2:error] [pid 1018003:tid 1018118] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/api/phpinfo.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIJgAF2mE"] [Sat Aug 29 05:06:56.624882 2026] [security2:error] [pid 1018003:tid 1018183] [client 4.205.62.107:58385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/aww.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIJwAABdg"] [Sat Aug 29 05:06:56.629128 2026] [security2:error] [pid 1028675:tid 1028898] [client 4.205.62.107:8980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/register.php"] [unique_id "apK9UNdHPfW2QFvhmL7Q9gAAAFg"] [Sat Aug 29 05:06:56.643370 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.643390 2026] [core:error] [pid 1018003:tid 1018175] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.647246 2026] [security2:error] [pid 1018003:tid 1018189] [client 4.205.62.107:22297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/v2.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIMAAABd4"] [Sat Aug 29 05:06:56.647263 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:25493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIMQAABb4"] [Sat Aug 29 05:06:56.654663 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.654676 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.655706 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.655718 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.675914 2026] [security2:error] [pid 1028675:tid 1028903] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9UNdHPfW2QFvhmL7Q_wAAAF0"] [Sat Aug 29 05:06:56.676757 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.676773 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.678906 2026] [security2:error] [pid 1018003:tid 1018270] [client 74.7.175.137:47102] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "scentsofmagic.store"] [uri "/robots.txt"] [unique_id "apK9UDAh5Y1i2tUxg4EIOAAABi4"], referer: http://scentsofmagic.store/robots.txt [Sat Aug 29 05:06:56.692883 2026] [security2:error] [pid 1028675:tid 1028847] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9UNdHPfW2QFvhmL7RAgAAACU"] [Sat Aug 29 05:06:56.697134 2026] [security2:error] [pid 1018003:tid 1018161] [client 216.244.66.243:45872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scottportfolio.com"] [uri "/userfiles/akkumuliatornaia-vozdukhoduvka-sadovyi-pylesos-makita-dub185z.xml"] [unique_id "apK9UDAh5Y1i2tUxg4EIOwAABcI"] [Sat Aug 29 05:06:56.697232 2026] [security2:error] [pid 1018003:tid 1018161] [client 216.244.66.243:45872] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scottportfolio.com"] [uri "/userfiles/akkumuliatornaia-vozdukhoduvka-sadovyi-pylesos-makita-dub185z.xml"] [unique_id "apK9UDAh5Y1i2tUxg4EIOwAABcI"] [Sat Aug 29 05:06:56.700779 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.700795 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.702025 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.702040 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.713861 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.160.90:51266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/431.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIQQAABes"] [Sat Aug 29 05:06:56.720834 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.158.54.35:29649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/t.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIQwAABfw"] [Sat Aug 29 05:06:56.720994 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.250.41:21372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/galer.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIRAAABgw"] [Sat Aug 29 05:06:56.735377 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.735402 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.735988 2026] [security2:error] [pid 1028675:tid 1028885] [client 158.158.54.35:9791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/goods.php"] [unique_id "apK9UNdHPfW2QFvhmL7RCgAAAEs"] [Sat Aug 29 05:06:56.757619 2026] [security2:error] [pid 1028675:tid 1028915] [client 68.155.159.216:49206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9UNdHPfW2QFvhmL7RCwAAAGk"] [Sat Aug 29 05:06:56.760968 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.151.200.44:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/wefile.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIRgAABh8"] [Sat Aug 29 05:06:56.763353 2026] [security2:error] [pid 1018003:tid 1018224] [client 74.7.175.137:47372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "scentsofmagic.store"] [uri "/robots.txt"] [unique_id "apK9UDAh5Y1i2tUxg4EIRwAABgE"] [Sat Aug 29 05:06:56.771820 2026] [security2:error] [pid 1028675:tid 1028933] [client 168.107.94.195:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9UNdHPfW2QFvhmL7RDAAAAHs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:56.782088 2026] [security2:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EISwAF1Ds"] [Sat Aug 29 05:06:56.789352 2026] [security2:error] [pid 1028675:tid 1028871] [client 158.23.147.79:48241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9UNdHPfW2QFvhmL7RDwAAAD0"] [Sat Aug 29 05:06:56.796919 2026] [cgid:error] [pid 1018003:tid 1018167] [client 20.52.41.200:1772] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:06:56.812584 2026] [security2:error] [pid 1018003:tid 1018190] [client 40.83.93.50:7591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/contentloader1.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIUAAABd8"] [Sat Aug 29 05:06:56.814758 2026] [core:error] [pid 1028675:tid 1028928] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.814773 2026] [core:error] [pid 1028675:tid 1028928] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.825113 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.825129 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.833621 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.833636 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.837960 2026] [core:error] [pid 1018003:tid 1018230] [client 74.7.241.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.837973 2026] [core:error] [pid 1018003:tid 1018230] [client 74.7.241.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.838074 2026] [security2:error] [pid 1018003:tid 1018230] [client 74.7.241.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.hdfbookkeeping.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIWgAABgY"] [Sat Aug 29 05:06:56.838199 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.838209 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.839060 2026] [security2:error] [pid 1018003:tid 1018243] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EIXQAABhM"] [Sat Aug 29 05:06:56.849915 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:21466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/baixy.php"] [unique_id "apK9UNdHPfW2QFvhmL7RFwAAAHM"] [Sat Aug 29 05:06:56.851631 2026] [core:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.851643 2026] [core:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.856929 2026] [security2:error] [pid 1028675:tid 1028892] [client 74.7.241.152:40066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.hdfbookkeeping.com"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "apK9UNdHPfW2QFvhmL7REQAAUh0"] [Sat Aug 29 05:06:56.859879 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.859893 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.863182 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.196.209.81:17194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK9UNdHPfW2QFvhmL7RGQAAAE0"] [Sat Aug 29 05:06:56.863228 2026] [security2:error] [pid 1018003:tid 1018101] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9UDAh5Y1i2tUxg4EIZAAF1FA"] [Sat Aug 29 05:06:56.863350 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.863387 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.866016 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.866027 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.894934 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.151.200.44:65003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/EM.php"] [unique_id "apK9UNdHPfW2QFvhmL7RIgAAAHo"] [Sat Aug 29 05:06:56.895287 2026] [security2:error] [pid 1028675:tid 1028835] [client 74.7.175.137:47116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "scentsofmagic.store"] [uri "/robots.txt"] [unique_id "apK9UNdHPfW2QFvhmL7RIQAAABk"], referer: http://scentsofmagic.store/robots.txt [Sat Aug 29 05:06:56.902974 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.902988 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.914005 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.914026 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.914057 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.914067 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.932390 2026] [security2:error] [pid 1018003:tid 1018157] [client 68.155.159.216:64463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIcQAABb4"] [Sat Aug 29 05:06:56.947486 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.52.41.200:1772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIdQAABik"] [Sat Aug 29 05:06:56.970121 2026] [core:error] [pid 1028675:tid 1028919] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.970141 2026] [core:error] [pid 1028675:tid 1028919] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.973647 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.973667 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.977370 2026] [core:error] [pid 1028675:tid 1028867] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.977384 2026] [core:error] [pid 1028675:tid 1028867] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.977559 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.977569 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:56.981918 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.48.250.41:21350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ava.php"] [unique_id "apK9UNdHPfW2QFvhmL7RMgAAAGE"] [Sat Aug 29 05:06:56.989648 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.151.200.44:47366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/x23.php"] [unique_id "apK9UNdHPfW2QFvhmL7RNAAAAAs"] [Sat Aug 29 05:06:56.998902 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.48.160.90:51682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/rxr.php"] [unique_id "apK9UDAh5Y1i2tUxg4EIfwAABi4"] [Sat Aug 29 05:06:57.003543 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.003559 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.005311 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.196.209.81:17877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/dxc.php"] [unique_id "apK9UddHPfW2QFvhmL7RNwAAAG8"] [Sat Aug 29 05:06:57.009398 2026] [core:error] [pid 1028675:tid 1028901] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.009412 2026] [core:error] [pid 1028675:tid 1028901] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.011101 2026] [core:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.011114 2026] [core:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.024566 2026] [core:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.024584 2026] [core:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.026654 2026] [core:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.026672 2026] [core:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.039637 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.039665 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.041072 2026] [security2:error] [pid 1028675:tid 1028886] [client 68.155.159.216:2005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9UddHPfW2QFvhmL7RPQAAAEw"] [Sat Aug 29 05:06:57.043581 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.043597 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.061595 2026] [security2:error] [pid 1028675:tid 1028911] [client 20.104.49.130:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/wpxml.php"] [unique_id "apK9UddHPfW2QFvhmL7RQAAAAGU"] [Sat Aug 29 05:06:57.067376 2026] [core:error] [pid 1018003:tid 1018147] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.067391 2026] [core:error] [pid 1018003:tid 1018147] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.068732 2026] [security2:error] [pid 1028675:tid 1028849] [client 4.205.62.107:55961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/application.config.php"] [unique_id "apK9UddHPfW2QFvhmL7RQgAAACc"] [Sat Aug 29 05:06:57.072227 2026] [security2:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EIkAAF1GY"] [Sat Aug 29 05:06:57.091855 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.091874 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.097350 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.097352 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.097375 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.097380 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.106577 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.151.200.44:64388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/ca4.php"] [unique_id "apK9UddHPfW2QFvhmL7RRwAAAB8"] [Sat Aug 29 05:06:57.118756 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.23.147.79:17482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/dropdown.php"] [unique_id "apK9UTAh5Y1i2tUxg4EIlAAABjU"] [Sat Aug 29 05:06:57.152653 2026] [security2:error] [pid 1018003:tid 1018255] [client 168.107.94.195:50957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9UTAh5Y1i2tUxg4EIlgAABh8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:57.153080 2026] [security2:error] [pid 1018003:tid 1018159] [client 68.155.159.216:24478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9UTAh5Y1i2tUxg4EIlwAABcA"] [Sat Aug 29 05:06:57.160173 2026] [security2:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EImQAF4QA"] [Sat Aug 29 05:06:57.162383 2026] [core:error] [pid 1018003:tid 1018031] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.162392 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.162397 2026] [core:error] [pid 1018003:tid 1018031] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.162401 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.170772 2026] [security2:error] [pid 1028675:tid 1028856] [client 158.158.54.35:34251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/i.php"] [unique_id "apK9UddHPfW2QFvhmL7RSgAAAC4"] [Sat Aug 29 05:06:57.177270 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.48.250.41:21400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/gdn.php"] [unique_id "apK9UddHPfW2QFvhmL7RSwAAACI"] [Sat Aug 29 05:06:57.179767 2026] [security2:error] [pid 1028675:tid 1028854] [client 158.158.54.35:18122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/css.php"] [unique_id "apK9UddHPfW2QFvhmL7RTAAAACw"] [Sat Aug 29 05:06:57.188867 2026] [core:error] [pid 1018003:tid 1018103] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.188884 2026] [core:error] [pid 1018003:tid 1018103] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.193402 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.193416 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.194442 2026] [core:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.194458 2026] [core:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.217412 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.217439 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.217454 2026] [core:error] [pid 1018003:tid 1018054] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.217460 2026] [core:error] [pid 1018003:tid 1018054] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.222046 2026] [security2:error] [pid 1028675:tid 1028830] [client 68.155.159.216:38556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/file.php"] [unique_id "apK9UddHPfW2QFvhmL7RTgAAABQ"] [Sat Aug 29 05:06:57.222419 2026] [security2:error] [pid 1028675:tid 1028909] [client 68.155.159.216:33736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9UddHPfW2QFvhmL7RTwAAAGM"] [Sat Aug 29 05:06:57.252699 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.197.61.180:13846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/1p.php"] [unique_id "apK9UTAh5Y1i2tUxg4EIrgAABcc"] [Sat Aug 29 05:06:57.257020 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.49.130:58101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9UTAh5Y1i2tUxg4EIrwAABdg"] [Sat Aug 29 05:06:57.260093 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.196.209.81:15091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK9UddHPfW2QFvhmL7RUQAAAEs"] [Sat Aug 29 05:06:57.287009 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.151.200.44:65010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/x0x.php"] [unique_id "apK9UddHPfW2QFvhmL7RUwAAAHM"] [Sat Aug 29 05:06:57.302487 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.302509 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.304913 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.147.79:26529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9UTAh5Y1i2tUxg4EIvgAABdc"] [Sat Aug 29 05:06:57.307626 2026] [core:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.307644 2026] [core:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.308352 2026] [core:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.308381 2026] [core:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.342758 2026] [security2:error] [pid 1028675:tid 1028845] [client 68.155.159.216:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9UddHPfW2QFvhmL7RXQAAACM"] [Sat Aug 29 05:06:57.346266 2026] [security2:error] [pid 1028675:tid 1028890] [client 74.7.244.40:34136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.edward.chow-s.com"] [uri "/robots.txt"] [unique_id "apK9UddHPfW2QFvhmL7RWwAAUB4"] [Sat Aug 29 05:06:57.352599 2026] [security2:error] [pid 1018003:tid 1018185] [client 158.23.147.79:61568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/radio.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI0AAABdo"] [Sat Aug 29 05:06:57.353542 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.353558 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.353675 2026] [security2:error] [pid 1018003:tid 1018163] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.isasi.cloverleafsystems.com"] [uri "/cgi-sys/404.html"] [unique_id "apK9UTAh5Y1i2tUxg4EIzgAABcQ"] [Sat Aug 29 05:06:57.354151 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.354162 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.357469 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.357491 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.358766 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.48.250.41:21454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/f2.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI0gAABiA"] [Sat Aug 29 05:06:57.360389 2026] [security2:error] [pid 1018003:tid 1018187] [client 74.7.228.2:46792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.isasi.cloverleafsystems.com"] [uri "/robots.txt"] [unique_id "apK9UTAh5Y1i2tUxg4EIxAAF3E8"] [Sat Aug 29 05:06:57.361167 2026] [security2:error] [pid 1028675:tid 1028936] [client 68.155.159.216:65024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9UddHPfW2QFvhmL7RYQAAAH4"] [Sat Aug 29 05:06:57.363060 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.363080 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.375020 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.375042 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.375924 2026] [core:error] [pid 1018003:tid 1018028] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.375938 2026] [core:error] [pid 1018003:tid 1018028] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.377530 2026] [security2:error] [pid 1028675:tid 1028881] [client 158.23.147.79:49840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/file5.php"] [unique_id "apK9UddHPfW2QFvhmL7RZAAAAEc"] [Sat Aug 29 05:06:57.378738 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.378752 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.380603 2026] [security2:error] [pid 1018003:tid 1018236] [client 158.23.147.79:24480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/first.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI2AAABgw"] [Sat Aug 29 05:06:57.381562 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.48.160.90:51307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/csst.php"] [unique_id "apK9UddHPfW2QFvhmL7RZQAAAHE"] [Sat Aug 29 05:06:57.397779 2026] [security2:error] [pid 1018003:tid 1018206] [client 93.123.109.228:52456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EI2gAABe8"] [Sat Aug 29 05:06:57.404086 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.52.41.200:1778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/css/index.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI2wAABfY"] [Sat Aug 29 05:06:57.408523 2026] [security2:error] [pid 1028675:tid 1028816] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9UddHPfW2QFvhmL7RZgAAAAY"] [Sat Aug 29 05:06:57.415215 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.196.209.81:9411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/wp-2019.php"] [unique_id "apK9UddHPfW2QFvhmL7RZwAAAGs"] [Sat Aug 29 05:06:57.431009 2026] [security2:error] [pid 1028675:tid 1028935] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9UddHPfW2QFvhmL7RaAAAAH0"] [Sat Aug 29 05:06:57.434283 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.151.200.44:64971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kozo.com.mx"] [uri "/fesa.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI3QAABfA"] [Sat Aug 29 05:06:57.440964 2026] [security2:error] [pid 1028675:tid 1028880] [client 4.205.62.107:22413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/koiy.php"] [unique_id "apK9UddHPfW2QFvhmL7RaQAAAEY"] [Sat Aug 29 05:06:57.451924 2026] [security2:error] [pid 1018003:tid 1018191] [client 40.83.93.50:17314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/al.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI4QAABeA"] [Sat Aug 29 05:06:57.463751 2026] [security2:error] [pid 1028675:tid 1028905] [client 127.0.0.1:28410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "apK9UddHPfW2QFvhmL7RYwAAAF8"] [Sat Aug 29 05:06:57.463807 2026] [security2:error] [pid 1028675:tid 1028833] [client 74.7.244.4:38834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.glow.clothing"] [uri "/robots.txt"] [unique_id "apK9UddHPfW2QFvhmL7RYgAAFx8"] [Sat Aug 29 05:06:57.464325 2026] [security2:error] [pid 1028675:tid 1028826] [client 93.123.109.228:52468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9UddHPfW2QFvhmL7RbAAAABA"] [Sat Aug 29 05:06:57.469024 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.469040 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.471974 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.471992 2026] [core:error] [pid 1018003:tid 1018186] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.476995 2026] [security2:error] [pid 1018003:tid 1018234] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EI6wAABgo"] [Sat Aug 29 05:06:57.478666 2026] [core:error] [pid 1028675:tid 1028814] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.478688 2026] [core:error] [pid 1028675:tid 1028814] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.484464 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:30654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI7AAABgc"] [Sat Aug 29 05:06:57.493693 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.147.79:35831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/lv.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI7gAABgI"] [Sat Aug 29 05:06:57.497216 2026] [security2:error] [pid 1028675:tid 1028829] [client 68.155.159.216:12126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-blog-header.php"] [unique_id "apK9UddHPfW2QFvhmL7RcQAAABM"] [Sat Aug 29 05:06:57.498597 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.498611 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.499034 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.499045 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.500806 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:51555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/nf_tracking.php"] [unique_id "apK9UTAh5Y1i2tUxg4EI8gAABgk"] [Sat Aug 29 05:06:57.502678 2026] [core:error] [pid 1028675:tid 1028907] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.502693 2026] [core:error] [pid 1028675:tid 1028907] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.504180 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.504192 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.504556 2026] [security2:error] [pid 1028675:tid 1028820] [client 93.123.109.228:52470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9UddHPfW2QFvhmL7RdQAAAAo"] [Sat Aug 29 05:06:57.509934 2026] [security2:error] [pid 1028675:tid 1028896] [client 93.123.109.228:52412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9UddHPfW2QFvhmL7RdgAAAFY"] [Sat Aug 29 05:06:57.521674 2026] [core:error] [pid 1018003:tid 1018115] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.521689 2026] [core:error] [pid 1018003:tid 1018115] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.523169 2026] [security2:error] [pid 1018003:tid 1018153] [client 93.123.109.228:52476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EI_gAABbo"] [Sat Aug 29 05:06:57.526487 2026] [security2:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EI_wAF_iM"] [Sat Aug 29 05:06:57.526753 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.48.250.41:21432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/grsiuk.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJAAAABdI"] [Sat Aug 29 05:06:57.532932 2026] [security2:error] [pid 1028675:tid 1028839] [client 168.107.94.195:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9UddHPfW2QFvhmL7RegAAAB0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:57.535484 2026] [security2:error] [pid 1028675:tid 1028821] [client 74.7.228.28:56394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ccfinancialaccounting.com"] [uri "/robots.txt"] [unique_id "apK9UddHPfW2QFvhmL7ReQAACyA"] [Sat Aug 29 05:06:57.537344 2026] [security2:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJBAAF_ls"] [Sat Aug 29 05:06:57.538148 2026] [security2:error] [pid 1018003:tid 1018104] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJBQAF_lM"] [Sat Aug 29 05:06:57.538155 2026] [security2:error] [pid 1018003:tid 1018081] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJBgAF_jw"] [Sat Aug 29 05:06:57.538660 2026] [security2:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJBwAF_iA"] [Sat Aug 29 05:06:57.539568 2026] [core:error] [pid 1028675:tid 1028875] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.539581 2026] [core:error] [pid 1028675:tid 1028875] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.555908 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.555929 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.573299 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.573317 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.580420 2026] [security2:error] [pid 1028675:tid 1028838] [client 127.0.0.1:28430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kingcoqui.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "apK9UddHPfW2QFvhmL7RcgAAABw"] [Sat Aug 29 05:06:57.580429 2026] [security2:error] [pid 1028675:tid 1028888] [client 127.0.0.1:28442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "apK9UddHPfW2QFvhmL7RdAAAAE4"] [Sat Aug 29 05:06:57.580489 2026] [security2:error] [pid 1018003:tid 1018167] [client 74.7.244.34:45588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kingcoqui.com"] [uri "/robots.txt"] [unique_id "apK9UTAh5Y1i2tUxg4EI8AAFyBE"] [Sat Aug 29 05:06:57.614773 2026] [security2:error] [pid 1028675:tid 1028904] [client 158.158.54.35:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/deepseek_d.php"] [unique_id "apK9UddHPfW2QFvhmL7RfgAAAF4"] [Sat Aug 29 05:06:57.639003 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.48.160.90:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apK9UddHPfW2QFvhmL7RgQAAAEk"] [Sat Aug 29 05:06:57.639545 2026] [security2:error] [pid 1028675:tid 1028929] [client 68.155.159.216:52794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/lv.php"] [unique_id "apK9UddHPfW2QFvhmL7RggAAAHc"] [Sat Aug 29 05:06:57.665094 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.196.209.81:17186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/security.php"] [unique_id "apK9UddHPfW2QFvhmL7RhAAAACY"] [Sat Aug 29 05:06:57.672591 2026] [security2:error] [pid 1018003:tid 1018277] [client 68.155.159.216:51471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJFgAABjU"] [Sat Aug 29 05:06:57.689873 2026] [security2:error] [pid 1028675:tid 1028899] [client 68.155.159.216:50355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9UddHPfW2QFvhmL7RhgAAAFk"] [Sat Aug 29 05:06:57.694202 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.48.250.41:21356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wp-scr1pts.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJHQAABeA"] [Sat Aug 29 05:06:57.732177 2026] [security2:error] [pid 1028675:tid 1028891] [client 93.123.109.228:52470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9UddHPfW2QFvhmL7RiQAAAFE"] [Sat Aug 29 05:06:57.733457 2026] [security2:error] [pid 1028675:tid 1028865] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9UddHPfW2QFvhmL7RigAAADc"] [Sat Aug 29 05:06:57.733592 2026] [security2:error] [pid 1018003:tid 1018172] [client 93.123.109.228:52512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9UTAh5Y1i2tUxg4EJIQAABc0"] [Sat Aug 29 05:06:57.743776 2026] [security2:error] [pid 1018003:tid 1018099] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJIgAF1U4"] [Sat Aug 29 05:06:57.746291 2026] [security2:error] [pid 1018003:tid 1018183] [client 4.205.62.107:22023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/xqq.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJIwAABdg"] [Sat Aug 29 05:06:57.750146 2026] [security2:error] [pid 1018003:tid 1018275] [client 93.123.109.228:52456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJJAAABjM"] [Sat Aug 29 05:06:57.755588 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:25420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/about.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJJQAABb4"] [Sat Aug 29 05:06:57.755591 2026] [security2:error] [pid 1028675:tid 1028846] [client 4.205.62.107:65458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/public/wp-blog.php"] [unique_id "apK9UddHPfW2QFvhmL7RjwAAACQ"] [Sat Aug 29 05:06:57.760909 2026] [security2:error] [pid 1028675:tid 1028858] [client 4.205.62.107:58386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/ty.php"] [unique_id "apK9UddHPfW2QFvhmL7RkAAAADA"] [Sat Aug 29 05:06:57.769435 2026] [security2:error] [pid 1018003:tid 1018175] [client 158.23.147.79:32729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJKQAABdA"] [Sat Aug 29 05:06:57.786554 2026] [security2:error] [pid 1018003:tid 1018152] [client 4.205.62.107:22401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/cli_bootstrap.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJKwAABbk"] [Sat Aug 29 05:06:57.790476 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.790496 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.797025 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.151.200.44:47321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/ws66.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJLAAABbo"] [Sat Aug 29 05:06:57.817093 2026] [core:error] [pid 1028675:tid 1028908] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.817109 2026] [core:error] [pid 1028675:tid 1028908] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.818972 2026] [core:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.818991 2026] [core:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.820521 2026] [security2:error] [pid 1028675:tid 1028870] [client 213.202.253.4:65392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/filefuns.php"] [unique_id "apK9UddHPfW2QFvhmL7RlAAAADw"], referer: www.google.com [Sat Aug 29 05:06:57.822347 2026] [core:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.822374 2026] [core:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.823712 2026] [core:error] [pid 1018003:tid 1018118] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.823725 2026] [core:error] [pid 1018003:tid 1018118] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.824212 2026] [core:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.824225 2026] [core:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.824808 2026] [core:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.824820 2026] [core:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.824911 2026] [core:error] [pid 1018003:tid 1018097] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.824916 2026] [core:error] [pid 1018003:tid 1018097] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.829180 2026] [core:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.829191 2026] [core:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.832227 2026] [security2:error] [pid 1018003:tid 1018258] [client 93.123.109.228:52516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJOgAABiI"] [Sat Aug 29 05:06:57.836046 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.196.209.81:9437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/menu.php"] [unique_id "apK9UddHPfW2QFvhmL7RlQAAADU"] [Sat Aug 29 05:06:57.837180 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.48.160.90:51669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apK9UddHPfW2QFvhmL7RlgAAAHs"] [Sat Aug 29 05:06:57.840089 2026] [security2:error] [pid 1018003:tid 1018271] [client 4.205.62.107:53366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/php-info.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJOwAABi8"] [Sat Aug 29 05:06:57.847949 2026] [security2:error] [pid 1018003:tid 1018066] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJPAAFxC0"] [Sat Aug 29 05:06:57.847973 2026] [security2:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJPgAFxCU"] [Sat Aug 29 05:06:57.849338 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:52476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJQQAABdw"] [Sat Aug 29 05:06:57.849377 2026] [core:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.849388 2026] [core:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.851990 2026] [core:error] [pid 1018003:tid 1018113] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.852000 2026] [core:error] [pid 1018003:tid 1018113] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.856209 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.52.41.200:1271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-cron.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJQgAABds"] [Sat Aug 29 05:06:57.872934 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.250.41:21378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/num.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJQwAABeU"] [Sat Aug 29 05:06:57.880812 2026] [security2:error] [pid 1028675:tid 1028857] [client 34.7.40.70:44868] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/credentials.js"] [unique_id "apK9UddHPfW2QFvhmL7RnAAAAC8"] [Sat Aug 29 05:06:57.881479 2026] [cgid:error] [pid 1018003:tid 1018190] [client 34.7.40.70:44978] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.885526 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.104.49.130:46529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/crgio.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJRwAABdo"] [Sat Aug 29 05:06:57.886076 2026] [cgid:error] [pid 1028675:tid 1028925] [client 34.7.40.70:44950] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.886820 2026] [cgid:error] [pid 1028675:tid 1028885] [client 34.7.40.70:44890] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.888403 2026] [cgid:error] [pid 1028675:tid 1028909] [client 34.7.40.70:44876] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.888428 2026] [cgid:error] [pid 1028675:tid 1028931] [client 34.7.40.70:44854] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.888428 2026] [cgid:error] [pid 1028675:tid 1028843] [client 34.7.40.70:44912] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.888541 2026] [security2:error] [pid 1028675:tid 1028931] [client 34.7.40.70:44854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9UddHPfW2QFvhmL7RoQAAAHk"] [Sat Aug 29 05:06:57.888541 2026] [security2:error] [pid 1028675:tid 1028843] [client 34.7.40.70:44912] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9UddHPfW2QFvhmL7RoAAAACE"] [Sat Aug 29 05:06:57.889289 2026] [cgid:error] [pid 1018003:tid 1018261] [client 34.7.40.70:44838] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.905165 2026] [core:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.905175 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.905186 2026] [core:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.905197 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.921058 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:48130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/themes/index.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJTwAABc8"] [Sat Aug 29 05:06:57.921803 2026] [security2:error] [pid 1028675:tid 1028833] [client 158.158.54.35:38448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/w.php"] [unique_id "apK9UddHPfW2QFvhmL7RowAAABc"] [Sat Aug 29 05:06:57.922672 2026] [security2:error] [pid 1028675:tid 1028826] [client 168.107.94.195:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9UddHPfW2QFvhmL7RpAAAABA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:57.928615 2026] [security2:error] [pid 1028675:tid 1028893] [client 34.7.40.70:44964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/telescope/requests"] [unique_id "apK9UddHPfW2QFvhmL7RpgAAAFM"] [Sat Aug 29 05:06:57.930495 2026] [security2:error] [pid 1018003:tid 1018172] [client 34.7.40.70:44952] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/api/v2/settings"] [unique_id "apK9UTAh5Y1i2tUxg4EJVQAABc0"] [Sat Aug 29 05:06:57.931832 2026] [security2:error] [pid 1018003:tid 1018244] [client 34.7.40.70:45040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.aider.conf.yml"] [unique_id "apK9UTAh5Y1i2tUxg4EJVwAABhQ"] [Sat Aug 29 05:06:57.933069 2026] [security2:error] [pid 1018003:tid 1018212] [client 34.7.40.70:45118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.aws/credentials.old"] [unique_id "apK9UTAh5Y1i2tUxg4EJUAAABfU"] [Sat Aug 29 05:06:57.934862 2026] [cgid:error] [pid 1018003:tid 1018224] [client 34.7.40.70:45098] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.934902 2026] [cgid:error] [pid 1028675:tid 1028884] [client 34.7.40.70:45020] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.934924 2026] [cgid:error] [pid 1018003:tid 1018225] [client 34.7.40.70:44970] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.935554 2026] [security2:error] [pid 1028675:tid 1028887] [client 34.7.40.70:45096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/aws/.env"] [unique_id "apK9UddHPfW2QFvhmL7RqQAAAE0"] [Sat Aug 29 05:06:57.936089 2026] [cgid:error] [pid 1028675:tid 1028855] [client 34.7.40.70:45030] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.936924 2026] [cgid:error] [pid 1018003:tid 1018231] [client 34.7.40.70:44948] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.937528 2026] [cgid:error] [pid 1028675:tid 1028890] [client 34.7.40.70:45006] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.938894 2026] [cgid:error] [pid 1018003:tid 1018266] [client 34.7.40.70:45048] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.941011 2026] [cgid:error] [pid 1028675:tid 1028845] [client 34.7.40.70:45062] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.941704 2026] [cgid:error] [pid 1028675:tid 1028892] [client 34.7.40.70:44906] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.941926 2026] [cgid:error] [pid 1018003:tid 1018200] [client 34.7.40.70:45082] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.943368 2026] [cgid:error] [pid 1018003:tid 1018156] [client 34.7.40.70:44980] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.945621 2026] [cgid:error] [pid 1018003:tid 1018203] [client 34.7.40.70:44998] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.947700 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.947721 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.950271 2026] [security2:error] [pid 1018003:tid 1018233] [client 34.7.40.70:45104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/.aws/credentials.bak"] [unique_id "apK9UTAh5Y1i2tUxg4EJXgAABgk"] [Sat Aug 29 05:06:57.951283 2026] [cgid:error] [pid 1018003:tid 1018166] [client 34.7.40.70:45070] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.954944 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.49.130:53843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/log.php"] [unique_id "apK9UTAh5Y1i2tUxg4EJYQAABgM"] [Sat Aug 29 05:06:57.968366 2026] [security2:error] [pid 1028675:tid 1028840] [client 34.7.40.70:45068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.40.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/config/aws.php"] [unique_id "apK9UddHPfW2QFvhmL7RsgAAAB4"] [Sat Aug 29 05:06:57.969693 2026] [cgid:error] [pid 1028675:tid 1028932] [client 34.7.40.70:45050] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.969716 2026] [cgid:error] [pid 1018003:tid 1018246] [client 34.7.40.70:44932] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.971269 2026] [cgid:error] [pid 1018003:tid 1018198] [client 34.7.40.70:44922] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.972403 2026] [cgid:error] [pid 1028675:tid 1028910] [client 34.7.40.70:45086] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:06:57.977117 2026] [security2:error] [pid 1018003:tid 1018101] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJawAGMVA"] [Sat Aug 29 05:06:57.982903 2026] [security2:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJbgAGMWk"] [Sat Aug 29 05:06:57.984240 2026] [core:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.984260 2026] [core:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:57.984651 2026] [security2:error] [pid 1018003:tid 1018234] [client 93.123.109.228:52498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJcwAABgo"] [Sat Aug 29 05:06:57.988707 2026] [security2:error] [pid 1018003:tid 1018175] [client 93.123.109.228:52516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9UTAh5Y1i2tUxg4EJdwAABdA"] [Sat Aug 29 05:06:58.001121 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.001138 2026] [core:error] [pid 1018003:tid 1018230] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.003010 2026] [core:error] [pid 1028675:tid 1028898] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.003025 2026] [core:error] [pid 1028675:tid 1028898] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.007106 2026] [security2:error] [pid 1018003:tid 1018152] [client 93.123.109.228:52476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJeQAABbk"] [Sat Aug 29 05:06:58.016162 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.016180 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.016285 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.016299 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.019579 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.019593 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.020700 2026] [core:error] [pid 1028675:tid 1028924] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.020715 2026] [core:error] [pid 1028675:tid 1028924] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.026673 2026] [core:error] [pid 1018003:tid 1018098] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.026687 2026] [core:error] [pid 1018003:tid 1018098] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.031563 2026] [security2:error] [pid 1028675:tid 1028896] [client 20.48.250.41:21423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/a4.php"] [unique_id "apK9UtdHPfW2QFvhmL7RvAAAAFY"] [Sat Aug 29 05:06:58.043337 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.48.160.90:51665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9UtdHPfW2QFvhmL7RvwAAAAs"] [Sat Aug 29 05:06:58.044871 2026] [security2:error] [pid 1028675:tid 1028935] [client 40.83.93.50:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/global.php"] [unique_id "apK9UtdHPfW2QFvhmL7RwAAAAH0"] [Sat Aug 29 05:06:58.052602 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.052621 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.058966 2026] [security2:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJgQAGMTQ"] [Sat Aug 29 05:06:58.062276 2026] [core:error] [pid 1018003:tid 1018109] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.062290 2026] [core:error] [pid 1018003:tid 1018109] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.066443 2026] [core:error] [pid 1028675:tid 1028927] [client 158.158.54.35:24943] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.066464 2026] [core:error] [pid 1028675:tid 1028927] [client 158.158.54.35:24943] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.076985 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.196.209.81:15504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJgwAABi4"] [Sat Aug 29 05:06:58.088740 2026] [security2:error] [pid 1018003:tid 1018212] [client 93.123.109.228:52420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJhgAABfU"] [Sat Aug 29 05:06:58.103784 2026] [security2:error] [pid 1028675:tid 1028897] [client 68.155.159.216:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9UtdHPfW2QFvhmL7RwwAAAFc"] [Sat Aug 29 05:06:58.109339 2026] [security2:error] [pid 1028675:tid 1028882] [client 20.197.61.180:8907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/Njima.php"] [unique_id "apK9UtdHPfW2QFvhmL7RxAAAAEg"] [Sat Aug 29 05:06:58.113515 2026] [security2:error] [pid 1018003:tid 1018224] [client 93.123.109.228:52456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJhwAABgE"] [Sat Aug 29 05:06:58.133406 2026] [security2:error] [pid 1018003:tid 1018119] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/app/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJjgAF5GI"] [Sat Aug 29 05:06:58.142772 2026] [security2:error] [pid 1018003:tid 1018179] [client 93.123.109.228:52506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJkgAABdQ"] [Sat Aug 29 05:06:58.149508 2026] [security2:error] [pid 1018003:tid 1018120] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/src/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJlgAF5GM"] [Sat Aug 29 05:06:58.166048 2026] [security2:error] [pid 1018003:tid 1018250] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJmAAABho"] [Sat Aug 29 05:06:58.171147 2026] [security2:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJmgAGAmg"] [Sat Aug 29 05:06:58.171210 2026] [security2:error] [pid 1028675:tid 1028856] [client 93.123.109.228:52428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9UtdHPfW2QFvhmL7RygAAAC4"] [Sat Aug 29 05:06:58.172310 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.172331 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.173483 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.173499 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.173754 2026] [core:error] [pid 1028675:tid 1028825] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.173763 2026] [core:error] [pid 1028675:tid 1028825] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.173874 2026] [core:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.173887 2026] [core:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.174161 2026] [security2:error] [pid 1018003:tid 1018255] [client 93.123.109.228:52476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJnQAABh8"] [Sat Aug 29 05:06:58.176165 2026] [security2:error] [pid 1018003:tid 1018191] [client 93.123.109.228:52548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJngAABeA"] [Sat Aug 29 05:06:58.176350 2026] [core:error] [pid 1028675:tid 1028915] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.176371 2026] [core:error] [pid 1028675:tid 1028915] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.176772 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.176781 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.177735 2026] [security2:error] [pid 1028675:tid 1028916] [client 93.123.109.228:52412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9UtdHPfW2QFvhmL7RzQAAAGo"] [Sat Aug 29 05:06:58.190598 2026] [security2:error] [pid 1018003:tid 1018169] [client 93.123.109.228:52492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJogAABco"] [Sat Aug 29 05:06:58.195319 2026] [core:error] [pid 1028675:tid 1028902] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.195332 2026] [core:error] [pid 1028675:tid 1028902] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.202535 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.250.41:21427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/tfm.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJpAAABis"] [Sat Aug 29 05:06:58.203551 2026] [core:error] [pid 1028675:tid 1028835] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.203565 2026] [core:error] [pid 1028675:tid 1028835] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.212040 2026] [core:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.212058 2026] [core:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.213280 2026] [security2:error] [pid 1018003:tid 1018147] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/config.inc.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJpwAGAn4"] [Sat Aug 29 05:06:58.213349 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.151.200.44:47341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/Cok.php"] [unique_id "apK9UtdHPfW2QFvhmL7R0wAAAGw"] [Sat Aug 29 05:06:58.217819 2026] [security2:error] [pid 1028675:tid 1028908] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9UtdHPfW2QFvhmL7R1QAAAGI"] [Sat Aug 29 05:06:58.219962 2026] [security2:error] [pid 1028675:tid 1028822] [client 4.205.62.107:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/xp.php"] [unique_id "apK9UtdHPfW2QFvhmL7R1gAAAAw"] [Sat Aug 29 05:06:58.220803 2026] [core:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.220817 2026] [core:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.221554 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.147.79:17419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/.well-known/index.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJqwAABgY"] [Sat Aug 29 05:06:58.229266 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.49.130:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/simple.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJrQAABf8"] [Sat Aug 29 05:06:58.235299 2026] [security2:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/aws.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJrwAGAnk"] [Sat Aug 29 05:06:58.238283 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.196.209.81:17905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/alfa.php"] [unique_id "apK9UtdHPfW2QFvhmL7R2QAAACg"] [Sat Aug 29 05:06:58.248553 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.248570 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.249663 2026] [core:error] [pid 1028675:tid 1028863] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.249680 2026] [core:error] [pid 1028675:tid 1028863] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.256961 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.256976 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.259585 2026] [security2:error] [pid 1028675:tid 1028857] [client 68.155.159.216:24556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/content.php"] [unique_id "apK9UtdHPfW2QFvhmL7R3AAAAC8"] [Sat Aug 29 05:06:58.267002 2026] [security2:error] [pid 1018003:tid 1018189] [client 93.123.109.228:52456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJswAABd4"] [Sat Aug 29 05:06:58.298240 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.48.160.90:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/haxor.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJtAAABhA"] [Sat Aug 29 05:06:58.304230 2026] [security2:error] [pid 1018003:tid 1018217] [client 168.107.94.195:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJtgAABfo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:58.305554 2026] [security2:error] [pid 1028675:tid 1028880] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9UtdHPfW2QFvhmL7R3gAAAEY"] [Sat Aug 29 05:06:58.318013 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.52.41.200:1160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-block.php"] [unique_id "apK9UtdHPfW2QFvhmL7R3wAAAFk"] [Sat Aug 29 05:06:58.325384 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.325413 2026] [core:error] [pid 1018003:tid 1018031] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.325414 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.325431 2026] [core:error] [pid 1018003:tid 1018031] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.328275 2026] [security2:error] [pid 1018003:tid 1018186] [client 68.155.159.216:38551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/file17.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJvAAABds"] [Sat Aug 29 05:06:58.330610 2026] [security2:error] [pid 1028675:tid 1028917] [client 68.155.159.216:33765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/dropdown.php"] [unique_id "apK9UtdHPfW2QFvhmL7R4gAAAGs"] [Sat Aug 29 05:06:58.346070 2026] [security2:error] [pid 1028675:tid 1028893] [client 20.48.250.41:21480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/Geforce.php"] [unique_id "apK9UtdHPfW2QFvhmL7R5AAAAFM"] [Sat Aug 29 05:06:58.368477 2026] [security2:error] [pid 1018003:tid 1018036] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/frontend/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJvwAF5A8"] [Sat Aug 29 05:06:58.369201 2026] [security2:error] [pid 1028675:tid 1028872] [client 158.158.54.35:7324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/ahax.php"] [unique_id "apK9UtdHPfW2QFvhmL7R5gAAAD4"] [Sat Aug 29 05:06:58.379157 2026] [core:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.379173 2026] [core:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.379500 2026] [core:error] [pid 1018003:tid 1018026] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.379510 2026] [core:error] [pid 1018003:tid 1018026] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.381692 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.104.49.130:60799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/ty.php"] [unique_id "apK9UtdHPfW2QFvhmL7R6AAAACM"] [Sat Aug 29 05:06:58.392551 2026] [core:error] [pid 1018003:tid 1018032] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.392568 2026] [core:error] [pid 1018003:tid 1018032] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.444018 2026] [security2:error] [pid 1028675:tid 1028910] [client 68.155.159.216:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9UtdHPfW2QFvhmL7R6gAAAGQ"] [Sat Aug 29 05:06:58.445131 2026] [security2:error] [pid 1018003:tid 1018124] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/server/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJxwAF5Gc"] [Sat Aug 29 05:06:58.446644 2026] [security2:error] [pid 1018003:tid 1018068] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/production/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJyAAF5C8"] [Sat Aug 29 05:06:58.450511 2026] [security2:error] [pid 1018003:tid 1018145] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/dev/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJygAF5Hw"] [Sat Aug 29 05:06:58.453970 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.160.90:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/google.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJywAABfU"] [Sat Aug 29 05:06:58.459225 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.23.147.79:26405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJzAAABgE"] [Sat Aug 29 05:06:58.467675 2026] [security2:error] [pid 1028675:tid 1028930] [client 68.155.159.216:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/radio.php"] [unique_id "apK9UtdHPfW2QFvhmL7R7AAAAHg"] [Sat Aug 29 05:06:58.471405 2026] [security2:error] [pid 1018003:tid 1018103] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/config.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJzgAF2VI"] [Sat Aug 29 05:06:58.474526 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.196.209.81:5880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/system.php"] [unique_id "apK9UtdHPfW2QFvhmL7R7gAAAG4"] [Sat Aug 29 05:06:58.476774 2026] [security2:error] [pid 1028675:tid 1028829] [client 20.48.250.41:21419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/click.php"] [unique_id "apK9UtdHPfW2QFvhmL7R7wAAABM"] [Sat Aug 29 05:06:58.502124 2026] [security2:error] [pid 1018003:tid 1018157] [client 87.219.197.128:61166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ0QAABb4"] [Sat Aug 29 05:06:58.502259 2026] [security2:error] [pid 1018003:tid 1018157] [client 87.219.197.128:61166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ0QAABb4"] [Sat Aug 29 05:06:58.506684 2026] [security2:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/env.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ0gAF_gw"] [Sat Aug 29 05:06:58.511503 2026] [core:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.511521 2026] [core:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.513213 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.158.54.35:29689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "apK9UtdHPfW2QFvhmL7R8wAAAEo"] [Sat Aug 29 05:06:58.514868 2026] [security2:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/nexmo.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ1wAF_hk"] [Sat Aug 29 05:06:58.518314 2026] [security2:error] [pid 1018003:tid 1018035] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/module.config.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ2gAF_g4"] [Sat Aug 29 05:06:58.519580 2026] [security2:error] [pid 1028675:tid 1028821] [client 158.23.147.79:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/file88.php"] [unique_id "apK9UtdHPfW2QFvhmL7R9gAAAAs"] [Sat Aug 29 05:06:58.528198 2026] [core:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.528217 2026] [core:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.529780 2026] [core:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.529797 2026] [core:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.535213 2026] [core:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.535230 2026] [core:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.536563 2026] [core:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.536579 2026] [core:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.541316 2026] [core:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.541331 2026] [core:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.548198 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.548214 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.551843 2026] [security2:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/stripe.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ5QAF_h8"] [Sat Aug 29 05:06:58.553908 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.553927 2026] [core:error] [pid 1018003:tid 1018239] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.556860 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.556875 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.570861 2026] [core:error] [pid 1028675:tid 1028913] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.570878 2026] [core:error] [pid 1028675:tid 1028913] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.576073 2026] [security2:error] [pid 1028675:tid 1028907] [client 4.205.62.107:22432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/w.php"] [unique_id "apK9UtdHPfW2QFvhmL7SAAAAAGE"] [Sat Aug 29 05:06:58.578854 2026] [security2:error] [pid 1018003:tid 1018174] [client 40.83.93.50:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/update.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ5gAABc8"] [Sat Aug 29 05:06:58.580136 2026] [security2:error] [pid 1018003:tid 1018252] [client 93.123.109.228:52548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJ5wAABhw"] [Sat Aug 29 05:06:58.585939 2026] [core:error] [pid 1028675:tid 1028888] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.585957 2026] [core:error] [pid 1028675:tid 1028888] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.589530 2026] [security2:error] [pid 1028675:tid 1028921] [client 68.155.159.216:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9UtdHPfW2QFvhmL7SAgAAAG8"] [Sat Aug 29 05:06:58.600252 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.147.79:35782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ6QAABgo"] [Sat Aug 29 05:06:58.614013 2026] [security2:error] [pid 1028675:tid 1028922] [client 93.123.109.228:52470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9UtdHPfW2QFvhmL7SAwAAAHA"] [Sat Aug 29 05:06:58.621383 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:12251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ7AAABco"] [Sat Aug 29 05:06:58.630583 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.48.250.41:21459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ms.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ7QAABis"] [Sat Aug 29 05:06:58.632181 2026] [security2:error] [pid 1028675:tid 1028916] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9UtdHPfW2QFvhmL7SBAAAAGo"] [Sat Aug 29 05:06:58.639770 2026] [security2:error] [pid 1018003:tid 1018222] [client 93.123.109.228:52506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJ7gAABf8"] [Sat Aug 29 05:06:58.659559 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.196.209.81:9775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK9UtdHPfW2QFvhmL7SBwAAAEE"] [Sat Aug 29 05:06:58.662472 2026] [core:error] [pid 1018003:tid 1018100] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.662493 2026] [core:error] [pid 1018003:tid 1018100] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.662571 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.48.160.90:51279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apK9UjAh5Y1i2tUxg4EJ9QAABfo"] [Sat Aug 29 05:06:58.665461 2026] [core:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.665473 2026] [core:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.667979 2026] [security2:error] [pid 1028675:tid 1028810] [client 93.123.109.228:52468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9UtdHPfW2QFvhmL7SCQAAAAA"] [Sat Aug 29 05:06:58.674885 2026] [security2:error] [pid 1018003:tid 1018188] [client 93.123.109.228:52498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EJ-AAABd0"] [Sat Aug 29 05:06:58.682508 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.682524 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.689802 2026] [core:error] [pid 1028675:tid 1028923] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.689824 2026] [core:error] [pid 1028675:tid 1028923] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.692581 2026] [security2:error] [pid 1028675:tid 1028850] [client 93.123.109.228:52428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9UtdHPfW2QFvhmL7SDQAAACg"] [Sat Aug 29 05:06:58.699375 2026] [core:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.699391 2026] [core:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.701570 2026] [security2:error] [pid 1028675:tid 1028933] [client 168.107.94.195:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9UtdHPfW2QFvhmL7SEAAAAHs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:58.707063 2026] [security2:error] [pid 1018003:tid 1018177] [client 93.123.109.228:52516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKAQAABdI"] [Sat Aug 29 05:06:58.709996 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.710012 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.714460 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.714478 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.734144 2026] [security2:error] [pid 1018003:tid 1018049] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/apps/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKCQAFyBw"] [Sat Aug 29 05:06:58.735202 2026] [core:error] [pid 1018003:tid 1018050] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.735224 2026] [core:error] [pid 1018003:tid 1018050] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.736228 2026] [core:error] [pid 1018003:tid 1018088] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.736243 2026] [core:error] [pid 1018003:tid 1018088] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.747017 2026] [security2:error] [pid 1028675:tid 1028899] [client 68.155.159.216:52813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9UtdHPfW2QFvhmL7SGgAAAFk"] [Sat Aug 29 05:06:58.747828 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.747845 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.763739 2026] [security2:error] [pid 1028675:tid 1028898] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9UtdHPfW2QFvhmL7SBgAAWCw"] [Sat Aug 29 05:06:58.764006 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.764019 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.766255 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.766273 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.770096 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.770115 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.771120 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.771134 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.771339 2026] [security2:error] [pid 1018003:tid 1018261] [client 93.123.109.228:52548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKDgAABiU"] [Sat Aug 29 05:06:58.771792 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.771805 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.773318 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.48.250.41:21465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/zxekqlxb.php"] [unique_id "apK9UtdHPfW2QFvhmL7SHwAAAE0"] [Sat Aug 29 05:06:58.775193 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.52.41.200:1265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apK9UtdHPfW2QFvhmL7SIAAAAC4"] [Sat Aug 29 05:06:58.775559 2026] [security2:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKDwAFw3E"] [Sat Aug 29 05:06:58.783508 2026] [security2:error] [pid 1018003:tid 1018085] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/v1/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKEAAGLEA"] [Sat Aug 29 05:06:58.802300 2026] [security2:error] [pid 1018003:tid 1018213] [client 68.155.159.216:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKEgAABfY"] [Sat Aug 29 05:06:58.809573 2026] [security2:error] [pid 1028675:tid 1028920] [client 158.23.147.79:30495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/lock.php"] [unique_id "apK9UtdHPfW2QFvhmL7SIwAAAG4"] [Sat Aug 29 05:06:58.812737 2026] [security2:error] [pid 1018003:tid 1018062] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/site/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKEwAGNSk"] [Sat Aug 29 05:06:58.817494 2026] [security2:error] [pid 1018003:tid 1018067] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/old/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKFQAF1C4"] [Sat Aug 29 05:06:58.827470 2026] [security2:error] [pid 1018003:tid 1018136] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/v2/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKFgAGA3M"] [Sat Aug 29 05:06:58.835458 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.48.160.90:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/robots.php"] [unique_id "apK9UtdHPfW2QFvhmL7SJgAAADQ"] [Sat Aug 29 05:06:58.841213 2026] [security2:error] [pid 1028675:tid 1028912] [client 158.158.54.35:22135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/shell.php"] [unique_id "apK9UtdHPfW2QFvhmL7SKAAAAGY"] [Sat Aug 29 05:06:58.841371 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.197.61.180:7878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/configs.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKGgAABio"] [Sat Aug 29 05:06:58.860841 2026] [security2:error] [pid 1018003:tid 1018115] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/docker/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKHAAGH14"] [Sat Aug 29 05:06:58.867896 2026] [security2:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKHgAF4yM"] [Sat Aug 29 05:06:58.874858 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.196.209.81:15501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/test.php"] [unique_id "apK9UtdHPfW2QFvhmL7SKgAAAEY"] [Sat Aug 29 05:06:58.876933 2026] [security2:error] [pid 1018003:tid 1018104] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKIAAFz1M"] [Sat Aug 29 05:06:58.876956 2026] [security2:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKIgAFzyA"] [Sat Aug 29 05:06:58.877811 2026] [security2:error] [pid 1018003:tid 1018206] [client 158.23.147.79:32715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/dropdown.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKJAAABe8"] [Sat Aug 29 05:06:58.883063 2026] [security2:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKKAAFzzE"] [Sat Aug 29 05:06:58.883533 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.883547 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.889531 2026] [security2:error] [pid 1018003:tid 1018159] [client 4.205.62.107:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/php-details.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKKQAABcA"] [Sat Aug 29 05:06:58.893853 2026] [security2:error] [pid 1018003:tid 1018234] [client 4.205.62.107:21581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/or.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKKgAABgo"] [Sat Aug 29 05:06:58.895683 2026] [security2:error] [pid 1018003:tid 1018089] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/.docker/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKKwAFvUQ"] [Sat Aug 29 05:06:58.900756 2026] [security2:error] [pid 1018003:tid 1018216] [client 4.205.62.107:58451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/grsiuk.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKLAAABfk"] [Sat Aug 29 05:06:58.902886 2026] [security2:error] [pid 1028675:tid 1028900] [client 52.139.37.240:32101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/c1.php"] [unique_id "apK9UtdHPfW2QFvhmL7SLQAAAFo"] [Sat Aug 29 05:06:58.906726 2026] [security2:error] [pid 1018003:tid 1018038] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/portal/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKLQAFwhE"] [Sat Aug 29 05:06:58.910350 2026] [security2:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKLgAFz0c"] [Sat Aug 29 05:06:58.915394 2026] [security2:error] [pid 1018003:tid 1018087] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/staging/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKLwAFwkI"] [Sat Aug 29 05:06:58.916949 2026] [security2:error] [pid 1018003:tid 1018230] [client 68.155.159.216:49274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/cong.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKMAAABgY"] [Sat Aug 29 05:06:58.933868 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.250.41:21260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/init.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKNAAABgY"] [Sat Aug 29 05:06:58.934508 2026] [security2:error] [pid 1018003:tid 1018222] [client 4.205.62.107:22411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/wander.php"] [unique_id "apK9UjAh5Y1i2tUxg4EKNQAABf8"] [Sat Aug 29 05:06:58.942923 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.942949 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.947635 2026] [core:error] [pid 1028675:tid 1028815] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.947653 2026] [core:error] [pid 1028675:tid 1028815] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.971960 2026] [security2:error] [pid 1018003:tid 1018059] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKOQAGDiY"] [Sat Aug 29 05:06:58.972124 2026] [core:error] [pid 1018003:tid 1018163] [client 158.158.54.35:28408] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.972137 2026] [core:error] [pid 1018003:tid 1018163] [client 158.158.54.35:28408] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:58.983634 2026] [security2:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9UjAh5Y1i2tUxg4EKOwAF20U"] [Sat Aug 29 05:06:59.015379 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.48.160.90:51608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKRQAABjE"] [Sat Aug 29 05:06:59.022570 2026] [core:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.022592 2026] [core:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.025928 2026] [core:error] [pid 1028675:tid 1028883] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.025953 2026] [core:error] [pid 1028675:tid 1028883] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.034027 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.147.79:48200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/about.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKUQAABiU"] [Sat Aug 29 05:06:59.034582 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.034596 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.040286 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.040300 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.050646 2026] [security2:error] [pid 1028675:tid 1028914] [client 4.205.62.107:9187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/xin1.php"] [unique_id "apK9U9dHPfW2QFvhmL7SOAAAAGg"] [Sat Aug 29 05:06:59.053692 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.053706 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.053720 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.053729 2026] [core:error] [pid 1018003:tid 1018277] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.053980 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.053992 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.065943 2026] [security2:error] [pid 1018003:tid 1018267] [client 40.83.93.50:7577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/blog.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKXAAABis"] [Sat Aug 29 05:06:59.066771 2026] [security2:error] [pid 1018003:tid 1018114] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/api/.env.bak"] [unique_id "apK9UzAh5Y1i2tUxg4EKWgAFx10"] [Sat Aug 29 05:06:59.067029 2026] [security2:error] [pid 1018003:tid 1018118] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/env.bak"] [unique_id "apK9UzAh5Y1i2tUxg4EKWwAFx2E"] [Sat Aug 29 05:06:59.068802 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.196.209.81:9744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/inputs.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKYAAABdc"] [Sat Aug 29 05:06:59.072063 2026] [security2:error] [pid 1018003:tid 1018097] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/env.old"] [unique_id "apK9UzAh5Y1i2tUxg4EKYQAF50w"] [Sat Aug 29 05:06:59.083843 2026] [security2:error] [pid 1028675:tid 1028922] [client 168.107.94.195:52674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9U9dHPfW2QFvhmL7SOwAAAHA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:59.084443 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.48.250.41:21424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/term.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKYwAABfk"] [Sat Aug 29 05:06:59.085658 2026] [core:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.085676 2026] [core:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.091240 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.091254 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.091264 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.091273 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.092348 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.092386 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.093067 2026] [core:error] [pid 1018003:tid 1018153] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.093076 2026] [core:error] [pid 1018003:tid 1018153] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.106179 2026] [security2:error] [pid 1028675:tid 1028854] [client 68.155.159.216:16191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/cong.php"] [unique_id "apK9U9dHPfW2QFvhmL7SQAAAACw"] [Sat Aug 29 05:06:59.114915 2026] [core:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.114929 2026] [core:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.124192 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.49.130:43646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/sta.php"] [unique_id "apK9U9dHPfW2QFvhmL7SQwAAAD0"] [Sat Aug 29 05:06:59.130458 2026] [security2:error] [pid 1028675:tid 1028838] [client 103.185.242.143:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9U9dHPfW2QFvhmL7SRAAAABw"] [Sat Aug 29 05:06:59.130536 2026] [security2:error] [pid 1028675:tid 1028838] [client 103.185.242.143:64161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9U9dHPfW2QFvhmL7SRAAAABw"] [Sat Aug 29 05:06:59.131129 2026] [security2:error] [pid 1018003:tid 1018116] [remote 74.7.227.189:35158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pinnacleforms.com"] [uri "/OeEmailReview.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKaAAFwl8"], referer: https://mail.pinnacleforms.com/ [Sat Aug 29 05:06:59.140956 2026] [core:error] [pid 1028675:tid 1028891] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.140969 2026] [core:error] [pid 1028675:tid 1028891] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.143710 2026] [security2:error] [pid 1018003:tid 1018252] [client 93.123.109.228:52548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9UzAh5Y1i2tUxg4EKaQAABhw"] [Sat Aug 29 05:06:59.155029 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.151.200.44:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/X7T6.php"] [unique_id "apK9U9dHPfW2QFvhmL7SRgAAAFw"] [Sat Aug 29 05:06:59.201533 2026] [security2:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKbgAF-gE"] [Sat Aug 29 05:06:59.209737 2026] [security2:error] [pid 1028675:tid 1028835] [client 68.155.159.216:64459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9U9dHPfW2QFvhmL7STAAAABk"] [Sat Aug 29 05:06:59.214327 2026] [security2:error] [pid 1018003:tid 1018101] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/.env.production.bak"] [unique_id "apK9UzAh5Y1i2tUxg4EKcAAGL1A"] [Sat Aug 29 05:06:59.215932 2026] [security2:error] [pid 1018003:tid 1018126] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/.env.prod.bak"] [unique_id "apK9UzAh5Y1i2tUxg4EKcgAGL2k"] [Sat Aug 29 05:06:59.229207 2026] [security2:error] [pid 1018003:tid 1018029] [remote 34.139.66.91:50250] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "tgd6.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9UzAh5Y1i2tUxg4EKdQAGKQg"] [Sat Aug 29 05:06:59.229954 2026] [security2:error] [pid 1018003:tid 1018139] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/@fs/root/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKdgAGKXY"] [Sat Aug 29 05:06:59.230172 2026] [core:error] [pid 1028675:tid 1028908] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.230181 2026] [core:error] [pid 1028675:tid 1028908] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.230593 2026] [security2:error] [pid 1018003:tid 1018027] [remote 34.139.66.91:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/@fs/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKdwAGKQY"] [Sat Aug 29 05:06:59.242308 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.52.41.200:1158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/m.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKeAAABiY"] [Sat Aug 29 05:06:59.246395 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.48.160.90:51644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apK9U9dHPfW2QFvhmL7SUAAAACg"] [Sat Aug 29 05:06:59.250123 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.104.49.130:36330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/ws85.php"] [unique_id "apK9U9dHPfW2QFvhmL7SUQAAAHs"] [Sat Aug 29 05:06:59.254595 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.254608 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.256240 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.48.250.41:21397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/aaa.php"] [unique_id "apK9U9dHPfW2QFvhmL7SUwAAAEs"] [Sat Aug 29 05:06:59.274408 2026] [core:error] [pid 1018003:tid 1018170] [client 20.196.209.81:15528] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.274428 2026] [core:error] [pid 1018003:tid 1018170] [client 20.196.209.81:15528] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.276291 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:52516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKfAAABdw"] [Sat Aug 29 05:06:59.276342 2026] [security2:error] [pid 1018003:tid 1018219] [client 93.123.109.228:52456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKfQAABfw"] [Sat Aug 29 05:06:59.278182 2026] [security2:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKfwAGMXU"] [Sat Aug 29 05:06:59.279193 2026] [security2:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKhQAGMXU"] [Sat Aug 29 05:06:59.279237 2026] [security2:error] [pid 1018003:tid 1018073] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKhAAGMTQ"] [Sat Aug 29 05:06:59.280132 2026] [security2:error] [pid 1028675:tid 1028857] [client 40.83.93.50:20829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK9U9dHPfW2QFvhmL7SVQAAAC8"] [Sat Aug 29 05:06:59.283530 2026] [security2:error] [pid 1028675:tid 1028865] [client 158.158.54.35:17630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/elp.php"] [unique_id "apK9U9dHPfW2QFvhmL7SWAAAADc"] [Sat Aug 29 05:06:59.297447 2026] [security2:error] [pid 1028675:tid 1028893] [client 93.123.109.228:52468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9U9dHPfW2QFvhmL7SWgAAAFM"] [Sat Aug 29 05:06:59.303569 2026] [security2:error] [pid 1018003:tid 1018091] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9UzAh5Y1i2tUxg4EKiwAGMUY"] [Sat Aug 29 05:06:59.310025 2026] [core:error] [pid 1028675:tid 1028936] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.310041 2026] [core:error] [pid 1028675:tid 1028936] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.310782 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.310799 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.313020 2026] [core:error] [pid 1028675:tid 1028931] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.313032 2026] [core:error] [pid 1028675:tid 1028931] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.313272 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.313283 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.323624 2026] [core:error] [pid 1028675:tid 1028863] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.323637 2026] [core:error] [pid 1028675:tid 1028863] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.331273 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.331299 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.343716 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.147.79:17447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKkQAABd4"] [Sat Aug 29 05:06:59.347383 2026] [security2:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9UzAh5Y1i2tUxg4EKkgAGMWM"] [Sat Aug 29 05:06:59.363291 2026] [security2:error] [pid 1018003:tid 1018258] [client 4.205.62.107:53311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/g3.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKlwAABiI"] [Sat Aug 29 05:06:59.369575 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.369593 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.383212 2026] [core:error] [pid 1028675:tid 1028814] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.383230 2026] [core:error] [pid 1028675:tid 1028814] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.387197 2026] [security2:error] [pid 1028675:tid 1028912] [client 68.155.159.216:24573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9U9dHPfW2QFvhmL7SZwAAAGY"] [Sat Aug 29 05:06:59.390708 2026] [core:error] [pid 1018003:tid 1018166] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.390733 2026] [core:error] [pid 1018003:tid 1018166] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.417139 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.104.49.130:60749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/dk.php"] [unique_id "apK9U9dHPfW2QFvhmL7SaQAAAEY"] [Sat Aug 29 05:06:59.420862 2026] [security2:error] [pid 1028675:tid 1028917] [client 158.158.54.35:20334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "apK9U9dHPfW2QFvhmL7SagAAAGs"] [Sat Aug 29 05:06:59.426036 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.48.250.41:21330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/xsox.php"] [unique_id "apK9U9dHPfW2QFvhmL7SawAAAB8"] [Sat Aug 29 05:06:59.431930 2026] [core:error] [pid 1018003:tid 1018216] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.431946 2026] [core:error] [pid 1018003:tid 1018216] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.432269 2026] [security2:error] [pid 1028675:tid 1028935] [client 93.123.109.228:52428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9U9dHPfW2QFvhmL7SbAAAAH0"] [Sat Aug 29 05:06:59.436722 2026] [security2:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/infophp.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKowAGMXg"] [Sat Aug 29 05:06:59.439259 2026] [security2:error] [pid 1028675:tid 1028859] [client 68.155.159.216:33694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/sad/about.php"] [unique_id "apK9U9dHPfW2QFvhmL7SbQAAADE"] [Sat Aug 29 05:06:59.439851 2026] [security2:error] [pid 1018003:tid 1018132] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/info.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKpgAGMW8"] [Sat Aug 29 05:06:59.441398 2026] [core:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.441410 2026] [core:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.446297 2026] [security2:error] [pid 1028675:tid 1028849] [client 68.155.159.216:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/file5.php"] [unique_id "apK9U9dHPfW2QFvhmL7SbwAAACc"] [Sat Aug 29 05:06:59.449745 2026] [security2:error] [pid 1018003:tid 1018180] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKpwAABdU"] [Sat Aug 29 05:06:59.461753 2026] [core:error] [pid 1028675:tid 1028828] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.461774 2026] [core:error] [pid 1028675:tid 1028828] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.464855 2026] [security2:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/infos.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKqwAGMVY"] [Sat Aug 29 05:06:59.480529 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.160.90:51585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKrgAABgY"] [Sat Aug 29 05:06:59.481661 2026] [security2:error] [pid 1018003:tid 1018161] [client 168.107.94.195:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKrwAABcI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:59.483592 2026] [security2:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKsAAGMWw"] [Sat Aug 29 05:06:59.485924 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.196.209.81:9419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKtAAABfU"] [Sat Aug 29 05:06:59.511790 2026] [security2:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKtgAGMWY"] [Sat Aug 29 05:06:59.511790 2026] [security2:error] [pid 1018003:tid 1018045] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKtQAGMRg"] [Sat Aug 29 05:06:59.517258 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.517275 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.520534 2026] [security2:error] [pid 1018003:tid 1018192] [client 93.123.109.228:52506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKtwAABeE"] [Sat Aug 29 05:06:59.522759 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.522776 2026] [core:error] [pid 1018003:tid 1018169] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.527686 2026] [security2:error] [pid 1028675:tid 1028922] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9U9dHPfW2QFvhmL7SdgAAAHA"] [Sat Aug 29 05:06:59.541079 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.197.61.180:9374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/disagraeed.php"] [unique_id "apK9U9dHPfW2QFvhmL7SeQAAACs"] [Sat Aug 29 05:06:59.555346 2026] [security2:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EKwgAGMQ8"] [Sat Aug 29 05:06:59.565016 2026] [security2:error] [pid 1018003:tid 1018186] [client 158.23.147.79:62990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKxwAABds"] [Sat Aug 29 05:06:59.565687 2026] [core:error] [pid 1018003:tid 1018163] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.565702 2026] [core:error] [pid 1018003:tid 1018163] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.568769 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.568787 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.572365 2026] [security2:error] [pid 1018003:tid 1018256] [client 68.155.159.216:63856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKygAABiA"] [Sat Aug 29 05:06:59.572799 2026] [core:error] [pid 1018003:tid 1018219] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.572808 2026] [core:error] [pid 1018003:tid 1018219] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.575786 2026] [security2:error] [pid 1028675:tid 1028821] [client 40.83.93.50:7740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/bypass.php"] [unique_id "apK9U9dHPfW2QFvhmL7SfAAAAAs"] [Sat Aug 29 05:06:59.581390 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.581409 2026] [core:error] [pid 1018003:tid 1018270] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.584647 2026] [security2:error] [pid 1028675:tid 1028906] [client 93.123.109.228:52428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9U9dHPfW2QFvhmL7SfQAAAGA"] [Sat Aug 29 05:06:59.595752 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.147.79:26532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/radio.php"] [unique_id "apK9UzAh5Y1i2tUxg4EKzgAABiU"] [Sat Aug 29 05:06:59.603484 2026] [security2:error] [pid 1018003:tid 1018026] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK0QAF9gU"] [Sat Aug 29 05:06:59.604056 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.48.250.41:21477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/lkui.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK1AAABdQ"] [Sat Aug 29 05:06:59.605125 2026] [security2:error] [pid 1018003:tid 1018032] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK0gAF9gs"] [Sat Aug 29 05:06:59.645463 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.645479 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.650047 2026] [security2:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK3QAF9m0"] [Sat Aug 29 05:06:59.654284 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.49.130:58087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/users.php"] [unique_id "apK9U9dHPfW2QFvhmL7SgwAAAD0"] [Sat Aug 29 05:06:59.661855 2026] [core:error] [pid 1028675:tid 1028873] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.661871 2026] [core:error] [pid 1028675:tid 1028873] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.668132 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.147.79:49845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/NewFile.php/"] [unique_id "apK9UzAh5Y1i2tUxg4EK3gAABgM"] [Sat Aug 29 05:06:59.671864 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.671882 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.671903 2026] [security2:error] [pid 1028675:tid 1028876] [client 20.196.209.81:17178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/user/f35.php"] [unique_id "apK9U9dHPfW2QFvhmL7ShgAAAEI"] [Sat Aug 29 05:06:59.691728 2026] [security2:error] [pid 1018003:tid 1018221] [client 68.155.159.216:1994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/simple.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK5AAABf4"] [Sat Aug 29 05:06:59.693179 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.52.41.200:1204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/css/wp-login.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK5QAABdg"] [Sat Aug 29 05:06:59.715940 2026] [security2:error] [pid 1018003:tid 1018222] [client 4.205.62.107:22484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/btx25.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK6QAABf8"] [Sat Aug 29 05:06:59.716474 2026] [security2:error] [pid 1018003:tid 1018239] [client 158.23.147.79:35824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/content.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK6gAABg8"] [Sat Aug 29 05:06:59.716479 2026] [security2:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK5gAF9hk"] [Sat Aug 29 05:06:59.716481 2026] [security2:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK5wAF9jI"] [Sat Aug 29 05:06:59.720881 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.48.160.90:51311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK7gAABfk"] [Sat Aug 29 05:06:59.721840 2026] [security2:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK7QAF9hQ"] [Sat Aug 29 05:06:59.721928 2026] [security2:error] [pid 1018003:tid 1018035] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK7AAF9g4"] [Sat Aug 29 05:06:59.721962 2026] [security2:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK6wAF9no"] [Sat Aug 29 05:06:59.722872 2026] [security2:error] [pid 1018003:tid 1018153] [client 93.123.109.228:52476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK7wAABbo"] [Sat Aug 29 05:06:59.724914 2026] [security2:error] [pid 1028675:tid 1028923] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9U9dHPfW2QFvhmL7SiQAAAHE"] [Sat Aug 29 05:06:59.726784 2026] [security2:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK8AAF9lE"] [Sat Aug 29 05:06:59.732746 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.158.54.35:10346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-content/cong.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK9AAABd0"] [Sat Aug 29 05:06:59.735491 2026] [security2:error] [pid 1018003:tid 1018172] [client 68.155.159.216:33571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK9QAABc0"] [Sat Aug 29 05:06:59.736108 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.151.200.44:47372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/see.php"] [unique_id "apK9U9dHPfW2QFvhmL7SjQAAAHs"] [Sat Aug 29 05:06:59.741635 2026] [security2:error] [pid 1018003:tid 1018195] [client 93.123.109.228:52420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK9wAABeQ"] [Sat Aug 29 05:06:59.743104 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.48.250.41:21478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9U9dHPfW2QFvhmL7SjgAAACI"] [Sat Aug 29 05:06:59.748795 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.203.141.11:13326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/.trash7206/index.php"] [unique_id "apK9U9dHPfW2QFvhmL7SjwAAAEs"] [Sat Aug 29 05:06:59.751927 2026] [security2:error] [pid 1018003:tid 1018185] [client 40.83.93.50:22836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/options-general.php"] [unique_id "apK9UzAh5Y1i2tUxg4EK-AAABdo"] [Sat Aug 29 05:06:59.755146 2026] [core:error] [pid 1028675:tid 1028830] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.755164 2026] [core:error] [pid 1028675:tid 1028830] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.762591 2026] [security2:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9UzAh5Y1i2tUxg4EK-gAF9h8"] [Sat Aug 29 05:06:59.766860 2026] [security2:error] [pid 1028675:tid 1028934] [client 68.155.159.216:12270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/user/index.php"] [unique_id "apK9U9dHPfW2QFvhmL7SkgAAAHw"] [Sat Aug 29 05:06:59.792781 2026] [security2:error] [pid 1028675:tid 1028872] [client 93.123.109.228:52468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9U9dHPfW2QFvhmL7SlgAAAD4"] [Sat Aug 29 05:06:59.794836 2026] [security2:error] [pid 1028675:tid 1028865] [client 57.141.14.22:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/"] [unique_id "apK9U9dHPfW2QFvhmL7SlAAAADc"] [Sat Aug 29 05:06:59.795038 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.795056 2026] [core:error] [pid 1018003:tid 1018243] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.795096 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.795107 2026] [core:error] [pid 1028675:tid 1028893] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.797343 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.797367 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.798225 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.798233 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.804704 2026] [security2:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9UzAh5Y1i2tUxg4ELAwAFyxY"] [Sat Aug 29 05:06:59.826536 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.104.49.130:63599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/txets.php"] [unique_id "apK9U9dHPfW2QFvhmL7SmQAAAB4"] [Sat Aug 29 05:06:59.840693 2026] [core:error] [pid 1028675:tid 1028932] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.840711 2026] [core:error] [pid 1028675:tid 1028932] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.846348 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.846380 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.861738 2026] [security2:error] [pid 1028675:tid 1028920] [client 168.107.94.195:53621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9U9dHPfW2QFvhmL7SnQAAAG4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:06:59.877066 2026] [security2:error] [pid 1028675:tid 1028852] [client 93.123.109.228:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9U9dHPfW2QFvhmL7SoAAAACo"] [Sat Aug 29 05:06:59.877741 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.48.250.41:21336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/motu.php"] [unique_id "apK9UzAh5Y1i2tUxg4ELEQAABik"] [Sat Aug 29 05:06:59.878730 2026] [security2:error] [pid 1028675:tid 1028810] [client 158.158.54.35:34245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/assets/images/doc.php"] [unique_id "apK9U9dHPfW2QFvhmL7SoQAAAAA"] [Sat Aug 29 05:06:59.923137 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.923164 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.939612 2026] [security2:error] [pid 1018003:tid 1018198] [client 68.155.159.216:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9UzAh5Y1i2tUxg4ELHAAABec"] [Sat Aug 29 05:06:59.972196 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.196.209.81:9644] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/1.php7"] [unique_id "apK9U9dHPfW2QFvhmL7SqAAAAEA"] [Sat Aug 29 05:06:59.972318 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.196.209.81:9644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/1.php7"] [unique_id "apK9U9dHPfW2QFvhmL7SqAAAAEA"] [Sat Aug 29 05:06:59.975883 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.975898 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.979935 2026] [security2:error] [pid 1028675:tid 1028815] [client 93.123.109.228:52468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9U9dHPfW2QFvhmL7SqgAAAAU"] [Sat Aug 29 05:06:59.981181 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.104.49.130:57504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/browse.php"] [unique_id "apK9UzAh5Y1i2tUxg4ELLQAABcg"] [Sat Aug 29 05:06:59.996939 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:06:59.996962 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.005936 2026] [core:error] [pid 1018003:tid 1018156] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.005956 2026] [core:error] [pid 1018003:tid 1018156] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.006461 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.006477 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.006806 2026] [core:error] [pid 1028675:tid 1028907] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.006822 2026] [core:error] [pid 1028675:tid 1028907] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.007505 2026] [core:error] [pid 1028675:tid 1028927] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.007520 2026] [core:error] [pid 1028675:tid 1028927] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.008787 2026] [core:error] [pid 1028675:tid 1028924] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.008807 2026] [core:error] [pid 1028675:tid 1028924] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.009349 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.009371 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.013095 2026] [core:error] [pid 1018003:tid 1018153] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.013109 2026] [core:error] [pid 1018003:tid 1018153] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.013796 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.013810 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.015975 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.015988 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.016517 2026] [core:error] [pid 1028675:tid 1028889] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.016529 2026] [core:error] [pid 1028675:tid 1028889] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.017288 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.017297 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.021454 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.021499 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.021763 2026] [security2:error] [pid 1028675:tid 1028906] [client 20.48.250.41:21269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/Ov-Simple1.php"] [unique_id "apK9VNdHPfW2QFvhmL7SuAAAAGA"] [Sat Aug 29 05:07:00.027824 2026] [security2:error] [pid 1028675:tid 1028916] [client 4.205.62.107:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/routes.php"] [unique_id "apK9VNdHPfW2QFvhmL7SuQAAAGo"] [Sat Aug 29 05:07:00.028779 2026] [security2:error] [pid 1018003:tid 1018277] [client 68.155.159.216:49225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELNgAABjU"] [Sat Aug 29 05:07:00.032019 2026] [security2:error] [pid 1028675:tid 1028886] [client 4.205.62.107:22348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/i.php"] [unique_id "apK9VNdHPfW2QFvhmL7SugAAAEw"] [Sat Aug 29 05:07:00.044488 2026] [security2:error] [pid 1018003:tid 1018266] [client 93.123.109.228:52506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELNwAABio"] [Sat Aug 29 05:07:00.053229 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.151.200.44:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/horeg.php"] [unique_id "apK9VNdHPfW2QFvhmL7SvQAAADI"] [Sat Aug 29 05:07:00.056469 2026] [security2:error] [pid 1028675:tid 1028928] [client 4.205.62.107:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/oiko6u.php"] [unique_id "apK9VNdHPfW2QFvhmL7SwAAAAHY"] [Sat Aug 29 05:07:00.059573 2026] [security2:error] [pid 1028675:tid 1028902] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9VNdHPfW2QFvhmL7SwgAAAFw"] [Sat Aug 29 05:07:00.077195 2026] [security2:error] [pid 1028675:tid 1028846] [client 4.205.62.107:22371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andresortega.org"] [uri "/ah25.php"] [unique_id "apK9VNdHPfW2QFvhmL7SxAAAACQ"] [Sat Aug 29 05:07:00.077282 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.196.209.81:22416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/user/min.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELPAAABcc"] [Sat Aug 29 05:07:00.088303 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.48.160.90:51288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apK9VNdHPfW2QFvhmL7SxQAAAHE"] [Sat Aug 29 05:07:00.094433 2026] [security2:error] [pid 1018003:tid 1018163] [client 93.123.109.228:52420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELPQAABcQ"] [Sat Aug 29 05:07:00.095983 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.095995 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.100880 2026] [security2:error] [pid 1018003:tid 1018179] [client 40.83.93.50:7602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/extractable-loader-head.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELPgAABdQ"] [Sat Aug 29 05:07:00.133616 2026] [security2:error] [pid 1028675:tid 1028899] [client 93.123.109.228:52428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9VNdHPfW2QFvhmL7SyAAAAFk"] [Sat Aug 29 05:07:00.140522 2026] [security2:error] [pid 1018003:tid 1018225] [client 93.123.109.228:52512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELQAAABgI"] [Sat Aug 29 05:07:00.143925 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.196.209.81:1776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/post.php"] [unique_id "apK9VNdHPfW2QFvhmL7SygAAACw"] [Sat Aug 29 05:07:00.144278 2026] [security2:error] [pid 1028675:tid 1028842] [client 158.23.147.79:48443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9VNdHPfW2QFvhmL7SywAAACA"] [Sat Aug 29 05:07:00.151094 2026] [security2:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/php-info.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELQgAF9nM"] [Sat Aug 29 05:07:00.152594 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.48.250.41:21471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/wp-blogs.php"] [unique_id "apK9VNdHPfW2QFvhmL7SzQAAAD4"] [Sat Aug 29 05:07:00.154730 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.52.41.200:1215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/222.php"] [unique_id "apK9VNdHPfW2QFvhmL7SzgAAADM"] [Sat Aug 29 05:07:00.157971 2026] [security2:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/php.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELRAAGECM"] [Sat Aug 29 05:07:00.158458 2026] [security2:error] [pid 1018003:tid 1018104] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/php_info.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELRQAGEFM"] [Sat Aug 29 05:07:00.158866 2026] [security2:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/phpinfo.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELRwAGECI"] [Sat Aug 29 05:07:00.189016 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.189040 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.189443 2026] [security2:error] [pid 1018003:tid 1018087] [remote 34.139.66.91:50252] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "tgd6.com"] [uri "/_image"] [unique_id "apK9VDAh5Y1i2tUxg4ELUAAF3EI"] [Sat Aug 29 05:07:00.205242 2026] [security2:error] [pid 1018003:tid 1018185] [client 158.158.54.35:10201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELVwAABdo"] [Sat Aug 29 05:07:00.209260 2026] [security2:error] [pid 1028675:tid 1028878] [client 4.205.62.107:9189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/adminfus.php"] [unique_id "apK9VNdHPfW2QFvhmL7S2AAAAEQ"] [Sat Aug 29 05:07:00.209755 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.203.141.11:1103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wk/index.php"] [unique_id "apK9VNdHPfW2QFvhmL7S2QAAAAE"] [Sat Aug 29 05:07:00.210640 2026] [security2:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELWQAGECo"] [Sat Aug 29 05:07:00.211465 2026] [core:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.211477 2026] [core:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.222666 2026] [security2:error] [pid 1028675:tid 1028876] [client 40.83.93.50:20817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/options.php"] [unique_id "apK9VNdHPfW2QFvhmL7S2wAAAEI"] [Sat Aug 29 05:07:00.222925 2026] [security2:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELXQAGEGU"] [Sat Aug 29 05:07:00.222943 2026] [security2:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELXgAGEAk"] [Sat Aug 29 05:07:00.223489 2026] [security2:error] [pid 1018003:tid 1018025] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELXAAGEAQ"] [Sat Aug 29 05:07:00.229897 2026] [security2:error] [pid 1028675:tid 1028856] [client 68.155.159.216:16148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/js/index.php"] [unique_id "apK9VNdHPfW2QFvhmL7S3gAAAC4"] [Sat Aug 29 05:07:00.231989 2026] [core:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.232002 2026] [core:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.232622 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.232696 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.233920 2026] [security2:error] [pid 1028675:tid 1028835] [client 106.213.87.167:18761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.87.213.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fieldssketchbook.com"] [uri "/xmlrpc.php"] [unique_id "apK9VNdHPfW2QFvhmL7S1wAAABk"] [Sat Aug 29 05:07:00.234033 2026] [security2:error] [pid 1028675:tid 1028835] [client 106.213.87.167:18761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fieldssketchbook.com"] [uri "/xmlrpc.php"] [unique_id "apK9VNdHPfW2QFvhmL7S1wAAABk"] [Sat Aug 29 05:07:00.234635 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.234652 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.235532 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.197.61.180:13876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/add_actualites.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELYwAABfk"] [Sat Aug 29 05:07:00.243291 2026] [security2:error] [pid 1018003:tid 1018261] [client 168.107.94.195:54022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELZAAABiU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:00.247935 2026] [security2:error] [pid 1018003:tid 1018118] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELZQAGEGE"] [Sat Aug 29 05:07:00.256002 2026] [core:error] [pid 1028675:tid 1028852] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.256019 2026] [core:error] [pid 1028675:tid 1028852] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.256548 2026] [core:error] [pid 1028675:tid 1028901] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.256563 2026] [core:error] [pid 1028675:tid 1028901] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.282793 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.151.200.44:47315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/basic.php"] [unique_id "apK9VNdHPfW2QFvhmL7S6QAAAEk"] [Sat Aug 29 05:07:00.298682 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.48.250.41:21380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/mini.php"] [unique_id "apK9VNdHPfW2QFvhmL7S6gAAAGE"] [Sat Aug 29 05:07:00.316209 2026] [security2:error] [pid 1028675:tid 1028826] [client 158.158.54.35:20311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/bgymj.php"] [unique_id "apK9VNdHPfW2QFvhmL7S7gAAABA"] [Sat Aug 29 05:07:00.316989 2026] [security2:error] [pid 1028675:tid 1028888] [client 68.155.159.216:64468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/simple.php"] [unique_id "apK9VNdHPfW2QFvhmL7S7wAAAE4"] [Sat Aug 29 05:07:00.320561 2026] [security2:error] [pid 1018003:tid 1018074] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/public/phpinfo.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELbQAF_jU"] [Sat Aug 29 05:07:00.320717 2026] [security2:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELbAAF_jc"] [Sat Aug 29 05:07:00.320721 2026] [security2:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELawAF_ks"] [Sat Aug 29 05:07:00.329482 2026] [security2:error] [pid 1028675:tid 1028858] [client 93.123.109.228:52468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9VNdHPfW2QFvhmL7S8AAAADA"] [Sat Aug 29 05:07:00.334152 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.334166 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.344037 2026] [security2:error] [pid 1018003:tid 1018222] [client 93.123.109.228:52464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELbwAABf8"] [Sat Aug 29 05:07:00.356600 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELcgAABgk"] [Sat Aug 29 05:07:00.359254 2026] [core:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.359272 2026] [core:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.370533 2026] [security2:error] [pid 1018003:tid 1018188] [client 93.123.109.228:52456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELdAAABd0"] [Sat Aug 29 05:07:00.376560 2026] [security2:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELdwAF3z8"] [Sat Aug 29 05:07:00.380509 2026] [security2:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELeAAF30E"] [Sat Aug 29 05:07:00.390368 2026] [security2:error] [pid 1028675:tid 1028915] [client 68.155.159.216:9271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/content.php"] [unique_id "apK9VNdHPfW2QFvhmL7S-AAAAGk"] [Sat Aug 29 05:07:00.400000 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.160.90:51615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELgQAABgM"] [Sat Aug 29 05:07:00.403275 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.403296 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.405113 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.405234 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.413677 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.413692 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.415258 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.415271 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.419780 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.196.209.81:9408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/ds.php"] [unique_id "apK9VNdHPfW2QFvhmL7TAQAAAAU"] [Sat Aug 29 05:07:00.422260 2026] [core:error] [pid 1028675:tid 1028902] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.422273 2026] [core:error] [pid 1028675:tid 1028902] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.430542 2026] [security2:error] [pid 1028675:tid 1028885] [client 216.244.66.243:38794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scottportfolio.com"] [uri "/userfiles/kupit-dlia-uvelicheniia-titan-gel-351.xml"] [unique_id "apK9VNdHPfW2QFvhmL7TBwAAAEs"] [Sat Aug 29 05:07:00.430628 2026] [security2:error] [pid 1028675:tid 1028885] [client 216.244.66.243:38794] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scottportfolio.com"] [uri "/userfiles/kupit-dlia-uvelicheniia-titan-gel-351.xml"] [unique_id "apK9VNdHPfW2QFvhmL7TBwAAAEs"] [Sat Aug 29 05:07:00.430970 2026] [core:error] [pid 1028675:tid 1028923] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.430979 2026] [core:error] [pid 1028675:tid 1028923] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.434601 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.434616 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.436677 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.436692 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.443218 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.443230 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.448018 2026] [security2:error] [pid 1028675:tid 1028850] [client 158.23.147.79:17458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/radio.php"] [unique_id "apK9VNdHPfW2QFvhmL7TDAAAACg"] [Sat Aug 29 05:07:00.450331 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.48.250.41:21422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/amp.php"] [unique_id "apK9VNdHPfW2QFvhmL7TDQAAACM"] [Sat Aug 29 05:07:00.461026 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.151.200.44:47365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/monso.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELiQAABiw"] [Sat Aug 29 05:07:00.479867 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.196.209.81:15530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/users.php"] [unique_id "apK9VNdHPfW2QFvhmL7TEAAAAAg"] [Sat Aug 29 05:07:00.497553 2026] [security2:error] [pid 1028675:tid 1028876] [client 4.205.62.107:55942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-konfig.php"] [unique_id "apK9VNdHPfW2QFvhmL7TFQAAAEI"] [Sat Aug 29 05:07:00.516169 2026] [core:error] [pid 1028675:tid 1028936] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.516190 2026] [core:error] [pid 1028675:tid 1028936] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.517757 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.517775 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.523347 2026] [core:error] [pid 1028675:tid 1028905] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.523376 2026] [core:error] [pid 1028675:tid 1028905] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.530672 2026] [security2:error] [pid 1018003:tid 1018203] [client 93.123.109.228:52516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9VDAh5Y1i2tUxg4ELkQAABew"] [Sat Aug 29 05:07:00.530695 2026] [security2:error] [pid 1028675:tid 1028733] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:href. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:href"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/_image"] [unique_id "apK9VNdHPfW2QFvhmL7THgAAKTQ"] [Sat Aug 29 05:07:00.542443 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.104.49.130:48610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/new.php"] [unique_id "apK9VNdHPfW2QFvhmL7TIgAAAFo"] [Sat Aug 29 05:07:00.542768 2026] [security2:error] [pid 1028675:tid 1028836] [client 20.196.209.81:11324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/flower.php"] [unique_id "apK9VNdHPfW2QFvhmL7TIwAAABo"] [Sat Aug 29 05:07:00.561668 2026] [security2:error] [pid 1018003:tid 1018207] [client 93.123.109.228:52506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fastnetus.com"] [uri "/wp-config.php.bak"] [unique_id "apK9VDAh5Y1i2tUxg4ELmQAABfA"] [Sat Aug 29 05:07:00.564290 2026] [security2:error] [pid 1028675:tid 1028826] [client 93.123.109.228:52546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fastnetus.com"] [uri "/wp-config.php.new"] [unique_id "apK9VNdHPfW2QFvhmL7TKQAAABA"] [Sat Aug 29 05:07:00.565072 2026] [core:error] [pid 1028675:tid 1028883] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.565090 2026] [core:error] [pid 1028675:tid 1028883] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.576162 2026] [core:error] [pid 1028675:tid 1028924] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.576190 2026] [core:error] [pid 1028675:tid 1028924] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.576742 2026] [security2:error] [pid 1018003:tid 1018175] [client 93.123.109.228:52548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fastnetus.com"] [uri "/wp-config.php.old"] [unique_id "apK9VDAh5Y1i2tUxg4ELmwAABdA"] [Sat Aug 29 05:07:00.596892 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.250.41:21449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/cc13.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELnQAABfU"] [Sat Aug 29 05:07:00.597847 2026] [security2:error] [pid 1028675:tid 1028875] [client 158.23.147.79:53811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9VNdHPfW2QFvhmL7TKwAAAEE"] [Sat Aug 29 05:07:00.605911 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.52.41.200:1154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/mini.php"] [unique_id "apK9VNdHPfW2QFvhmL7TLwAAAFI"] [Sat Aug 29 05:07:00.606793 2026] [core:error] [pid 1028675:tid 1028918] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.606812 2026] [core:error] [pid 1028675:tid 1028918] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.612195 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.147.79:30647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/index/function.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELnwAABiA"] [Sat Aug 29 05:07:00.614033 2026] [security2:error] [pid 1028675:tid 1028929] [client 68.155.159.216:51259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wzy.php"] [unique_id "apK9VNdHPfW2QFvhmL7TMQAAAHc"] [Sat Aug 29 05:07:00.614902 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.614914 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.624035 2026] [security2:error] [pid 1028675:tid 1028842] [client 40.83.93.50:7569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/defaults.php"] [unique_id "apK9VNdHPfW2QFvhmL7TMwAAACA"] [Sat Aug 29 05:07:00.624393 2026] [security2:error] [pid 1018003:tid 1018261] [client 168.107.94.195:54371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELpgAABiU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:00.632204 2026] [security2:error] [pid 1028675:tid 1028886] [client 93.123.109.228:52412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.fastnetus.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9VNdHPfW2QFvhmL7TNQAAAEw"] [Sat Aug 29 05:07:00.651657 2026] [security2:error] [pid 1028675:tid 1028928] [client 20.48.160.90:51599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/650.php"] [unique_id "apK9VNdHPfW2QFvhmL7TOgAAAHY"] [Sat Aug 29 05:07:00.655496 2026] [security2:error] [pid 1028675:tid 1028816] [client 158.158.54.35:17655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-mail.php"] [unique_id "apK9VNdHPfW2QFvhmL7TPgAAAAY"] [Sat Aug 29 05:07:00.657231 2026] [core:error] [pid 1028675:tid 1028825] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.657249 2026] [core:error] [pid 1028675:tid 1028825] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.658109 2026] [core:error] [pid 1028675:tid 1028846] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.658121 2026] [core:error] [pid 1028675:tid 1028846] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.669733 2026] [core:error] [pid 1028675:tid 1028923] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.669751 2026] [core:error] [pid 1028675:tid 1028923] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.677072 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.677094 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.681262 2026] [security2:error] [pid 1028675:tid 1028832] [client 68.155.159.216:65134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/makeasmtp.php"] [unique_id "apK9VNdHPfW2QFvhmL7TQwAAABY"] [Sat Aug 29 05:07:00.722128 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.151.200.44:46596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/rce.php"] [unique_id "apK9VNdHPfW2QFvhmL7TRwAAADM"] [Sat Aug 29 05:07:00.723266 2026] [core:error] [pid 1018003:tid 1018188] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.723280 2026] [core:error] [pid 1018003:tid 1018188] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.723837 2026] [core:error] [pid 1028675:tid 1028867] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.723851 2026] [core:error] [pid 1028675:tid 1028867] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.724571 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.724588 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.725077 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.725088 2026] [core:error] [pid 1018003:tid 1018160] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.725119 2026] [security2:error] [pid 1018003:tid 1018153] [client 103.168.67.159:32700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELwAAABbo"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:07:00.725913 2026] [security2:error] [pid 1028675:tid 1028833] [client 40.83.93.50:22844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/panel.php"] [unique_id "apK9VNdHPfW2QFvhmL7TSAAAABc"] [Sat Aug 29 05:07:00.728281 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.728297 2026] [core:error] [pid 1018003:tid 1018194] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.731416 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.731444 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.742189 2026] [security2:error] [pid 1028675:tid 1028909] [client 158.23.147.79:26410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9VNdHPfW2QFvhmL7TTQAAAGM"] [Sat Aug 29 05:07:00.743613 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.743632 2026] [core:error] [pid 1028675:tid 1028895] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.744794 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.744807 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.745081 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.48.250.41:21403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/aa.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELxAAABeE"] [Sat Aug 29 05:07:00.753290 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.104.49.130:63597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/memberfuns.php"] [unique_id "apK9VNdHPfW2QFvhmL7TTgAAAC4"] [Sat Aug 29 05:07:00.760881 2026] [core:error] [pid 1028675:tid 1028810] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.760902 2026] [core:error] [pid 1028675:tid 1028810] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.776686 2026] [security2:error] [pid 1028675:tid 1028915] [client 158.158.54.35:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9VNdHPfW2QFvhmL7TVgAAAGk"] [Sat Aug 29 05:07:00.778548 2026] [core:error] [pid 1028675:tid 1028901] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.778568 2026] [core:error] [pid 1028675:tid 1028901] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.793102 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.203.141.11:22411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/admin.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELyQAABh8"] [Sat Aug 29 05:07:00.798964 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.798984 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.812799 2026] [security2:error] [pid 1018003:tid 1018113] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9VDAh5Y1i2tUxg4ELywAGDlw"] [Sat Aug 29 05:07:00.820330 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.48.160.90:51267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/nakrip.php"] [unique_id "apK9VNdHPfW2QFvhmL7TWAAAAFo"] [Sat Aug 29 05:07:00.828325 2026] [security2:error] [pid 1028675:tid 1028907] [client 158.23.147.79:35788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9VNdHPfW2QFvhmL7TWgAAAGE"] [Sat Aug 29 05:07:00.828662 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.828677 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.829117 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.196.209.81:9615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/GOD.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELzAAABek"] [Sat Aug 29 05:07:00.829465 2026] [security2:error] [pid 1028675:tid 1028826] [client 158.23.147.79:50133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/dropdown.php"] [unique_id "apK9VNdHPfW2QFvhmL7TWwAAABA"] [Sat Aug 29 05:07:00.845341 2026] [security2:error] [pid 1018003:tid 1018207] [client 68.155.159.216:33630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9VDAh5Y1i2tUxg4ELzgAABfA"] [Sat Aug 29 05:07:00.852542 2026] [security2:error] [pid 1028675:tid 1028924] [client 4.205.62.107:22374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/app_dev.php"] [unique_id "apK9VNdHPfW2QFvhmL7TXQAAAHI"] [Sat Aug 29 05:07:00.871103 2026] [security2:error] [pid 1018003:tid 1018270] [client 158.23.147.79:25523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9VDAh5Y1i2tUxg4EL0gAABi4"] [Sat Aug 29 05:07:00.875073 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.875094 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.878258 2026] [security2:error] [pid 1028675:tid 1028882] [client 68.155.159.216:12223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/plugins.php"] [unique_id "apK9VNdHPfW2QFvhmL7TYQAAAEg"] [Sat Aug 29 05:07:00.878910 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.196.209.81:22441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK9VDAh5Y1i2tUxg4EL1AAABjM"] [Sat Aug 29 05:07:00.882846 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.48.250.41:21485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/s1.php"] [unique_id "apK9VNdHPfW2QFvhmL7TYwAAAEc"] [Sat Aug 29 05:07:00.884131 2026] [core:error] [pid 1028675:tid 1028875] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.884143 2026] [core:error] [pid 1028675:tid 1028875] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.893312 2026] [core:error] [pid 1028675:tid 1028918] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.893326 2026] [core:error] [pid 1028675:tid 1028918] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:00.910841 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.49.130:60759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/tiny2.php"] [unique_id "apK9VNdHPfW2QFvhmL7TZQAAAE8"] [Sat Aug 29 05:07:00.940071 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.23.147.79:62989] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sprint52.com"] [uri "/ioxi002.PhP7"] [unique_id "apK9VDAh5Y1i2tUxg4EL1QAABdI"] [Sat Aug 29 05:07:00.940956 2026] [security2:error] [pid 1028675:tid 1028893] [client 20.196.209.81:11292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/meta.php"] [unique_id "apK9VNdHPfW2QFvhmL7TZgAAAFM"] [Sat Aug 29 05:07:00.958978 2026] [security2:error] [pid 1028675:tid 1028815] [client 158.23.147.79:30621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/content.php"] [unique_id "apK9VNdHPfW2QFvhmL7TaAAAAAU"] [Sat Aug 29 05:07:00.969519 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.48.160.90:51590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apK9VNdHPfW2QFvhmL7TagAAAFw"] [Sat Aug 29 05:07:00.970487 2026] [security2:error] [pid 1028675:tid 1028921] [client 68.155.159.216:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9VNdHPfW2QFvhmL7TawAAAG8"] [Sat Aug 29 05:07:00.993815 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.197.61.180:8083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/alfanew.php7"] [unique_id "apK9VNdHPfW2QFvhmL7TbQAAACU"] [Sat Aug 29 05:07:01.006343 2026] [security2:error] [pid 1028675:tid 1028830] [client 168.107.94.195:54797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9VddHPfW2QFvhmL7TbgAAABQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:01.013052 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.250.41:21408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/0byte.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL1wAABcM"] [Sat Aug 29 05:07:01.024044 2026] [security2:error] [pid 1028675:tid 1028844] [client 158.23.147.79:32671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/sad/about.php"] [unique_id "apK9VddHPfW2QFvhmL7TbwAAACI"] [Sat Aug 29 05:07:01.032601 2026] [security2:error] [pid 1018003:tid 1018221] [client 63.179.191.156:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.jobindjibouti.com"] [uri "/"] [unique_id "apK9VTAh5Y1i2tUxg4EL2QAABf4"] [Sat Aug 29 05:07:01.047444 2026] [security2:error] [pid 1028675:tid 1028832] [client 68.155.159.216:38557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/file88.php"] [unique_id "apK9VddHPfW2QFvhmL7TcAAAABY"] [Sat Aug 29 05:07:01.047764 2026] [security2:error] [pid 1028675:tid 1028849] [client 68.155.159.216:51469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9VddHPfW2QFvhmL7TcQAAACc"] [Sat Aug 29 05:07:01.049399 2026] [security2:error] [pid 1028675:tid 1028835] [client 68.155.159.216:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/admin.php"] [unique_id "apK9VddHPfW2QFvhmL7TcgAAABk"] [Sat Aug 29 05:07:01.066281 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.52.41.200:1419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/aa.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL2gAABik"] [Sat Aug 29 05:07:01.069349 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.151.200.44:47326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/exec.php"] [unique_id "apK9VddHPfW2QFvhmL7TcwAAACY"] [Sat Aug 29 05:07:01.122919 2026] [security2:error] [pid 1028675:tid 1028913] [client 158.158.54.35:9741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-content.php"] [unique_id "apK9VddHPfW2QFvhmL7TeAAAAGc"] [Sat Aug 29 05:07:01.166946 2026] [security2:error] [pid 1018003:tid 1018172] [client 4.205.62.107:22372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/aww.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL3AAABc0"] [Sat Aug 29 05:07:01.177744 2026] [security2:error] [pid 1028675:tid 1028833] [client 68.155.159.216:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9VddHPfW2QFvhmL7TeQAAABc"] [Sat Aug 29 05:07:01.183871 2026] [security2:error] [pid 1028675:tid 1028931] [client 4.205.62.107:65513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/aww.php"] [unique_id "apK9VddHPfW2QFvhmL7TegAAAHk"] [Sat Aug 29 05:07:01.191694 2026] [security2:error] [pid 1018003:tid 1018153] [client 4.205.62.107:58369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/edit.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL3QAABbo"] [Sat Aug 29 05:07:01.198076 2026] [security2:error] [pid 1018003:tid 1018234] [client 40.83.93.50:13575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/pk.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL3wAABgo"] [Sat Aug 29 05:07:01.203713 2026] [security2:error] [pid 1028675:tid 1028909] [client 20.48.250.41:21392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/xr.php"] [unique_id "apK9VddHPfW2QFvhmL7TewAAAGM"] [Sat Aug 29 05:07:01.220215 2026] [core:error] [pid 1018003:tid 1018233] [client 158.158.54.35:8750] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.220230 2026] [core:error] [pid 1018003:tid 1018233] [client 158.158.54.35:8750] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.220700 2026] [security2:error] [pid 1028675:tid 1028812] [client 40.83.93.50:7258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/post.php"] [unique_id "apK9VddHPfW2QFvhmL7TfQAAAAI"] [Sat Aug 29 05:07:01.249194 2026] [security2:error] [pid 1028675:tid 1028810] [client 158.23.147.79:48331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/themes.php"] [unique_id "apK9VddHPfW2QFvhmL7TfgAAAAA"] [Sat Aug 29 05:07:01.251755 2026] [security2:error] [pid 1028675:tid 1028855] [client 20.48.160.90:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/xcc.php"] [unique_id "apK9VddHPfW2QFvhmL7TfwAAAC0"] [Sat Aug 29 05:07:01.273366 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.196.209.81:22457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK9VddHPfW2QFvhmL7TgAAAADI"] [Sat Aug 29 05:07:01.286936 2026] [security2:error] [pid 1028675:tid 1028865] [client 20.196.209.81:17911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/ggfi.php"] [unique_id "apK9VddHPfW2QFvhmL7TgQAAADc"] [Sat Aug 29 05:07:01.308606 2026] [security2:error] [pid 1028675:tid 1028831] [client 20.203.141.11:11529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/php8.php"] [unique_id "apK9VddHPfW2QFvhmL7TggAAABU"] [Sat Aug 29 05:07:01.340506 2026] [security2:error] [pid 1028675:tid 1028876] [client 20.196.209.81:11314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/randkeyword.php"] [unique_id "apK9VddHPfW2QFvhmL7ThQAAAEI"] [Sat Aug 29 05:07:01.349689 2026] [security2:error] [pid 1018003:tid 1018266] [client 4.205.62.107:8714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/env.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL5AAABio"] [Sat Aug 29 05:07:01.353087 2026] [security2:error] [pid 1028675:tid 1028880] [client 68.155.159.216:16252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/index.php"] [unique_id "apK9VddHPfW2QFvhmL7ThwAAAEY"] [Sat Aug 29 05:07:01.363722 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.48.250.41:21430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/h02ugyh.php"] [unique_id "apK9VddHPfW2QFvhmL7TiQAAAAE"] [Sat Aug 29 05:07:01.380020 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.151.200.44:46651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/dbc.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL5QAABeE"] [Sat Aug 29 05:07:01.385740 2026] [security2:error] [pid 1018003:tid 1018191] [client 168.107.94.195:55333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL5gAABeA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:01.392995 2026] [security2:error] [pid 1028675:tid 1028820] [client 63.179.191.156:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.jobindjibouti.com"] [uri "/jobs/"] [unique_id "apK9VddHPfW2QFvhmL7TigAAAAo"] [Sat Aug 29 05:07:01.439911 2026] [security2:error] [pid 1018003:tid 1018111] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9VTAh5Y1i2tUxg4EL6QAFx1o"] [Sat Aug 29 05:07:01.453872 2026] [security2:error] [pid 1028675:tid 1028858] [client 68.155.159.216:65126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-admin/about.php"] [unique_id "apK9VddHPfW2QFvhmL7TkQAAADA"] [Sat Aug 29 05:07:01.458018 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.48.160.90:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apK9VddHPfW2QFvhmL7TkgAAAB4"] [Sat Aug 29 05:07:01.463412 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.463439 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.466122 2026] [core:error] [pid 1018003:tid 1018031] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.466137 2026] [core:error] [pid 1018003:tid 1018031] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.468789 2026] [core:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.468802 2026] [core:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.470202 2026] [core:error] [pid 1018003:tid 1018026] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.470221 2026] [core:error] [pid 1018003:tid 1018026] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.470577 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.470590 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.482309 2026] [security2:error] [pid 1018003:tid 1018032] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9VTAh5Y1i2tUxg4EL8QAFxws"] [Sat Aug 29 05:07:01.491823 2026] [core:error] [pid 1028675:tid 1028926] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.491838 2026] [core:error] [pid 1028675:tid 1028926] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.519988 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.48.250.41:21328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/xxw.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL8wAABdw"] [Sat Aug 29 05:07:01.523650 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.52.41.200:1734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/c.php"] [unique_id "apK9VddHPfW2QFvhmL7TlAAAAEA"] [Sat Aug 29 05:07:01.531739 2026] [core:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.531751 2026] [core:error] [pid 1018003:tid 1018068] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.531753 2026] [core:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.531759 2026] [core:error] [pid 1018003:tid 1018068] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.531855 2026] [core:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.531864 2026] [core:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.558783 2026] [security2:error] [pid 1018003:tid 1018270] [client 158.23.147.79:17459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL9wAABi4"] [Sat Aug 29 05:07:01.559816 2026] [security2:error] [pid 1028675:tid 1028857] [client 68.155.159.216:6022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/file.php"] [unique_id "apK9VddHPfW2QFvhmL7TlwAAAC8"] [Sat Aug 29 05:07:01.564869 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.158.54.35:17997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "apK9VTAh5Y1i2tUxg4EL-AAABco"] [Sat Aug 29 05:07:01.568270 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.104.49.130:47868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/reop3.php"] [unique_id "apK9VddHPfW2QFvhmL7TmAAAAEE"] [Sat Aug 29 05:07:01.633141 2026] [security2:error] [pid 1018003:tid 1018177] [client 4.205.62.107:56030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/25.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMAQAABdI"] [Sat Aug 29 05:07:01.645349 2026] [core:error] [pid 1028675:tid 1028889] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.645372 2026] [core:error] [pid 1028675:tid 1028889] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.657493 2026] [core:error] [pid 1028675:tid 1028932] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.657509 2026] [core:error] [pid 1028675:tid 1028932] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.658999 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.659010 2026] [core:error] [pid 1028675:tid 1028906] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.660167 2026] [security2:error] [pid 1018003:tid 1018145] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9VTAh5Y1i2tUxg4EMAwAFy3w"] [Sat Aug 29 05:07:01.662570 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.662584 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.667409 2026] [security2:error] [pid 1028675:tid 1028893] [client 20.48.250.41:21418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/bolt.php"] [unique_id "apK9VddHPfW2QFvhmL7TpAAAAFM"] [Sat Aug 29 05:07:01.667573 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.667581 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.668068 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.158.54.35:16897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-load.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMBwAABek"] [Sat Aug 29 05:07:01.668718 2026] [core:error] [pid 1018003:tid 1018103] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.668733 2026] [core:error] [pid 1018003:tid 1018103] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.673835 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.196.209.81:15488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/wp-load.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMCAAABcI"] [Sat Aug 29 05:07:01.676325 2026] [security2:error] [pid 1018003:tid 1018196] [client 40.83.93.50:22786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMCQAABeU"] [Sat Aug 29 05:07:01.682703 2026] [core:error] [pid 1028675:tid 1028847] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.682715 2026] [core:error] [pid 1028675:tid 1028847] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.690106 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.48.160.90:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMCwAABb4"] [Sat Aug 29 05:07:01.690380 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.196.209.81:9755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/alfa-rex.php"] [unique_id "apK9VddHPfW2QFvhmL7TrgAAADw"] [Sat Aug 29 05:07:01.702732 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.702744 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.718586 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.23.147.79:30540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/cong.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMDAAABgE"] [Sat Aug 29 05:07:01.725677 2026] [security2:error] [pid 1028675:tid 1028835] [client 68.155.159.216:51865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9VddHPfW2QFvhmL7TsQAAABk"] [Sat Aug 29 05:07:01.725724 2026] [security2:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9VTAh5Y1i2tUxg4EMDQAFwxc"] [Sat Aug 29 05:07:01.727064 2026] [security2:error] [pid 1028675:tid 1028881] [client 40.83.93.50:7729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/csv.php"] [unique_id "apK9VddHPfW2QFvhmL7TsgAAAEc"] [Sat Aug 29 05:07:01.741732 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.196.209.81:11297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/goods.php"] [unique_id "apK9VddHPfW2QFvhmL7TtAAAAFI"] [Sat Aug 29 05:07:01.741798 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.197.61.180:8137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/xmlrpc.php0"] [unique_id "apK9VTAh5Y1i2tUxg4EMDgAABgI"] [Sat Aug 29 05:07:01.764968 2026] [security2:error] [pid 1028675:tid 1028933] [client 168.107.94.195:55724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9VddHPfW2QFvhmL7TtQAAAHs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:01.769158 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.23.147.79:59841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/login.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMDwAABdg"] [Sat Aug 29 05:07:01.786288 2026] [security2:error] [pid 1018003:tid 1018265] [client 68.155.159.216:65124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMEgAABik"] [Sat Aug 29 05:07:01.787066 2026] [security2:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9VTAh5Y1i2tUxg4EMEAAGGko"] [Sat Aug 29 05:07:01.822459 2026] [core:error] [pid 1018003:tid 1018153] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.822471 2026] [core:error] [pid 1018003:tid 1018153] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.829543 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.151.200.44:47316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/wp-wlx.php"] [unique_id "apK9VddHPfW2QFvhmL7TvAAAAAg"] [Sat Aug 29 05:07:01.830836 2026] [security2:error] [pid 1028675:tid 1028931] [client 20.48.250.41:21429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/rtx.php"] [unique_id "apK9VddHPfW2QFvhmL7TvQAAAHk"] [Sat Aug 29 05:07:01.848227 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.23.147.79:26575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/login.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMHAAABb0"] [Sat Aug 29 05:07:01.849182 2026] [core:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.849197 2026] [core:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.870074 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.48.160.90:51284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-settings.php"] [unique_id "apK9VddHPfW2QFvhmL7TxQAAAE0"] [Sat Aug 29 05:07:01.874550 2026] [security2:error] [pid 1018003:tid 1018048] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9VTAh5Y1i2tUxg4EMIQAGKhs"] [Sat Aug 29 05:07:01.875871 2026] [security2:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9VTAh5Y1i2tUxg4EMIgAGKhI"] [Sat Aug 29 05:07:01.876531 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.876547 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.876727 2026] [core:error] [pid 1028675:tid 1028856] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.876737 2026] [core:error] [pid 1028675:tid 1028856] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.878640 2026] [core:error] [pid 1028675:tid 1028814] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.878654 2026] [core:error] [pid 1028675:tid 1028814] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.878980 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.878988 2026] [core:error] [pid 1018003:tid 1018192] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.902140 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.902161 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.902403 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.902433 2026] [core:error] [pid 1028675:tid 1028831] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.939953 2026] [security2:error] [pid 1028675:tid 1028880] [client 158.23.147.79:49985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/.well-known/index.php"] [unique_id "apK9VddHPfW2QFvhmL7TzAAAAEY"] [Sat Aug 29 05:07:01.942520 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.147.79:35222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/goat.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMKgAABfA"] [Sat Aug 29 05:07:01.951323 2026] [security2:error] [pid 1018003:tid 1018037] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9VTAh5Y1i2tUxg4EMLwAGLhA"] [Sat Aug 29 05:07:01.955277 2026] [core:error] [pid 1018003:tid 1018075] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.955298 2026] [core:error] [pid 1018003:tid 1018075] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.971402 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.971420 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.973281 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.147.79:25410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/themes.php"] [unique_id "apK9VTAh5Y1i2tUxg4EMMgAABjM"] [Sat Aug 29 05:07:01.976150 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.976178 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:01.982902 2026] [security2:error] [pid 1028675:tid 1028888] [client 68.155.159.216:12125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9VddHPfW2QFvhmL7T0wAAAE4"] [Sat Aug 29 05:07:01.983552 2026] [security2:error] [pid 1028675:tid 1028833] [client 20.52.41.200:1205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/f.php"] [unique_id "apK9VddHPfW2QFvhmL7T1AAAABc"] [Sat Aug 29 05:07:01.992470 2026] [security2:error] [pid 1028675:tid 1028858] [client 4.205.62.107:22465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/php-info.php"] [unique_id "apK9VddHPfW2QFvhmL7T1QAAADA"] [Sat Aug 29 05:07:01.996309 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.48.250.41:21312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/ckk.php"] [unique_id "apK9VddHPfW2QFvhmL7T1gAAAB4"] [Sat Aug 29 05:07:02.018821 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.018839 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.031113 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.203.141.11:23667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/install.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMNQAABek"] [Sat Aug 29 05:07:02.041037 2026] [security2:error] [pid 1028675:tid 1028915] [client 158.158.54.35:38457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/css/wp-login.php"] [unique_id "apK9VtdHPfW2QFvhmL7T3QAAAGk"] [Sat Aug 29 05:07:02.059446 2026] [security2:error] [pid 1028675:tid 1028842] [client 158.23.147.79:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK9VtdHPfW2QFvhmL7T4AAAACA"] [Sat Aug 29 05:07:02.060436 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.48.160.90:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-signup.php"] [unique_id "apK9VtdHPfW2QFvhmL7T4QAAAE8"] [Sat Aug 29 05:07:02.067584 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:30488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMNgAABc8"] [Sat Aug 29 05:07:02.073377 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.196.209.81:13126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMOAAABdw"] [Sat Aug 29 05:07:02.086199 2026] [security2:error] [pid 1028675:tid 1028908] [client 68.155.159.216:50350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/packed.php"] [unique_id "apK9VtdHPfW2QFvhmL7T5QAAAGI"] [Sat Aug 29 05:07:02.087146 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.196.209.81:14653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/cookie.php"] [unique_id "apK9VtdHPfW2QFvhmL7T5gAAABI"] [Sat Aug 29 05:07:02.089029 2026] [security2:error] [pid 1028675:tid 1028891] [client 195.178.110.105:58334] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "landonrian.com"] [uri "/wp/"] [unique_id "apK9VtdHPfW2QFvhmL7T5AAAAFE"] [Sat Aug 29 05:07:02.109675 2026] [core:error] [pid 1018003:tid 1018050] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.109692 2026] [core:error] [pid 1018003:tid 1018050] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.134054 2026] [security2:error] [pid 1028675:tid 1028816] [client 158.23.147.79:32681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/admin.php"] [unique_id "apK9VtdHPfW2QFvhmL7T6QAAAAY"] [Sat Aug 29 05:07:02.135015 2026] [core:error] [pid 1028675:tid 1028826] [client 158.158.54.35:8730] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.135034 2026] [core:error] [pid 1028675:tid 1028826] [client 158.158.54.35:8730] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.142679 2026] [security2:error] [pid 1028675:tid 1028899] [client 40.83.93.50:13577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK9VtdHPfW2QFvhmL7T6gAAAFk"] [Sat Aug 29 05:07:02.145636 2026] [security2:error] [pid 1028675:tid 1028902] [client 168.107.94.195:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9VtdHPfW2QFvhmL7T6wAAAFw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:02.149810 2026] [core:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.149825 2026] [core:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.150384 2026] [core:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.150399 2026] [core:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.172604 2026] [core:error] [pid 1018003:tid 1018040] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.172622 2026] [core:error] [pid 1018003:tid 1018040] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.173884 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.173896 2026] [core:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.174341 2026] [core:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.174350 2026] [core:error] [pid 1018003:tid 1018060] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.200847 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.48.160.90:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-conffg.php"] [unique_id "apK9VtdHPfW2QFvhmL7T7gAAAEs"] [Sat Aug 29 05:07:02.208941 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.48.250.41:21433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fpm.net.cn"] [uri "/R57.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMRgAABdg"] [Sat Aug 29 05:07:02.210687 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.210702 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.211925 2026] [core:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.211942 2026] [core:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.215678 2026] [security2:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMSAAGKXM"] [Sat Aug 29 05:07:02.216968 2026] [core:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.216980 2026] [core:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.229853 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.196.209.81:1985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/hehe.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMSwAABhA"] [Sat Aug 29 05:07:02.230561 2026] [security2:error] [pid 1018003:tid 1018056] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMSQAGKSM"] [Sat Aug 29 05:07:02.233117 2026] [security2:error] [pid 1018003:tid 1018104] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMTAAGKVM"] [Sat Aug 29 05:07:02.234969 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.234983 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.256689 2026] [core:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.256708 2026] [core:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.257176 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.257187 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.272733 2026] [security2:error] [pid 1028675:tid 1028882] [client 40.83.93.50:7684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/fox.php"] [unique_id "apK9VtdHPfW2QFvhmL7T9QAAAEg"] [Sat Aug 29 05:07:02.288404 2026] [security2:error] [pid 1028675:tid 1028933] [client 68.155.159.216:49230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9VtdHPfW2QFvhmL7T9wAAAHs"] [Sat Aug 29 05:07:02.306951 2026] [security2:error] [pid 1028675:tid 1028877] [client 4.205.62.107:22467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/sgd.php"] [unique_id "apK9VtdHPfW2QFvhmL7T-QAAAEM"] [Sat Aug 29 05:07:02.319576 2026] [security2:error] [pid 1028675:tid 1028867] [client 4.205.62.107:65442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/maxro.php"] [unique_id "apK9VtdHPfW2QFvhmL7T-gAAADk"] [Sat Aug 29 05:07:02.323212 2026] [security2:error] [pid 1018003:tid 1018089] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMUAAGCkQ"] [Sat Aug 29 05:07:02.325136 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.325153 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.325154 2026] [core:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.325164 2026] [core:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.330712 2026] [security2:error] [pid 1028675:tid 1028845] [client 4.205.62.107:58404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/gnmlc.php"] [unique_id "apK9VtdHPfW2QFvhmL7T-wAAACM"] [Sat Aug 29 05:07:02.344769 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.151.200.44:45915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/attack.php"] [unique_id "apK9VtdHPfW2QFvhmL7T_AAAACw"] [Sat Aug 29 05:07:02.355611 2026] [security2:error] [pid 1028675:tid 1028887] [client 158.23.147.79:48133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-mail.php"] [unique_id "apK9VtdHPfW2QFvhmL7T_QAAAE0"] [Sat Aug 29 05:07:02.362410 2026] [core:error] [pid 1018003:tid 1018038] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.362434 2026] [core:error] [pid 1018003:tid 1018038] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.373285 2026] [security2:error] [pid 1028675:tid 1028810] [client 20.48.160.90:51700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-validate.php"] [unique_id "apK9VtdHPfW2QFvhmL7T_wAAAAA"] [Sat Aug 29 05:07:02.383077 2026] [core:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.383091 2026] [core:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.383156 2026] [core:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.383167 2026] [core:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.383643 2026] [security2:error] [pid 1018003:tid 1018025] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMWAAGDwQ"] [Sat Aug 29 05:07:02.384576 2026] [core:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.384594 2026] [core:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.385058 2026] [core:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.385067 2026] [core:error] [pid 1018003:tid 1018114] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.410385 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.410403 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.410402 2026] [core:error] [pid 1028675:tid 1028823] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.410411 2026] [core:error] [pid 1028675:tid 1028823] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.411949 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.411965 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.413673 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.413686 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.431776 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.49.130:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/az.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMXQAABb0"] [Sat Aug 29 05:07:02.445648 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.52.41.200:1167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/av.php"] [unique_id "apK9VtdHPfW2QFvhmL7UDAAAACY"] [Sat Aug 29 05:07:02.451069 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.197.61.180:18322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/content.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMXgAABjE"] [Sat Aug 29 05:07:02.457934 2026] [security2:error] [pid 1028675:tid 1028839] [client 68.155.159.216:16199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/about/function.php"] [unique_id "apK9VtdHPfW2QFvhmL7UDgAAAB0"] [Sat Aug 29 05:07:02.473823 2026] [security2:error] [pid 1028675:tid 1028913] [client 158.158.54.35:22095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/images/index.php"] [unique_id "apK9VtdHPfW2QFvhmL7UEgAAAGc"] [Sat Aug 29 05:07:02.483939 2026] [security2:error] [pid 1028675:tid 1028909] [client 20.196.209.81:17199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "apK9VtdHPfW2QFvhmL7UFAAAAGM"] [Sat Aug 29 05:07:02.489441 2026] [core:error] [pid 1028675:tid 1028841] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.489460 2026] [core:error] [pid 1028675:tid 1028841] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.490209 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.490219 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.493529 2026] [security2:error] [pid 1028675:tid 1028935] [client 4.205.62.107:53387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/ms-edit.php"] [unique_id "apK9VtdHPfW2QFvhmL7UGAAAAH0"] [Sat Aug 29 05:07:02.495484 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.495505 2026] [core:error] [pid 1028675:tid 1028900] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.503131 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.196.209.81:9762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/NewFile.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMYwAABec"] [Sat Aug 29 05:07:02.526230 2026] [security2:error] [pid 1028675:tid 1028936] [client 168.107.94.195:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9VtdHPfW2QFvhmL7UGQAAAH4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:02.555006 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.48.160.90:51710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/700.php"] [unique_id "apK9VtdHPfW2QFvhmL7UGgAAAGw"] [Sat Aug 29 05:07:02.563805 2026] [security2:error] [pid 1028675:tid 1028838] [client 68.155.159.216:65055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9VtdHPfW2QFvhmL7UGwAAABw"] [Sat Aug 29 05:07:02.576747 2026] [security2:error] [pid 1028675:tid 1028831] [client 20.203.141.11:1364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/ioxi-o.php"] [unique_id "apK9VtdHPfW2QFvhmL7UHAAAABU"] [Sat Aug 29 05:07:02.587721 2026] [security2:error] [pid 1028675:tid 1028926] [client 158.158.54.35:2879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/a.php"] [unique_id "apK9VtdHPfW2QFvhmL7UHQAAAHQ"] [Sat Aug 29 05:07:02.606732 2026] [security2:error] [pid 1018003:tid 1018028] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9VjAh5Y1i2tUxg4EMZAAFygc"] [Sat Aug 29 05:07:02.607628 2026] [core:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.607645 2026] [core:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.609686 2026] [security2:error] [pid 1028675:tid 1028844] [client 40.83.93.50:22824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/security.php"] [unique_id "apK9VtdHPfW2QFvhmL7UHgAAACI"] [Sat Aug 29 05:07:02.626200 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.626214 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.636020 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.636031 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.662231 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.196.209.81:15198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/wp-admin/class-db.php"] [unique_id "apK9VtdHPfW2QFvhmL7UJwAAAHc"] [Sat Aug 29 05:07:02.663451 2026] [security2:error] [pid 1028675:tid 1028861] [client 158.23.147.79:17450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/makeasmtp.php"] [unique_id "apK9VtdHPfW2QFvhmL7UKAAAADM"] [Sat Aug 29 05:07:02.674798 2026] [security2:error] [pid 1028675:tid 1028877] [client 195.178.110.105:58334] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "landonrian.com"] [uri "/wordpress/"] [unique_id "apK9VtdHPfW2QFvhmL7UKQAAAEM"] [Sat Aug 29 05:07:02.685408 2026] [security2:error] [pid 1018003:tid 1018230] [client 68.155.159.216:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/file17.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMawAABgY"] [Sat Aug 29 05:07:02.705980 2026] [security2:error] [pid 1018003:tid 1018148] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/test.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMbAAGLn8"] [Sat Aug 29 05:07:02.706984 2026] [security2:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMbQAGLj8"] [Sat Aug 29 05:07:02.709063 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.48.160.90:51318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/c4.php"] [unique_id "apK9VtdHPfW2QFvhmL7UKwAAAAg"] [Sat Aug 29 05:07:02.734723 2026] [cgid:error] [pid 1028675:tid 1028918] [client 34.7.40.70:9626] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.734975 2026] [security2:error] [pid 1018003:tid 1018166] [client 34.7.40.70:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/sendgrid/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMcQAABcc"] [Sat Aug 29 05:07:02.735056 2026] [security2:error] [pid 1018003:tid 1018166] [client 34.7.40.70:9716] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/sendgrid/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMcQAABcc"] [Sat Aug 29 05:07:02.735351 2026] [cgid:error] [pid 1028675:tid 1028908] [client 34.7.40.70:9636] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.735471 2026] [security2:error] [pid 1028675:tid 1028893] [client 34.7.40.70:9702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/var/www/html/.env"] [unique_id "apK9VtdHPfW2QFvhmL7UMAAAAFM"] [Sat Aug 29 05:07:02.735668 2026] [security2:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMcgAF6Vc"] [Sat Aug 29 05:07:02.737510 2026] [cgid:error] [pid 1028675:tid 1028826] [client 34.7.40.70:9762] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.737870 2026] [security2:error] [pid 1018003:tid 1018101] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMdQAF6VA"] [Sat Aug 29 05:07:02.738132 2026] [cgid:error] [pid 1028675:tid 1028816] [client 34.7.40.70:9708] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.738373 2026] [cgid:error] [pid 1028675:tid 1028815] [client 34.7.40.70:9664] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.738492 2026] [cgid:error] [pid 1028675:tid 1028821] [client 34.7.40.70:9680] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.739013 2026] [security2:error] [pid 1028675:tid 1028821] [client 34.7.40.70:9680] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9VtdHPfW2QFvhmL7UNwAAAAs"] [Sat Aug 29 05:07:02.745555 2026] [core:error] [pid 1028675:tid 1028865] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.745567 2026] [core:error] [pid 1028675:tid 1028865] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.748969 2026] [core:error] [pid 1028675:tid 1028905] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.748981 2026] [core:error] [pid 1028675:tid 1028905] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.749416 2026] [security2:error] [pid 1028675:tid 1028899] [client 34.7.40.70:9770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/stripe/.env"] [unique_id "apK9VtdHPfW2QFvhmL7UPgAAAFk"] [Sat Aug 29 05:07:02.750459 2026] [cgid:error] [pid 1028675:tid 1028872] [client 34.7.40.70:9732] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.750610 2026] [cgid:error] [pid 1028675:tid 1028891] [client 34.7.40.70:9660] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.750839 2026] [security2:error] [pid 1018003:tid 1018207] [client 34.7.40.70:9692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/var/www/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMeAAABfA"] [Sat Aug 29 05:07:02.751042 2026] [security2:error] [pid 1028675:tid 1028927] [client 34.7.40.70:9736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/mail/.env"] [unique_id "apK9VtdHPfW2QFvhmL7UQAAAAHU"] [Sat Aug 29 05:07:02.751466 2026] [cgid:error] [pid 1028675:tid 1028902] [client 34.7.40.70:9754] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.758734 2026] [cgid:error] [pid 1028675:tid 1028828] [client 34.7.40.70:9652] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:02.760683 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.760694 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.760694 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.760702 2026] [core:error] [pid 1018003:tid 1018226] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.765587 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.765604 2026] [core:error] [pid 1018003:tid 1018224] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.766740 2026] [security2:error] [pid 1028675:tid 1028921] [client 34.7.40.70:9746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/email/.env"] [unique_id "apK9VtdHPfW2QFvhmL7UQgAAAG8"] [Sat Aug 29 05:07:02.770273 2026] [security2:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMfAAF6Wk"] [Sat Aug 29 05:07:02.771223 2026] [security2:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9VjAh5Y1i2tUxg4EMfQAF6QE"] [Sat Aug 29 05:07:02.771876 2026] [security2:error] [pid 1018003:tid 1018216] [client 4.205.62.107:55958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/nlnub.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMfwAABfk"] [Sat Aug 29 05:07:02.792029 2026] [security2:error] [pid 1028675:tid 1028835] [client 40.83.93.50:7701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/disagraeosc.php"] [unique_id "apK9VtdHPfW2QFvhmL7URgAAABk"] [Sat Aug 29 05:07:02.803929 2026] [security2:error] [pid 1028675:tid 1028907] [client 68.155.159.216:2004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-admin/about.php"] [unique_id "apK9VtdHPfW2QFvhmL7USQAAAGE"] [Sat Aug 29 05:07:02.808270 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.151.200.44:47297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/file66.php"] [unique_id "apK9VtdHPfW2QFvhmL7USgAAAGQ"] [Sat Aug 29 05:07:02.814757 2026] [core:error] [pid 1028675:tid 1028836] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.814769 2026] [core:error] [pid 1028675:tid 1028836] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.825241 2026] [security2:error] [pid 1028675:tid 1028898] [client 158.23.147.79:30527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/index.php"] [unique_id "apK9VtdHPfW2QFvhmL7UTQAAAFg"] [Sat Aug 29 05:07:02.834753 2026] [security2:error] [pid 1028675:tid 1028924] [client 68.155.159.216:51873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9VtdHPfW2QFvhmL7UTgAAAHI"] [Sat Aug 29 05:07:02.858348 2026] [security2:error] [pid 1028675:tid 1028913] [client 20.48.160.90:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-tymanage.php"] [unique_id "apK9VtdHPfW2QFvhmL7UUAAAAGc"] [Sat Aug 29 05:07:02.874042 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.874059 2026] [core:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.881584 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.881614 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.899252 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.899273 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.899481 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.52.41.200:1202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/file.php"] [unique_id "apK9VtdHPfW2QFvhmL7UVQAAAAQ"] [Sat Aug 29 05:07:02.900851 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.900849 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.900865 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.900867 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.902791 2026] [security2:error] [pid 1028675:tid 1028876] [client 20.196.209.81:5833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK9VtdHPfW2QFvhmL7UVgAAAEI"] [Sat Aug 29 05:07:02.905920 2026] [security2:error] [pid 1018003:tid 1018277] [client 168.107.94.195:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9VjAh5Y1i2tUxg4EMjQAABjU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:02.917662 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.917682 2026] [core:error] [pid 1018003:tid 1018250] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.939291 2026] [security2:error] [pid 1028675:tid 1028888] [client 20.196.209.81:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/config.php"] [unique_id "apK9VtdHPfW2QFvhmL7UXQAAAE4"] [Sat Aug 29 05:07:02.941922 2026] [core:error] [pid 1018003:tid 1018098] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.941957 2026] [core:error] [pid 1018003:tid 1018098] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.951795 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.951811 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.952477 2026] [core:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.952496 2026] [core:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.960572 2026] [core:error] [pid 1028675:tid 1028885] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.960588 2026] [core:error] [pid 1028675:tid 1028885] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.970900 2026] [security2:error] [pid 1028675:tid 1028824] [client 158.23.147.79:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/hehehehe.php"] [unique_id "apK9VtdHPfW2QFvhmL7UawAAAA4"] [Sat Aug 29 05:07:02.978516 2026] [core:error] [pid 1028675:tid 1028904] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.978532 2026] [core:error] [pid 1028675:tid 1028904] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.978659 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.978671 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.983880 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:02.983898 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.000212 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.48.160.90:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/ajfto.php"] [unique_id "apK9VtdHPfW2QFvhmL7UbwAAAEQ"] [Sat Aug 29 05:07:03.002339 2026] [security2:error] [pid 1018003:tid 1018156] [client 52.139.37.240:21158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMlwAABb0"] [Sat Aug 29 05:07:03.009216 2026] [security2:error] [pid 1028675:tid 1028822] [client 213.202.253.4:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/filefuns.php"] [unique_id "apK9V9dHPfW2QFvhmL7UcAAAAAw"], referer: www.google.com [Sat Aug 29 05:07:03.030539 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.158.54.35:20326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/u.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMmAAABiw"] [Sat Aug 29 05:07:03.043083 2026] [security2:error] [pid 1028675:tid 1028920] [client 158.23.147.79:53766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/hehehehe.php"] [unique_id "apK9V9dHPfW2QFvhmL7UcgAAAG4"] [Sat Aug 29 05:07:03.043422 2026] [security2:error] [pid 1028675:tid 1028812] [client 52.139.37.240:31100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/ac.php"] [unique_id "apK9V9dHPfW2QFvhmL7UcQAAAAI"] [Sat Aug 29 05:07:03.056119 2026] [security2:error] [pid 1028675:tid 1028918] [client 158.23.147.79:50061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9V9dHPfW2QFvhmL7UcwAAAGw"] [Sat Aug 29 05:07:03.063603 2026] [security2:error] [pid 1028675:tid 1028810] [client 158.23.147.79:35726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9V9dHPfW2QFvhmL7UdAAAAAA"] [Sat Aug 29 05:07:03.064942 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.196.209.81:15205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/wp-contentt.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMmgAABhY"] [Sat Aug 29 05:07:03.068278 2026] [security2:error] [pid 1028675:tid 1028925] [client 52.139.37.240:33552] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "superresources.com"] [uri "/c99.php"] [unique_id "apK9V9dHPfW2QFvhmL7UdgAAAHM"] [Sat Aug 29 05:07:03.069397 2026] [security2:error] [pid 1028675:tid 1028865] [client 158.158.54.35:9765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/inputs.php"] [unique_id "apK9V9dHPfW2QFvhmL7UeAAAADc"] [Sat Aug 29 05:07:03.072258 2026] [security2:error] [pid 1018003:tid 1018261] [client 52.139.37.240:2570] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "fairfaxbible.org"] [uri "/c99.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMnAAABiU"] [Sat Aug 29 05:07:03.091902 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.091916 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.091963 2026] [security2:error] [pid 1028675:tid 1028887] [client 158.23.147.79:25492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-mail.php"] [unique_id "apK9V9dHPfW2QFvhmL7UeQAAAE0"] [Sat Aug 29 05:07:03.091966 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.091975 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.100216 2026] [security2:error] [pid 1028675:tid 1028912] [client 40.83.93.50:20833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9V9dHPfW2QFvhmL7UewAAAGY"] [Sat Aug 29 05:07:03.108092 2026] [security2:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9VzAh5Y1i2tUxg4EMowAGM2M"] [Sat Aug 29 05:07:03.119739 2026] [security2:error] [pid 1018003:tid 1018140] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9VzAh5Y1i2tUxg4EMpAAF_Hc"] [Sat Aug 29 05:07:03.121189 2026] [core:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.121206 2026] [core:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.121470 2026] [security2:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9VzAh5Y1i2tUxg4EMpwAF_Gs"] [Sat Aug 29 05:07:03.122843 2026] [core:error] [pid 1018003:tid 1018113] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.122854 2026] [core:error] [pid 1018003:tid 1018113] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.122899 2026] [core:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.122906 2026] [core:error] [pid 1018003:tid 1018093] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.124178 2026] [core:error] [pid 1018003:tid 1018117] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.124190 2026] [core:error] [pid 1018003:tid 1018117] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.124259 2026] [core:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.124267 2026] [core:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.125200 2026] [core:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.125213 2026] [core:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.130259 2026] [security2:error] [pid 1028675:tid 1028891] [client 4.205.62.107:22445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/infos.php"] [unique_id "apK9V9dHPfW2QFvhmL7UfgAAAFE"] [Sat Aug 29 05:07:03.141864 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.104.49.130:29961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/f35.update.php"] [unique_id "apK9V9dHPfW2QFvhmL7UfwAAAG8"] [Sat Aug 29 05:07:03.143675 2026] [security2:error] [pid 1028675:tid 1028917] [client 68.155.159.216:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9V9dHPfW2QFvhmL7UgQAAAGs"] [Sat Aug 29 05:07:03.144929 2026] [core:error] [pid 1028675:tid 1028896] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.144940 2026] [core:error] [pid 1028675:tid 1028896] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.148112 2026] [security2:error] [pid 1028675:tid 1028871] [client 68.155.159.216:38555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/NewFile.php/"] [unique_id "apK9V9dHPfW2QFvhmL7UggAAAD0"] [Sat Aug 29 05:07:03.156193 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.197.61.180:9709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/wxo.php"] [unique_id "apK9V9dHPfW2QFvhmL7UhQAAAFA"] [Sat Aug 29 05:07:03.160168 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.151.200.44:46583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/zafir1.php"] [unique_id "apK9V9dHPfW2QFvhmL7UhgAAADI"] [Sat Aug 29 05:07:03.168464 2026] [security2:error] [pid 1028675:tid 1028933] [client 103.240.76.112:42707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9V9dHPfW2QFvhmL7UhwAAAHs"] [Sat Aug 29 05:07:03.168553 2026] [security2:error] [pid 1028675:tid 1028933] [client 103.240.76.112:42707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9V9dHPfW2QFvhmL7UhwAAAHs"] [Sat Aug 29 05:07:03.172607 2026] [security2:error] [pid 1028675:tid 1028855] [client 158.23.147.79:30476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/about/function.php"] [unique_id "apK9V9dHPfW2QFvhmL7UiAAAAC0"] [Sat Aug 29 05:07:03.174991 2026] [security2:error] [pid 1028675:tid 1028906] [client 20.203.141.11:9992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/xmlrpc.php"] [unique_id "apK9V9dHPfW2QFvhmL7UfQAAAGA"] [Sat Aug 29 05:07:03.194737 2026] [security2:error] [pid 1028675:tid 1028852] [client 52.139.37.240:20772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/zafir1.php"] [unique_id "apK9V9dHPfW2QFvhmL7UiQAAACo"] [Sat Aug 29 05:07:03.214841 2026] [security2:error] [pid 1028675:tid 1028894] [client 158.23.147.79:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/ans.php"] [unique_id "apK9V9dHPfW2QFvhmL7UkAAAAFQ"] [Sat Aug 29 05:07:03.239485 2026] [security2:error] [pid 1028675:tid 1028862] [client 52.139.37.240:31675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/ctex1.php"] [unique_id "apK9V9dHPfW2QFvhmL7UkgAAADQ"] [Sat Aug 29 05:07:03.242348 2026] [security2:error] [pid 1028675:tid 1028923] [client 158.23.147.79:32678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9V9dHPfW2QFvhmL7UkwAAAHE"] [Sat Aug 29 05:07:03.259747 2026] [security2:error] [pid 1028675:tid 1028858] [client 52.139.37.240:2248] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "fairfaxbible.org"] [uri "/c99.php"] [unique_id "apK9V9dHPfW2QFvhmL7UlgAAADA"] [Sat Aug 29 05:07:03.282586 2026] [security2:error] [pid 1028675:tid 1028913] [client 52.139.37.240:32832] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "superresources.com"] [uri "/c99.php"] [unique_id "apK9V9dHPfW2QFvhmL7UnQAAAGc"] [Sat Aug 29 05:07:03.284500 2026] [security2:error] [pid 1028675:tid 1028900] [client 195.178.110.105:58334] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "landonrian.com"] [uri "/blog/"] [unique_id "apK9V9dHPfW2QFvhmL7UnAAAAFo"] [Sat Aug 29 05:07:03.285255 2026] [security2:error] [pid 1028675:tid 1028901] [client 168.107.94.195:57488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9V9dHPfW2QFvhmL7UngAAAFs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:03.294468 2026] [security2:error] [pid 1028675:tid 1028927] [client 40.83.93.50:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/about.php525"] [unique_id "apK9V9dHPfW2QFvhmL7UnwAAAHU"] [Sat Aug 29 05:07:03.296214 2026] [security2:error] [pid 1028675:tid 1028833] [client 20.196.209.81:22401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-blog-header.php"] [unique_id "apK9V9dHPfW2QFvhmL7UoAAAABc"] [Sat Aug 29 05:07:03.298628 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.48.160.90:51686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apK9V9dHPfW2QFvhmL7UoQAAAA8"] [Sat Aug 29 05:07:03.313803 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.104.49.130:57476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/ab.php"] [unique_id "apK9V9dHPfW2QFvhmL7UogAAACU"] [Sat Aug 29 05:07:03.330209 2026] [core:error] [pid 1018003:tid 1018045] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.330223 2026] [core:error] [pid 1018003:tid 1018045] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.353648 2026] [security2:error] [pid 1028675:tid 1028836] [client 20.52.41.200:1408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9V9dHPfW2QFvhmL7UpAAAABo"] [Sat Aug 29 05:07:03.357509 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.196.209.81:9624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/22.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMtAAABiI"] [Sat Aug 29 05:07:03.361640 2026] [security2:error] [pid 1028675:tid 1028830] [client 20.104.49.130:43635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/talkxkej.php"] [unique_id "apK9V9dHPfW2QFvhmL7UpQAAABQ"] [Sat Aug 29 05:07:03.366491 2026] [security2:error] [pid 1028675:tid 1028875] [client 158.23.147.79:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/worksec.php"] [unique_id "apK9V9dHPfW2QFvhmL7UpgAAAEE"] [Sat Aug 29 05:07:03.394899 2026] [security2:error] [pid 1028675:tid 1028885] [client 52.139.37.240:21123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/abc.php"] [unique_id "apK9V9dHPfW2QFvhmL7UpwAAAEs"] [Sat Aug 29 05:07:03.403154 2026] [core:error] [pid 1028675:tid 1028859] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.403166 2026] [core:error] [pid 1028675:tid 1028859] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.430816 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.48.250.41:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMuAAABiY"] [Sat Aug 29 05:07:03.444982 2026] [security2:error] [pid 1018003:tid 1018167] [client 4.205.62.107:22041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/gecko-litespeed.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMugAABcg"] [Sat Aug 29 05:07:03.452450 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.452464 2026] [core:error] [pid 1018003:tid 1018196] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.454559 2026] [security2:error] [pid 1018003:tid 1018187] [client 52.139.37.240:2899] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "fairfaxbible.org"] [uri "/c99.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMvAAABdw"] [Sat Aug 29 05:07:03.456847 2026] [security2:error] [pid 1028675:tid 1028818] [client 4.205.62.107:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/brc.php"] [unique_id "apK9V9dHPfW2QFvhmL7UswAAAAg"] [Sat Aug 29 05:07:03.458981 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.48.160.90:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apK9V9dHPfW2QFvhmL7UtQAAACw"] [Sat Aug 29 05:07:03.460256 2026] [core:error] [pid 1028675:tid 1028914] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.460273 2026] [core:error] [pid 1028675:tid 1028914] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.462078 2026] [security2:error] [pid 1028675:tid 1028831] [client 158.158.54.35:20586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/r.php"] [unique_id "apK9V9dHPfW2QFvhmL7UtgAAABU"] [Sat Aug 29 05:07:03.470164 2026] [security2:error] [pid 1028675:tid 1028812] [client 4.205.62.107:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/wp-access.php"] [unique_id "apK9V9dHPfW2QFvhmL7UtwAAAAI"] [Sat Aug 29 05:07:03.476925 2026] [security2:error] [pid 1028675:tid 1028937] [client 52.139.37.240:31105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/defaults.php"] [unique_id "apK9V9dHPfW2QFvhmL7UuAAAAH8"] [Sat Aug 29 05:07:03.484993 2026] [security2:error] [pid 1018003:tid 1018026] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/wp-config.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMwQAFywU"] [Sat Aug 29 05:07:03.485957 2026] [security2:error] [pid 1018003:tid 1018031] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9VzAh5Y1i2tUxg4EMvwAFywo"] [Sat Aug 29 05:07:03.487871 2026] [core:error] [pid 1018003:tid 1018111] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.487887 2026] [core:error] [pid 1018003:tid 1018111] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.494760 2026] [security2:error] [pid 1018003:tid 1018032] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/wp-config.php.bak"] [unique_id "apK9VzAh5Y1i2tUxg4EMwgAFyws"] [Sat Aug 29 05:07:03.510131 2026] [security2:error] [pid 1028675:tid 1028916] [client 158.158.54.35:9770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/alfa.php"] [unique_id "apK9V9dHPfW2QFvhmL7UuwAAAGo"] [Sat Aug 29 05:07:03.520675 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.520692 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.527108 2026] [security2:error] [pid 1018003:tid 1018147] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/wp-config.php.new"] [unique_id "apK9VzAh5Y1i2tUxg4EMxQAFy34"] [Sat Aug 29 05:07:03.529310 2026] [security2:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/wp-config.php.old"] [unique_id "apK9VzAh5Y1i2tUxg4EMxgAFyw8"] [Sat Aug 29 05:07:03.530696 2026] [security2:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:58270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9VzAh5Y1i2tUxg4EMyAAFy20"] [Sat Aug 29 05:07:03.531526 2026] [core:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.531537 2026] [core:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.537796 2026] [core:error] [pid 1018003:tid 1018068] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.537810 2026] [core:error] [pid 1018003:tid 1018068] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.542161 2026] [core:error] [pid 1028675:tid 1028810] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.542173 2026] [core:error] [pid 1028675:tid 1028810] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.545914 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMygAABdc"] [Sat Aug 29 05:07:03.547922 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.196.209.81:2033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/theme.php"] [unique_id "apK9V9dHPfW2QFvhmL7UvQAAAFI"] [Sat Aug 29 05:07:03.569732 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.569744 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.569876 2026] [security2:error] [pid 1028675:tid 1028860] [client 68.155.159.216:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9V9dHPfW2QFvhmL7UvgAAADI"] [Sat Aug 29 05:07:03.588802 2026] [security2:error] [pid 1028675:tid 1028887] [client 52.139.37.240:21416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/c1.php"] [unique_id "apK9V9dHPfW2QFvhmL7UvwAAAE0"] [Sat Aug 29 05:07:03.602420 2026] [security2:error] [pid 1028675:tid 1028861] [client 40.83.93.50:22840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/system.php"] [unique_id "apK9V9dHPfW2QFvhmL7UwAAAADM"] [Sat Aug 29 05:07:03.612642 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.48.160.90:51625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apK9V9dHPfW2QFvhmL7UwgAAAEo"] [Sat Aug 29 05:07:03.614157 2026] [security2:error] [pid 1028675:tid 1028852] [client 20.48.250.41:62579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9V9dHPfW2QFvhmL7UwwAAACo"] [Sat Aug 29 05:07:03.638981 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.203.141.11:45444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/filemanager.php"] [unique_id "apK9V9dHPfW2QFvhmL7UxAAAAGw"] [Sat Aug 29 05:07:03.664638 2026] [security2:error] [pid 1018003:tid 1018189] [client 168.107.94.195:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9VzAh5Y1i2tUxg4EMzwAABd4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:03.672519 2026] [security2:error] [pid 1028675:tid 1028923] [client 4.205.62.107:53411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/avim.php"] [unique_id "apK9V9dHPfW2QFvhmL7UxwAAAHE"] [Sat Aug 29 05:07:03.675497 2026] [security2:error] [pid 1018003:tid 1018152] [client 68.155.159.216:65040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM0AAABbk"] [Sat Aug 29 05:07:03.683762 2026] [security2:error] [pid 1018003:tid 1018162] [client 60.243.207.176:61892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM0gAABcM"] [Sat Aug 29 05:07:03.683866 2026] [security2:error] [pid 1018003:tid 1018162] [client 60.243.207.176:61892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM0gAABcM"] [Sat Aug 29 05:07:03.687921 2026] [security2:error] [pid 1028675:tid 1028896] [client 20.196.209.81:22414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-blogs.php"] [unique_id "apK9V9dHPfW2QFvhmL7UyAAAAFY"] [Sat Aug 29 05:07:03.692462 2026] [security2:error] [pid 1028675:tid 1028924] [client 52.139.37.240:31043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/domains.php"] [unique_id "apK9V9dHPfW2QFvhmL7UyQAAAHI"] [Sat Aug 29 05:07:03.700246 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.700263 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:58270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.754289 2026] [security2:error] [pid 1028675:tid 1028858] [client 68.155.159.216:33573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apK9V9dHPfW2QFvhmL7U0AAAADA"] [Sat Aug 29 05:07:03.765444 2026] [security2:error] [pid 1028675:tid 1028846] [client 20.48.250.41:59359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ff1.php"] [unique_id "apK9V9dHPfW2QFvhmL7U0QAAACQ"] [Sat Aug 29 05:07:03.769620 2026] [security2:error] [pid 1028675:tid 1028888] [client 158.23.147.79:17431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9V9dHPfW2QFvhmL7U0gAAAE4"] [Sat Aug 29 05:07:03.782965 2026] [security2:error] [pid 1028675:tid 1028863] [client 52.139.37.240:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/index.php/feed/atom/"] [unique_id "apK9V9dHPfW2QFvhmL7U0wAAADU"] [Sat Aug 29 05:07:03.797511 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.48.160.90:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-mini.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM2AAABhY"] [Sat Aug 29 05:07:03.803291 2026] [security2:error] [pid 1018003:tid 1018184] [client 40.83.93.50:17306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/spip.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM2QAABdk"] [Sat Aug 29 05:07:03.805369 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.52.41.200:1260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/gmo.php"] [unique_id "apK9V9dHPfW2QFvhmL7U1AAAAB8"] [Sat Aug 29 05:07:03.815642 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.815659 2026] [core:error] [pid 1018003:tid 1018203] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:03.832099 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.196.209.81:9773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/bak.phps"] [unique_id "apK9VzAh5Y1i2tUxg4EM2wAABhw"] [Sat Aug 29 05:07:03.834879 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.49.130:57611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/talkxkej.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM3AAABfo"] [Sat Aug 29 05:07:03.837480 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.104.49.130:60757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/v2.php"] [unique_id "apK9V9dHPfW2QFvhmL7U1QAAACI"] [Sat Aug 29 05:07:03.888386 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.197.61.180:7892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/as.php"] [unique_id "apK9V9dHPfW2QFvhmL7U3AAAAB0"] [Sat Aug 29 05:07:03.896251 2026] [security2:error] [pid 1028675:tid 1028928] [client 52.139.37.240:30808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/dropdown.php"] [unique_id "apK9V9dHPfW2QFvhmL7U3QAAAHY"] [Sat Aug 29 05:07:03.901927 2026] [security2:error] [pid 1028675:tid 1028849] [client 68.155.159.216:64480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9V9dHPfW2QFvhmL7U3gAAACc"] [Sat Aug 29 05:07:03.911047 2026] [security2:error] [pid 1018003:tid 1018261] [client 4.205.62.107:55937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/mga.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM3QAABiU"] [Sat Aug 29 05:07:03.911787 2026] [security2:error] [pid 1018003:tid 1018275] [client 68.155.159.216:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM3gAABjM"] [Sat Aug 29 05:07:03.915452 2026] [security2:error] [pid 1028675:tid 1028901] [client 158.158.54.35:16916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-blog.php"] [unique_id "apK9V9dHPfW2QFvhmL7U3wAAAFs"] [Sat Aug 29 05:07:03.932316 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.48.160.90:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/xmini4.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM3wAABiA"] [Sat Aug 29 05:07:03.933578 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.250.41:62548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/t.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM4AAABco"] [Sat Aug 29 05:07:03.952747 2026] [security2:error] [pid 1028675:tid 1028879] [client 158.23.147.79:30505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9V9dHPfW2QFvhmL7U4AAAAEU"] [Sat Aug 29 05:07:03.954372 2026] [security2:error] [pid 1028675:tid 1028820] [client 68.155.159.216:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9V9dHPfW2QFvhmL7U4QAAAAo"] [Sat Aug 29 05:07:03.961091 2026] [security2:error] [pid 1028675:tid 1028857] [client 158.158.54.35:10572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/403.php"] [unique_id "apK9V9dHPfW2QFvhmL7U4gAAAC8"] [Sat Aug 29 05:07:03.974815 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.196.209.81:15198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/alumni_reg.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM4QAABcQ"] [Sat Aug 29 05:07:03.992120 2026] [security2:error] [pid 1018003:tid 1018219] [client 52.139.37.240:20798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/root.php"] [unique_id "apK9VzAh5Y1i2tUxg4EM4gAABfw"] [Sat Aug 29 05:07:04.002525 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.147.79:48269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/cgi-bin/index.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM4wAABgY"] [Sat Aug 29 05:07:04.043652 2026] [security2:error] [pid 1028675:tid 1028920] [client 168.107.94.195:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9WNdHPfW2QFvhmL7U6gAAAG4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:04.049237 2026] [security2:error] [pid 1018003:tid 1018166] [client 93.123.109.228:39106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9WDAh5Y1i2tUxg4EM5AAABcc"] [Sat Aug 29 05:07:04.078062 2026] [security2:error] [pid 1028675:tid 1028937] [client 158.23.147.79:26528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9WNdHPfW2QFvhmL7U8gAAAH8"] [Sat Aug 29 05:07:04.082336 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.196.209.81:15522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-comments-post.php"] [unique_id "apK9WNdHPfW2QFvhmL7U8wAAAEs"] [Sat Aug 29 05:07:04.085160 2026] [core:error] [pid 1028675:tid 1028915] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:04.085175 2026] [core:error] [pid 1028675:tid 1028915] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:04.093204 2026] [security2:error] [pid 1018003:tid 1018155] [client 52.139.37.240:31551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/files/index.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM5wAABbw"] [Sat Aug 29 05:07:04.097996 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.104.49.130:54793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/term.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM6AAABfk"] [Sat Aug 29 05:07:04.098947 2026] [security2:error] [pid 1018003:tid 1018177] [client 40.83.93.50:20861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/test.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM6QAABdI"] [Sat Aug 29 05:07:04.100451 2026] [security2:error] [pid 1028675:tid 1028816] [client 20.48.160.90:51300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/reop3.php"] [unique_id "apK9WNdHPfW2QFvhmL7U9QAAAAY"] [Sat Aug 29 05:07:04.113509 2026] [security2:error] [pid 1028675:tid 1028821] [client 93.123.109.228:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9WNdHPfW2QFvhmL7U9gAAAAs"] [Sat Aug 29 05:07:04.133232 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.48.250.41:60734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/erty.php"] [unique_id "apK9WNdHPfW2QFvhmL7U-QAAAD4"] [Sat Aug 29 05:07:04.166974 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.151.200.44:47303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/console.php"] [unique_id "apK9WNdHPfW2QFvhmL7U-gAAAFI"] [Sat Aug 29 05:07:04.176312 2026] [security2:error] [pid 1018003:tid 1018164] [client 93.123.109.228:39186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9WDAh5Y1i2tUxg4EM7AAABcU"] [Sat Aug 29 05:07:04.179154 2026] [security2:error] [pid 1028675:tid 1028902] [client 158.23.147.79:35742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9WNdHPfW2QFvhmL7U_QAAAFw"] [Sat Aug 29 05:07:04.187691 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.203.141.11:12699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM7gAABeA"] [Sat Aug 29 05:07:04.188750 2026] [security2:error] [pid 1018003:tid 1018188] [client 52.139.37.240:21385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/shell.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM7wAABd0"] [Sat Aug 29 05:07:04.223156 2026] [security2:error] [pid 1018003:tid 1018187] [client 68.155.159.216:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/packed.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM8AAABdw"] [Sat Aug 29 05:07:04.224509 2026] [security2:error] [pid 1028675:tid 1028873] [client 158.23.184.117:2567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/update/da222.php"] [unique_id "apK9WNdHPfW2QFvhmL7VAAAAAD8"] [Sat Aug 29 05:07:04.232690 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.196.209.81:9409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/install.php"] [unique_id "apK9WNdHPfW2QFvhmL7VAQAAABA"] [Sat Aug 29 05:07:04.240021 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.48.160.90:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-mail.php"] [unique_id "apK9WNdHPfW2QFvhmL7VAwAAADI"] [Sat Aug 29 05:07:04.244282 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.52.41.200:1214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/classwithtostring.php"] [unique_id "apK9WNdHPfW2QFvhmL7VBAAAAEQ"] [Sat Aug 29 05:07:04.253378 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.104.18.15:5095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM8QAABcs"] [Sat Aug 29 05:07:04.268196 2026] [security2:error] [pid 1018003:tid 1018152] [client 4.205.62.107:22038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/env.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM8gAABbk"] [Sat Aug 29 05:07:04.276813 2026] [security2:error] [pid 1028675:tid 1028861] [client 158.23.147.79:30554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/index.php"] [unique_id "apK9WNdHPfW2QFvhmL7VCgAAADM"] [Sat Aug 29 05:07:04.288742 2026] [security2:error] [pid 1018003:tid 1018190] [client 52.139.37.240:31091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swumc.com"] [uri "/flower.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM8wAABd8"] [Sat Aug 29 05:07:04.299618 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.48.250.41:60704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/0x.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM9QAABgo"] [Sat Aug 29 05:07:04.319177 2026] [security2:error] [pid 1028675:tid 1028926] [client 40.83.93.50:3868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/backup.php"] [unique_id "apK9WNdHPfW2QFvhmL7VEAAAAHQ"] [Sat Aug 29 05:07:04.346708 2026] [security2:error] [pid 1028675:tid 1028896] [client 158.23.147.79:32707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9WNdHPfW2QFvhmL7VEwAAAFY"] [Sat Aug 29 05:07:04.348197 2026] [security2:error] [pid 1018003:tid 1018184] [client 93.123.109.228:39186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9WDAh5Y1i2tUxg4EM9wAABdk"] [Sat Aug 29 05:07:04.365939 2026] [security2:error] [pid 1028675:tid 1028835] [client 158.158.54.35:29677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/xxx.php"] [unique_id "apK9WNdHPfW2QFvhmL7VFQAAABk"] [Sat Aug 29 05:07:04.368042 2026] [security2:error] [pid 1028675:tid 1028931] [client 158.23.184.117:2568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/xmr.php"] [unique_id "apK9WNdHPfW2QFvhmL7VFgAAAHk"] [Sat Aug 29 05:07:04.382171 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.48.160.90:51683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-conffg.php"] [unique_id "apK9WNdHPfW2QFvhmL7VFwAAAHI"] [Sat Aug 29 05:07:04.382173 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.196.209.81:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/colors.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM-gAABbo"] [Sat Aug 29 05:07:04.383637 2026] [security2:error] [pid 1028675:tid 1028910] [client 52.139.37.240:21148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9WNdHPfW2QFvhmL7VGAAAAGQ"] [Sat Aug 29 05:07:04.389237 2026] [security2:error] [pid 1028675:tid 1028935] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9WNdHPfW2QFvhmL7VGQAAAH0"] [Sat Aug 29 05:07:04.421576 2026] [security2:error] [pid 1028675:tid 1028900] [client 168.107.94.195:58743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9WNdHPfW2QFvhmL7VIQAAAFo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:04.469270 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.18.15:5118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM_QAABfU"] [Sat Aug 29 05:07:04.469333 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.158.54.35:17559] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "traditionalslateroofing.com"] [uri "/1.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM_AAABik"] [Sat Aug 29 05:07:04.469471 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.158.54.35:17559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/1.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM_AAABik"] [Sat Aug 29 05:07:04.476485 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.196.209.81:15539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-config.php"] [unique_id "apK9WNdHPfW2QFvhmL7VKwAAAFc"] [Sat Aug 29 05:07:04.478236 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.48.250.41:60788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/66.php"] [unique_id "apK9WDAh5Y1i2tUxg4EM_wAABdo"] [Sat Aug 29 05:07:04.494719 2026] [security2:error] [pid 1028675:tid 1028824] [client 158.23.147.79:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/x.php"] [unique_id "apK9WNdHPfW2QFvhmL7VLQAAAA4"] [Sat Aug 29 05:07:04.513211 2026] [security2:error] [pid 1028675:tid 1028853] [client 158.23.184.117:2581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9WNdHPfW2QFvhmL7VLgAAACs"] [Sat Aug 29 05:07:04.523443 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.48.160.90:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/filefuns.php"] [unique_id "apK9WNdHPfW2QFvhmL7VLwAAAEc"] [Sat Aug 29 05:07:04.541900 2026] [security2:error] [pid 1028675:tid 1028820] [client 68.155.159.216:24534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/goat.php"] [unique_id "apK9WNdHPfW2QFvhmL7VMAAAAAo"] [Sat Aug 29 05:07:04.578654 2026] [security2:error] [pid 1028675:tid 1028849] [client 52.139.37.240:21395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK9WNdHPfW2QFvhmL7VOwAAACc"] [Sat Aug 29 05:07:04.581200 2026] [core:error] [pid 1028675:tid 1028858] [client 40.83.93.50:22785] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:04.581218 2026] [core:error] [pid 1028675:tid 1028858] [client 40.83.93.50:22785] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:04.598909 2026] [security2:error] [pid 1018003:tid 1018202] [client 4.205.62.107:26667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/vx.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENAAAABes"] [Sat Aug 29 05:07:04.607432 2026] [security2:error] [pid 1018003:tid 1018163] [client 4.205.62.107:58478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/xda.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENAQAABcQ"] [Sat Aug 29 05:07:04.607875 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.104.49.130:63612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/dehnl.php"] [unique_id "apK9WNdHPfW2QFvhmL7VPwAAAGg"] [Sat Aug 29 05:07:04.611827 2026] [security2:error] [pid 1028675:tid 1028831] [client 93.123.109.228:39206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9WNdHPfW2QFvhmL7VQAAAABU"] [Sat Aug 29 05:07:04.613322 2026] [security2:error] [pid 1028675:tid 1028856] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9WNdHPfW2QFvhmL7VQgAAAC4"] [Sat Aug 29 05:07:04.613973 2026] [security2:error] [pid 1028675:tid 1028937] [client 4.205.62.107:21619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/motu.php"] [unique_id "apK9WNdHPfW2QFvhmL7VQwAAAH8"] [Sat Aug 29 05:07:04.630286 2026] [security2:error] [pid 1028675:tid 1028767] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/phpinfo.php"] [unique_id "apK9WNdHPfW2QFvhmL7VSgAAalY"] [Sat Aug 29 05:07:04.636337 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.197.61.180:16614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/room.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENAwAABdQ"] [Sat Aug 29 05:07:04.639134 2026] [security2:error] [pid 1018003:tid 1018207] [client 197.219.150.206:61372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENBQAABfA"] [Sat Aug 29 05:07:04.639215 2026] [security2:error] [pid 1018003:tid 1018207] [client 197.219.150.206:61372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENBQAABfA"] [Sat Aug 29 05:07:04.647543 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.48.250.41:62565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/f35.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENBwAABiI"] [Sat Aug 29 05:07:04.648042 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.196.209.81:17866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/colour.php"] [unique_id "apK9WNdHPfW2QFvhmL7VTwAAAF4"] [Sat Aug 29 05:07:04.652071 2026] [security2:error] [pid 1028675:tid 1028925] [client 103.171.189.88:57012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9WNdHPfW2QFvhmL7VUAAAAHM"] [Sat Aug 29 05:07:04.652183 2026] [security2:error] [pid 1028675:tid 1028925] [client 103.171.189.88:57012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9WNdHPfW2QFvhmL7VUAAAAHM"] [Sat Aug 29 05:07:04.654104 2026] [security2:error] [pid 1028675:tid 1028865] [client 20.104.18.15:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/ap.php"] [unique_id "apK9WNdHPfW2QFvhmL7VUQAAADc"] [Sat Aug 29 05:07:04.656649 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.184.117:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-act.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENCAAABcQ"] [Sat Aug 29 05:07:04.682021 2026] [security2:error] [pid 1018003:tid 1018155] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9WDAh5Y1i2tUxg4ENCgAABbw"] [Sat Aug 29 05:07:04.686777 2026] [security2:error] [pid 1028675:tid 1028891] [client 158.23.147.79:53820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9WNdHPfW2QFvhmL7VWQAAAFE"] [Sat Aug 29 05:07:04.696103 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.48.160.90:51697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-cron.php"] [unique_id "apK9WNdHPfW2QFvhmL7VWwAAAGs"] [Sat Aug 29 05:07:04.697773 2026] [security2:error] [pid 1028675:tid 1028819] [client 20.203.141.11:27397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-admin/css/admin.php"] [unique_id "apK9WNdHPfW2QFvhmL7VXAAAAAk"] [Sat Aug 29 05:07:04.697871 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.52.41.200:1241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/404.php"] [unique_id "apK9WNdHPfW2QFvhmL7VXQAAAC8"] [Sat Aug 29 05:07:04.698630 2026] [security2:error] [pid 1028675:tid 1028810] [client 68.155.159.216:16224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-admin/index.php"] [unique_id "apK9WNdHPfW2QFvhmL7VXgAAAAA"] [Sat Aug 29 05:07:04.767234 2026] [security2:error] [pid 1028675:tid 1028813] [client 52.139.37.240:20739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-header-json.php"] [unique_id "apK9WNdHPfW2QFvhmL7VZAAAAAM"] [Sat Aug 29 05:07:04.777516 2026] [security2:error] [pid 1028675:tid 1028887] [client 68.155.159.216:65115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/chosen.php"] [unique_id "apK9WNdHPfW2QFvhmL7VZgAAAE0"] [Sat Aug 29 05:07:04.801291 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.184.117:2968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/fff.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENDgAABdc"] [Sat Aug 29 05:07:04.803159 2026] [core:error] [pid 1028675:tid 1028880] [client 158.158.54.35:20296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:04.803175 2026] [core:error] [pid 1028675:tid 1028880] [client 158.158.54.35:20296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:04.806202 2026] [security2:error] [pid 1018003:tid 1018188] [client 93.123.109.228:39186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9WDAh5Y1i2tUxg4ENDwAABd0"] [Sat Aug 29 05:07:04.809944 2026] [security2:error] [pid 1028675:tid 1028918] [client 93.123.109.228:39190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/.env.php"] [unique_id "apK9WNdHPfW2QFvhmL7VbgAAAGw"] [Sat Aug 29 05:07:04.816157 2026] [security2:error] [pid 1028675:tid 1028898] [client 57.141.14.36:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/5/"] [unique_id "apK9WNdHPfW2QFvhmL7VbwAAAFg"] [Sat Aug 29 05:07:04.817416 2026] [security2:error] [pid 1028675:tid 1028866] [client 168.107.94.195:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9WNdHPfW2QFvhmL7VcAAAADg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:04.818451 2026] [security2:error] [pid 1018003:tid 1018233] [client 4.205.62.107:8990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/file21.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENEAAABgk"] [Sat Aug 29 05:07:04.820591 2026] [security2:error] [pid 1018003:tid 1018166] [client 40.83.93.50:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/haiterus.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENEQAABcc"] [Sat Aug 29 05:07:04.827609 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.196.209.81:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/Js.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENEgAABcg"] [Sat Aug 29 05:07:04.833676 2026] [security2:error] [pid 1028675:tid 1028774] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/pi.php"] [unique_id "apK9WNdHPfW2QFvhmL7VdAAAZV0"] [Sat Aug 29 05:07:04.836524 2026] [security2:error] [pid 1028675:tid 1028785] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/info.php"] [unique_id "apK9WNdHPfW2QFvhmL7VdQAABGg"] [Sat Aug 29 05:07:04.837015 2026] [security2:error] [pid 1028675:tid 1028786] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/test.php"] [unique_id "apK9WNdHPfW2QFvhmL7VdwAABGk"] [Sat Aug 29 05:07:04.837336 2026] [security2:error] [pid 1028675:tid 1028783] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/i.php"] [unique_id "apK9WNdHPfW2QFvhmL7VeAAABGY"] [Sat Aug 29 05:07:04.857178 2026] [security2:error] [pid 1028675:tid 1028910] [client 68.155.159.216:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9WNdHPfW2QFvhmL7VfgAAAGQ"] [Sat Aug 29 05:07:04.860989 2026] [security2:error] [pid 1028675:tid 1028909] [client 20.48.250.41:62545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wen.php"] [unique_id "apK9WNdHPfW2QFvhmL7VfwAAAGM"] [Sat Aug 29 05:07:04.874051 2026] [security2:error] [pid 1028675:tid 1028935] [client 158.23.147.79:17502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9WNdHPfW2QFvhmL7VgAAAAH0"] [Sat Aug 29 05:07:04.879819 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.196.209.81:17174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-configs.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENFQAABdg"] [Sat Aug 29 05:07:04.902541 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.18.15:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/media.php"] [unique_id "apK9WNdHPfW2QFvhmL7ViAAAAHo"] [Sat Aug 29 05:07:04.917531 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.48.160.90:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/lock360.php"] [unique_id "apK9WDAh5Y1i2tUxg4ENFgAABgo"] [Sat Aug 29 05:07:04.937203 2026] [security2:error] [pid 1028675:tid 1028798] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/.env.php"] [unique_id "apK9WNdHPfW2QFvhmL7VjgAASnU"] [Sat Aug 29 05:07:04.939332 2026] [security2:error] [pid 1028675:tid 1028853] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9WNdHPfW2QFvhmL7VjQAAACs"] [Sat Aug 29 05:07:04.955350 2026] [security2:error] [pid 1028675:tid 1028900] [client 52.139.37.240:21424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/zup.php"] [unique_id "apK9WNdHPfW2QFvhmL7VjwAAAFo"] [Sat Aug 29 05:07:04.959958 2026] [security2:error] [pid 1028675:tid 1028799] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/app_dev.php/_profiler"] [unique_id "apK9WNdHPfW2QFvhmL7VkQAAB3Y"] [Sat Aug 29 05:07:04.959975 2026] [security2:error] [pid 1028675:tid 1028794] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.66.139.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgd6.com"] [uri "/app_dev.php"] [unique_id "apK9WNdHPfW2QFvhmL7VkgAAB3E"] [Sat Aug 29 05:07:04.979632 2026] [security2:error] [pid 1028675:tid 1028841] [client 158.23.184.117:2776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9WNdHPfW2QFvhmL7VkwAAAB8"] [Sat Aug 29 05:07:05.009947 2026] [security2:error] [pid 1028675:tid 1028906] [client 20.48.250.41:60757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/inc.php"] [unique_id "apK9WddHPfW2QFvhmL7VnwAAAGA"] [Sat Aug 29 05:07:05.011376 2026] [security2:error] [pid 1018003:tid 1018261] [client 68.155.159.216:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENGwAABiU"] [Sat Aug 29 05:07:05.018452 2026] [security2:error] [pid 1028675:tid 1028849] [client 68.155.159.216:1990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9WddHPfW2QFvhmL7VoAAAACc"] [Sat Aug 29 05:07:05.025692 2026] [security2:error] [pid 1018003:tid 1018275] [client 93.123.109.228:39106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9WTAh5Y1i2tUxg4ENHAAABjM"] [Sat Aug 29 05:07:05.049731 2026] [security2:error] [pid 1028675:tid 1028842] [client 4.205.62.107:56055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ccou.php"] [unique_id "apK9WddHPfW2QFvhmL7VpAAAACA"] [Sat Aug 29 05:07:05.049962 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.196.209.81:17859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/OK.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENHwAABd8"] [Sat Aug 29 05:07:05.054723 2026] [security2:error] [pid 1028675:tid 1028919] [client 158.23.147.79:30514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9WddHPfW2QFvhmL7VpwAAAG0"] [Sat Aug 29 05:07:05.056795 2026] [security2:error] [pid 1018003:tid 1018156] [client 68.155.159.216:51848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENIAAABb0"] [Sat Aug 29 05:07:05.071738 2026] [security2:error] [pid 1028675:tid 1028844] [client 40.83.93.50:21201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/user/f35.php"] [unique_id "apK9WddHPfW2QFvhmL7VqQAAACI"] [Sat Aug 29 05:07:05.094049 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.158.54.35:17550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/s.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENIgAABgc"] [Sat Aug 29 05:07:05.094460 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.48.160.90:51607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-theme.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENIwAABeE"] [Sat Aug 29 05:07:05.096988 2026] [security2:error] [pid 1028675:tid 1028831] [client 20.104.18.15:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/adminfuns.php"] [unique_id "apK9WddHPfW2QFvhmL7VrwAAABU"] [Sat Aug 29 05:07:05.122243 2026] [security2:error] [pid 1028675:tid 1028916] [client 158.23.147.79:48169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9WddHPfW2QFvhmL7VsgAAAGo"] [Sat Aug 29 05:07:05.140500 2026] [security2:error] [pid 1028675:tid 1028854] [client 158.23.184.117:2775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/robots.php"] [unique_id "apK9WddHPfW2QFvhmL7VtAAAACw"] [Sat Aug 29 05:07:05.152325 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.52.41.200:1170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/php.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENJAAABhQ"] [Sat Aug 29 05:07:05.163413 2026] [security2:error] [pid 1018003:tid 1018159] [client 52.139.37.240:21429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/a9.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENJwAABcA"] [Sat Aug 29 05:07:05.166446 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.147.79:50106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/radio.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENKAAABgI"] [Sat Aug 29 05:07:05.171219 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:62563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/6bcwiqwj.php"] [unique_id "apK9WddHPfW2QFvhmL7VuAAAAHM"] [Sat Aug 29 05:07:05.183769 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.23.147.79:26369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/admin.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENKgAABfo"] [Sat Aug 29 05:07:05.193958 2026] [security2:error] [pid 1018003:tid 1018187] [client 149.34.210.141:42204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENKwAABdw"] [Sat Aug 29 05:07:05.194055 2026] [security2:error] [pid 1018003:tid 1018187] [client 149.34.210.141:42204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENKwAABdw"] [Sat Aug 29 05:07:05.197535 2026] [security2:error] [pid 1018003:tid 1018160] [client 168.107.94.195:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENLAAABcE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:05.232184 2026] [security2:error] [pid 1028675:tid 1028871] [client 93.123.109.228:39132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9WddHPfW2QFvhmL7VxAAAAD0"] [Sat Aug 29 05:07:05.242968 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.151.200.44:46533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/blnux.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENLwAABeU"] [Sat Aug 29 05:07:05.244782 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.147.79:25500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/cgi-bin/index.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENMQAABcQ"] [Sat Aug 29 05:07:05.249398 2026] [core:error] [pid 1018003:tid 1018267] [client 158.158.54.35:28379] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:05.249420 2026] [core:error] [pid 1018003:tid 1018267] [client 158.158.54.35:28379] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:05.251504 2026] [security2:error] [pid 1028675:tid 1028812] [client 20.196.209.81:11279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/access.php"] [unique_id "apK9WddHPfW2QFvhmL7VxQAAAAI"] [Sat Aug 29 05:07:05.255102 2026] [security2:error] [pid 1028675:tid 1028936] [client 20.104.18.15:5003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/classwithtostring.php"] [unique_id "apK9WddHPfW2QFvhmL7VxgAAAH4"] [Sat Aug 29 05:07:05.259398 2026] [security2:error] [pid 1028675:tid 1028813] [client 68.155.159.216:33537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9WddHPfW2QFvhmL7VxwAAAAM"] [Sat Aug 29 05:07:05.274561 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.49.130:36237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/wp-the.php"] [unique_id "apK9WddHPfW2QFvhmL7VyAAAADI"] [Sat Aug 29 05:07:05.274575 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.48.160.90:51304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/2d7433/index.php"] [unique_id "apK9WddHPfW2QFvhmL7VyQAAADM"] [Sat Aug 29 05:07:05.276524 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.196.209.81:22447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-conflg.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENMwAABek"] [Sat Aug 29 05:07:05.281596 2026] [security2:error] [pid 1028675:tid 1028878] [client 93.123.109.228:39206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9WddHPfW2QFvhmL7VygAAAEQ"] [Sat Aug 29 05:07:05.284329 2026] [security2:error] [pid 1028675:tid 1028826] [client 158.23.184.117:2583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/.well-known/install.php"] [unique_id "apK9WddHPfW2QFvhmL7VywAAABA"] [Sat Aug 29 05:07:05.284330 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.203.141.11:1224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/adminfuns.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENNAAABfU"] [Sat Aug 29 05:07:05.285011 2026] [security2:error] [pid 1028675:tid 1028872] [client 158.23.147.79:35744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9WddHPfW2QFvhmL7VzAAAAD4"] [Sat Aug 29 05:07:05.298464 2026] [security2:error] [pid 1028675:tid 1028815] [client 93.123.109.228:39204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9WddHPfW2QFvhmL7VzQAAAAU"] [Sat Aug 29 05:07:05.307596 2026] [security2:error] [pid 1028675:tid 1028926] [client 20.48.250.41:60759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/easy.php"] [unique_id "apK9WddHPfW2QFvhmL7VzwAAAHQ"] [Sat Aug 29 05:07:05.337208 2026] [security2:error] [pid 1028675:tid 1028874] [client 40.83.93.50:17288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/go.php"] [unique_id "apK9WddHPfW2QFvhmL7V0QAAAEA"] [Sat Aug 29 05:07:05.357711 2026] [security2:error] [pid 1028675:tid 1028915] [client 20.197.61.180:13839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/class-wp-cmd.php"] [unique_id "apK9WddHPfW2QFvhmL7V0wAAAGk"] [Sat Aug 29 05:07:05.358917 2026] [security2:error] [pid 1028675:tid 1028814] [client 68.155.159.216:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-l0gin.php"] [unique_id "apK9WddHPfW2QFvhmL7V1AAAAAQ"] [Sat Aug 29 05:07:05.367737 2026] [security2:error] [pid 1028675:tid 1028929] [client 52.139.37.240:21176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/admin/index.php"] [unique_id "apK9WddHPfW2QFvhmL7V1gAAAHc"] [Sat Aug 29 05:07:05.382201 2026] [security2:error] [pid 1018003:tid 1018195] [client 171.61.160.196:29939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENOAAABeQ"] [Sat Aug 29 05:07:05.382318 2026] [security2:error] [pid 1018003:tid 1018195] [client 171.61.160.196:29939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENOAAABeQ"] [Sat Aug 29 05:07:05.387639 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.23.147.79:30575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENOQAABho"] [Sat Aug 29 05:07:05.389365 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.104.18.15:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK9WddHPfW2QFvhmL7V2gAAAFc"] [Sat Aug 29 05:07:05.404792 2026] [security2:error] [pid 1028675:tid 1028839] [client 68.155.159.216:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/radio.php"] [unique_id "apK9WddHPfW2QFvhmL7V2wAAAB0"] [Sat Aug 29 05:07:05.420457 2026] [security2:error] [pid 1018003:tid 1018186] [client 4.205.62.107:22380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/xve22.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENOwAABds"] [Sat Aug 29 05:07:05.429401 2026] [security2:error] [pid 1018003:tid 1018167] [client 20.48.160.90:51616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-login.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENOgAABcg"] [Sat Aug 29 05:07:05.452901 2026] [security2:error] [pid 1028675:tid 1028830] [client 158.23.147.79:32597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/classwithtostring.php"] [unique_id "apK9WddHPfW2QFvhmL7V3QAAABQ"] [Sat Aug 29 05:07:05.476780 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.48.250.41:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/fresh3.php"] [unique_id "apK9WddHPfW2QFvhmL7V3gAAAEc"] [Sat Aug 29 05:07:05.480774 2026] [security2:error] [pid 1028675:tid 1028841] [client 158.23.184.117:2577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-admin/about.php"] [unique_id "apK9WddHPfW2QFvhmL7V3wAAAB8"] [Sat Aug 29 05:07:05.526246 2026] [security2:error] [pid 1028675:tid 1028704] [remote 34.139.66.91:50268] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "tgd6.com"] [uri "/server-info"] [unique_id "apK9WddHPfW2QFvhmL7V5AAAJBc"] [Sat Aug 29 05:07:05.544565 2026] [security2:error] [pid 1028675:tid 1028913] [client 158.158.54.35:10584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/test1.php"] [unique_id "apK9WddHPfW2QFvhmL7V6gAAAGc"] [Sat Aug 29 05:07:05.547549 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.104.18.15:5010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK9WddHPfW2QFvhmL7V6wAAACU"] [Sat Aug 29 05:07:05.565027 2026] [security2:error] [pid 1028675:tid 1028907] [client 52.139.37.240:20791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/makeasmtp.php"] [unique_id "apK9WddHPfW2QFvhmL7V7gAAAGE"] [Sat Aug 29 05:07:05.565497 2026] [security2:error] [pid 1018003:tid 1018233] [client 40.83.93.50:13630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/user/min.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENPgAABgk"] [Sat Aug 29 05:07:05.578832 2026] [security2:error] [pid 1028675:tid 1028914] [client 168.107.94.195:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9WddHPfW2QFvhmL7V8QAAAGg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:05.583598 2026] [access_compat:error] [pid 1028675:tid 1028707] [remote 34.139.66.91:50268] AH01797: client denied by server configuration: /var/www/html/server-status [Sat Aug 29 05:07:05.606351 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.48.250.41:59309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/bgymj.php"] [unique_id "apK9WddHPfW2QFvhmL7V9AAAAF4"] [Sat Aug 29 05:07:05.609034 2026] [security2:error] [pid 1028675:tid 1028817] [client 20.52.41.200:1440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/init.php"] [unique_id "apK9WddHPfW2QFvhmL7V9QAAAAc"] [Sat Aug 29 05:07:05.613611 2026] [security2:error] [pid 1018003:tid 1018153] [client 20.48.160.90:51621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/images.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENQQAABbo"] [Sat Aug 29 05:07:05.615321 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.196.209.81:9750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blocktshirts.glowt-shirt.com"] [uri "/aaa.php"] [unique_id "apK9WddHPfW2QFvhmL7V-wAAADw"] [Sat Aug 29 05:07:05.626309 2026] [security2:error] [pid 1028675:tid 1028876] [client 158.23.184.117:2781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/backup.php"] [unique_id "apK9WddHPfW2QFvhmL7V_AAAAEI"] [Sat Aug 29 05:07:05.639657 2026] [security2:error] [pid 1028675:tid 1028873] [client 158.23.147.79:63853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/x.php"] [unique_id "apK9WddHPfW2QFvhmL7V_gAAAD8"] [Sat Aug 29 05:07:05.663378 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.196.209.81:11302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/classsmtps.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENQwAABhY"] [Sat Aug 29 05:07:05.675370 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.196.209.81:5986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content.php"] [unique_id "apK9WddHPfW2QFvhmL7WAQAAAG0"] [Sat Aug 29 05:07:05.704522 2026] [security2:error] [pid 1028675:tid 1028863] [client 158.158.54.35:8714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/tool.php"] [unique_id "apK9WddHPfW2QFvhmL7WBAAAADU"] [Sat Aug 29 05:07:05.736096 2026] [security2:error] [pid 1028675:tid 1028855] [client 4.205.62.107:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/ty.php"] [unique_id "apK9WddHPfW2QFvhmL7WCQAAAC0"] [Sat Aug 29 05:07:05.747003 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:5110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENRQAABeE"] [Sat Aug 29 05:07:05.747733 2026] [security2:error] [pid 1028675:tid 1028814] [client 4.205.62.107:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/motu.php"] [unique_id "apK9WddHPfW2QFvhmL7WCwAAAAQ"] [Sat Aug 29 05:07:05.753533 2026] [security2:error] [pid 1028675:tid 1028929] [client 4.205.62.107:22016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/rpk.php"] [unique_id "apK9WddHPfW2QFvhmL7WDAAAAHc"] [Sat Aug 29 05:07:05.754836 2026] [security2:error] [pid 1028675:tid 1028922] [client 20.48.160.90:51672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/ops.php"] [unique_id "apK9WddHPfW2QFvhmL7WDQAAAHA"] [Sat Aug 29 05:07:05.757607 2026] [security2:error] [pid 1028675:tid 1028878] [client 52.139.37.240:20744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/paku.php"] [unique_id "apK9WddHPfW2QFvhmL7WDgAAAEQ"] [Sat Aug 29 05:07:05.762726 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.48.250.41:60710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ws69.php"] [unique_id "apK9WddHPfW2QFvhmL7WDwAAABk"] [Sat Aug 29 05:07:05.770095 2026] [security2:error] [pid 1028675:tid 1028890] [client 158.23.184.117:2774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/.well-known/aa.php"] [unique_id "apK9WddHPfW2QFvhmL7WEAAAAFA"] [Sat Aug 29 05:07:05.772574 2026] [security2:error] [pid 1028675:tid 1028891] [client 20.203.141.11:11226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/goods.php"] [unique_id "apK9WddHPfW2QFvhmL7WEQAAAFE"] [Sat Aug 29 05:07:05.843556 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.49.130:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/well.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENSgAABcI"] [Sat Aug 29 05:07:05.886658 2026] [security2:error] [pid 1028675:tid 1028849] [client 68.155.159.216:65027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/goods.php"] [unique_id "apK9WddHPfW2QFvhmL7WFgAAACc"] [Sat Aug 29 05:07:05.916724 2026] [security2:error] [pid 1028675:tid 1028840] [client 158.23.184.117:2778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9WddHPfW2QFvhmL7WGAAAAB4"] [Sat Aug 29 05:07:05.926953 2026] [security2:error] [pid 1028675:tid 1028897] [client 40.83.93.50:7589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/gecko-new.php"] [unique_id "apK9WddHPfW2QFvhmL7WGwAAAFc"] [Sat Aug 29 05:07:05.939129 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.48.250.41:60760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ccs.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENTQAABiY"] [Sat Aug 29 05:07:05.946590 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.104.18.15:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/wsd.php"] [unique_id "apK9WddHPfW2QFvhmL7WHQAAAGg"] [Sat Aug 29 05:07:05.958243 2026] [security2:error] [pid 1018003:tid 1018157] [client 168.107.94.195:60213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENTgAABb4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:05.961472 2026] [security2:error] [pid 1028675:tid 1028865] [client 20.48.160.90:51309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK9WddHPfW2QFvhmL7WHwAAADc"] [Sat Aug 29 05:07:05.962659 2026] [security2:error] [pid 1028675:tid 1028833] [client 52.139.37.240:20790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/rtx.php"] [unique_id "apK9WddHPfW2QFvhmL7WIAAAABc"] [Sat Aug 29 05:07:05.964287 2026] [security2:error] [pid 1028675:tid 1028892] [client 61.9.8.103:6998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9WddHPfW2QFvhmL7WIQAAAFI"] [Sat Aug 29 05:07:05.964414 2026] [security2:error] [pid 1028675:tid 1028892] [client 61.9.8.103:6998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9WddHPfW2QFvhmL7WIQAAAFI"] [Sat Aug 29 05:07:05.978768 2026] [security2:error] [pid 1028675:tid 1028899] [client 68.155.159.216:33786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/simple.php"] [unique_id "apK9WddHPfW2QFvhmL7WIgAAAFk"] [Sat Aug 29 05:07:05.991343 2026] [security2:error] [pid 1028675:tid 1028817] [client 158.23.147.79:17498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9WddHPfW2QFvhmL7WIwAAAAc"] [Sat Aug 29 05:07:05.994328 2026] [security2:error] [pid 1018003:tid 1018252] [client 52.139.37.240:30005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/aged.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENUAAABhw"] [Sat Aug 29 05:07:05.997258 2026] [security2:error] [pid 1018003:tid 1018177] [client 4.205.62.107:53351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/wsws.php"] [unique_id "apK9WTAh5Y1i2tUxg4ENUQAABdI"] [Sat Aug 29 05:07:06.003140 2026] [security2:error] [pid 1028675:tid 1028879] [client 158.158.54.35:7350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/ws.php"] [unique_id "apK9WtdHPfW2QFvhmL7WJAAAAEU"] [Sat Aug 29 05:07:06.036601 2026] [security2:error] [pid 1028675:tid 1028828] [client 40.83.93.50:22791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/users.php"] [unique_id "apK9WtdHPfW2QFvhmL7WJwAAABI"] [Sat Aug 29 05:07:06.068148 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.52.41.200:1192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "apK9WtdHPfW2QFvhmL7WKQAAADA"] [Sat Aug 29 05:07:06.079063 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.197.61.180:13862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/disagreed.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENVAAABfA"] [Sat Aug 29 05:07:06.082621 2026] [security2:error] [pid 1028675:tid 1028873] [client 158.23.184.117:2588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9WtdHPfW2QFvhmL7WKwAAAD8"] [Sat Aug 29 05:07:06.084661 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.151.200.44:47349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/pentest.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENVQAABho"] [Sat Aug 29 05:07:06.086535 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.250.41:60744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/mar.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENVgAABjU"] [Sat Aug 29 05:07:06.102934 2026] [core:error] [pid 1028675:tid 1028831] [client 20.196.209.81:20362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:06.102950 2026] [core:error] [pid 1028675:tid 1028831] [client 20.196.209.81:20362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:06.116611 2026] [security2:error] [pid 1018003:tid 1018186] [client 68.155.159.216:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENVwAABds"] [Sat Aug 29 05:07:06.116866 2026] [security2:error] [pid 1028675:tid 1028926] [client 20.48.160.90:51271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK9WtdHPfW2QFvhmL7WMAAAAHQ"] [Sat Aug 29 05:07:06.120262 2026] [security2:error] [pid 1028675:tid 1028919] [client 52.139.37.240:32124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/index.php/feed/atom/"] [unique_id "apK9WtdHPfW2QFvhmL7WMQAAAG0"] [Sat Aug 29 05:07:06.124443 2026] [security2:error] [pid 1028675:tid 1028863] [client 68.155.159.216:2011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/chosen.php"] [unique_id "apK9WtdHPfW2QFvhmL7WMgAAADU"] [Sat Aug 29 05:07:06.146444 2026] [security2:error] [pid 1028675:tid 1028898] [client 158.23.184.117:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/update/da222.php"] [unique_id "apK9WtdHPfW2QFvhmL7WOQAAAFg"] [Sat Aug 29 05:07:06.160312 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.196.209.81:11280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/contentloader1.php"] [unique_id "apK9WtdHPfW2QFvhmL7WPgAAAAg"] [Sat Aug 29 05:07:06.161721 2026] [security2:error] [pid 1018003:tid 1018166] [client 52.139.37.240:21399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/update/da222.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENXAAABcc"] [Sat Aug 29 05:07:06.163214 2026] [security2:error] [pid 1028675:tid 1028876] [client 158.158.54.35:16915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/k.php"] [unique_id "apK9WtdHPfW2QFvhmL7WPwAAAEI"] [Sat Aug 29 05:07:06.171479 2026] [security2:error] [pid 1028675:tid 1028915] [client 68.155.159.216:51458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9WtdHPfW2QFvhmL7WQAAAAGk"] [Sat Aug 29 05:07:06.202901 2026] [security2:error] [pid 1028675:tid 1028890] [client 4.205.62.107:56062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/rum.or.php"] [unique_id "apK9WtdHPfW2QFvhmL7WQQAAAFA"] [Sat Aug 29 05:07:06.217423 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.104.18.15:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/bulet.php"] [unique_id "apK9WtdHPfW2QFvhmL7WQwAAACM"] [Sat Aug 29 05:07:06.229001 2026] [security2:error] [pid 1028675:tid 1028933] [client 158.23.147.79:48231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/content.php"] [unique_id "apK9WtdHPfW2QFvhmL7WRAAAAHs"] [Sat Aug 29 05:07:06.232159 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.48.250.41:60765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ccu.php"] [unique_id "apK9WtdHPfW2QFvhmL7WRQAAAEc"] [Sat Aug 29 05:07:06.238567 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.49.130:51376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/js.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENXgAABdQ"] [Sat Aug 29 05:07:06.268050 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.147.79:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENXwAABew"] [Sat Aug 29 05:07:06.269548 2026] [security2:error] [pid 1028675:tid 1028851] [client 52.139.37.240:29854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/essexec.php"] [unique_id "apK9WtdHPfW2QFvhmL7WSgAAACk"] [Sat Aug 29 05:07:06.271736 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.203.141.11:18164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/css.php"] [unique_id "apK9WtdHPfW2QFvhmL7WSwAAAG4"] [Sat Aug 29 05:07:06.288120 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.48.160.90:51586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/about.php"] [unique_id "apK9WtdHPfW2QFvhmL7WTAAAAFQ"] [Sat Aug 29 05:07:06.324988 2026] [security2:error] [pid 1028675:tid 1028849] [client 158.23.184.117:2771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/test.php"] [unique_id "apK9WtdHPfW2QFvhmL7WUQAAACc"] [Sat Aug 29 05:07:06.337045 2026] [security2:error] [pid 1028675:tid 1028910] [client 158.23.184.117:12069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/xmr.php"] [unique_id "apK9WtdHPfW2QFvhmL7WUgAAAGQ"] [Sat Aug 29 05:07:06.337490 2026] [security2:error] [pid 1018003:tid 1018190] [client 168.107.94.195:60521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENYgAABd8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:06.341251 2026] [security2:error] [pid 1018003:tid 1018224] [client 52.139.37.240:32752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/root.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENZAAABgE"] [Sat Aug 29 05:07:06.358265 2026] [core:error] [pid 1018003:tid 1018221] [client 52.139.37.240:20756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:06.358283 2026] [core:error] [pid 1018003:tid 1018221] [client 52.139.37.240:20756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:06.367651 2026] [security2:error] [pid 1028675:tid 1028843] [client 158.23.147.79:25503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9WtdHPfW2QFvhmL7WWgAAACE"] [Sat Aug 29 05:07:06.369553 2026] [security2:error] [pid 1028675:tid 1028888] [client 68.155.159.216:33643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9WtdHPfW2QFvhmL7WWwAAAE4"] [Sat Aug 29 05:07:06.373636 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.48.250.41:60797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ak.php"] [unique_id "apK9WtdHPfW2QFvhmL7WXAAAAHU"] [Sat Aug 29 05:07:06.393697 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:35809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/dropdown.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENaAAABgc"] [Sat Aug 29 05:07:06.402813 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.151.200.44:46649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/6y7t.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENbAAABfo"] [Sat Aug 29 05:07:06.404079 2026] [security2:error] [pid 1028675:tid 1028885] [client 93.123.109.228:39092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/.wp-config.php.swp"] [unique_id "apK9WtdHPfW2QFvhmL7WYQAAAEs"] [Sat Aug 29 05:07:06.425994 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.18.15:4992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/av.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENbgAABfw"] [Sat Aug 29 05:07:06.427153 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.48.160.90:51229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/admin.php/admin.php"] [unique_id "apK9WtdHPfW2QFvhmL7WZgAAAEE"] [Sat Aug 29 05:07:06.446112 2026] [security2:error] [pid 1028675:tid 1028906] [client 158.158.54.35:18010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-themes.php"] [unique_id "apK9WtdHPfW2QFvhmL7WaQAAAGA"] [Sat Aug 29 05:07:06.464128 2026] [security2:error] [pid 1018003:tid 1018175] [client 68.155.159.216:50178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENcAAABdA"] [Sat Aug 29 05:07:06.464523 2026] [security2:error] [pid 1018003:tid 1018268] [client 52.139.37.240:29953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/fw.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENcQAABiw"] [Sat Aug 29 05:07:06.470305 2026] [security2:error] [pid 1018003:tid 1018202] [client 158.23.184.117:2574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/mani.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENcgAABes"] [Sat Aug 29 05:07:06.483775 2026] [security2:error] [pid 1028675:tid 1028819] [client 158.23.184.117:11943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9WtdHPfW2QFvhmL7WagAAAAk"] [Sat Aug 29 05:07:06.488306 2026] [security2:error] [pid 1018003:tid 1018275] [client 40.83.93.50:7583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/wp-admin.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENcwAABjM"] [Sat Aug 29 05:07:06.499090 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:30552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/about.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENdAAABb4"] [Sat Aug 29 05:07:06.506826 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.48.250.41:60732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/lib.php"] [unique_id "apK9WtdHPfW2QFvhmL7WbAAAAH8"] [Sat Aug 29 05:07:06.511495 2026] [autoindex:error] [pid 1028675:tid 1028835] [client 43.157.149.188:55172] AH01276: Cannot serve directory /home1/thrbikes/public_html/deargabriel/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://deargabriel.com [Sat Aug 29 05:07:06.525321 2026] [cgid:error] [pid 1018003:tid 1018256] [client 20.52.41.200:1446] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:07:06.528649 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.196.209.81:22411] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/1.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENdgAABh8"] [Sat Aug 29 05:07:06.528760 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.196.209.81:22411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/1.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENdgAABh8"] [Sat Aug 29 05:07:06.534752 2026] [security2:error] [pid 1018003:tid 1018230] [client 52.139.37.240:32121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/shell.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENdwAABgY"] [Sat Aug 29 05:07:06.540225 2026] [security2:error] [pid 1028675:tid 1028914] [client 40.83.93.50:13572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK9WtdHPfW2QFvhmL7WcAAAAGg"] [Sat Aug 29 05:07:06.552997 2026] [security2:error] [pid 1028675:tid 1028905] [client 93.123.109.228:39226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9WtdHPfW2QFvhmL7WcQAAAF8"] [Sat Aug 29 05:07:06.553144 2026] [security2:error] [pid 1018003:tid 1018262] [client 52.139.37.240:20763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-admin/min.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENeAAABiY"] [Sat Aug 29 05:07:06.558617 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.196.209.81:2034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/al.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENeQAABgw"] [Sat Aug 29 05:07:06.560478 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.147.79:32672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/install.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENegAABf8"] [Sat Aug 29 05:07:06.561508 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.160.90:51705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/media.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENewAABdc"] [Sat Aug 29 05:07:06.567048 2026] [security2:error] [pid 1028675:tid 1028856] [client 93.123.109.228:39206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9WtdHPfW2QFvhmL7WdgAAAC4"] [Sat Aug 29 05:07:06.574525 2026] [security2:error] [pid 1028675:tid 1028861] [client 4.205.62.107:22151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/06.php"] [unique_id "apK9WtdHPfW2QFvhmL7WeAAAADM"] [Sat Aug 29 05:07:06.613801 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.49.130:63559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/red.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENfAAABeQ"] [Sat Aug 29 05:07:06.619871 2026] [security2:error] [pid 1028675:tid 1028873] [client 158.23.184.117:2764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/Test.php"] [unique_id "apK9WtdHPfW2QFvhmL7WewAAAD8"] [Sat Aug 29 05:07:06.619893 2026] [security2:error] [pid 1028675:tid 1028917] [client 158.158.54.35:20558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/root.php"] [unique_id "apK9WtdHPfW2QFvhmL7WfAAAAGs"] [Sat Aug 29 05:07:06.632988 2026] [security2:error] [pid 1028675:tid 1028831] [client 158.23.184.117:12052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-act.php"] [unique_id "apK9WtdHPfW2QFvhmL7WgQAAABU"] [Sat Aug 29 05:07:06.647057 2026] [security2:error] [pid 1028675:tid 1028855] [client 20.104.18.15:5116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/images.php"] [unique_id "apK9WtdHPfW2QFvhmL7WgwAAAC0"] [Sat Aug 29 05:07:06.655950 2026] [security2:error] [pid 1028675:tid 1028926] [client 52.139.37.240:29870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/zwso.php"] [unique_id "apK9WtdHPfW2QFvhmL7WhwAAAHQ"] [Sat Aug 29 05:07:06.666690 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.48.250.41:59346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wp-style.php"] [unique_id "apK9WtdHPfW2QFvhmL7WigAAAHc"] [Sat Aug 29 05:07:06.676407 2026] [cgid:error] [pid 1018003:tid 1018166] [client 20.52.41.200:1446] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:07:06.683478 2026] [security2:error] [pid 1028675:tid 1028922] [client 158.23.147.79:30491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9WtdHPfW2QFvhmL7WiwAAAHA"] [Sat Aug 29 05:07:06.696827 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.48.160.90:51265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/mac.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENggAABec"] [Sat Aug 29 05:07:06.704652 2026] [security2:error] [pid 1028675:tid 1028874] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9WtdHPfW2QFvhmL7WjAAAAEA"] [Sat Aug 29 05:07:06.717188 2026] [security2:error] [pid 1028675:tid 1028935] [client 168.107.94.195:60898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9WtdHPfW2QFvhmL7WjQAAAH0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:06.729867 2026] [security2:error] [pid 1028675:tid 1028896] [client 52.139.37.240:32072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9WtdHPfW2QFvhmL7WjwAAAFY"] [Sat Aug 29 05:07:06.742125 2026] [security2:error] [pid 1018003:tid 1018155] [client 180.190.5.40:39901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.5.190.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcrl.tech"] [uri "/xmlrpc.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENhAAABbw"] [Sat Aug 29 05:07:06.742263 2026] [security2:error] [pid 1018003:tid 1018155] [client 180.190.5.40:39901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mcrl.tech"] [uri "/xmlrpc.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENhAAABbw"] [Sat Aug 29 05:07:06.750486 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.139.37.240:20776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENhQAABdg"] [Sat Aug 29 05:07:06.762977 2026] [security2:error] [pid 1028675:tid 1028880] [client 158.23.184.117:2813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/pomo.php"] [unique_id "apK9WtdHPfW2QFvhmL7WkQAAAEY"] [Sat Aug 29 05:07:06.773285 2026] [security2:error] [pid 1018003:tid 1018179] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9WjAh5Y1i2tUxg4ENhgAABdQ"] [Sat Aug 29 05:07:06.777244 2026] [security2:error] [pid 1028675:tid 1028932] [client 158.23.184.117:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/fff.php"] [unique_id "apK9WtdHPfW2QFvhmL7WkwAAAHo"] [Sat Aug 29 05:07:06.799616 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.147.79:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENhwAABew"] [Sat Aug 29 05:07:06.805527 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.151.200.44:47401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/0xs.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENiAAABc0"] [Sat Aug 29 05:07:06.805840 2026] [security2:error] [pid 1028675:tid 1028841] [client 111.235.68.106:53740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9WtdHPfW2QFvhmL7WlAAAAB8"] [Sat Aug 29 05:07:06.805933 2026] [security2:error] [pid 1028675:tid 1028841] [client 111.235.68.106:53740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9WtdHPfW2QFvhmL7WlAAAAB8"] [Sat Aug 29 05:07:06.808388 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.197.61.180:13857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/class_api.php"] [unique_id "apK9WtdHPfW2QFvhmL7WlQAAADA"] [Sat Aug 29 05:07:06.817694 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.250.41:59300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/browse.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENigAABd8"] [Sat Aug 29 05:07:06.824877 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.52.41.200:1446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-content/admin.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENiwAABgE"] [Sat Aug 29 05:07:06.845706 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.48.160.90:51695] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "highqualitytea.com"] [uri "/1.php"] [unique_id "apK9WtdHPfW2QFvhmL7WngAAACY"] [Sat Aug 29 05:07:06.845802 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.48.160.90:51695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/1.php"] [unique_id "apK9WtdHPfW2QFvhmL7WngAAACY"] [Sat Aug 29 05:07:06.846544 2026] [security2:error] [pid 1028675:tid 1028859] [client 158.23.147.79:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/admin.php"] [unique_id "apK9WtdHPfW2QFvhmL7WnwAAADE"] [Sat Aug 29 05:07:06.851413 2026] [security2:error] [pid 1028675:tid 1028933] [client 52.139.37.240:30145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/admin/function.php"] [unique_id "apK9WtdHPfW2QFvhmL7WoAAAAHs"] [Sat Aug 29 05:07:06.872922 2026] [security2:error] [pid 1028675:tid 1028822] [client 93.123.109.228:39148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9WtdHPfW2QFvhmL7WpAAAAAw"] [Sat Aug 29 05:07:06.876996 2026] [security2:error] [pid 1018003:tid 1018217] [client 93.123.109.228:39186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9WjAh5Y1i2tUxg4ENjAAABfo"] [Sat Aug 29 05:07:06.886168 2026] [security2:error] [pid 1018003:tid 1018244] [client 4.205.62.107:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/adminer-4.7.6-en.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENjgAABhQ"] [Sat Aug 29 05:07:06.890999 2026] [security2:error] [pid 1028675:tid 1028850] [client 4.205.62.107:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/G-in.php"] [unique_id "apK9WtdHPfW2QFvhmL7WqQAAACg"] [Sat Aug 29 05:07:06.910865 2026] [security2:error] [pid 1018003:tid 1018159] [client 4.205.62.107:22391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/ms.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENkAAABcA"] [Sat Aug 29 05:07:06.917591 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/ops.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENkQAABcA"] [Sat Aug 29 05:07:06.927535 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.196.209.81:5866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/about.php"] [unique_id "apK9WtdHPfW2QFvhmL7WqwAAAEc"] [Sat Aug 29 05:07:06.928647 2026] [security2:error] [pid 1018003:tid 1018169] [client 52.139.37.240:32029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENkgAABco"] [Sat Aug 29 05:07:06.932313 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.184.117:11961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENkwAABeE"] [Sat Aug 29 05:07:06.938398 2026] [security2:error] [pid 1028675:tid 1028930] [client 158.158.54.35:10332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-trackback.php"] [unique_id "apK9WtdHPfW2QFvhmL7WrAAAAHg"] [Sat Aug 29 05:07:06.947963 2026] [security2:error] [pid 1018003:tid 1018187] [client 52.139.37.240:21166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENlAAABdw"] [Sat Aug 29 05:07:06.950074 2026] [security2:error] [pid 1018003:tid 1018196] [client 68.155.159.216:30696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/NewFile.php/"] [unique_id "apK9WjAh5Y1i2tUxg4ENlQAABeU"] [Sat Aug 29 05:07:06.951272 2026] [security2:error] [pid 1028675:tid 1028833] [client 20.48.250.41:60777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/zoo.php"] [unique_id "apK9WtdHPfW2QFvhmL7WtAAAABc"] [Sat Aug 29 05:07:06.958705 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.196.209.81:11275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/global.php"] [unique_id "apK9WtdHPfW2QFvhmL7WtgAAACk"] [Sat Aug 29 05:07:06.980867 2026] [security2:error] [pid 1028675:tid 1028811] [client 158.23.184.117:63751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wk/admin.php"] [unique_id "apK9WtdHPfW2QFvhmL7WuwAAAAE"] [Sat Aug 29 05:07:06.980950 2026] [security2:error] [pid 1028675:tid 1028904] [client 93.123.109.228:39206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9WtdHPfW2QFvhmL7WuQAAAF4"] [Sat Aug 29 05:07:06.984847 2026] [security2:error] [pid 1028675:tid 1028854] [client 93.123.109.228:39226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9WtdHPfW2QFvhmL7WvAAAACw"] [Sat Aug 29 05:07:06.987962 2026] [security2:error] [pid 1018003:tid 1018246] [client 40.83.93.50:3872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/wp-configs.php"] [unique_id "apK9WjAh5Y1i2tUxg4ENmAAABhY"] [Sat Aug 29 05:07:06.989192 2026] [security2:error] [pid 1028675:tid 1028817] [client 68.155.159.216:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9WtdHPfW2QFvhmL7WvQAAAAc"] [Sat Aug 29 05:07:07.021485 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.160.90:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/classwithtostring.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENnQAABgY"] [Sat Aug 29 05:07:07.036126 2026] [security2:error] [pid 1028675:tid 1028823] [client 20.203.141.11:45420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/w.php"] [unique_id "apK9W9dHPfW2QFvhmL7WvwAAAA0"] [Sat Aug 29 05:07:07.049095 2026] [security2:error] [pid 1028675:tid 1028849] [client 40.83.93.50:13608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK9W9dHPfW2QFvhmL7WwAAAACc"] [Sat Aug 29 05:07:07.051112 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.184.117:2590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-admin/link-add.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENoQAABiY"] [Sat Aug 29 05:07:07.064506 2026] [security2:error] [pid 1018003:tid 1018157] [client 52.139.37.240:29999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/zoom1.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENogAABb4"] [Sat Aug 29 05:07:07.065193 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.158.54.35:35228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/p.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENowAABcQ"] [Sat Aug 29 05:07:07.075998 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.104.18.15:13757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/img.php"] [unique_id "apK9W9dHPfW2QFvhmL7WwgAAABk"] [Sat Aug 29 05:07:07.077920 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.23.184.117:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/robots.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENpAAABfk"] [Sat Aug 29 05:07:07.083546 2026] [security2:error] [pid 1028675:tid 1028936] [client 93.123.109.228:39100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9W9dHPfW2QFvhmL7WwwAAAH4"] [Sat Aug 29 05:07:07.086184 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.18.15:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/coffexium.php"] [unique_id "apK9W9dHPfW2QFvhmL7WxAAAAE8"] [Sat Aug 29 05:07:07.086670 2026] [security2:error] [pid 1028675:tid 1028856] [client 68.155.159.216:33737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-admin/about.php"] [unique_id "apK9W9dHPfW2QFvhmL7WxQAAAC4"] [Sat Aug 29 05:07:07.091757 2026] [security2:error] [pid 1028675:tid 1028832] [client 158.23.147.79:17415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9W9dHPfW2QFvhmL7WxgAAABY"] [Sat Aug 29 05:07:07.096365 2026] [security2:error] [pid 1028675:tid 1028830] [client 168.107.94.195:61245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9W9dHPfW2QFvhmL7WxwAAABQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:07.102110 2026] [security2:error] [pid 1028675:tid 1028826] [client 68.155.159.216:12252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/goat1.php"] [unique_id "apK9W9dHPfW2QFvhmL7WyAAAABA"] [Sat Aug 29 05:07:07.117613 2026] [security2:error] [pid 1028675:tid 1028872] [client 103.162.125.59:55748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9W9dHPfW2QFvhmL7WyQAAAD4"] [Sat Aug 29 05:07:07.117772 2026] [security2:error] [pid 1028675:tid 1028872] [client 103.162.125.59:55748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9W9dHPfW2QFvhmL7WyQAAAD4"] [Sat Aug 29 05:07:07.125302 2026] [security2:error] [pid 1028675:tid 1028871] [client 158.23.184.117:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/admin.php"] [unique_id "apK9W9dHPfW2QFvhmL7WygAAAD0"] [Sat Aug 29 05:07:07.133271 2026] [security2:error] [pid 1028675:tid 1028873] [client 20.104.18.15:36722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/vpn.php"] [unique_id "apK9W9dHPfW2QFvhmL7WywAAAD8"] [Sat Aug 29 05:07:07.136295 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.48.250.41:60718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/elp.php"] [unique_id "apK9W9dHPfW2QFvhmL7WzAAAAFg"] [Sat Aug 29 05:07:07.140456 2026] [security2:error] [pid 1028675:tid 1028842] [client 52.139.37.240:21146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK9W9dHPfW2QFvhmL7WzgAAACA"] [Sat Aug 29 05:07:07.145684 2026] [security2:error] [pid 1028675:tid 1028828] [client 52.139.37.240:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-header-json.php"] [unique_id "apK9W9dHPfW2QFvhmL7W0QAAABI"] [Sat Aug 29 05:07:07.162962 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.48.160.90:51617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-ws68.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENqQAABcs"] [Sat Aug 29 05:07:07.188680 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.49.130:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/x1da.php"] [unique_id "apK9W9dHPfW2QFvhmL7W1AAAADI"] [Sat Aug 29 05:07:07.197046 2026] [security2:error] [pid 1028675:tid 1028922] [client 158.23.184.117:2769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/Text.php"] [unique_id "apK9W9dHPfW2QFvhmL7W1QAAAHA"] [Sat Aug 29 05:07:07.198027 2026] [security2:error] [pid 1028675:tid 1028900] [client 4.205.62.107:53326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/ebahvhhh.php"] [unique_id "apK9W9dHPfW2QFvhmL7W1gAAAFo"] [Sat Aug 29 05:07:07.215952 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.104.18.15:13716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/222.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENrQAABjE"] [Sat Aug 29 05:07:07.224731 2026] [security2:error] [pid 1018003:tid 1018191] [client 68.155.159.216:64470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENrgAABeA"] [Sat Aug 29 05:07:07.226299 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.104.18.15:5108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/BDKR28WP.php"] [unique_id "apK9W9dHPfW2QFvhmL7W2gAAAHs"] [Sat Aug 29 05:07:07.230471 2026] [security2:error] [pid 1028675:tid 1028894] [client 68.155.159.216:1935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/goods.php"] [unique_id "apK9W9dHPfW2QFvhmL7W3QAAAFQ"] [Sat Aug 29 05:07:07.232310 2026] [security2:error] [pid 1028675:tid 1028921] [client 68.155.159.216:24558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9W9dHPfW2QFvhmL7W4gAAAG8"] [Sat Aug 29 05:07:07.236319 2026] [security2:error] [pid 1028675:tid 1028880] [client 158.23.184.117:11949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/.well-known/install.php"] [unique_id "apK9W9dHPfW2QFvhmL7W4wAAAEY"] [Sat Aug 29 05:07:07.259419 2026] [security2:error] [pid 1028675:tid 1028853] [client 52.139.37.240:29831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/about.php7"] [unique_id "apK9W9dHPfW2QFvhmL7W5gAAACs"] [Sat Aug 29 05:07:07.266559 2026] [security2:error] [pid 1028675:tid 1028931] [client 20.48.250.41:59340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/666.php"] [unique_id "apK9W9dHPfW2QFvhmL7W6AAAAHk"] [Sat Aug 29 05:07:07.269412 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.151.200.44:47333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/waf.php"] [unique_id "apK9W9dHPfW2QFvhmL7W6QAAAEc"] [Sat Aug 29 05:07:07.269910 2026] [security2:error] [pid 1028675:tid 1028859] [client 158.23.184.117:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/goods.php"] [unique_id "apK9W9dHPfW2QFvhmL7W6gAAADE"] [Sat Aug 29 05:07:07.273988 2026] [security2:error] [pid 1028675:tid 1028772] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/.wp-config.php.swp"] [unique_id "apK9W9dHPfW2QFvhmL7W6wAAW1s"] [Sat Aug 29 05:07:07.276140 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.52.41.200:1417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-configs.php"] [unique_id "apK9W9dHPfW2QFvhmL7W7AAAADU"] [Sat Aug 29 05:07:07.279412 2026] [security2:error] [pid 1028675:tid 1028930] [client 20.104.18.15:36558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/shiny.php"] [unique_id "apK9W9dHPfW2QFvhmL7W7gAAAHg"] [Sat Aug 29 05:07:07.292168 2026] [security2:error] [pid 1018003:tid 1018238] [client 68.155.159.216:51300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/packed.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENsgAABg4"] [Sat Aug 29 05:07:07.331061 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.196.209.81:22452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/admin-header.php"] [unique_id "apK9W9dHPfW2QFvhmL7W8AAAACM"] [Sat Aug 29 05:07:07.340265 2026] [security2:error] [pid 1028675:tid 1028918] [client 4.205.62.107:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/xmy.php"] [unique_id "apK9W9dHPfW2QFvhmL7W8QAAAGw"] [Sat Aug 29 05:07:07.340265 2026] [security2:error] [pid 1018003:tid 1018179] [client 52.139.37.240:32078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/zup.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENswAABdQ"] [Sat Aug 29 05:07:07.343875 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.48.160.90:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/simple.php"] [unique_id "apK9W9dHPfW2QFvhmL7W8gAAAAs"] [Sat Aug 29 05:07:07.347235 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.147.79:48318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/css/index.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENtAAABiU"] [Sat Aug 29 05:07:07.353275 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.184.117:2561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-trackback.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENtQAABik"] [Sat Aug 29 05:07:07.358686 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:26435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/xmlrpc.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENuAAABgc"] [Sat Aug 29 05:07:07.360242 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.104.18.15:13739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/key.php"] [unique_id "apK9W9dHPfW2QFvhmL7W9QAAAC8"] [Sat Aug 29 05:07:07.373738 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.196.209.81:11274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/update.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENuQAABec"] [Sat Aug 29 05:07:07.374836 2026] [security2:error] [pid 1028675:tid 1028937] [client 158.23.147.79:50100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/makeasmtp.php"] [unique_id "apK9W9dHPfW2QFvhmL7W-AAAAH8"] [Sat Aug 29 05:07:07.375026 2026] [security2:error] [pid 1028675:tid 1028810] [client 20.104.18.15:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/sf.php"] [unique_id "apK9W9dHPfW2QFvhmL7W-QAAAAA"] [Sat Aug 29 05:07:07.377949 2026] [core:error] [pid 1028675:tid 1028916] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:07.377967 2026] [core:error] [pid 1028675:tid 1028916] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:07.414767 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.184.117:63788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/w.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENvAAABfw"] [Sat Aug 29 05:07:07.432663 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.48.250.41:60747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/knmt.php"] [unique_id "apK9W9dHPfW2QFvhmL7W_gAAAD4"] [Sat Aug 29 05:07:07.435080 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:39166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENvQAABdw"] [Sat Aug 29 05:07:07.439663 2026] [security2:error] [pid 1028675:tid 1028923] [client 158.23.184.117:11947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-admin/about.php"] [unique_id "apK9W9dHPfW2QFvhmL7XAQAAAHE"] [Sat Aug 29 05:07:07.455063 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.104.18.15:36612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/goods.php"] [unique_id "apK9W9dHPfW2QFvhmL7XBAAAAFg"] [Sat Aug 29 05:07:07.455259 2026] [security2:error] [pid 1028675:tid 1028936] [client 52.139.37.240:30148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/cron.php"] [unique_id "apK9W9dHPfW2QFvhmL7XBQAAAH4"] [Sat Aug 29 05:07:07.466880 2026] [security2:error] [pid 1028675:tid 1028877] [client 40.83.93.50:17327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/essexec.php"] [unique_id "apK9W9dHPfW2QFvhmL7XBgAAAEM"] [Sat Aug 29 05:07:07.472818 2026] [security2:error] [pid 1028675:tid 1028915] [client 158.23.147.79:25472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/content.php"] [unique_id "apK9W9dHPfW2QFvhmL7XCAAAAGk"] [Sat Aug 29 05:07:07.478174 2026] [security2:error] [pid 1028675:tid 1028855] [client 168.107.94.195:61526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9W9dHPfW2QFvhmL7XCQAAAC0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:07.480452 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.48.160.90:51613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/aaa.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENvwAABiw"] [Sat Aug 29 05:07:07.483730 2026] [security2:error] [pid 1018003:tid 1018202] [client 68.155.159.216:33725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/classwithtostring.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENwAAABes"] [Sat Aug 29 05:07:07.502344 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.203.141.11:43359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/ahax.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENwgAABgE"] [Sat Aug 29 05:07:07.507882 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.104.18.15:4993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/k.php"] [unique_id "apK9W9dHPfW2QFvhmL7XCwAAAE0"] [Sat Aug 29 05:07:07.511187 2026] [security2:error] [pid 1018003:tid 1018221] [client 158.23.184.117:2954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-admin/maint.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENwwAABf4"] [Sat Aug 29 05:07:07.511970 2026] [security2:error] [pid 1018003:tid 1018213] [client 68.155.159.216:18419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/admin.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENxAAABfY"] [Sat Aug 29 05:07:07.517025 2026] [security2:error] [pid 1028675:tid 1028902] [client 40.83.93.50:20850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/wp-load.php"] [unique_id "apK9W9dHPfW2QFvhmL7XDAAAAFw"] [Sat Aug 29 05:07:07.527492 2026] [security2:error] [pid 1028675:tid 1028835] [client 158.158.54.35:14923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/a1.php"] [unique_id "apK9W9dHPfW2QFvhmL7XDQAAABk"] [Sat Aug 29 05:07:07.529231 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.104.18.15:13736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/chosen.php"] [unique_id "apK9W9dHPfW2QFvhmL7XDgAAAA8"] [Sat Aug 29 05:07:07.533000 2026] [security2:error] [pid 1028675:tid 1028842] [client 52.139.37.240:32110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/a9.php"] [unique_id "apK9W9dHPfW2QFvhmL7XDwAAACA"] [Sat Aug 29 05:07:07.536669 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.197.61.180:13856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/aksinet.php"] [unique_id "apK9W9dHPfW2QFvhmL7XEAAAACw"] [Sat Aug 29 05:07:07.548594 2026] [security2:error] [pid 1018003:tid 1018270] [client 68.155.159.216:49250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENxQAABi4"] [Sat Aug 29 05:07:07.558257 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.184.117:63775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/new.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENxgAABiA"] [Sat Aug 29 05:07:07.565612 2026] [security2:error] [pid 1028675:tid 1028920] [client 158.158.54.35:38417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/222.php"] [unique_id "apK9W9dHPfW2QFvhmL7XEgAAAG4"] [Sat Aug 29 05:07:07.576168 2026] [security2:error] [pid 1028675:tid 1028891] [client 52.139.37.240:21423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9W9dHPfW2QFvhmL7XFAAAAFE"] [Sat Aug 29 05:07:07.605534 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.48.250.41:62516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/sbhu.php"] [unique_id "apK9W9dHPfW2QFvhmL7XFwAAABs"] [Sat Aug 29 05:07:07.611935 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.184.117:11929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-content/backup.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENywAABb4"] [Sat Aug 29 05:07:07.613631 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.147.79:30669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/themes.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENzAAABdc"] [Sat Aug 29 05:07:07.649066 2026] [security2:error] [pid 1018003:tid 1018236] [client 52.139.37.240:29956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/wp-2019.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENzQAABgw"] [Sat Aug 29 05:07:07.662733 2026] [security2:error] [pid 1028675:tid 1028895] [client 158.23.184.117:2790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/num.php"] [unique_id "apK9W9dHPfW2QFvhmL7XIwAAAFU"] [Sat Aug 29 05:07:07.666035 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.18.15:13658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/file1221.php"] [unique_id "apK9WzAh5Y1i2tUxg4ENzwAABcU"] [Sat Aug 29 05:07:07.667564 2026] [security2:error] [pid 1028675:tid 1028859] [client 93.123.109.228:39132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XJAAAADE"] [Sat Aug 29 05:07:07.672261 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.104.18.15:36654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/alfa.php"] [unique_id "apK9W9dHPfW2QFvhmL7XJQAAAHU"] [Sat Aug 29 05:07:07.685825 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.104.18.15:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/82.php"] [unique_id "apK9W9dHPfW2QFvhmL7XJwAAAFI"] [Sat Aug 29 05:07:07.688701 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.23.147.79:32594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN0gAABjU"] [Sat Aug 29 05:07:07.712971 2026] [security2:error] [pid 1028675:tid 1028897] [client 4.205.62.107:22404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/xin1.php"] [unique_id "apK9W9dHPfW2QFvhmL7XKQAAAFc"] [Sat Aug 29 05:07:07.722728 2026] [security2:error] [pid 1028675:tid 1028888] [client 158.23.184.117:39989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/php8.php"] [unique_id "apK9W9dHPfW2QFvhmL7XKwAAAE4"] [Sat Aug 29 05:07:07.728274 2026] [security2:error] [pid 1028675:tid 1028881] [client 52.139.37.240:32030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/admin/index.php"] [unique_id "apK9W9dHPfW2QFvhmL7XLQAAAEc"] [Sat Aug 29 05:07:07.729294 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.104.49.130:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/chosen.php"] [unique_id "apK9W9dHPfW2QFvhmL7XLgAAACM"] [Sat Aug 29 05:07:07.730088 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.196.209.81:13157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/admin.php"] [unique_id "apK9W9dHPfW2QFvhmL7XLwAAAFk"] [Sat Aug 29 05:07:07.730153 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.52.41.200:1267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/index.php"] [unique_id "apK9W9dHPfW2QFvhmL7XMAAAAEE"] [Sat Aug 29 05:07:07.738754 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.48.250.41:59390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/a332.php"] [unique_id "apK9W9dHPfW2QFvhmL7XMgAAAAs"] [Sat Aug 29 05:07:07.766244 2026] [security2:error] [pid 1028675:tid 1028873] [client 93.123.109.228:39226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/admin/phpinfo.php"] [unique_id "apK9W9dHPfW2QFvhmL7XNgAAAD8"] [Sat Aug 29 05:07:07.766433 2026] [security2:error] [pid 1028675:tid 1028817] [client 158.23.184.117:11960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/.well-known/aa.php"] [unique_id "apK9W9dHPfW2QFvhmL7XNwAAAAc"] [Sat Aug 29 05:07:07.769675 2026] [security2:error] [pid 1028675:tid 1028924] [client 52.139.37.240:21438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-info.php"] [unique_id "apK9W9dHPfW2QFvhmL7XOAAAAHI"] [Sat Aug 29 05:07:07.801791 2026] [security2:error] [pid 1028675:tid 1028874] [client 68.155.159.216:16082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-content/themes/index.php"] [unique_id "apK9W9dHPfW2QFvhmL7XPAAAAEA"] [Sat Aug 29 05:07:07.808469 2026] [security2:error] [pid 1018003:tid 1018217] [client 68.155.159.216:6036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/file5.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN1gAABfo"] [Sat Aug 29 05:07:07.810295 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/nox.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN1wAABec"] [Sat Aug 29 05:07:07.814521 2026] [security2:error] [pid 1028675:tid 1028914] [client 158.23.184.117:2563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/identity.php"] [unique_id "apK9W9dHPfW2QFvhmL7XPQAAAGg"] [Sat Aug 29 05:07:07.825707 2026] [security2:error] [pid 1028675:tid 1028935] [client 20.104.18.15:36584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/33.php"] [unique_id "apK9W9dHPfW2QFvhmL7XPgAAAH0"] [Sat Aug 29 05:07:07.836886 2026] [security2:error] [pid 1018003:tid 1018159] [client 158.23.147.79:30588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-mail.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN2QAABcA"] [Sat Aug 29 05:07:07.838731 2026] [security2:error] [pid 1028675:tid 1028898] [client 52.139.37.240:30153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/gecko-new.php"] [unique_id "apK9W9dHPfW2QFvhmL7XPwAAAFg"] [Sat Aug 29 05:07:07.842314 2026] [http2:warn] [pid 1017536:tid 1017690] [client 57.141.14.59:50242] h2_stream(1017536-275-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:07:07.858995 2026] [security2:error] [pid 1018003:tid 1018187] [client 168.107.94.195:61827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN2wAABdw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:07.868527 2026] [security2:error] [pid 1018003:tid 1018258] [client 158.23.184.117:63744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN3AAABiI"] [Sat Aug 29 05:07:07.897596 2026] [cgid:error] [pid 1018003:tid 1018177] [client 34.7.40.70:9784] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.898233 2026] [security2:error] [pid 1028675:tid 1028906] [client 34.7.40.70:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/prod/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XSwAAAGA"] [Sat Aug 29 05:07:07.899593 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.18.15:5002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/dex.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN3gAABhY"] [Sat Aug 29 05:07:07.900495 2026] [security2:error] [pid 1018003:tid 1018233] [client 34.7.40.70:9844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/test/.env"] [unique_id "apK9WzAh5Y1i2tUxg4EN3wAABgk"] [Sat Aug 29 05:07:07.900653 2026] [security2:error] [pid 1018003:tid 1018203] [client 34.7.40.70:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/internal/.env"] [unique_id "apK9WzAh5Y1i2tUxg4EN4AAABew"] [Sat Aug 29 05:07:07.901931 2026] [security2:error] [pid 1028675:tid 1028812] [client 34.7.40.70:9864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/services/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XTAAAAAI"] [Sat Aug 29 05:07:07.902104 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.196.209.81:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/blog.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN4QAABcE"] [Sat Aug 29 05:07:07.904664 2026] [security2:error] [pid 1028675:tid 1028867] [client 34.7.40.70:9800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/back/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XTQAAADk"] [Sat Aug 29 05:07:07.904958 2026] [security2:error] [pid 1018003:tid 1018183] [client 34.7.40.70:9820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/development/.env"] [unique_id "apK9WzAh5Y1i2tUxg4EN4wAABdg"] [Sat Aug 29 05:07:07.908526 2026] [security2:error] [pid 1028675:tid 1028937] [client 34.7.40.70:9804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/backend-api/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XTgAAAH8"] [Sat Aug 29 05:07:07.908699 2026] [security2:error] [pid 1028675:tid 1028831] [client 34.7.40.70:10014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.40.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/config/env.php"] [unique_id "apK9W9dHPfW2QFvhmL7XUQAAABU"] [Sat Aug 29 05:07:07.910816 2026] [security2:error] [pid 1028675:tid 1028810] [client 34.7.40.70:9928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/backend/api/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XUAAAAAA"] [Sat Aug 29 05:07:07.910840 2026] [security2:error] [pid 1018003:tid 1018172] [client 34.7.40.70:9896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/app/backend/.env"] [unique_id "apK9WzAh5Y1i2tUxg4EN5AAABc0"] [Sat Aug 29 05:07:07.910874 2026] [security2:error] [pid 1018003:tid 1018190] [client 34.7.40.70:9848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/node/.env"] [unique_id "apK9WzAh5Y1i2tUxg4EN5QAABd8"] [Sat Aug 29 05:07:07.911177 2026] [security2:error] [pid 1028675:tid 1028857] [client 34.7.40.70:9828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/stage/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XUgAAAC8"] [Sat Aug 29 05:07:07.911635 2026] [cgid:error] [pid 1018003:tid 1018238] [client 34.7.40.70:9962] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.911977 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.184.117:11925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN6AAABc8"] [Sat Aug 29 05:07:07.914926 2026] [security2:error] [pid 1018003:tid 1018265] [client 34.7.40.70:10028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/private/.env"] [unique_id "apK9WzAh5Y1i2tUxg4EN5gAABik"] [Sat Aug 29 05:07:07.915082 2026] [security2:error] [pid 1028675:tid 1028856] [client 34.7.40.70:9932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/frontend/.env.local"] [unique_id "apK9W9dHPfW2QFvhmL7XWQAAAC4"] [Sat Aug 29 05:07:07.916695 2026] [cgid:error] [pid 1028675:tid 1028849] [client 34.7.40.70:9918] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.916697 2026] [cgid:error] [pid 1028675:tid 1028905] [client 34.7.40.70:9946] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.917225 2026] [security2:error] [pid 1028675:tid 1028850] [client 34.7.40.70:10018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/src/api/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XUwAAACg"] [Sat Aug 29 05:07:07.920523 2026] [security2:error] [pid 1028675:tid 1028826] [client 34.7.40.70:9994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/apps/backend/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XWgAAABA"] [Sat Aug 29 05:07:07.921317 2026] [cgid:error] [pid 1028675:tid 1028813] [client 34.7.40.70:9998] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.921676 2026] [security2:error] [pid 1028675:tid 1028839] [client 34.7.40.70:9984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/apps/api/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XVQAAAB0"] [Sat Aug 29 05:07:07.922714 2026] [cgid:error] [pid 1028675:tid 1028819] [client 34.7.40.70:9944] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.923911 2026] [cgid:error] [pid 1028675:tid 1028872] [client 34.7.40.70:10004] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.924180 2026] [cgid:error] [pid 1028675:tid 1028917] [client 34.7.40.70:10016] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.924611 2026] [security2:error] [pid 1028675:tid 1028861] [client 34.7.40.70:9990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/database/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XXwAAADM"] [Sat Aug 29 05:07:07.924832 2026] [cgid:error] [pid 1028675:tid 1028830] [client 34.7.40.70:9972] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.926668 2026] [cgid:error] [pid 1028675:tid 1028832] [client 34.7.40.70:9964] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.929042 2026] [security2:error] [pid 1018003:tid 1018234] [client 52.139.37.240:32706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/makeasmtp.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN6QAABgo"] [Sat Aug 29 05:07:07.929287 2026] [security2:error] [pid 1018003:tid 1018221] [client 158.23.147.79:38746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/log-mama/function.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN6gAABf4"] [Sat Aug 29 05:07:07.931653 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.250.41:62529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ws66.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN7AAABfU"] [Sat Aug 29 05:07:07.934617 2026] [security2:error] [pid 1028675:tid 1028916] [client 34.7.40.70:9902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/app/api/.env"] [unique_id "apK9W9dHPfW2QFvhmL7XYAAAAGo"] [Sat Aug 29 05:07:07.938006 2026] [cgid:error] [pid 1018003:tid 1018261] [client 34.7.40.70:9978] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.938462 2026] [cgid:error] [pid 1018003:tid 1018179] [client 34.7.40.70:9956] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.941154 2026] [cgid:error] [pid 1028675:tid 1028833] [client 34.7.40.70:9980] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/textualconcepts/404.shtml [Sat Aug 29 05:07:07.941322 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.104.18.15:13750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/akismet.php"] [unique_id "apK9W9dHPfW2QFvhmL7XYgAAABk"] [Sat Aug 29 05:07:07.947334 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.151.200.44:47342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/bnnof6.php"] [unique_id "apK9W9dHPfW2QFvhmL7XYwAAAA8"] [Sat Aug 29 05:07:07.947494 2026] [security2:error] [pid 1018003:tid 1018261] [client 34.7.40.70:9978] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9WzAh5Y1i2tUxg4EN5wAABiU"] [Sat Aug 29 05:07:07.947604 2026] [security2:error] [pid 1018003:tid 1018179] [client 34.7.40.70:9956] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "textualconcepts.lowfatdinnermenus.com"] [uri "/404.shtml"] [unique_id "apK9WzAh5Y1i2tUxg4EN6wAABdQ"] [Sat Aug 29 05:07:07.953700 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.147.79:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/xmlrpc.php"] [unique_id "apK9W9dHPfW2QFvhmL7XZAAAADA"] [Sat Aug 29 05:07:07.964277 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.203.141.11:11201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/shell.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN7QAABb0"] [Sat Aug 29 05:07:07.966972 2026] [security2:error] [pid 1028675:tid 1028890] [client 52.139.37.240:21154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK9W9dHPfW2QFvhmL7XZgAAAFA"] [Sat Aug 29 05:07:07.971868 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.104.49.130:60935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/yawa.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN7gAABiA"] [Sat Aug 29 05:07:07.974004 2026] [security2:error] [pid 1028675:tid 1028862] [client 40.83.93.50:7599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/hello.php"] [unique_id "apK9W9dHPfW2QFvhmL7XZwAAADQ"] [Sat Aug 29 05:07:07.984774 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.158.54.35:29664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9WzAh5Y1i2tUxg4EN8AAABdk"] [Sat Aug 29 05:07:07.989295 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.104.18.15:36660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/133.php"] [unique_id "apK9W9dHPfW2QFvhmL7XaQAAAEo"] [Sat Aug 29 05:07:07.990366 2026] [security2:error] [pid 1028675:tid 1028933] [client 93.123.109.228:39162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/admin_phpinfo.php"] [unique_id "apK9W9dHPfW2QFvhmL7XagAAAHs"] [Sat Aug 29 05:07:07.995169 2026] [security2:error] [pid 1028675:tid 1028828] [client 40.83.93.50:20845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK9W9dHPfW2QFvhmL7XawAAABI"] [Sat Aug 29 05:07:08.013797 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.184.117:63786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/txets.php"] [unique_id "apK9XDAh5Y1i2tUxg4EN8QAABhA"] [Sat Aug 29 05:07:08.023713 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.184.117:2582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/Radio.php"] [unique_id "apK9XDAh5Y1i2tUxg4EN8gAABf8"] [Sat Aug 29 05:07:08.034452 2026] [security2:error] [pid 1018003:tid 1018230] [client 52.139.37.240:29873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/add_actualites.php"] [unique_id "apK9XDAh5Y1i2tUxg4EN8wAABgY"] [Sat Aug 29 05:07:08.036323 2026] [security2:error] [pid 1018003:tid 1018262] [client 4.205.62.107:65424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/phpi.php"] [unique_id "apK9XDAh5Y1i2tUxg4EN9AAABiY"] [Sat Aug 29 05:07:08.044076 2026] [security2:error] [pid 1028675:tid 1028814] [client 4.205.62.107:22398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/ccou.php"] [unique_id "apK9XNdHPfW2QFvhmL7XdgAAAAQ"] [Sat Aug 29 05:07:08.052603 2026] [security2:error] [pid 1018003:tid 1018195] [client 93.123.109.228:39094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9XDAh5Y1i2tUxg4EN9QAABeQ"] [Sat Aug 29 05:07:08.054613 2026] [security2:error] [pid 1028675:tid 1028840] [client 4.205.62.107:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/classsmtps.php"] [unique_id "apK9XNdHPfW2QFvhmL7XdwAAAB4"] [Sat Aug 29 05:07:08.063789 2026] [security2:error] [pid 1028675:tid 1028894] [client 158.23.184.117:11913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9XNdHPfW2QFvhmL7XeAAAAFQ"] [Sat Aug 29 05:07:08.065651 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.158.54.35:16781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/x.php"] [unique_id "apK9XDAh5Y1i2tUxg4EN9gAABd4"] [Sat Aug 29 05:07:08.073736 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.104.18.15:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/inso.php"] [unique_id "apK9XNdHPfW2QFvhmL7XeQAAADU"] [Sat Aug 29 05:07:08.093028 2026] [security2:error] [pid 1028675:tid 1028892] [client 68.155.159.216:64478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9XNdHPfW2QFvhmL7XewAAAFI"] [Sat Aug 29 05:07:08.101922 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.48.250.41:60735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ws68.php"] [unique_id "apK9XNdHPfW2QFvhmL7XfAAAAGE"] [Sat Aug 29 05:07:08.125809 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.196.209.81:17195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK9XNdHPfW2QFvhmL7XfgAAAEk"] [Sat Aug 29 05:07:08.134453 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.104.18.15:13679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/ajax.php"] [unique_id "apK9XNdHPfW2QFvhmL7XhAAAACM"] [Sat Aug 29 05:07:08.138297 2026] [security2:error] [pid 1028675:tid 1028875] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9XNdHPfW2QFvhmL7XhgAAAEE"] [Sat Aug 29 05:07:08.142144 2026] [security2:error] [pid 1028675:tid 1028859] [client 52.139.37.240:32126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/paku.php"] [unique_id "apK9XNdHPfW2QFvhmL7XhwAAADE"] [Sat Aug 29 05:07:08.144270 2026] [security2:error] [pid 1028675:tid 1028919] [client 213.202.253.4:60113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/wp-content/postnews.php"] [unique_id "apK9XNdHPfW2QFvhmL7XiAAAAG0"], referer: www.google.com [Sat Aug 29 05:07:08.154468 2026] [security2:error] [pid 1028675:tid 1028870] [client 158.23.184.117:63757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/adminfuns.php"] [unique_id "apK9XNdHPfW2QFvhmL7XigAAADw"] [Sat Aug 29 05:07:08.163596 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.104.18.15:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/sym.php"] [unique_id "apK9XNdHPfW2QFvhmL7XjAAAAHI"] [Sat Aug 29 05:07:08.165123 2026] [security2:error] [pid 1028675:tid 1028851] [client 52.139.37.240:21428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/ws49.php"] [unique_id "apK9XNdHPfW2QFvhmL7XjQAAACk"] [Sat Aug 29 05:07:08.170453 2026] [security2:error] [pid 1028675:tid 1028816] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9XNdHPfW2QFvhmL7XjwAAAAY"] [Sat Aug 29 05:07:08.188491 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.52.41.200:1157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin/a.php"] [unique_id "apK9XDAh5Y1i2tUxg4EN-wAABgw"] [Sat Aug 29 05:07:08.192304 2026] [security2:error] [pid 1028675:tid 1028929] [client 68.155.159.216:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9XNdHPfW2QFvhmL7XkQAAAHc"] [Sat Aug 29 05:07:08.210031 2026] [security2:error] [pid 1028675:tid 1028855] [client 20.48.160.90:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/shiny.php"] [unique_id "apK9XNdHPfW2QFvhmL7XlgAAAC0"] [Sat Aug 29 05:07:08.212301 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.104.18.15:5077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/aa.php"] [unique_id "apK9XNdHPfW2QFvhmL7XlwAAAHE"] [Sat Aug 29 05:07:08.214494 2026] [security2:error] [pid 1018003:tid 1018159] [client 68.155.159.216:12118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9XDAh5Y1i2tUxg4EN_QAABcA"] [Sat Aug 29 05:07:08.215561 2026] [security2:error] [pid 1028675:tid 1028935] [client 158.23.184.117:2575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/Requests/Exception/file.php"] [unique_id "apK9XNdHPfW2QFvhmL7XnAAAAH0"] [Sat Aug 29 05:07:08.228737 2026] [security2:error] [pid 1028675:tid 1028836] [client 52.139.37.240:29863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/browse.php"] [unique_id "apK9XNdHPfW2QFvhmL7XnQAAABo"] [Sat Aug 29 05:07:08.242129 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.49.130:30063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/sd.php"] [unique_id "apK9XNdHPfW2QFvhmL7XoAAAAFw"] [Sat Aug 29 05:07:08.261361 2026] [security2:error] [pid 1028675:tid 1028928] [client 168.107.94.195:62183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9XNdHPfW2QFvhmL7XoQAAAHY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:08.269571 2026] [security2:error] [pid 1028675:tid 1028922] [client 93.123.109.228:39132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9XNdHPfW2QFvhmL7XogAAAHA"] [Sat Aug 29 05:07:08.272735 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.197.61.180:13880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/alfa-rex1.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOAQAABgM"] [Sat Aug 29 05:07:08.273904 2026] [security2:error] [pid 1018003:tid 1018196] [client 158.23.184.117:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/test.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOAgAABeU"] [Sat Aug 29 05:07:08.274115 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.48.250.41:60751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/users.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOAwAABbk"] [Sat Aug 29 05:07:08.275034 2026] [security2:error] [pid 1028675:tid 1028812] [client 20.104.18.15:13749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/atomlib.php"] [unique_id "apK9XNdHPfW2QFvhmL7XowAAAAI"] [Sat Aug 29 05:07:08.299025 2026] [security2:error] [pid 1028675:tid 1028879] [client 158.23.184.117:39966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/403.php"] [unique_id "apK9XNdHPfW2QFvhmL7XpAAAAEU"] [Sat Aug 29 05:07:08.308543 2026] [security2:error] [pid 1018003:tid 1018268] [client 93.123.109.228:39106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/api/info.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOBgAABiw"] [Sat Aug 29 05:07:08.308911 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.104.104.62:44606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9XNdHPfW2QFvhmL7XpQAAACg"] [Sat Aug 29 05:07:08.309209 2026] [security2:error] [pid 1028675:tid 1028936] [client 20.196.209.81:15168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/bypass.php"] [unique_id "apK9XNdHPfW2QFvhmL7XpgAAAH4"] [Sat Aug 29 05:07:08.329619 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:36657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/8.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOCAAABes"] [Sat Aug 29 05:07:08.330700 2026] [security2:error] [pid 1028675:tid 1028813] [client 68.155.159.216:24448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9XNdHPfW2QFvhmL7XpwAAAAM"] [Sat Aug 29 05:07:08.332041 2026] [security2:error] [pid 1028675:tid 1028839] [client 68.155.159.216:65141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/asd.php"] [unique_id "apK9XNdHPfW2QFvhmL7XqAAAAB0"] [Sat Aug 29 05:07:08.336916 2026] [security2:error] [pid 1028675:tid 1028819] [client 68.155.159.216:1933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9XNdHPfW2QFvhmL7XqQAAAAk"] [Sat Aug 29 05:07:08.341110 2026] [security2:error] [pid 1028675:tid 1028841] [client 52.139.37.240:32745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/rtx.php"] [unique_id "apK9XNdHPfW2QFvhmL7XqgAAAB8"] [Sat Aug 29 05:07:08.348239 2026] [security2:error] [pid 1028675:tid 1028832] [client 20.151.200.44:47422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/ah24.php"] [unique_id "apK9XNdHPfW2QFvhmL7XqwAAABY"] [Sat Aug 29 05:07:08.362817 2026] [security2:error] [pid 1018003:tid 1018258] [client 52.139.37.240:21160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/xxx.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOCQAABiI"] [Sat Aug 29 05:07:08.370024 2026] [security2:error] [pid 1028675:tid 1028880] [client 4.205.62.107:9195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/bthil.php"] [unique_id "apK9XNdHPfW2QFvhmL7XsQAAAEY"] [Sat Aug 29 05:07:08.388572 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.48.160.90:51285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/goods.php"] [unique_id "apK9XNdHPfW2QFvhmL7XtQAAAEo"] [Sat Aug 29 05:07:08.404271 2026] [security2:error] [pid 1028675:tid 1028828] [client 93.123.109.228:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/api/phpinfo.php"] [unique_id "apK9XNdHPfW2QFvhmL7XtgAAABI"] [Sat Aug 29 05:07:08.412089 2026] [security2:error] [pid 1028675:tid 1028903] [client 158.23.184.117:2773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-admin/add.php"] [unique_id "apK9XNdHPfW2QFvhmL7XtwAAAF0"] [Sat Aug 29 05:07:08.414080 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.23.184.117:12038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/mani.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOCwAABdI"] [Sat Aug 29 05:07:08.426114 2026] [security2:error] [pid 1028675:tid 1028835] [client 52.139.37.240:29998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/contentloader1.php"] [unique_id "apK9XNdHPfW2QFvhmL7XuAAAABk"] [Sat Aug 29 05:07:08.433560 2026] [security2:error] [pid 1028675:tid 1028937] [client 158.158.54.35:14938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/alfa-rex.php7"] [unique_id "apK9XNdHPfW2QFvhmL7XugAAAH8"] [Sat Aug 29 05:07:08.433579 2026] [security2:error] [pid 1028675:tid 1028867] [client 20.203.141.11:13364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/elp.php"] [unique_id "apK9XNdHPfW2QFvhmL7XuQAAADk"] [Sat Aug 29 05:07:08.436044 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.104.18.15:5114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/img.php"] [unique_id "apK9XNdHPfW2QFvhmL7XuwAAAGQ"] [Sat Aug 29 05:07:08.445906 2026] [security2:error] [pid 1028675:tid 1028822] [client 20.104.104.62:44549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9XNdHPfW2QFvhmL7XvQAAAAw"] [Sat Aug 29 05:07:08.449746 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.104.18.15:13585] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lunar-festival.com"] [uri "/1.php"] [unique_id "apK9XNdHPfW2QFvhmL7XvgAAADg"] [Sat Aug 29 05:07:08.449807 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.104.18.15:13585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/1.php"] [unique_id "apK9XNdHPfW2QFvhmL7XvgAAADg"] [Sat Aug 29 05:07:08.460013 2026] [security2:error] [pid 1028675:tid 1028931] [client 20.48.250.41:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/bzjdlofz.php"] [unique_id "apK9XNdHPfW2QFvhmL7XwQAAAHk"] [Sat Aug 29 05:07:08.475870 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:26498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/atomlib.php"] [unique_id "apK9XDAh5Y1i2tUxg4EODQAABc8"] [Sat Aug 29 05:07:08.476733 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.49.130:43803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/echkm.php"] [unique_id "apK9XDAh5Y1i2tUxg4EODgAABik"] [Sat Aug 29 05:07:08.478108 2026] [security2:error] [pid 1018003:tid 1018213] [client 4.205.62.107:53124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ms-edit.php"] [unique_id "apK9XDAh5Y1i2tUxg4EODwAABfY"] [Sat Aug 29 05:07:08.486351 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.18.15:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/goods.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOEAAABgo"] [Sat Aug 29 05:07:08.493159 2026] [security2:error] [pid 1028675:tid 1028904] [client 158.23.184.117:63765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/.trash7206/index.php"] [unique_id "apK9XNdHPfW2QFvhmL7XwwAAAF4"] [Sat Aug 29 05:07:08.497302 2026] [security2:error] [pid 1028675:tid 1028826] [client 40.83.93.50:13591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "apK9XNdHPfW2QFvhmL7XxAAAABA"] [Sat Aug 29 05:07:08.499024 2026] [security2:error] [pid 1028675:tid 1028883] [client 158.23.147.79:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9XNdHPfW2QFvhmL7XxgAAAEk"] [Sat Aug 29 05:07:08.521636 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.48.160.90:51664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/000.php/index.php"] [unique_id "apK9XNdHPfW2QFvhmL7XyAAAAG0"] [Sat Aug 29 05:07:08.524179 2026] [security2:error] [pid 1028675:tid 1028702] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9XNdHPfW2QFvhmL7XyQAAbBU"] [Sat Aug 29 05:07:08.524763 2026] [security2:error] [pid 1028675:tid 1028896] [client 158.158.54.35:17661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/new.php"] [unique_id "apK9XNdHPfW2QFvhmL7XygAAAFY"] [Sat Aug 29 05:07:08.525876 2026] [security2:error] [pid 1028675:tid 1028833] [client 40.83.93.50:7615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/fi2.php"] [unique_id "apK9XNdHPfW2QFvhmL7XzAAAABc"] [Sat Aug 29 05:07:08.528525 2026] [security2:error] [pid 1028675:tid 1028876] [client 52.139.37.240:32095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/update/da222.php"] [unique_id "apK9XNdHPfW2QFvhmL7X1AAAAEI"] [Sat Aug 29 05:07:08.529335 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.196.209.81:22437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK9XNdHPfW2QFvhmL7X1gAAAHs"] [Sat Aug 29 05:07:08.558828 2026] [security2:error] [pid 1028675:tid 1028859] [client 158.23.184.117:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/Test.php"] [unique_id "apK9XNdHPfW2QFvhmL7X2QAAADE"] [Sat Aug 29 05:07:08.564846 2026] [security2:error] [pid 1028675:tid 1028881] [client 52.139.37.240:20754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/0x.php"] [unique_id "apK9XNdHPfW2QFvhmL7X2wAAAEc"] [Sat Aug 29 05:07:08.575753 2026] [security2:error] [pid 1028675:tid 1028924] [client 158.23.147.79:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK9XNdHPfW2QFvhmL7X3AAAAHI"] [Sat Aug 29 05:07:08.581387 2026] [security2:error] [pid 1028675:tid 1028921] [client 68.155.159.216:30677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/dropdown.php"] [unique_id "apK9XNdHPfW2QFvhmL7X3QAAAG8"] [Sat Aug 29 05:07:08.588262 2026] [security2:error] [pid 1028675:tid 1028925] [client 158.23.184.117:2615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/assets/about.php"] [unique_id "apK9XNdHPfW2QFvhmL7X3wAAAHM"] [Sat Aug 29 05:07:08.594733 2026] [security2:error] [pid 1028675:tid 1028877] [client 20.104.104.62:10477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/baee.php"] [unique_id "apK9XNdHPfW2QFvhmL7X4AAAAEM"] [Sat Aug 29 05:07:08.605017 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.104.18.15:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/222.php"] [unique_id "apK9XNdHPfW2QFvhmL7X4QAAAEs"] [Sat Aug 29 05:07:08.640178 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.23.184.117:39955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/.trash7206/admin.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOEgAABjM"] [Sat Aug 29 05:07:08.642976 2026] [security2:error] [pid 1028675:tid 1028887] [client 168.107.94.195:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9XNdHPfW2QFvhmL7X5AAAAE0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:08.644742 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.18.15:13705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/samll.php"] [unique_id "apK9XNdHPfW2QFvhmL7X5QAAAFw"] [Sat Aug 29 05:07:08.644806 2026] [security2:error] [pid 1018003:tid 1018167] [client 52.139.37.240:29976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/upfile.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOEwAABcg"] [Sat Aug 29 05:07:08.646438 2026] [cgid:error] [pid 1028675:tid 1028897] [client 20.52.41.200:1172] AH01230: invalid CGI ref "/cgi-sys/fourohfour.cgi" in /home1/lowfatdi/public_html/cpslggc/404.shtml [Sat Aug 29 05:07:08.651695 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.48.250.41:60766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/selesai.php"] [unique_id "apK9XNdHPfW2QFvhmL7X5gAAAHo"] [Sat Aug 29 05:07:08.652447 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.18.15:36661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ah.php"] [unique_id "apK9XNdHPfW2QFvhmL7X5wAAADI"] [Sat Aug 29 05:07:08.660894 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.48.160.90:51694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/Jcrop.php"] [unique_id "apK9XNdHPfW2QFvhmL7X6gAAAAg"] [Sat Aug 29 05:07:08.688736 2026] [security2:error] [pid 1028675:tid 1028861] [client 68.155.159.216:18410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/xmlrpc.php"] [unique_id "apK9XNdHPfW2QFvhmL7X7AAAADM"] [Sat Aug 29 05:07:08.720339 2026] [security2:error] [pid 1028675:tid 1028890] [client 158.23.147.79:30473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/cgi-bin/index.php"] [unique_id "apK9XNdHPfW2QFvhmL7X7gAAAFA"] [Sat Aug 29 05:07:08.727989 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.151.200.44:46593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/ztv.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOFgAABjU"] [Sat Aug 29 05:07:08.738886 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.104.104.62:10855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/d12.php"] [unique_id "apK9XNdHPfW2QFvhmL7X8gAAADg"] [Sat Aug 29 05:07:08.742157 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.196.209.81:1989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/extractable-loader-head.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOGAAABiA"] [Sat Aug 29 05:07:08.747952 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.184.117:11934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/pomo.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOGQAABgY"] [Sat Aug 29 05:07:08.752846 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.184.117:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/themes/twentytwentythree.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOGgAABdc"] [Sat Aug 29 05:07:08.757902 2026] [security2:error] [pid 1028675:tid 1028841] [client 52.139.37.240:21430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/CDX1.php"] [unique_id "apK9XNdHPfW2QFvhmL7X9QAAAB8"] [Sat Aug 29 05:07:08.758761 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.104.18.15:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/key.php"] [unique_id "apK9XNdHPfW2QFvhmL7X9gAAAFQ"] [Sat Aug 29 05:07:08.785063 2026] [security2:error] [pid 1028675:tid 1028846] [client 158.23.184.117:56517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wp-content/admin.php"] [unique_id "apK9XNdHPfW2QFvhmL7X-QAAACQ"] [Sat Aug 29 05:07:08.788701 2026] [security2:error] [pid 1028675:tid 1028840] [client 52.139.37.240:32739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-admin/min.php"] [unique_id "apK9XNdHPfW2QFvhmL7X-gAAAB4"] [Sat Aug 29 05:07:08.793911 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.48.250.41:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/shlo.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOHQAABeA"] [Sat Aug 29 05:07:08.795074 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.52.41.200:1172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9XNdHPfW2QFvhmL7X-wAAAGE"] [Sat Aug 29 05:07:08.814631 2026] [security2:error] [pid 1028675:tid 1028721] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/admin/phpinfo.php"] [unique_id "apK9XNdHPfW2QFvhmL7YAwAASSg"] [Sat Aug 29 05:07:08.827682 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.104.18.15:13700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/she11.php"] [unique_id "apK9XNdHPfW2QFvhmL7YBgAAAG0"] [Sat Aug 29 05:07:08.830224 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.48.160.90:51685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apK9XNdHPfW2QFvhmL7YBwAAAGw"] [Sat Aug 29 05:07:08.840724 2026] [security2:error] [pid 1028675:tid 1028863] [client 52.139.37.240:29986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/form.php"] [unique_id "apK9XNdHPfW2QFvhmL7YCAAAADU"] [Sat Aug 29 05:07:08.847475 2026] [security2:error] [pid 1028675:tid 1028833] [client 4.205.62.107:22425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/sadd.php"] [unique_id "apK9XNdHPfW2QFvhmL7YCQAAABc"] [Sat Aug 29 05:07:08.852834 2026] [security2:error] [pid 1028675:tid 1028876] [client 20.104.18.15:36643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ws55.php"] [unique_id "apK9XNdHPfW2QFvhmL7YCgAAAEI"] [Sat Aug 29 05:07:08.878903 2026] [security2:error] [pid 1028675:tid 1028811] [client 93.123.109.228:39204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9XNdHPfW2QFvhmL7YDAAAAAE"] [Sat Aug 29 05:07:08.882177 2026] [security2:error] [pid 1028675:tid 1028910] [client 158.158.54.35:29695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK9XNdHPfW2QFvhmL7YDQAAAGQ"] [Sat Aug 29 05:07:08.889594 2026] [security2:error] [pid 1028675:tid 1028817] [client 20.104.18.15:5101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/chosen.php"] [unique_id "apK9XNdHPfW2QFvhmL7YDgAAAAc"] [Sat Aug 29 05:07:08.891546 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.104.104.62:10473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/yyy.php"] [unique_id "apK9XNdHPfW2QFvhmL7YDwAAAEc"] [Sat Aug 29 05:07:08.903657 2026] [security2:error] [pid 1028675:tid 1028931] [client 20.203.141.11:24096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-content/cong.php"] [unique_id "apK9XNdHPfW2QFvhmL7YEAAAAHk"] [Sat Aug 29 05:07:08.905563 2026] [security2:error] [pid 1028675:tid 1028924] [client 93.123.109.228:39250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9XNdHPfW2QFvhmL7YEQAAAHI"] [Sat Aug 29 05:07:08.922916 2026] [security2:error] [pid 1028675:tid 1028725] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/admin_phpinfo.php"] [unique_id "apK9XNdHPfW2QFvhmL7YEwAAdyw"] [Sat Aug 29 05:07:08.924648 2026] [security2:error] [pid 1028675:tid 1028871] [client 68.155.159.216:6125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/file88.php"] [unique_id "apK9XNdHPfW2QFvhmL7YFAAAAD0"] [Sat Aug 29 05:07:08.929421 2026] [security2:error] [pid 1028675:tid 1028820] [client 158.23.184.117:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wp-mail.php"] [unique_id "apK9XNdHPfW2QFvhmL7YFQAAAAo"] [Sat Aug 29 05:07:08.930599 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:60689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/asax.php"] [unique_id "apK9XNdHPfW2QFvhmL7YFgAAAHM"] [Sat Aug 29 05:07:08.931972 2026] [security2:error] [pid 1028675:tid 1028871] [client 68.155.159.216:16069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/about.php"] [unique_id "apK9XNdHPfW2QFvhmL7YFwAAAD0"] [Sat Aug 29 05:07:08.945934 2026] [security2:error] [pid 1028675:tid 1028873] [client 158.23.147.79:30573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9XNdHPfW2QFvhmL7YGQAAAD8"] [Sat Aug 29 05:07:08.949642 2026] [security2:error] [pid 1018003:tid 1018225] [client 158.23.184.117:2963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/languages/themes/num.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOJQAABgI"] [Sat Aug 29 05:07:08.949782 2026] [security2:error] [pid 1018003:tid 1018196] [client 52.139.37.240:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/akcc.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOJgAABeU"] [Sat Aug 29 05:07:08.956766 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.196.209.81:13121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9XNdHPfW2QFvhmL7YGwAAABA"] [Sat Aug 29 05:07:08.964498 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:13755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/kerang.php"] [unique_id "apK9XDAh5Y1i2tUxg4EOJwAABes"] [Sat Aug 29 05:07:08.971667 2026] [security2:error] [pid 1028675:tid 1028899] [client 158.158.54.35:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/menu.php"] [unique_id "apK9XNdHPfW2QFvhmL7YHgAAAFk"] [Sat Aug 29 05:07:08.977777 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.48.160.90:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/btx25.php"] [unique_id "apK9XNdHPfW2QFvhmL7YIAAAAFc"] [Sat Aug 29 05:07:08.987934 2026] [security2:error] [pid 1028675:tid 1028845] [client 40.83.93.50:22793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK9XNdHPfW2QFvhmL7YIgAAACM"] [Sat Aug 29 05:07:08.989042 2026] [security2:error] [pid 1028675:tid 1028895] [client 20.197.61.180:7911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/headerg.php"] [unique_id "apK9XNdHPfW2QFvhmL7YIwAAAFU"] [Sat Aug 29 05:07:09.011686 2026] [security2:error] [pid 1018003:tid 1018169] [client 40.83.93.50:7542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/1p.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOKQAABco"] [Sat Aug 29 05:07:09.015280 2026] [security2:error] [pid 1018003:tid 1018258] [client 158.23.184.117:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-admin/link-add.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOKgAABiI"] [Sat Aug 29 05:07:09.026849 2026] [security2:error] [pid 1028675:tid 1028831] [client 20.104.18.15:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/file1221.php"] [unique_id "apK9XddHPfW2QFvhmL7YJQAAABU"] [Sat Aug 29 05:07:09.028481 2026] [security2:error] [pid 1028675:tid 1028810] [client 168.107.94.195:62908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9XddHPfW2QFvhmL7YJgAAAAA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:09.034777 2026] [security2:error] [pid 1028675:tid 1028923] [client 52.139.37.240:32707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK9XddHPfW2QFvhmL7YJwAAAHE"] [Sat Aug 29 05:07:09.035686 2026] [security2:error] [pid 1028675:tid 1028836] [client 52.139.37.240:30008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/wp-sigunq.php"] [unique_id "apK9XddHPfW2QFvhmL7YKAAAABo"] [Sat Aug 29 05:07:09.046114 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.104.104.62:10841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/bgymj.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOKwAABd8"] [Sat Aug 29 05:07:09.059479 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.104.18.15:36725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/drykl.php"] [unique_id "apK9XddHPfW2QFvhmL7YKgAAAB0"] [Sat Aug 29 05:07:09.059621 2026] [security2:error] [pid 1028675:tid 1028859] [client 87.219.197.128:61747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9XddHPfW2QFvhmL7YKwAAADE"] [Sat Aug 29 05:07:09.059959 2026] [security2:error] [pid 1028675:tid 1028859] [client 87.219.197.128:61747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9XddHPfW2QFvhmL7YKwAAADE"] [Sat Aug 29 05:07:09.075143 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:37922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/bk/index.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOLQAABgc"] [Sat Aug 29 05:07:09.096893 2026] [security2:error] [pid 1028675:tid 1028936] [client 158.23.184.117:2760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp.php"] [unique_id "apK9XddHPfW2QFvhmL7YLgAAAH4"] [Sat Aug 29 05:07:09.099517 2026] [security2:error] [pid 1028675:tid 1028915] [client 20.104.18.15:13742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/m.php"] [unique_id "apK9XddHPfW2QFvhmL7YMAAAAGk"] [Sat Aug 29 05:07:09.118936 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.23.184.117:63781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/3.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOLgAABdg"] [Sat Aug 29 05:07:09.146984 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.48.250.41:59380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/fetch.php"] [unique_id "apK9XddHPfW2QFvhmL7YMwAAABs"] [Sat Aug 29 05:07:09.149925 2026] [security2:error] [pid 1028675:tid 1028822] [client 68.155.159.216:49175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/login.php"] [unique_id "apK9XddHPfW2QFvhmL7YNAAAAAw"] [Sat Aug 29 05:07:09.167733 2026] [security2:error] [pid 1028675:tid 1028913] [client 4.205.62.107:65411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9XddHPfW2QFvhmL7YNQAAAGc"] [Sat Aug 29 05:07:09.171212 2026] [security2:error] [pid 1028675:tid 1028884] [client 52.139.37.240:20787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9XddHPfW2QFvhmL7YNgAAAEo"] [Sat Aug 29 05:07:09.180014 2026] [security2:error] [pid 1028675:tid 1028903] [client 158.23.184.117:11914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/Text.php"] [unique_id "apK9XddHPfW2QFvhmL7YNwAAAF0"] [Sat Aug 29 05:07:09.182909 2026] [security2:error] [pid 1018003:tid 1018270] [client 4.205.62.107:22343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/66.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOMgAABi4"] [Sat Aug 29 05:07:09.187271 2026] [security2:error] [pid 1028675:tid 1028930] [client 20.104.18.15:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/nox.php"] [unique_id "apK9XddHPfW2QFvhmL7YOQAAAHg"] [Sat Aug 29 05:07:09.192366 2026] [security2:error] [pid 1018003:tid 1018275] [client 4.205.62.107:58391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/tax.php"] [unique_id "apK9XTAh5Y1i2tUxg4EONAAABjM"] [Sat Aug 29 05:07:09.200278 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.104.62:10687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/fh26.php"] [unique_id "apK9XTAh5Y1i2tUxg4EONgAABf8"] [Sat Aug 29 05:07:09.216339 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.48.160.90:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/radio.php"] [unique_id "apK9XddHPfW2QFvhmL7YQgAAAEQ"] [Sat Aug 29 05:07:09.220128 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.196.209.81:1729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/defaults.php"] [unique_id "apK9XTAh5Y1i2tUxg4EONwAABc8"] [Sat Aug 29 05:07:09.227807 2026] [security2:error] [pid 1018003:tid 1018262] [client 158.23.147.79:17434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOOAAABiY"] [Sat Aug 29 05:07:09.229791 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.104.18.15:36791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/backup.php"] [unique_id "apK9XddHPfW2QFvhmL7YRgAAAG0"] [Sat Aug 29 05:07:09.230578 2026] [security2:error] [pid 1028675:tid 1028814] [client 52.139.37.240:32728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK9XddHPfW2QFvhmL7YRwAAAAQ"] [Sat Aug 29 05:07:09.238815 2026] [security2:error] [pid 1028675:tid 1028823] [client 20.104.49.130:48579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/dex.php"] [unique_id "apK9XddHPfW2QFvhmL7YSgAAAA0"] [Sat Aug 29 05:07:09.240743 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.184.117:2587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/xmlrpc.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOOQAABcg"] [Sat Aug 29 05:07:09.243302 2026] [security2:error] [pid 1028675:tid 1028894] [client 52.139.37.240:29883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greathairkc.com"] [uri "/07.php"] [unique_id "apK9XddHPfW2QFvhmL7YSwAAAFQ"] [Sat Aug 29 05:07:09.264294 2026] [security2:error] [pid 1028675:tid 1028891] [client 158.23.184.117:39992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK9XddHPfW2QFvhmL7YTAAAAFE"] [Sat Aug 29 05:07:09.267613 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.104.18.15:13738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/fling.php"] [unique_id "apK9XddHPfW2QFvhmL7YTQAAAEk"] [Sat Aug 29 05:07:09.271746 2026] [security2:error] [pid 1028675:tid 1028916] [client 20.52.41.200:1276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.41.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpsl-ggc.org"] [uri "/wp-admin.php"] [unique_id "apK9XddHPfW2QFvhmL7YTgAAAGo"] [Sat Aug 29 05:07:09.314306 2026] [security2:error] [pid 1028675:tid 1028841] [client 158.158.54.35:16950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/upload.php"] [unique_id "apK9XddHPfW2QFvhmL7YUQAAAB8"] [Sat Aug 29 05:07:09.320155 2026] [security2:error] [pid 1028675:tid 1028921] [client 68.155.159.216:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/network/index.php"] [unique_id "apK9XddHPfW2QFvhmL7YUgAAAG8"] [Sat Aug 29 05:07:09.325764 2026] [security2:error] [pid 1028675:tid 1028881] [client 158.23.184.117:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-trackback.php"] [unique_id "apK9XddHPfW2QFvhmL7YVQAAAEc"] [Sat Aug 29 05:07:09.337772 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.104.62:10848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/fgd.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOPQAABh8"] [Sat Aug 29 05:07:09.354848 2026] [security2:error] [pid 1028675:tid 1028908] [client 20.48.250.41:58453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/vx.php"] [unique_id "apK9XddHPfW2QFvhmL7YXAAAAGI"] [Sat Aug 29 05:07:09.356579 2026] [security2:error] [pid 1028675:tid 1028855] [client 93.123.109.228:39252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9XddHPfW2QFvhmL7YWwAAAC0"] [Sat Aug 29 05:07:09.360695 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.196.209.81:22412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/config.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOPgAABb4"] [Sat Aug 29 05:07:09.364604 2026] [security2:error] [pid 1028675:tid 1028851] [client 52.139.37.240:20789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/s.php"] [unique_id "apK9XddHPfW2QFvhmL7YXQAAACk"] [Sat Aug 29 05:07:09.365709 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.104.18.15:5060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/akismet.php"] [unique_id "apK9XddHPfW2QFvhmL7YXgAAAAU"] [Sat Aug 29 05:07:09.383586 2026] [security2:error] [pid 1018003:tid 1018230] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9XTAh5Y1i2tUxg4EOPwAABgY"] [Sat Aug 29 05:07:09.386578 2026] [security2:error] [pid 1028675:tid 1028914] [client 158.23.184.117:2789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/app.php"] [unique_id "apK9XddHPfW2QFvhmL7YYQAAAGg"] [Sat Aug 29 05:07:09.397822 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.203.141.11:7388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9XddHPfW2QFvhmL7YYwAAAAE"] [Sat Aug 29 05:07:09.397844 2026] [security2:error] [pid 1028675:tid 1028895] [client 20.104.18.15:13659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/btyuio.php"] [unique_id "apK9XddHPfW2QFvhmL7YZAAAAFU"] [Sat Aug 29 05:07:09.406500 2026] [core:error] [pid 1028675:tid 1028860] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.406517 2026] [core:error] [pid 1028675:tid 1028860] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.408544 2026] [security2:error] [pid 1028675:tid 1028898] [client 168.107.94.195:63265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9XddHPfW2QFvhmL7YZwAAAFg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:09.411484 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.48.160.90:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/dex.php"] [unique_id "apK9XddHPfW2QFvhmL7YaAAAAEY"] [Sat Aug 29 05:07:09.412848 2026] [security2:error] [pid 1028675:tid 1028746] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/api/info.php"] [unique_id "apK9XddHPfW2QFvhmL7YaQAAXEE"] [Sat Aug 29 05:07:09.416156 2026] [security2:error] [pid 1028675:tid 1028750] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/api/phpinfo.php"] [unique_id "apK9XddHPfW2QFvhmL7YcAAAXEU"] [Sat Aug 29 05:07:09.422939 2026] [security2:error] [pid 1028675:tid 1028821] [client 158.158.54.35:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9XddHPfW2QFvhmL7YdAAAAAs"] [Sat Aug 29 05:07:09.422992 2026] [security2:error] [pid 1028675:tid 1028844] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9XddHPfW2QFvhmL7YUAAAIjs"] [Sat Aug 29 05:07:09.423804 2026] [security2:error] [pid 1028675:tid 1028843] [client 52.139.37.240:52205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK9XddHPfW2QFvhmL7YdQAAACE"] [Sat Aug 29 05:07:09.441697 2026] [security2:error] [pid 1028675:tid 1028899] [client 52.139.37.240:30168] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.greathairkc.com"] [uri "/c99.php"] [unique_id "apK9XddHPfW2QFvhmL7YdwAAAFk"] [Sat Aug 29 05:07:09.442272 2026] [security2:error] [pid 1028675:tid 1028905] [client 68.155.159.216:65088] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "snackgaro.com"] [uri "/1.php"] [unique_id "apK9XddHPfW2QFvhmL7YeAAAAF8"] [Sat Aug 29 05:07:09.442473 2026] [security2:error] [pid 1028675:tid 1028905] [client 68.155.159.216:65088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/1.php"] [unique_id "apK9XddHPfW2QFvhmL7YeAAAAF8"] [Sat Aug 29 05:07:09.444635 2026] [security2:error] [pid 1028675:tid 1028928] [client 68.155.159.216:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9XddHPfW2QFvhmL7YegAAAHY"] [Sat Aug 29 05:07:09.451012 2026] [security2:error] [pid 1028675:tid 1028836] [client 68.155.159.216:24541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9XddHPfW2QFvhmL7YfAAAABo"] [Sat Aug 29 05:07:09.458155 2026] [security2:error] [pid 1028675:tid 1028816] [client 40.83.93.50:20826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-blog-header.php"] [unique_id "apK9XddHPfW2QFvhmL7YfgAAAAY"] [Sat Aug 29 05:07:09.459078 2026] [security2:error] [pid 1018003:tid 1018236] [client 158.23.184.117:40016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wp-admin/css/admin.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOQgAABgw"] [Sat Aug 29 05:07:09.460820 2026] [security2:error] [pid 1028675:tid 1028812] [client 20.104.18.15:36644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/indo.php"] [unique_id "apK9XddHPfW2QFvhmL7YfwAAAAI"] [Sat Aug 29 05:07:09.464756 2026] [security2:error] [pid 1028675:tid 1028813] [client 20.151.200.44:47350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/kure.php"] [unique_id "apK9XddHPfW2QFvhmL7YgAAAAAM"] [Sat Aug 29 05:07:09.469983 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.184.117:11918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-admin/maint.php"] [unique_id "apK9XTAh5Y1i2tUxg4EORAAABdc"] [Sat Aug 29 05:07:09.470352 2026] [security2:error] [pid 1028675:tid 1028861] [client 68.155.159.216:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/packed.php"] [unique_id "apK9XddHPfW2QFvhmL7YgQAAADM"] [Sat Aug 29 05:07:09.482888 2026] [core:error] [pid 1028675:tid 1028917] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.482903 2026] [core:error] [pid 1028675:tid 1028917] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.488553 2026] [security2:error] [pid 1028675:tid 1028911] [client 20.104.104.62:10466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/inject.php"] [unique_id "apK9XddHPfW2QFvhmL7YhQAAAGU"] [Sat Aug 29 05:07:09.493148 2026] [security2:error] [pid 1018003:tid 1018166] [client 40.83.93.50:3847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/Njima.php"] [unique_id "apK9XTAh5Y1i2tUxg4EORgAABcc"] [Sat Aug 29 05:07:09.494064 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.104.49.130:57721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/run.php"] [unique_id "apK9XddHPfW2QFvhmL7YhwAAAD4"] [Sat Aug 29 05:07:09.508818 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.147.79:35763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/sad/about.php"] [unique_id "apK9XTAh5Y1i2tUxg4EORwAABgM"] [Sat Aug 29 05:07:09.522979 2026] [security2:error] [pid 1028675:tid 1028822] [client 20.48.250.41:59365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/global.php"] [unique_id "apK9XddHPfW2QFvhmL7YigAAAAw"] [Sat Aug 29 05:07:09.530636 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.184.117:2780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/aaa.php"] [unique_id "apK9XddHPfW2QFvhmL7YiwAAADA"] [Sat Aug 29 05:07:09.547728 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.104.18.15:5011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/ajax.php"] [unique_id "apK9XddHPfW2QFvhmL7YjQAAAEo"] [Sat Aug 29 05:07:09.553719 2026] [security2:error] [pid 1028675:tid 1028825] [client 52.139.37.240:21437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/sagax.php"] [unique_id "apK9XddHPfW2QFvhmL7YjgAAAA8"] [Sat Aug 29 05:07:09.567309 2026] [security2:error] [pid 1028675:tid 1028814] [client 158.23.147.79:53761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/atomlib.php"] [unique_id "apK9XddHPfW2QFvhmL7YkgAAAAQ"] [Sat Aug 29 05:07:09.571312 2026] [security2:error] [pid 1028675:tid 1028863] [client 4.205.62.107:8998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/aws_auth.php"] [unique_id "apK9XddHPfW2QFvhmL7YlAAAADU"] [Sat Aug 29 05:07:09.585472 2026] [security2:error] [pid 1018003:tid 1018225] [client 20.104.18.15:13730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/dehnl.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOSgAABgI"] [Sat Aug 29 05:07:09.590388 2026] [security2:error] [pid 1018003:tid 1018196] [client 158.23.147.79:26433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/lv.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOSwAABeU"] [Sat Aug 29 05:07:09.591295 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.48.160.90:49487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/giodywky.php"] [unique_id "apK9XddHPfW2QFvhmL7YmAAAAHU"] [Sat Aug 29 05:07:09.603289 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.104.18.15:36621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/sign.php"] [unique_id "apK9XddHPfW2QFvhmL7YmQAAACs"] [Sat Aug 29 05:07:09.603314 2026] [security2:error] [pid 1028675:tid 1028878] [client 158.23.184.117:39976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/bthil.php"] [unique_id "apK9XddHPfW2QFvhmL7YmgAAAEQ"] [Sat Aug 29 05:07:09.615373 2026] [security2:error] [pid 1028675:tid 1028931] [client 4.205.62.107:56021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/sys.php"] [unique_id "apK9XddHPfW2QFvhmL7YoQAAAHk"] [Sat Aug 29 05:07:09.615977 2026] [security2:error] [pid 1018003:tid 1018271] [client 158.23.184.117:11716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/num.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOTAAABi8"] [Sat Aug 29 05:07:09.627457 2026] [security2:error] [pid 1028675:tid 1028842] [client 20.196.209.81:15193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/post.php"] [unique_id "apK9XddHPfW2QFvhmL7YpAAAACA"] [Sat Aug 29 05:07:09.630971 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.104.62:44571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/mga.php"] [unique_id "apK9XddHPfW2QFvhmL7YpgAAAD0"] [Sat Aug 29 05:07:09.631222 2026] [security2:error] [pid 1028675:tid 1028841] [client 158.23.147.79:50067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9XddHPfW2QFvhmL7YpwAAAB8"] [Sat Aug 29 05:07:09.640617 2026] [security2:error] [pid 1018003:tid 1018152] [client 52.139.37.240:29866] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.greathairkc.com"] [uri "/c99.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOTwAABbk"] [Sat Aug 29 05:07:09.655303 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.48.250.41:62509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/fs.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOUgAABhA"] [Sat Aug 29 05:07:09.668262 2026] [core:error] [pid 1018003:tid 1018185] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.668280 2026] [core:error] [pid 1018003:tid 1018185] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.671618 2026] [security2:error] [pid 1028675:tid 1028851] [client 158.23.147.79:25531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9XddHPfW2QFvhmL7YqgAAACk"] [Sat Aug 29 05:07:09.686431 2026] [security2:error] [pid 1018003:tid 1018177] [client 68.155.159.216:30712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/.well-known/index.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOVwAABdI"] [Sat Aug 29 05:07:09.688328 2026] [security2:error] [pid 1028675:tid 1028914] [client 52.139.37.240:32720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9XddHPfW2QFvhmL7YqwAAAGg"] [Sat Aug 29 05:07:09.710470 2026] [security2:error] [pid 1028675:tid 1028866] [client 103.185.242.143:64751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9XddHPfW2QFvhmL7YrgAAADg"] [Sat Aug 29 05:07:09.713142 2026] [security2:error] [pid 1028675:tid 1028866] [client 103.185.242.143:64751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9XddHPfW2QFvhmL7YrgAAADg"] [Sat Aug 29 05:07:09.727584 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.184.117:2761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/hehe.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOWQAABfY"] [Sat Aug 29 05:07:09.731989 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.48.160.90:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-kz.php"] [unique_id "apK9XddHPfW2QFvhmL7YtAAAAEY"] [Sat Aug 29 05:07:09.732014 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.197.61.180:7755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/meta.php"] [unique_id "apK9XddHPfW2QFvhmL7YtQAAAB0"] [Sat Aug 29 05:07:09.748020 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.184.117:63767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/file.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOWwAABik"] [Sat Aug 29 05:07:09.749423 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.104.18.15:13717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/zoo2.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOXAAABb0"] [Sat Aug 29 05:07:09.750177 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.184.117:30209] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mikelait.managemymood.com"] [uri "/1.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOXQAABdQ"] [Sat Aug 29 05:07:09.750274 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.184.117:30209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/1.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOXQAABdQ"] [Sat Aug 29 05:07:09.754307 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:5084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/atomlib.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOXgAABi4"] [Sat Aug 29 05:07:09.758071 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.18.15:36635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wnnjpsby.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOXwAABjM"] [Sat Aug 29 05:07:09.763708 2026] [core:error] [pid 1028675:tid 1028883] [client 158.158.54.35:14958] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.763728 2026] [core:error] [pid 1028675:tid 1028883] [client 158.158.54.35:14958] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.768961 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.104.62:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/inwp.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOYQAABf8"] [Sat Aug 29 05:07:09.784730 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.196.209.81:5769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/cong.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOYgAABgE"] [Sat Aug 29 05:07:09.787591 2026] [security2:error] [pid 1018003:tid 1018162] [client 168.107.94.195:63613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOYwAABcM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:09.797878 2026] [core:error] [pid 1018003:tid 1018207] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.797902 2026] [core:error] [pid 1018003:tid 1018207] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.802375 2026] [security2:error] [pid 1018003:tid 1018261] [client 158.23.184.117:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/identity.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOaAAABiU"] [Sat Aug 29 05:07:09.828412 2026] [security2:error] [pid 1018003:tid 1018194] [client 158.23.147.79:30460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/content.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOagAABeM"] [Sat Aug 29 05:07:09.832860 2026] [security2:error] [pid 1018003:tid 1018216] [client 52.139.37.240:29869] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.greathairkc.com"] [uri "/c99.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOawAABfk"] [Sat Aug 29 05:07:09.842214 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.48.250.41:62541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ioxi.php"] [unique_id "apK9XTAh5Y1i2tUxg4EObQAABeA"] [Sat Aug 29 05:07:09.855470 2026] [security2:error] [pid 1028675:tid 1028899] [client 158.23.147.79:32739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9XddHPfW2QFvhmL7Y3AAAAFk"] [Sat Aug 29 05:07:09.859229 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.203.141.11:35247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-mail.php"] [unique_id "apK9XddHPfW2QFvhmL7Y3QAAAAE"] [Sat Aug 29 05:07:09.872725 2026] [core:error] [pid 1018003:tid 1018155] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.872741 2026] [core:error] [pid 1018003:tid 1018155] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:09.874471 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.23.184.117:2597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/PHPMailer.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOcAAABgY"] [Sat Aug 29 05:07:09.880056 2026] [security2:error] [pid 1028675:tid 1028846] [client 20.104.18.15:13698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/zoo1.php"] [unique_id "apK9XddHPfW2QFvhmL7Y4AAAACQ"] [Sat Aug 29 05:07:09.893912 2026] [security2:error] [pid 1028675:tid 1028922] [client 158.23.184.117:63759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/lock360.php"] [unique_id "apK9XddHPfW2QFvhmL7Y4gAAAHA"] [Sat Aug 29 05:07:09.896456 2026] [security2:error] [pid 1018003:tid 1018219] [client 93.123.109.228:39186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9XTAh5Y1i2tUxg4EOcQAABfw"] [Sat Aug 29 05:07:09.899983 2026] [security2:error] [pid 1028675:tid 1028915] [client 20.104.104.62:10632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/ad1.php"] [unique_id "apK9XddHPfW2QFvhmL7Y5AAAAGk"] [Sat Aug 29 05:07:09.900788 2026] [security2:error] [pid 1028675:tid 1028911] [client 52.139.37.240:32733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-info.php"] [unique_id "apK9XddHPfW2QFvhmL7Y5QAAAGU"] [Sat Aug 29 05:07:09.901262 2026] [security2:error] [pid 1028675:tid 1028917] [client 158.23.184.117:30259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/2.php"] [unique_id "apK9XddHPfW2QFvhmL7Y4wAAAGs"] [Sat Aug 29 05:07:09.901283 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.18.15:36557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/gigi.php"] [unique_id "apK9XddHPfW2QFvhmL7Y5gAAAFw"] [Sat Aug 29 05:07:09.902668 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.104.49.130:47855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/wp-blog-header.php"] [unique_id "apK9XddHPfW2QFvhmL7Y5wAAAF0"] [Sat Aug 29 05:07:09.916815 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.18.15:5025] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.enveso.com"] [uri "/1.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOcwAABeU"] [Sat Aug 29 05:07:09.916956 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.18.15:5025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/1.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOcwAABeU"] [Sat Aug 29 05:07:09.918663 2026] [security2:error] [pid 1018003:tid 1018225] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9XTAh5Y1i2tUxg4EOcgAABgI"] [Sat Aug 29 05:07:09.923772 2026] [security2:error] [pid 1028675:tid 1028889] [client 93.123.109.228:39272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9XddHPfW2QFvhmL7Y6AAAAE8"] [Sat Aug 29 05:07:09.929508 2026] [security2:error] [pid 1028675:tid 1028825] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9XddHPfW2QFvhmL7Y6gAAAA8"] [Sat Aug 29 05:07:09.944615 2026] [security2:error] [pid 1018003:tid 1018167] [client 40.83.93.50:13637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-blogs.php"] [unique_id "apK9XTAh5Y1i2tUxg4EOdAAABcg"] [Sat Aug 29 05:07:09.945350 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.48.160.90:49529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apK9XddHPfW2QFvhmL7Y6wAAAAQ"] [Sat Aug 29 05:07:09.951465 2026] [security2:error] [pid 1028675:tid 1028933] [client 93.123.109.228:39206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9XddHPfW2QFvhmL7Y7QAAAHs"] [Sat Aug 29 05:07:09.973693 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.48.250.41:62499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/bootstrap.php"] [unique_id "apK9XddHPfW2QFvhmL7Y8gAAADw"] [Sat Aug 29 05:07:09.986289 2026] [security2:error] [pid 1028675:tid 1028931] [client 20.104.104.62:4846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/wefile.php"] [unique_id "apK9XddHPfW2QFvhmL7Y8wAAAHk"] [Sat Aug 29 05:07:09.988923 2026] [security2:error] [pid 1028675:tid 1028842] [client 4.205.62.107:22266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/application.config.php"] [unique_id "apK9XddHPfW2QFvhmL7Y9QAAACA"] [Sat Aug 29 05:07:09.994181 2026] [security2:error] [pid 1028675:tid 1028875] [client 52.139.37.240:20760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-content/plugins/ftde.php"] [unique_id "apK9XddHPfW2QFvhmL7Y9wAAAEE"] [Sat Aug 29 05:07:09.999743 2026] [security2:error] [pid 1028675:tid 1028820] [client 158.23.184.117:12060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/Radio.php"] [unique_id "apK9XddHPfW2QFvhmL7Y-QAAAAo"] [Sat Aug 29 05:07:10.018700 2026] [security2:error] [pid 1028675:tid 1028851] [client 158.158.54.35:10569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/lite.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZAAAAACk"] [Sat Aug 29 05:07:10.020392 2026] [security2:error] [pid 1028675:tid 1028878] [client 158.23.184.117:2805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "apK9XtdHPfW2QFvhmL7ZAQAAAEQ"] [Sat Aug 29 05:07:10.022299 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.104.62:42731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/admin123.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZAwAAACk"] [Sat Aug 29 05:07:10.031987 2026] [security2:error] [pid 1028675:tid 1028914] [client 68.155.159.216:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/NewFile.php/"] [unique_id "apK9XtdHPfW2QFvhmL7ZBQAAAGg"] [Sat Aug 29 05:07:10.038074 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.104.18.15:13591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/radio.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZBwAAAEs"] [Sat Aug 29 05:07:10.038101 2026] [security2:error] [pid 1028675:tid 1028871] [client 158.23.184.117:40046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/fpwch.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZBgAAAD0"] [Sat Aug 29 05:07:10.045813 2026] [security2:error] [pid 1028675:tid 1028831] [client 68.155.159.216:16164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZCQAAABU"] [Sat Aug 29 05:07:10.050367 2026] [security2:error] [pid 1028675:tid 1028874] [client 158.23.184.117:30218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/7.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZDAAAAEA"] [Sat Aug 29 05:07:10.054162 2026] [security2:error] [pid 1028675:tid 1028896] [client 20.104.18.15:36731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/info.php/new.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZDQAAAFY"] [Sat Aug 29 05:07:10.066165 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.196.209.81:15190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/csv.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOeAAABcQ"] [Sat Aug 29 05:07:10.070829 2026] [security2:error] [pid 1018003:tid 1018185] [client 158.23.147.79:30500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/css/index.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOeQAABdo"] [Sat Aug 29 05:07:10.072069 2026] [security2:error] [pid 1028675:tid 1028928] [client 20.104.104.62:44573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/1vbqo.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZDgAAAHY"] [Sat Aug 29 05:07:10.076449 2026] [security2:error] [pid 1028675:tid 1028898] [client 93.123.109.228:39256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9XtdHPfW2QFvhmL7ZEAAAAFg"] [Sat Aug 29 05:07:10.081184 2026] [security2:error] [pid 1028675:tid 1028830] [client 93.123.109.228:39272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9XtdHPfW2QFvhmL7ZEQAAABQ"] [Sat Aug 29 05:07:10.083996 2026] [security2:error] [pid 1018003:tid 1018152] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9XjAh5Y1i2tUxg4EOewAABbk"] [Sat Aug 29 05:07:10.095664 2026] [security2:error] [pid 1018003:tid 1018271] [client 40.83.93.50:3861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/configs.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOfAAABi8"] [Sat Aug 29 05:07:10.105892 2026] [security2:error] [pid 1028675:tid 1028866] [client 52.139.37.240:32007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZFQAAADg"] [Sat Aug 29 05:07:10.123203 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.18.15:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/samll.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOfQAABgo"] [Sat Aug 29 05:07:10.142401 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.104.104.62:4817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/EM.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZGgAAAFI"] [Sat Aug 29 05:07:10.164905 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.23.184.117:2576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/admin/alfa-rex.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOgAAABdI"] [Sat Aug 29 05:07:10.169135 2026] [security2:error] [pid 1028675:tid 1028911] [client 168.107.94.195:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZJgAAAGU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:10.182414 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.184.117:39988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/storage/index.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOggAABis"] [Sat Aug 29 05:07:10.184963 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.48.250.41:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/export.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZJwAAAA4"] [Sat Aug 29 05:07:10.186757 2026] [security2:error] [pid 1018003:tid 1018268] [client 52.139.37.240:20775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOgwAABiw"] [Sat Aug 29 05:07:10.199843 2026] [security2:error] [pid 1028675:tid 1028846] [client 158.23.184.117:30056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/10.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZKgAAACQ"] [Sat Aug 29 05:07:10.200473 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.18.15:13636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/one.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZKwAAAE8"] [Sat Aug 29 05:07:10.201725 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.23.147.79:62713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sprint52.com"] [uri "/first.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZLAAAAEo"] [Sat Aug 29 05:07:10.203076 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.151.200.44:45996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/cafe.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZLQAAAGE"] [Sat Aug 29 05:07:10.209402 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.196.209.81:15494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/content.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOhQAABcE"] [Sat Aug 29 05:07:10.210810 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.104.62:10816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/h02ugyh.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOhgAABjM"] [Sat Aug 29 05:07:10.211034 2026] [security2:error] [pid 1018003:tid 1018221] [client 158.23.184.117:11939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/Requests/Exception/file.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOhwAABf4"] [Sat Aug 29 05:07:10.217281 2026] [core:error] [pid 1028675:tid 1028883] [client 158.158.54.35:20581] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:10.217296 2026] [core:error] [pid 1028675:tid 1028883] [client 158.158.54.35:20581] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:10.222948 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.104.104.62:64756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wso2022_shell.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZMQAAACc"] [Sat Aug 29 05:07:10.235813 2026] [security2:error] [pid 1018003:tid 1018207] [client 68.155.159.216:50344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOigAABfA"] [Sat Aug 29 05:07:10.240800 2026] [security2:error] [pid 1028675:tid 1028932] [client 93.123.109.228:39132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9XtdHPfW2QFvhmL7ZMgAAAHo"] [Sat Aug 29 05:07:10.268874 2026] [security2:error] [pid 1028675:tid 1028894] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9XtdHPfW2QFvhmL7ZNAAAAFQ"] [Sat Aug 29 05:07:10.277800 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.104.62:4819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/ca4.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOjgAABeA"] [Sat Aug 29 05:07:10.302978 2026] [security2:error] [pid 1028675:tid 1028913] [client 52.139.37.240:32077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/ws49.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZPAAAAGc"] [Sat Aug 29 05:07:10.303873 2026] [security2:error] [pid 1028675:tid 1028888] [client 20.104.18.15:5013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/she11.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZPQAAAE4"] [Sat Aug 29 05:07:10.304410 2026] [security2:error] [pid 1028675:tid 1028931] [client 68.155.159.216:33744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZPgAAAHk"] [Sat Aug 29 05:07:10.305759 2026] [security2:error] [pid 1028675:tid 1028842] [client 4.205.62.107:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/myfile.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZPwAAACA"] [Sat Aug 29 05:07:10.308754 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.184.117:2807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/export.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOkAAABb4"] [Sat Aug 29 05:07:10.315888 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.48.160.90:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/session.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZQAAAACU"] [Sat Aug 29 05:07:10.320441 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.48.250.41:60707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/gk.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZQQAAAAU"] [Sat Aug 29 05:07:10.324501 2026] [security2:error] [pid 1028675:tid 1028848] [client 4.205.62.107:22406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wp-act.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZQgAAACY"] [Sat Aug 29 05:07:10.326766 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.23.147.79:17489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/asd.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOkgAABcI"] [Sat Aug 29 05:07:10.331919 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.104.62:23415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/7h.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZQwAAAEQ"] [Sat Aug 29 05:07:10.337733 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.18.15:13643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/503.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZRAAAACk"] [Sat Aug 29 05:07:10.344725 2026] [security2:error] [pid 1028675:tid 1028925] [client 4.205.62.107:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/themes.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZRgAAAHM"] [Sat Aug 29 05:07:10.349532 2026] [security2:error] [pid 1028675:tid 1028916] [client 158.23.184.117:30229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/13.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZSAAAAGo"] [Sat Aug 29 05:07:10.353057 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.203.141.11:27422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-content.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZSwAAAFw"] [Sat Aug 29 05:07:10.355288 2026] [security2:error] [pid 1028675:tid 1028871] [client 93.123.109.228:39148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZTQAAAD0"] [Sat Aug 29 05:07:10.362641 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.104.104.62:44583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/shelp.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOkwAABfk"] [Sat Aug 29 05:07:10.378985 2026] [security2:error] [pid 1018003:tid 1018164] [client 158.23.184.117:63778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wp-includes/blocks/search/index.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOlAAABcU"] [Sat Aug 29 05:07:10.399046 2026] [security2:error] [pid 1028675:tid 1028861] [client 158.23.184.117:12061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-admin/add.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZVQAAADM"] [Sat Aug 29 05:07:10.413229 2026] [security2:error] [pid 1018003:tid 1018170] [client 40.83.93.50:13605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-comments-post.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOlQAABcs"] [Sat Aug 29 05:07:10.427858 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.104.104.62:64700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/x0x.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZXgAAAFA"] [Sat Aug 29 05:07:10.429723 2026] [security2:error] [pid 1028675:tid 1028877] [client 68.155.159.216:12262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZXwAAAEM"] [Sat Aug 29 05:07:10.431339 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.104.18.15:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/kerang.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZYQAAAD4"] [Sat Aug 29 05:07:10.451343 2026] [security2:error] [pid 1028675:tid 1028936] [client 158.23.184.117:2619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/new.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZZQAAAH4"] [Sat Aug 29 05:07:10.455393 2026] [security2:error] [pid 1018003:tid 1018196] [client 93.123.109.228:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9XjAh5Y1i2tUxg4EOmAAABeU"] [Sat Aug 29 05:07:10.463281 2026] [security2:error] [pid 1028675:tid 1028826] [client 158.158.54.35:10215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/term.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZawAAABA"] [Sat Aug 29 05:07:10.466372 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.197.61.180:13832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/dxc.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZbAAAAHs"] [Sat Aug 29 05:07:10.485276 2026] [core:error] [pid 1018003:tid 1018258] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:10.485295 2026] [core:error] [pid 1018003:tid 1018258] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:10.492117 2026] [security2:error] [pid 1018003:tid 1018167] [client 93.123.109.228:39234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/aws.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOmwAABcg"] [Sat Aug 29 05:07:10.495816 2026] [security2:error] [pid 1028675:tid 1028892] [client 158.23.184.117:30213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/100.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZcwAAAFI"] [Sat Aug 29 05:07:10.501491 2026] [security2:error] [pid 1028675:tid 1028895] [client 52.139.37.240:52199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/xxx.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZdQAAAFU"] [Sat Aug 29 05:07:10.506471 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.104.62:44603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/13ede.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZdgAAAE8"] [Sat Aug 29 05:07:10.520882 2026] [security2:error] [pid 1028675:tid 1028879] [client 20.196.209.81:1993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/fox.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZegAAAEU"] [Sat Aug 29 05:07:10.523365 2026] [security2:error] [pid 1028675:tid 1028922] [client 158.23.184.117:63777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wp-signup.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZfQAAAHA"] [Sat Aug 29 05:07:10.542870 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.23.184.117:12075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/assets/about.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOngAABfo"] [Sat Aug 29 05:07:10.543615 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.48.160.90:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/eagle.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZgAAAAHU"] [Sat Aug 29 05:07:10.550899 2026] [security2:error] [pid 1018003:tid 1018244] [client 168.107.94.195:64336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOnwAABhQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:10.561914 2026] [security2:error] [pid 1028675:tid 1028847] [client 93.123.109.228:39272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/config.inc.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZhQAAACU"] [Sat Aug 29 05:07:10.563986 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.18.15:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/504.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOoAAABcQ"] [Sat Aug 29 05:07:10.564518 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.48.250.41:62531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/logs1.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZhwAAABs"] [Sat Aug 29 05:07:10.576504 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.104.104.62:36986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/wp-gzone.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZiwAAAHM"] [Sat Aug 29 05:07:10.579519 2026] [security2:error] [pid 1028675:tid 1028916] [client 20.104.18.15:5009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/m.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZjAAAAGo"] [Sat Aug 29 05:07:10.581265 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.104.62:40248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wpxadmin.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZjQAAAFw"] [Sat Aug 29 05:07:10.583845 2026] [security2:error] [pid 1028675:tid 1028875] [client 68.155.159.216:51857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-l0gin.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZjgAAAEE"] [Sat Aug 29 05:07:10.587634 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.104.18.15:36611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/w.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZkAAAAAE"] [Sat Aug 29 05:07:10.595021 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.184.117:2785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/plugins/revslider/admin.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOoQAABhA"] [Sat Aug 29 05:07:10.603810 2026] [security2:error] [pid 1028675:tid 1028822] [client 20.196.209.81:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/core.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZlAAAAAw"] [Sat Aug 29 05:07:10.609742 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.104.104.62:4137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.americanvarietyradio.net"] [uri "/fesa.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZlQAAABI"] [Sat Aug 29 05:07:10.611506 2026] [security2:error] [pid 1018003:tid 1018190] [client 93.123.109.228:39186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/config.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOpAAABd8"] [Sat Aug 29 05:07:10.638173 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.104.68.135:9026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/sm.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZmwAAAFg"] [Sat Aug 29 05:07:10.639394 2026] [security2:error] [pid 1028675:tid 1028904] [client 40.83.93.50:7509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/disagraeed.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZnAAAAF4"] [Sat Aug 29 05:07:10.645168 2026] [security2:error] [pid 1018003:tid 1018172] [client 158.23.184.117:60612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/222.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOpwAABc0"] [Sat Aug 29 05:07:10.651081 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.104.104.62:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/k8.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZowAAAFk"] [Sat Aug 29 05:07:10.657475 2026] [security2:error] [pid 1028675:tid 1028816] [client 93.123.109.228:39132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/env.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZpQAAAAY"] [Sat Aug 29 05:07:10.663410 2026] [security2:error] [pid 1028675:tid 1028833] [client 158.158.54.35:20604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/file.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZqgAAABc"] [Sat Aug 29 05:07:10.667845 2026] [security2:error] [pid 1018003:tid 1018213] [client 158.23.184.117:63768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/404.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOqQAABfY"] [Sat Aug 29 05:07:10.675027 2026] [security2:error] [pid 1028675:tid 1028920] [client 158.23.147.79:59886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/lv.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZrAAAAG4"] [Sat Aug 29 05:07:10.682148 2026] [security2:error] [pid 1028675:tid 1028881] [client 52.139.37.240:21177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/z.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZrQAAAEc"] [Sat Aug 29 05:07:10.686121 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.48.160.90:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/up-kon.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZrgAAABA"] [Sat Aug 29 05:07:10.686216 2026] [security2:error] [pid 1028675:tid 1028836] [client 158.23.184.117:11956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-content/themes/twentytwentythree.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZrwAAABo"] [Sat Aug 29 05:07:10.693290 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.48.250.41:58385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/inege.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZsAAAAH8"] [Sat Aug 29 05:07:10.695689 2026] [security2:error] [pid 1028675:tid 1028857] [client 52.139.37.240:32100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/0x.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZsgAAAC8"] [Sat Aug 29 05:07:10.702519 2026] [security2:error] [pid 1028675:tid 1028924] [client 93.123.109.228:39252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/nexmo.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZtAAAAHI"] [Sat Aug 29 05:07:10.705387 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.104.18.15:13674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/admin.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZtgAAAG8"] [Sat Aug 29 05:07:10.708315 2026] [security2:error] [pid 1028675:tid 1028863] [client 93.123.109.228:39206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/module.config.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZtwAAADU"] [Sat Aug 29 05:07:10.737151 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.184.117:2767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/images/uploads/admin.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOrAAABis"] [Sat Aug 29 05:07:10.740990 2026] [security2:error] [pid 1028675:tid 1028912] [client 20.104.18.15:36659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/x.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZugAAAGY"] [Sat Aug 29 05:07:10.752412 2026] [security2:error] [pid 1018003:tid 1018162] [client 93.123.109.228:39286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/config/stripe.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOrQAABcM"] [Sat Aug 29 05:07:10.759336 2026] [security2:error] [pid 1018003:tid 1018195] [client 4.205.62.107:8999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/queue.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOrgAABeQ"] [Sat Aug 29 05:07:10.766640 2026] [security2:error] [pid 1018003:tid 1018189] [client 4.205.62.107:55981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/phpsysinfo.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOrwAABd4"] [Sat Aug 29 05:07:10.767216 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.18.15:4941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/fling.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOsAAABgc"] [Sat Aug 29 05:07:10.773465 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.104.62:42682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/str.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOsgAABds"] [Sat Aug 29 05:07:10.775165 2026] [security2:error] [pid 1028675:tid 1028844] [client 158.23.147.79:50114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZwQAAACI"] [Sat Aug 29 05:07:10.777648 2026] [security2:error] [pid 1028675:tid 1028905] [client 158.23.147.79:25579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/index.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZwgAAAF8"] [Sat Aug 29 05:07:10.784567 2026] [security2:error] [pid 1028675:tid 1028882] [client 68.155.159.216:49228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/hehehehe.php"] [unique_id "apK9XtdHPfW2QFvhmL7ZxwAAAEg"] [Sat Aug 29 05:07:10.786248 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.104.62:10828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/alog.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOtAAABdc"] [Sat Aug 29 05:07:10.790825 2026] [security2:error] [pid 1018003:tid 1018191] [client 68.155.159.216:30719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOtQAABeA"] [Sat Aug 29 05:07:10.822700 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.184.117:63763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/as.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOuAAABfA"] [Sat Aug 29 05:07:10.829223 2026] [security2:error] [pid 1028675:tid 1028878] [client 68.155.159.216:18369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/atomlib.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z0QAAAEQ"] [Sat Aug 29 05:07:10.836748 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.48.160.90:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/tinny.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOugAABek"] [Sat Aug 29 05:07:10.837382 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.48.250.41:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wp-link10.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z2AAAAFw"] [Sat Aug 29 05:07:10.848304 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.23.184.117:60614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/adminfuns.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z2gAAAEo"] [Sat Aug 29 05:07:10.848662 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.203.141.11:13364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOvAAABiw"] [Sat Aug 29 05:07:10.877685 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.104.18.15:13733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/ws85.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOwAAABiI"] [Sat Aug 29 05:07:10.877685 2026] [security2:error] [pid 1028675:tid 1028880] [client 52.139.37.240:20762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/f35.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z3QAAAEY"] [Sat Aug 29 05:07:10.881060 2026] [security2:error] [pid 1028675:tid 1028900] [client 158.23.184.117:11931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-content/languages/themes/num.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z3gAAAFo"] [Sat Aug 29 05:07:10.883214 2026] [security2:error] [pid 1018003:tid 1018174] [client 40.83.93.50:22835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-config.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOwQAABc8"] [Sat Aug 29 05:07:10.897010 2026] [security2:error] [pid 1018003:tid 1018236] [client 52.139.37.240:32060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/CDX1.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOwwAABgw"] [Sat Aug 29 05:07:10.909493 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.104.68.135:9085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/shell.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z5wAAAF4"] [Sat Aug 29 05:07:10.910863 2026] [security2:error] [pid 1028675:tid 1028871] [client 158.23.184.117:2810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/tools.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z6wAAAD0"] [Sat Aug 29 05:07:10.918967 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.158.54.35:18029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/config.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOxAAABjU"] [Sat Aug 29 05:07:10.920809 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.104.62:10840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/adin.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOxQAABgk"] [Sat Aug 29 05:07:10.927436 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.104.62:60425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/mega.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z8AAAADI"] [Sat Aug 29 05:07:10.928395 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.196.209.81:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/disagraeosc.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z7wAAAHU"] [Sat Aug 29 05:07:10.928395 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.104.18.15:36786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ssla.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOxwAABhw"] [Sat Aug 29 05:07:10.933148 2026] [security2:error] [pid 1028675:tid 1028813] [client 168.107.94.195:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z8gAAAAM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:10.934125 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.104.49.130:60947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/ops.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z8wAAADQ"] [Sat Aug 29 05:07:10.951129 2026] [security2:error] [pid 1018003:tid 1018185] [client 158.23.147.79:30581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOygAABdo"] [Sat Aug 29 05:07:10.953868 2026] [security2:error] [pid 1028675:tid 1028933] [client 87.199.194.213:64082] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.194.213" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "thesmartpm.com"] [uri "/apps/wp-comments-post.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z-QAAAHs"], referer: https://thesmartpm.com/ut-dallas-applied-project-management-forum-november-2014-presentation/ [Sat Aug 29 05:07:10.953985 2026] [security2:error] [pid 1028675:tid 1028933] [client 87.199.194.213:64082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "thesmartpm.com"] [uri "/apps/wp-comments-post.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z-QAAAHs"], referer: https://thesmartpm.com/ut-dallas-applied-project-management-forum-november-2014-presentation/ [Sat Aug 29 05:07:10.966267 2026] [security2:error] [pid 1028675:tid 1028810] [client 20.104.18.15:5050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/btyuio.php"] [unique_id "apK9XtdHPfW2QFvhmL7Z_AAAAAA"] [Sat Aug 29 05:07:10.969132 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.184.117:63806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/php.php"] [unique_id "apK9XjAh5Y1i2tUxg4EOzAAABhY"] [Sat Aug 29 05:07:10.988726 2026] [security2:error] [pid 1028675:tid 1028826] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9XtdHPfW2QFvhmL7Z_wAAABA"] [Sat Aug 29 05:07:10.999219 2026] [security2:error] [pid 1028675:tid 1028937] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9XtdHPfW2QFvhmL7aAAAAAH8"] [Sat Aug 29 05:07:11.002506 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.184.117:30208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/abcd.php"] [unique_id "apK9XzAh5Y1i2tUxg4EOzQAABcQ"] [Sat Aug 29 05:07:11.004181 2026] [security2:error] [pid 1018003:tid 1018183] [client 93.123.109.228:39304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EOzgAABdg"] [Sat Aug 29 05:07:11.016217 2026] [security2:error] [pid 1028675:tid 1028866] [client 93.123.109.228:39312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9X9dHPfW2QFvhmL7aAQAAADg"] [Sat Aug 29 05:07:11.028384 2026] [security2:error] [pid 1028675:tid 1028936] [client 52.139.37.240:53207] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.greathairkc.com"] [uri "/c99.php"] [unique_id "apK9X9dHPfW2QFvhmL7aAgAAAH4"] [Sat Aug 29 05:07:11.030759 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.196.209.81:22435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/db-status.php"] [unique_id "apK9X9dHPfW2QFvhmL7aAwAAAB0"] [Sat Aug 29 05:07:11.033897 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.160.90:51679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp-easy.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO0AAABf4"] [Sat Aug 29 05:07:11.041253 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.48.250.41:60685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ww.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO0QAABeQ"] [Sat Aug 29 05:07:11.047314 2026] [http2:warn] [pid 1018003:tid 1018214] [client 57.141.14.83:32086] h2_stream(1018003-136-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:07:11.059579 2026] [core:error] [pid 1018003:tid 1018186] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:11.059598 2026] [core:error] [pid 1018003:tid 1018186] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:11.064415 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:13635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/ffs.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO1AAABcA"] [Sat Aug 29 05:07:11.065749 2026] [security2:error] [pid 1028675:tid 1028901] [client 20.104.104.62:10858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/sf9.php"] [unique_id "apK9X9dHPfW2QFvhmL7aCAAAAFs"] [Sat Aug 29 05:07:11.067502 2026] [security2:error] [pid 1018003:tid 1018261] [client 68.155.159.216:24468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/dropdown.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO1QAABiU"] [Sat Aug 29 05:07:11.083735 2026] [security2:error] [pid 1028675:tid 1028857] [client 52.139.37.240:21182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/file61.php"] [unique_id "apK9X9dHPfW2QFvhmL7aCQAAAC8"] [Sat Aug 29 05:07:11.085166 2026] [security2:error] [pid 1018003:tid 1018166] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EO1wAABcc"] [Sat Aug 29 05:07:11.089024 2026] [security2:error] [pid 1018003:tid 1018157] [client 93.123.109.228:39346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EO2AAABb4"] [Sat Aug 29 05:07:11.092928 2026] [security2:error] [pid 1028675:tid 1028819] [client 52.139.37.240:32735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/akcc.php"] [unique_id "apK9X9dHPfW2QFvhmL7aCgAAAAk"] [Sat Aug 29 05:07:11.097214 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.104.62:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wso2.5.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO2QAABcI"] [Sat Aug 29 05:07:11.101265 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.104.104.62:52069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/ww3.php"] [unique_id "apK9X9dHPfW2QFvhmL7aDwAAAE0"] [Sat Aug 29 05:07:11.103176 2026] [security2:error] [pid 1018003:tid 1018104] [remote 40.77.167.35:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO2gAFw1M"] [Sat Aug 29 05:07:11.105227 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.104.68.135:55655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/simple.php"] [unique_id "apK9X9dHPfW2QFvhmL7aEwAAAHI"] [Sat Aug 29 05:07:11.110878 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.158.54.35:20320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/files.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO2wAABec"] [Sat Aug 29 05:07:11.123127 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.18.15:5004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/dehnl.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO3AAABek"] [Sat Aug 29 05:07:11.125714 2026] [security2:error] [pid 1028675:tid 1028854] [client 93.123.109.228:39204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9X9dHPfW2QFvhmL7aFQAAACw"] [Sat Aug 29 05:07:11.125862 2026] [security2:error] [pid 1018003:tid 1018256] [client 4.205.62.107:22420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/xp.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO3QAABiA"] [Sat Aug 29 05:07:11.136724 2026] [security2:error] [pid 1028675:tid 1028872] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9X9dHPfW2QFvhmL7aFgAAAD4"] [Sat Aug 29 05:07:11.199296 2026] [security2:error] [pid 1028675:tid 1028848] [client 158.23.147.79:30709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/index.php"] [unique_id "apK9X9dHPfW2QFvhmL7aIgAAACY"] [Sat Aug 29 05:07:11.201949 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.104.18.15:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/nano.php"] [unique_id "apK9X9dHPfW2QFvhmL7aIwAAAHE"] [Sat Aug 29 05:07:11.202494 2026] [security2:error] [pid 1018003:tid 1018160] [client 68.155.159.216:5986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/dropdown.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO4gAABcE"] [Sat Aug 29 05:07:11.203336 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.104.104.62:10636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/lte7.php"] [unique_id "apK9X9dHPfW2QFvhmL7aJQAAAGw"] [Sat Aug 29 05:07:11.206306 2026] [security2:error] [pid 1028675:tid 1028842] [client 68.155.159.216:64442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/file.php"] [unique_id "apK9X9dHPfW2QFvhmL7aJgAAACA"] [Sat Aug 29 05:07:11.207330 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.48.160.90:51598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/d7.php"] [unique_id "apK9X9dHPfW2QFvhmL7aJwAAACk"] [Sat Aug 29 05:07:11.222445 2026] [security2:error] [pid 1028675:tid 1028832] [client 20.197.61.180:13830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/wp-2019.php"] [unique_id "apK9X9dHPfW2QFvhmL7aKQAAABY"] [Sat Aug 29 05:07:11.279070 2026] [security2:error] [pid 1028675:tid 1028916] [client 52.139.37.240:21421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/mah.php"] [unique_id "apK9X9dHPfW2QFvhmL7aNAAAAGo"] [Sat Aug 29 05:07:11.282516 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.151.200.44:47405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/eval.php"] [unique_id "apK9X9dHPfW2QFvhmL7aNQAAAAU"] [Sat Aug 29 05:07:11.284448 2026] [security2:error] [pid 1028675:tid 1028846] [client 20.104.18.15:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/zoo2.php"] [unique_id "apK9X9dHPfW2QFvhmL7aNgAAACQ"] [Sat Aug 29 05:07:11.286986 2026] [security2:error] [pid 1028675:tid 1028919] [client 52.139.37.240:32104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9X9dHPfW2QFvhmL7aNwAAAG0"] [Sat Aug 29 05:07:11.288062 2026] [security2:error] [pid 1028675:tid 1028859] [client 20.48.250.41:60771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/w1px.php"] [unique_id "apK9X9dHPfW2QFvhmL7aOgAAADE"] [Sat Aug 29 05:07:11.290308 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.104.62:52087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/sko.php"] [unique_id "apK9X9dHPfW2QFvhmL7aPQAAAD0"] [Sat Aug 29 05:07:11.301448 2026] [security2:error] [pid 1018003:tid 1018175] [client 93.123.109.228:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EO6AAABdA"] [Sat Aug 29 05:07:11.301504 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.104.68.135:9061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-admin.php"] [unique_id "apK9X9dHPfW2QFvhmL7aQgAAAEo"] [Sat Aug 29 05:07:11.316058 2026] [security2:error] [pid 1028675:tid 1028862] [client 168.107.94.195:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9X9dHPfW2QFvhmL7aQwAAADQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:11.319884 2026] [security2:error] [pid 1018003:tid 1018185] [client 93.123.109.228:39288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9XzAh5Y1i2tUxg4EO6QAABdo"] [Sat Aug 29 05:07:11.324156 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.203.141.11:45407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/css/wp-login.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO6wAABfw"] [Sat Aug 29 05:07:11.328815 2026] [security2:error] [pid 1028675:tid 1028898] [client 93.123.109.228:39100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9X9dHPfW2QFvhmL7aRAAAAFg"] [Sat Aug 29 05:07:11.330995 2026] [security2:error] [pid 1028675:tid 1028935] [client 20.196.209.81:15188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/about.php525"] [unique_id "apK9X9dHPfW2QFvhmL7aRQAAAH0"] [Sat Aug 29 05:07:11.332581 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.104.18.15:36730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO7QAABbk"] [Sat Aug 29 05:07:11.332974 2026] [security2:error] [pid 1018003:tid 1018240] [client 93.123.109.228:39304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EO7AAABhA"] [Sat Aug 29 05:07:11.335702 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.104.62:10818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/tanjiro.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO7gAABdQ"] [Sat Aug 29 05:07:11.350663 2026] [security2:error] [pid 1028675:tid 1028841] [client 68.155.159.216:50215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/ans.php"] [unique_id "apK9X9dHPfW2QFvhmL7aTgAAAB8"] [Sat Aug 29 05:07:11.359786 2026] [security2:error] [pid 1018003:tid 1018167] [client 40.83.93.50:13610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-configs.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO8QAABcg"] [Sat Aug 29 05:07:11.376599 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.104.18.15:13635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/ano.php"] [unique_id "apK9X9dHPfW2QFvhmL7aUwAAAEc"] [Sat Aug 29 05:07:11.384277 2026] [security2:error] [pid 1028675:tid 1028866] [client 93.123.109.228:39312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9X9dHPfW2QFvhmL7aVAAAADg"] [Sat Aug 29 05:07:11.385479 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.48.160.90:51217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/v5.php"] [unique_id "apK9X9dHPfW2QFvhmL7aVQAAAB0"] [Sat Aug 29 05:07:11.393230 2026] [security2:error] [pid 1028675:tid 1028853] [client 93.123.109.228:39256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9X9dHPfW2QFvhmL7aVgAAACs"] [Sat Aug 29 05:07:11.394274 2026] [security2:error] [pid 1028675:tid 1028840] [client 158.158.54.35:10615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9X9dHPfW2QFvhmL7aVwAAAB4"] [Sat Aug 29 05:07:11.410110 2026] [security2:error] [pid 1028675:tid 1028831] [client 40.83.93.50:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/add_actualites.php"] [unique_id "apK9X9dHPfW2QFvhmL7aWQAAABU"] [Sat Aug 29 05:07:11.427454 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.196.209.81:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK9X9dHPfW2QFvhmL7aWgAAAGg"] [Sat Aug 29 05:07:11.434627 2026] [security2:error] [pid 1028675:tid 1028911] [client 158.23.147.79:17486] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/1.php"] [unique_id "apK9X9dHPfW2QFvhmL7aXQAAAGU"] [Sat Aug 29 05:07:11.434710 2026] [security2:error] [pid 1028675:tid 1028911] [client 158.23.147.79:17486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/1.php"] [unique_id "apK9X9dHPfW2QFvhmL7aXQAAAGU"] [Sat Aug 29 05:07:11.439949 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.104.62:20687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-mode.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO9AAABdg"] [Sat Aug 29 05:07:11.451893 2026] [security2:error] [pid 1028675:tid 1028906] [client 68.155.159.216:33674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/chosen.php"] [unique_id "apK9X9dHPfW2QFvhmL7aXwAAAGA"] [Sat Aug 29 05:07:11.453068 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.48.250.41:59363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/to.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO9gAABi4"] [Sat Aug 29 05:07:11.457122 2026] [security2:error] [pid 1028675:tid 1028780] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config.php"] [unique_id "apK9X9dHPfW2QFvhmL7aYAAAXWM"] [Sat Aug 29 05:07:11.457219 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.104.18.15:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/zoo1.php"] [unique_id "apK9X9dHPfW2QFvhmL7aYQAAAC8"] [Sat Aug 29 05:07:11.469409 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.104.104.62:10867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/Rk41.php"] [unique_id "apK9X9dHPfW2QFvhmL7aYwAAAEA"] [Sat Aug 29 05:07:11.471712 2026] [security2:error] [pid 1028675:tid 1028835] [client 4.205.62.107:65524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/lm15.php"] [unique_id "apK9X9dHPfW2QFvhmL7aZAAAABk"] [Sat Aug 29 05:07:11.472592 2026] [security2:error] [pid 1028675:tid 1028885] [client 4.205.62.107:22461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/samll.php"] [unique_id "apK9X9dHPfW2QFvhmL7aZQAAAEs"] [Sat Aug 29 05:07:11.474523 2026] [security2:error] [pid 1018003:tid 1018190] [client 52.139.37.240:20788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/mini.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO-gAABd8"] [Sat Aug 29 05:07:11.478669 2026] [security2:error] [pid 1028675:tid 1028921] [client 52.139.37.240:32740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/s.php"] [unique_id "apK9X9dHPfW2QFvhmL7aZwAAAG8"] [Sat Aug 29 05:07:11.484625 2026] [security2:error] [pid 1018003:tid 1018267] [client 4.205.62.107:58448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/tinyfilemanager.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO-wAABis"] [Sat Aug 29 05:07:11.486809 2026] [security2:error] [pid 1018003:tid 1018262] [client 93.123.109.228:39304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/info.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO_AAABiY"] [Sat Aug 29 05:07:11.490322 2026] [security2:error] [pid 1018003:tid 1018224] [client 87.199.194.213:64116] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.194.213" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "thesmartpm.com"] [uri "/apps/wp-comments-post.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO_QAABgE"], referer: https://thesmartpm.com/ut-dallas-applied-project-management-forum-november-2014-presentation/ [Sat Aug 29 05:07:11.490412 2026] [security2:error] [pid 1018003:tid 1018224] [client 87.199.194.213:64116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "thesmartpm.com"] [uri "/apps/wp-comments-post.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO_QAABgE"], referer: https://thesmartpm.com/ut-dallas-applied-project-management-forum-november-2014-presentation/ [Sat Aug 29 05:07:11.490447 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.104.62:42730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/zoz.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO_gAABdI"] [Sat Aug 29 05:07:11.491163 2026] [security2:error] [pid 1028675:tid 1028932] [client 93.123.109.228:39100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/infophp.php"] [unique_id "apK9X9dHPfW2QFvhmL7aaAAAAHo"] [Sat Aug 29 05:07:11.496655 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.104.68.135:2979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "apK9X9dHPfW2QFvhmL7aaQAAADU"] [Sat Aug 29 05:07:11.511759 2026] [security2:error] [pid 1028675:tid 1028891] [client 93.123.109.228:39250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/infos.php"] [unique_id "apK9X9dHPfW2QFvhmL7abAAAAFE"] [Sat Aug 29 05:07:11.520424 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.147.79:32666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9XzAh5Y1i2tUxg4EO_wAABfU"] [Sat Aug 29 05:07:11.522706 2026] [security2:error] [pid 1018003:tid 1018186] [client 93.123.109.228:39094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EPAAAABds"] [Sat Aug 29 05:07:11.529609 2026] [security2:error] [pid 1028675:tid 1028894] [client 93.123.109.228:39282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9X9dHPfW2QFvhmL7aeAAAAFQ"] [Sat Aug 29 05:07:11.532511 2026] [security2:error] [pid 1028675:tid 1028837] [client 68.155.159.216:12188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/.well-knownold/index.php"] [unique_id "apK9X9dHPfW2QFvhmL7aeQAAABs"] [Sat Aug 29 05:07:11.551059 2026] [security2:error] [pid 1028675:tid 1028842] [client 20.104.18.15:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/mgrr.php"] [unique_id "apK9X9dHPfW2QFvhmL7afgAAACA"] [Sat Aug 29 05:07:11.555851 2026] [security2:error] [pid 1028675:tid 1028851] [client 93.123.109.228:39312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9X9dHPfW2QFvhmL7afwAAACk"] [Sat Aug 29 05:07:11.556155 2026] [security2:error] [pid 1018003:tid 1018217] [client 68.155.159.216:65046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/ws.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPAwAABfo"] [Sat Aug 29 05:07:11.556775 2026] [security2:error] [pid 1028675:tid 1028877] [client 158.158.54.35:14914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/o.php"] [unique_id "apK9X9dHPfW2QFvhmL7agAAAAEM"] [Sat Aug 29 05:07:11.562451 2026] [security2:error] [pid 1028675:tid 1028897] [client 68.155.159.216:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/file.php"] [unique_id "apK9X9dHPfW2QFvhmL7aggAAAFc"] [Sat Aug 29 05:07:11.570005 2026] [security2:error] [pid 1028675:tid 1028794] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/config.inc.php"] [unique_id "apK9X9dHPfW2QFvhmL7ahgAACHE"] [Sat Aug 29 05:07:11.575770 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.48.160.90:51698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/az.php"] [unique_id "apK9X9dHPfW2QFvhmL7aiQAAAHc"] [Sat Aug 29 05:07:11.592149 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.104.18.15:36646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-aothait.php"] [unique_id "apK9X9dHPfW2QFvhmL7aiwAAAAU"] [Sat Aug 29 05:07:11.608092 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.104.104.62:44593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/7logs.php"] [unique_id "apK9X9dHPfW2QFvhmL7ajQAAAF4"] [Sat Aug 29 05:07:11.620985 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.104.18.15:5096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/radio.php"] [unique_id "apK9X9dHPfW2QFvhmL7ajgAAADQ"] [Sat Aug 29 05:07:11.631533 2026] [security2:error] [pid 1028675:tid 1028797] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/aws.php"] [unique_id "apK9X9dHPfW2QFvhmL7akAAACHQ"] [Sat Aug 29 05:07:11.634081 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.250.41:62490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/thui.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPBQAABcM"] [Sat Aug 29 05:07:11.649663 2026] [security2:error] [pid 1018003:tid 1018216] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EPBgAABfk"] [Sat Aug 29 05:07:11.652963 2026] [security2:error] [pid 1028675:tid 1028873] [client 158.23.147.79:35802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/admin.php"] [unique_id "apK9X9dHPfW2QFvhmL7akgAAAD8"] [Sat Aug 29 05:07:11.669130 2026] [security2:error] [pid 1028675:tid 1028871] [client 52.139.37.240:20797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/v.php"] [unique_id "apK9X9dHPfW2QFvhmL7akwAAAD0"] [Sat Aug 29 05:07:11.669151 2026] [security2:error] [pid 1028675:tid 1028927] [client 52.139.37.240:32082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/sagax.php"] [unique_id "apK9X9dHPfW2QFvhmL7alAAAAHU"] [Sat Aug 29 05:07:11.681314 2026] [security2:error] [pid 1018003:tid 1018256] [client 93.123.109.228:39094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EPCQAABiA"] [Sat Aug 29 05:07:11.682472 2026] [security2:error] [pid 1028675:tid 1028810] [client 20.104.104.62:20839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-mailcek.php"] [unique_id "apK9X9dHPfW2QFvhmL7alQAAAAA"] [Sat Aug 29 05:07:11.687110 2026] [security2:error] [pid 1018003:tid 1018268] [client 93.123.109.228:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EPCwAABiw"] [Sat Aug 29 05:07:11.689138 2026] [security2:error] [pid 1028675:tid 1028867] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9X9dHPfW2QFvhmL7algAAADk"] [Sat Aug 29 05:07:11.694105 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.68.135:18271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-admin/includes/about.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPDAAABcI"] [Sat Aug 29 05:07:11.698271 2026] [security2:error] [pid 1018003:tid 1018196] [client 168.107.94.195:49394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPDwAABeU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:11.702799 2026] [security2:error] [pid 1028675:tid 1028937] [client 93.123.109.228:39282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9X9dHPfW2QFvhmL7amwAAAH8"] [Sat Aug 29 05:07:11.705136 2026] [security2:error] [pid 1028675:tid 1028839] [client 93.123.109.228:39256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9X9dHPfW2QFvhmL7anAAAAB0"] [Sat Aug 29 05:07:11.706563 2026] [security2:error] [pid 1028675:tid 1028839] [client 93.123.109.228:39348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9X9dHPfW2QFvhmL7anQAAAB0"] [Sat Aug 29 05:07:11.713069 2026] [security2:error] [pid 1028675:tid 1028853] [client 93.123.109.228:39366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9X9dHPfW2QFvhmL7aoAAAACs"] [Sat Aug 29 05:07:11.713254 2026] [security2:error] [pid 1018003:tid 1018188] [client 158.23.147.79:26442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPEAAABd0"] [Sat Aug 29 05:07:11.716253 2026] [security2:error] [pid 1028675:tid 1028812] [client 20.104.18.15:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/mac.php"] [unique_id "apK9X9dHPfW2QFvhmL7aoQAAAAI"] [Sat Aug 29 05:07:11.728554 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.196.209.81:15187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/spip.php"] [unique_id "apK9X9dHPfW2QFvhmL7aogAAAG0"] [Sat Aug 29 05:07:11.728569 2026] [security2:error] [pid 1028675:tid 1028807] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/config.php"] [unique_id "apK9X9dHPfW2QFvhmL7aowAAUH4"] [Sat Aug 29 05:07:11.744925 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.104.104.62:23369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/mmm.php"] [unique_id "apK9X9dHPfW2QFvhmL7apQAAACE"] [Sat Aug 29 05:07:11.746326 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.160.90:51629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/js.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPEQAABcE"] [Sat Aug 29 05:07:11.748411 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.104.62:10664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/sf.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPEgAABjM"] [Sat Aug 29 05:07:11.758186 2026] [security2:error] [pid 1028675:tid 1028824] [client 68.155.159.216:51315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9X9dHPfW2QFvhmL7apgAAAA4"] [Sat Aug 29 05:07:11.771666 2026] [security2:error] [pid 1028675:tid 1028936] [client 93.123.109.228:39312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9X9dHPfW2QFvhmL7apwAAAH4"] [Sat Aug 29 05:07:11.773334 2026] [security2:error] [pid 1028675:tid 1028821] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9X9dHPfW2QFvhmL7aqAAAAAs"] [Sat Aug 29 05:07:11.774954 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.18.15:5031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/one.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPEwAABew"] [Sat Aug 29 05:07:11.793648 2026] [security2:error] [pid 1028675:tid 1028686] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/module.config.php"] [unique_id "apK9X9dHPfW2QFvhmL7arQAALwY"] [Sat Aug 29 05:07:11.793674 2026] [security2:error] [pid 1028675:tid 1028683] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/env.php"] [unique_id "apK9X9dHPfW2QFvhmL7asQAALwM"] [Sat Aug 29 05:07:11.793689 2026] [security2:error] [pid 1028675:tid 1028687] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/nexmo.php"] [unique_id "apK9X9dHPfW2QFvhmL7aqwAALwc"] [Sat Aug 29 05:07:11.795309 2026] [security2:error] [pid 1028675:tid 1028903] [client 158.23.147.79:61624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9X9dHPfW2QFvhmL7aswAAAF0"] [Sat Aug 29 05:07:11.816510 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.48.250.41:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/Jcrop.php"] [unique_id "apK9X9dHPfW2QFvhmL7atAAAAEA"] [Sat Aug 29 05:07:11.828169 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.196.209.81:15543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/f35.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPFgAABdk"] [Sat Aug 29 05:07:11.829471 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.203.141.11:43347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/images/index.php"] [unique_id "apK9X9dHPfW2QFvhmL7atgAAAHs"] [Sat Aug 29 05:07:11.836453 2026] [security2:error] [pid 1018003:tid 1018179] [client 93.123.109.228:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EPFwAABdQ"] [Sat Aug 29 05:07:11.843299 2026] [security2:error] [pid 1018003:tid 1018246] [client 93.123.109.228:39288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9XzAh5Y1i2tUxg4EPGAAABhY"] [Sat Aug 29 05:07:11.852362 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.18.15:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/simple.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPGgAABco"] [Sat Aug 29 05:07:11.863615 2026] [security2:error] [pid 1018003:tid 1018164] [client 40.83.93.50:20837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-conflg.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPGwAABcU"] [Sat Aug 29 05:07:11.876434 2026] [security2:error] [pid 1028675:tid 1028863] [client 158.23.147.79:50169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9X9dHPfW2QFvhmL7avQAAADU"] [Sat Aug 29 05:07:11.878914 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.158.54.35:17639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-good.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPHgAABc8"] [Sat Aug 29 05:07:11.884455 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.104.62:10821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/super.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPHwAABcQ"] [Sat Aug 29 05:07:11.888818 2026] [security2:error] [pid 1028675:tid 1028835] [client 52.139.37.240:20888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9X9dHPfW2QFvhmL7awAAAABk"] [Sat Aug 29 05:07:11.889196 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.68.135:19282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-admin/js/index.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPIAAABhA"] [Sat Aug 29 05:07:11.896931 2026] [security2:error] [pid 1028675:tid 1028891] [client 158.23.147.79:25438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/mah.php"] [unique_id "apK9X9dHPfW2QFvhmL7awgAAAFE"] [Sat Aug 29 05:07:11.909184 2026] [security2:error] [pid 1018003:tid 1018190] [client 4.205.62.107:53123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/sgd.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPIgAABd8"] [Sat Aug 29 05:07:11.911350 2026] [security2:error] [pid 1028675:tid 1028690] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/stripe.php"] [unique_id "apK9X9dHPfW2QFvhmL7axgAABAo"] [Sat Aug 29 05:07:11.933038 2026] [security2:error] [pid 1018003:tid 1018262] [client 4.205.62.107:53433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/plss3.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPJAAABiY"] [Sat Aug 29 05:07:11.942919 2026] [security2:error] [pid 1028675:tid 1028847] [client 68.155.159.216:18393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/lv.php"] [unique_id "apK9X9dHPfW2QFvhmL7azgAAACU"] [Sat Aug 29 05:07:11.943353 2026] [security2:error] [pid 1028675:tid 1028905] [client 52.139.37.240:32763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-content/plugins/ftde.php"] [unique_id "apK9X9dHPfW2QFvhmL7azwAAAF8"] [Sat Aug 29 05:07:11.958420 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.104.104.62:23371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/advanced.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPJwAABd4"] [Sat Aug 29 05:07:11.968648 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.104.62:20700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-config-blog.php"] [unique_id "apK9X9dHPfW2QFvhmL7a1AAAAEQ"] [Sat Aug 29 05:07:11.985243 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.18.15:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/503.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPKwAABdc"] [Sat Aug 29 05:07:11.988165 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.160.90:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/hd.php"] [unique_id "apK9XzAh5Y1i2tUxg4EPLAAABh8"] [Sat Aug 29 05:07:11.990407 2026] [core:error] [pid 1028675:tid 1028879] [client 20.196.209.81:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:11.990424 2026] [core:error] [pid 1028675:tid 1028879] [client 20.196.209.81:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:12.004497 2026] [security2:error] [pid 1028675:tid 1028889] [client 158.158.54.35:20562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/file2.php"] [unique_id "apK9YNdHPfW2QFvhmL7a3AAAAE8"] [Sat Aug 29 05:07:12.007239 2026] [security2:error] [pid 1028675:tid 1028924] [client 40.83.93.50:3884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/alfanew.php7"] [unique_id "apK9YNdHPfW2QFvhmL7a3QAAAHI"] [Sat Aug 29 05:07:12.008028 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.18.15:13689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/xty.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPMAAABiU"] [Sat Aug 29 05:07:12.018855 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.197.61.180:8139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/menu.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPMgAABdA"] [Sat Aug 29 05:07:12.036012 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.104.104.62:10490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/lufix1.php"] [unique_id "apK9YNdHPfW2QFvhmL7a4QAAAAU"] [Sat Aug 29 05:07:12.039866 2026] [security2:error] [pid 1018003:tid 1018162] [client 93.123.109.228:39394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/php-info.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPMwAABcM"] [Sat Aug 29 05:07:12.040717 2026] [security2:error] [pid 1028675:tid 1028916] [client 20.48.250.41:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ws58.php"] [unique_id "apK9YNdHPfW2QFvhmL7a4wAAAGo"] [Sat Aug 29 05:07:12.042976 2026] [security2:error] [pid 1018003:tid 1018226] [client 93.123.109.228:39346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/php.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPNAAABgM"] [Sat Aug 29 05:07:12.043986 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.104.18.15:36582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-includes/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7a5QAAAF4"] [Sat Aug 29 05:07:12.048720 2026] [security2:error] [pid 1028675:tid 1028860] [client 93.123.109.228:39366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/php_info.php"] [unique_id "apK9YNdHPfW2QFvhmL7a5wAAADI"] [Sat Aug 29 05:07:12.058863 2026] [security2:error] [pid 1028675:tid 1028884] [client 93.123.109.228:39256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/phpinfo.php"] [unique_id "apK9YNdHPfW2QFvhmL7a6gAAAEo"] [Sat Aug 29 05:07:12.072882 2026] [security2:error] [pid 1028675:tid 1028862] [client 158.23.147.79:30480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/mah.php"] [unique_id "apK9YNdHPfW2QFvhmL7a6wAAADQ"] [Sat Aug 29 05:07:12.078164 2026] [security2:error] [pid 1028675:tid 1028875] [client 168.107.94.195:49860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7a7wAAAEE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:12.081118 2026] [security2:error] [pid 1018003:tid 1018277] [client 52.139.37.240:21163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPNgAABjU"] [Sat Aug 29 05:07:12.088451 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.104.68.135:19317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7a8wAAAHc"] [Sat Aug 29 05:07:12.103083 2026] [security2:error] [pid 1028675:tid 1028928] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9YNdHPfW2QFvhmL7a9wAAAHY"] [Sat Aug 29 05:07:12.139497 2026] [security2:error] [pid 1028675:tid 1028935] [client 52.139.37.240:32108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9YNdHPfW2QFvhmL7a_QAAAH0"] [Sat Aug 29 05:07:12.145173 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.104.18.15:5074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/504.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPNwAABiI"] [Sat Aug 29 05:07:12.146928 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.18.15:13747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/sallu.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPOAAABgw"] [Sat Aug 29 05:07:12.147338 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.160.90:51707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/xl2023.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPOQAABcE"] [Sat Aug 29 05:07:12.153238 2026] [security2:error] [pid 1028675:tid 1028896] [client 182.178.76.234:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.76.178.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mmhvacllc.com"] [uri "/xmlrpc.php"] [unique_id "apK9YNdHPfW2QFvhmL7a-QAAAFY"] [Sat Aug 29 05:07:12.153409 2026] [security2:error] [pid 1028675:tid 1028896] [client 182.178.76.234:57324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mmhvacllc.com"] [uri "/xmlrpc.php"] [unique_id "apK9YNdHPfW2QFvhmL7a-QAAAFY"] [Sat Aug 29 05:07:12.153580 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.196.209.81:2025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/backup.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPOwAABf8"] [Sat Aug 29 05:07:12.162789 2026] [security2:error] [pid 1028675:tid 1028866] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9YNdHPfW2QFvhmL7a_gAAADg"] [Sat Aug 29 05:07:12.163571 2026] [security2:error] [pid 1028675:tid 1028839] [client 93.123.109.228:39204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9YNdHPfW2QFvhmL7a_wAAAB0"] [Sat Aug 29 05:07:12.171090 2026] [security2:error] [pid 1028675:tid 1028853] [client 68.155.159.216:24570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/sad/about.php"] [unique_id "apK9YNdHPfW2QFvhmL7bAQAAACs"] [Sat Aug 29 05:07:12.185415 2026] [security2:error] [pid 1028675:tid 1028890] [client 93.123.109.228:39282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9YNdHPfW2QFvhmL7bBAAAAFA"] [Sat Aug 29 05:07:12.192595 2026] [security2:error] [pid 1018003:tid 1018203] [client 93.123.109.228:39288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9YDAh5Y1i2tUxg4EPPgAABew"] [Sat Aug 29 05:07:12.204417 2026] [security2:error] [pid 1028675:tid 1028936] [client 20.104.104.62:10495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/hack.php"] [unique_id "apK9YNdHPfW2QFvhmL7bBgAAAH4"] [Sat Aug 29 05:07:12.213545 2026] [security2:error] [pid 1018003:tid 1018184] [client 93.123.109.228:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9YDAh5Y1i2tUxg4EPQAAABdk"] [Sat Aug 29 05:07:12.225941 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.196.209.81:15517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7bDQAAAHU"] [Sat Aug 29 05:07:12.240769 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.104.104.62:40214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-thumbs.php"] [unique_id "apK9YNdHPfW2QFvhmL7bDwAAAE0"] [Sat Aug 29 05:07:12.241510 2026] [security2:error] [pid 1028675:tid 1028883] [client 93.123.109.228:39348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9YNdHPfW2QFvhmL7bDgAAAEk"] [Sat Aug 29 05:07:12.242305 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.104.104.62:36962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/blox.php"] [unique_id "apK9YNdHPfW2QFvhmL7bEAAAAC8"] [Sat Aug 29 05:07:12.245720 2026] [security2:error] [pid 1018003:tid 1018271] [client 93.123.109.228:39380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/public/phpinfo.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPQQAABi8"] [Sat Aug 29 05:07:12.249942 2026] [security2:error] [pid 1028675:tid 1028854] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9YNdHPfW2QFvhmL7bEQAAACw"] [Sat Aug 29 05:07:12.266099 2026] [security2:error] [pid 1028675:tid 1028921] [client 4.205.62.107:21614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/g3.php"] [unique_id "apK9YNdHPfW2QFvhmL7bFAAAAG8"] [Sat Aug 29 05:07:12.275881 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.18.15:5015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/admin.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPQgAABhQ"] [Sat Aug 29 05:07:12.276461 2026] [security2:error] [pid 1028675:tid 1028821] [client 52.139.37.240:21408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7bFgAAAAs"] [Sat Aug 29 05:07:12.283104 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.104.68.135:23912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-admin/network/admin.php"] [unique_id "apK9YNdHPfW2QFvhmL7bFwAAACI"] [Sat Aug 29 05:07:12.290676 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.18.15:13710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/codex.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPQwAABc8"] [Sat Aug 29 05:07:12.295453 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.48.250.41:62530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/xs.php"] [unique_id "apK9YNdHPfW2QFvhmL7bGgAAAGQ"] [Sat Aug 29 05:07:12.306196 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:36650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/file31.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPRAAABi4"] [Sat Aug 29 05:07:12.312097 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.147.79:30536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-blog-header.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPRQAABhA"] [Sat Aug 29 05:07:12.312603 2026] [security2:error] [pid 1028675:tid 1028848] [client 93.123.109.228:39204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9YNdHPfW2QFvhmL7bHgAAACY"] [Sat Aug 29 05:07:12.326412 2026] [security2:error] [pid 1018003:tid 1018265] [client 68.155.159.216:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/file17.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPRwAABik"] [Sat Aug 29 05:07:12.339072 2026] [security2:error] [pid 1028675:tid 1028843] [client 158.158.54.35:17555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7bJAAAACE"] [Sat Aug 29 05:07:12.347550 2026] [security2:error] [pid 1028675:tid 1028914] [client 40.83.93.50:22805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content.php"] [unique_id "apK9YNdHPfW2QFvhmL7bJgAAAGg"] [Sat Aug 29 05:07:12.357786 2026] [security2:error] [pid 1018003:tid 1018202] [client 68.155.159.216:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/.well-known/index.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPSwAABes"] [Sat Aug 29 05:07:12.382844 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.48.160.90:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/V2.php"] [unique_id "apK9YNdHPfW2QFvhmL7bLgAAAFc"] [Sat Aug 29 05:07:12.385030 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.104.62:20854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-mobfi.php"] [unique_id "apK9YNdHPfW2QFvhmL7bMAAAAE8"] [Sat Aug 29 05:07:12.402398 2026] [security2:error] [pid 1028675:tid 1028859] [client 52.139.37.240:32074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/z.php"] [unique_id "apK9YNdHPfW2QFvhmL7bOQAAADE"] [Sat Aug 29 05:07:12.412833 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.18.15:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/ws85.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPTgAABgc"] [Sat Aug 29 05:07:12.428241 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.18.15:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/5656.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPTwAABfo"] [Sat Aug 29 05:07:12.430941 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.104.104.62:42718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/kcs.php"] [unique_id "apK9YNdHPfW2QFvhmL7bPAAAAEo"] [Sat Aug 29 05:07:12.453494 2026] [security2:error] [pid 1028675:tid 1028823] [client 158.158.54.35:2851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apK9YNdHPfW2QFvhmL7bPwAAAA0"] [Sat Aug 29 05:07:12.455827 2026] [security2:error] [pid 1028675:tid 1028816] [client 20.104.104.62:10851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/155.php"] [unique_id "apK9YNdHPfW2QFvhmL7bQgAAAAY"] [Sat Aug 29 05:07:12.459961 2026] [security2:error] [pid 1018003:tid 1018191] [client 168.107.94.195:50329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPUAAABeA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:12.480269 2026] [security2:error] [pid 1028675:tid 1028855] [client 20.104.68.135:19321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-conflg/function.php"] [unique_id "apK9YNdHPfW2QFvhmL7bRwAAAC0"] [Sat Aug 29 05:07:12.494002 2026] [security2:error] [pid 1028675:tid 1028830] [client 20.104.49.130:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/dragonshell.php"] [unique_id "apK9YNdHPfW2QFvhmL7bSAAAABQ"] [Sat Aug 29 05:07:12.497398 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.203.141.11:25404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/inputs.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPVgAABec"] [Sat Aug 29 05:07:12.509077 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.18.15:36618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/dk.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPWAAABgM"] [Sat Aug 29 05:07:12.527364 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.48.250.41:60761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/zu.php"] [unique_id "apK9YNdHPfW2QFvhmL7bUQAAADg"] [Sat Aug 29 05:07:12.530569 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.48.160.90:51294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/mad.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPWQAABfk"] [Sat Aug 29 05:07:12.544610 2026] [core:error] [pid 1018003:tid 1018162] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:12.544627 2026] [core:error] [pid 1018003:tid 1018162] [client 52.139.37.240:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:12.557366 2026] [security2:error] [pid 1028675:tid 1028890] [client 158.23.147.79:17462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/ws.php"] [unique_id "apK9YNdHPfW2QFvhmL7bVQAAAFA"] [Sat Aug 29 05:07:12.560643 2026] [security2:error] [pid 1028675:tid 1028911] [client 20.104.18.15:13758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/w3lls.php"] [unique_id "apK9YNdHPfW2QFvhmL7bVgAAAGU"] [Sat Aug 29 05:07:12.565267 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.196.209.81:4503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/haiterus.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPXgAABfw"] [Sat Aug 29 05:07:12.577885 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.104.18.15:5031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/ffs.php"] [unique_id "apK9YNdHPfW2QFvhmL7bWwAAADM"] [Sat Aug 29 05:07:12.589883 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.104.104.62:10854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/mcd.php"] [unique_id "apK9YNdHPfW2QFvhmL7bXwAAAF0"] [Sat Aug 29 05:07:12.598619 2026] [security2:error] [pid 1028675:tid 1028839] [client 52.139.37.240:32091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/f35.php"] [unique_id "apK9YNdHPfW2QFvhmL7bYwAAAB0"] [Sat Aug 29 05:07:12.611903 2026] [security2:error] [pid 1018003:tid 1018188] [client 4.205.62.107:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/test.config.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPXwAABd0"] [Sat Aug 29 05:07:12.612339 2026] [security2:error] [pid 1018003:tid 1018170] [client 68.155.159.216:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/install.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPYAAABcs"] [Sat Aug 29 05:07:12.614404 2026] [security2:error] [pid 1028675:tid 1028885] [client 4.205.62.107:22320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/pass4.php"] [unique_id "apK9YNdHPfW2QFvhmL7bZgAAAEs"] [Sat Aug 29 05:07:12.629739 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.23.147.79:32682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-login.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPYQAABg4"] [Sat Aug 29 05:07:12.638931 2026] [security2:error] [pid 1028675:tid 1028825] [client 68.155.159.216:12195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7bawAAAA8"] [Sat Aug 29 05:07:12.640010 2026] [security2:error] [pid 1028675:tid 1028854] [client 4.205.62.107:51472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/min.php"] [unique_id "apK9YNdHPfW2QFvhmL7bbAAAACw"] [Sat Aug 29 05:07:12.653422 2026] [security2:error] [pid 1028675:tid 1028935] [client 20.196.209.81:17201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/install.php"] [unique_id "apK9YNdHPfW2QFvhmL7bcAAAAH0"] [Sat Aug 29 05:07:12.661608 2026] [security2:error] [pid 1028675:tid 1028821] [client 68.155.159.216:65125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7bcgAAAAs"] [Sat Aug 29 05:07:12.664153 2026] [security2:error] [pid 1028675:tid 1028891] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9YNdHPfW2QFvhmL7bcwAAAFE"] [Sat Aug 29 05:07:12.669784 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.48.250.41:62554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/lanka.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPZQAABdk"] [Sat Aug 29 05:07:12.670441 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.160.90:51209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/st.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPZgAABco"] [Sat Aug 29 05:07:12.670499 2026] [security2:error] [pid 1028675:tid 1028910] [client 68.155.159.216:2041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/file17.php"] [unique_id "apK9YNdHPfW2QFvhmL7bdQAAAGQ"] [Sat Aug 29 05:07:12.695258 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.104.68.135:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPZwAABcE"] [Sat Aug 29 05:07:12.699524 2026] [security2:error] [pid 1028675:tid 1028888] [client 20.104.18.15:13569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/fpwch.php"] [unique_id "apK9YNdHPfW2QFvhmL7beAAAAE4"] [Sat Aug 29 05:07:12.716679 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.104.18.15:36491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/ta.php"] [unique_id "apK9YNdHPfW2QFvhmL7bfAAAABk"] [Sat Aug 29 05:07:12.723972 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.104.62:10817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/waw.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPagAABi4"] [Sat Aug 29 05:07:12.726486 2026] [security2:error] [pid 1028675:tid 1028842] [client 146.70.194.254:40494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/wp-includes/wlwmanifest.xml"] [unique_id "apK9YNdHPfW2QFvhmL7bgwAAACA"] [Sat Aug 29 05:07:12.727491 2026] [security2:error] [pid 1028675:tid 1028881] [client 40.83.93.50:7474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/xmlrpc.php0"] [unique_id "apK9YNdHPfW2QFvhmL7bhAAAAEc"] [Sat Aug 29 05:07:12.736692 2026] [security2:error] [pid 1018003:tid 1018183] [client 195.178.110.247:38196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lexusdealership.com"] [uri "/index.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPbAAABdg"] [Sat Aug 29 05:07:12.737579 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.104.18.15:5016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/nano.php"] [unique_id "apK9YNdHPfW2QFvhmL7bhQAAAGg"] [Sat Aug 29 05:07:12.738662 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.104.62:60447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/wsz.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPbQAABis"] [Sat Aug 29 05:07:12.755726 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.197.61.180:13872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/alfa.php"] [unique_id "apK9YNdHPfW2QFvhmL7bhwAAAB8"] [Sat Aug 29 05:07:12.759911 2026] [security2:error] [pid 1028675:tid 1028870] [client 93.123.109.228:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9YNdHPfW2QFvhmL7biAAAADw"] [Sat Aug 29 05:07:12.768170 2026] [security2:error] [pid 1018003:tid 1018246] [client 52.139.37.240:20781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/wp-index.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPbgAABhY"] [Sat Aug 29 05:07:12.777070 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.104.62:40217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-comments-post.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPbwAABiY"] [Sat Aug 29 05:07:12.777473 2026] [security2:error] [pid 1028675:tid 1028897] [client 93.123.109.228:39428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9YNdHPfW2QFvhmL7biQAAAFc"] [Sat Aug 29 05:07:12.787046 2026] [security2:error] [pid 1028675:tid 1028814] [client 93.123.109.228:39434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9YNdHPfW2QFvhmL7bjwAAAAQ"] [Sat Aug 29 05:07:12.809479 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.160.90:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/alfanew.php"] [unique_id "apK9YNdHPfW2QFvhmL7blwAAAHM"] [Sat Aug 29 05:07:12.818890 2026] [security2:error] [pid 1028675:tid 1028923] [client 52.139.37.240:32102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/file61.php"] [unique_id "apK9YNdHPfW2QFvhmL7bmwAAAHE"] [Sat Aug 29 05:07:12.819793 2026] [security2:error] [pid 1028675:tid 1028815] [client 158.23.147.79:26432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/content.php"] [unique_id "apK9YNdHPfW2QFvhmL7bnAAAAAU"] [Sat Aug 29 05:07:12.830040 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.104.18.15:13737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/domvf.php"] [unique_id "apK9YNdHPfW2QFvhmL7bnQAAADQ"] [Sat Aug 29 05:07:12.832529 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.48.250.41:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/gettest.php"] [unique_id "apK9YNdHPfW2QFvhmL7bnwAAAHc"] [Sat Aug 29 05:07:12.833269 2026] [core:error] [pid 1028675:tid 1028908] [client 40.83.93.50:20811] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:12.833282 2026] [core:error] [pid 1028675:tid 1028908] [client 40.83.93.50:20811] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:12.853156 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.104.62:44547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/x23.php"] [unique_id "apK9YNdHPfW2QFvhmL7bogAAADI"] [Sat Aug 29 05:07:12.860152 2026] [security2:error] [pid 1018003:tid 1018156] [client 158.158.54.35:21962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/abcd.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPcwAABb0"] [Sat Aug 29 05:07:12.864998 2026] [security2:error] [pid 1028675:tid 1028855] [client 168.107.94.195:50795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9YNdHPfW2QFvhmL7bpQAAAC0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:12.878686 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.104.18.15:5076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/ano.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPdAAABfo"] [Sat Aug 29 05:07:12.884708 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.104.18.15:36666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/bo.php"] [unique_id "apK9YNdHPfW2QFvhmL7bpgAAAC4"] [Sat Aug 29 05:07:12.901456 2026] [security2:error] [pid 1018003:tid 1018190] [client 158.158.54.35:15176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/xda.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPdQAABd8"] [Sat Aug 29 05:07:12.909987 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.104.62:52032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/msy.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPdwAABdA"] [Sat Aug 29 05:07:12.912106 2026] [security2:error] [pid 1018003:tid 1018275] [client 195.178.110.247:65002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lexusdealership.com"] [uri "/index.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPeAAABjM"] [Sat Aug 29 05:07:12.922969 2026] [security2:error] [pid 1018003:tid 1018187] [client 93.123.109.228:39094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9YDAh5Y1i2tUxg4EPeQAABdw"] [Sat Aug 29 05:07:12.933780 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:30701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/radio.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPegAABbw"] [Sat Aug 29 05:07:12.948596 2026] [security2:error] [pid 1028675:tid 1028919] [client 93.123.109.228:39282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9YNdHPfW2QFvhmL7bsAAAAG0"] [Sat Aug 29 05:07:12.960607 2026] [security2:error] [pid 1028675:tid 1028937] [client 52.139.37.240:21432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/ww2.php"] [unique_id "apK9YNdHPfW2QFvhmL7btQAAAH8"] [Sat Aug 29 05:07:12.962737 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.48.160.90:51655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/ioxi.php"] [unique_id "apK9YDAh5Y1i2tUxg4EPfAAABiU"] [Sat Aug 29 05:07:12.963940 2026] [security2:error] [pid 1028675:tid 1028936] [client 20.104.18.15:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/biufile.php"] [unique_id "apK9YNdHPfW2QFvhmL7btgAAAH4"] [Sat Aug 29 05:07:12.964705 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.104.68.135:55660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-content/themes/fitnessbase/404.php"] [unique_id "apK9YNdHPfW2QFvhmL7btwAAABI"] [Sat Aug 29 05:07:12.966853 2026] [security2:error] [pid 1028675:tid 1028903] [client 68.155.159.216:50274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/worksec.php"] [unique_id "apK9YNdHPfW2QFvhmL7buAAAAF0"] [Sat Aug 29 05:07:12.984265 2026] [security2:error] [pid 1028675:tid 1028873] [client 20.203.141.11:27451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/alfa.php"] [unique_id "apK9YNdHPfW2QFvhmL7bvgAAAD8"] [Sat Aug 29 05:07:12.985327 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.104.104.62:10871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/ws66.php"] [unique_id "apK9YNdHPfW2QFvhmL7bvwAAAE0"] [Sat Aug 29 05:07:12.986253 2026] [security2:error] [pid 1028675:tid 1028824] [client 57.141.14.83:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/42/"] [unique_id "apK9YNdHPfW2QFvhmL7bvQAAAA4"] [Sat Aug 29 05:07:12.996990 2026] [security2:error] [pid 1028675:tid 1028928] [client 20.196.209.81:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/go.php"] [unique_id "apK9YNdHPfW2QFvhmL7bwAAAAHY"] [Sat Aug 29 05:07:13.005862 2026] [security2:error] [pid 1028675:tid 1028791] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/info.php"] [unique_id "apK9YddHPfW2QFvhmL7bxAAAAm4"] [Sat Aug 29 05:07:13.008125 2026] [security2:error] [pid 1028675:tid 1028927] [client 158.23.147.79:25495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-blog-header.php"] [unique_id "apK9YddHPfW2QFvhmL7bxQAAAHU"] [Sat Aug 29 05:07:13.012700 2026] [security2:error] [pid 1028675:tid 1028920] [client 213.202.253.4:60048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/wp-content/postnews.php"] [unique_id "apK9YddHPfW2QFvhmL7bxgAAAG4"], referer: www.google.com [Sat Aug 29 05:07:13.014939 2026] [security2:error] [pid 1028675:tid 1028798] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/infophp.php"] [unique_id "apK9YddHPfW2QFvhmL7bxwAAAnU"] [Sat Aug 29 05:07:13.016493 2026] [security2:error] [pid 1028675:tid 1028899] [client 52.139.37.240:32631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/mah.php"] [unique_id "apK9YddHPfW2QFvhmL7byAAAAFk"] [Sat Aug 29 05:07:13.018589 2026] [security2:error] [pid 1028675:tid 1028794] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/infos.php"] [unique_id "apK9YddHPfW2QFvhmL7bygAAAnE"] [Sat Aug 29 05:07:13.045400 2026] [security2:error] [pid 1018003:tid 1018196] [client 4.205.62.107:55968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/fleen.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPgAAABeU"] [Sat Aug 29 05:07:13.052615 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.104.18.15:5039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/mgrr.php"] [unique_id "apK9YddHPfW2QFvhmL7b1AAAAGQ"] [Sat Aug 29 05:07:13.052645 2026] [security2:error] [pid 1028675:tid 1028909] [client 20.48.250.41:62478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/35.php"] [unique_id "apK9YddHPfW2QFvhmL7b0wAAAGM"] [Sat Aug 29 05:07:13.053190 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.104.18.15:36629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/44.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPggAABfY"] [Sat Aug 29 05:07:13.055462 2026] [core:error] [pid 1028675:tid 1028890] [client 20.196.209.81:22431] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:13.055477 2026] [core:error] [pid 1028675:tid 1028890] [client 20.196.209.81:22431] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:13.055576 2026] [security2:error] [pid 1028675:tid 1028822] [client 20.104.49.130:60989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/css.php"] [unique_id "apK9YddHPfW2QFvhmL7b1QAAAAw"] [Sat Aug 29 05:07:13.065905 2026] [security2:error] [pid 1018003:tid 1018188] [client 93.123.109.228:39510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9YTAh5Y1i2tUxg4EPgwAABd0"] [Sat Aug 29 05:07:13.067502 2026] [security2:error] [pid 1018003:tid 1018170] [client 158.23.147.79:50137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPhAAABcs"] [Sat Aug 29 05:07:13.096344 2026] [security2:error] [pid 1028675:tid 1028835] [client 68.155.159.216:33720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/goods.php"] [unique_id "apK9YddHPfW2QFvhmL7b2QAAABk"] [Sat Aug 29 05:07:13.108952 2026] [security2:error] [pid 1028675:tid 1028843] [client 93.123.109.228:39408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9YddHPfW2QFvhmL7b2wAAACE"] [Sat Aug 29 05:07:13.114150 2026] [security2:error] [pid 1028675:tid 1028851] [client 4.205.62.107:8993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/configuration.php"] [unique_id "apK9YddHPfW2QFvhmL7b3AAAACk"] [Sat Aug 29 05:07:13.114759 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.104.104.62:40232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-config-style.php"] [unique_id "apK9YddHPfW2QFvhmL7b3gAAADw"] [Sat Aug 29 05:07:13.114907 2026] [security2:error] [pid 1028675:tid 1028849] [client 93.123.109.228:39312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9YddHPfW2QFvhmL7b3QAAACc"] [Sat Aug 29 05:07:13.121197 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.104.18.15:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/blacks.php"] [unique_id "apK9YddHPfW2QFvhmL7b4gAAAF4"] [Sat Aug 29 05:07:13.123687 2026] [security2:error] [pid 1028675:tid 1028926] [client 20.104.104.62:10482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/Cok.php"] [unique_id "apK9YddHPfW2QFvhmL7b5QAAAHQ"] [Sat Aug 29 05:07:13.148368 2026] [security2:error] [pid 1018003:tid 1018236] [client 52.139.37.240:14955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/ahax.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPiAAABgw"] [Sat Aug 29 05:07:13.152425 2026] [security2:error] [pid 1028675:tid 1028837] [client 52.139.37.240:21404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/7logs.php"] [unique_id "apK9YddHPfW2QFvhmL7b5wAAABs"] [Sat Aug 29 05:07:13.161754 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.68.135:3003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9YddHPfW2QFvhmL7b6QAAAEQ"] [Sat Aug 29 05:07:13.180768 2026] [security2:error] [pid 1028675:tid 1028908] [client 158.23.147.79:30499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9YddHPfW2QFvhmL7b6wAAAGI"] [Sat Aug 29 05:07:13.199402 2026] [security2:error] [pid 1018003:tid 1018184] [client 103.168.67.159:40294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPiwAABdk"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:07:13.206167 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.104.18.15:5106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/mac.php"] [unique_id "apK9YddHPfW2QFvhmL7b8AAAAGw"] [Sat Aug 29 05:07:13.211160 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.104.18.15:36549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/h2.php"] [unique_id "apK9YddHPfW2QFvhmL7b8gAAAC4"] [Sat Aug 29 05:07:13.211858 2026] [security2:error] [pid 1028675:tid 1028923] [client 52.139.37.240:51754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/mini.php"] [unique_id "apK9YddHPfW2QFvhmL7b8wAAAHE"] [Sat Aug 29 05:07:13.221169 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.48.250.41:62552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/maraz.php"] [unique_id "apK9YddHPfW2QFvhmL7b9QAAADA"] [Sat Aug 29 05:07:13.225515 2026] [security2:error] [pid 1028675:tid 1028857] [client 40.83.93.50:17312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/content.php"] [unique_id "apK9YddHPfW2QFvhmL7b9wAAAC8"] [Sat Aug 29 05:07:13.233702 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.104.49.130:34499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/002.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPjgAABcQ"] [Sat Aug 29 05:07:13.243064 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.48.160.90:51326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/TNT.php"] [unique_id "apK9YddHPfW2QFvhmL7cAgAAAB4"] [Sat Aug 29 05:07:13.269161 2026] [security2:error] [pid 1028675:tid 1028861] [client 93.123.109.228:39408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9YddHPfW2QFvhmL7cBgAAADM"] [Sat Aug 29 05:07:13.271634 2026] [security2:error] [pid 1018003:tid 1018265] [client 93.123.109.228:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9YTAh5Y1i2tUxg4EPjwAABik"] [Sat Aug 29 05:07:13.279307 2026] [security2:error] [pid 1028675:tid 1028839] [client 68.155.159.216:24561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/admin.php"] [unique_id "apK9YddHPfW2QFvhmL7cCwAAAB0"] [Sat Aug 29 05:07:13.279579 2026] [security2:error] [pid 1028675:tid 1028810] [client 93.123.109.228:39414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9YddHPfW2QFvhmL7cCgAAAAA"] [Sat Aug 29 05:07:13.282804 2026] [security2:error] [pid 1028675:tid 1028892] [client 168.107.94.195:51241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9YddHPfW2QFvhmL7cAwAAAFI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:13.289523 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.104.104.62:44561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/X7T6.php"] [unique_id "apK9YddHPfW2QFvhmL7cDAAAAEs"] [Sat Aug 29 05:07:13.293583 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.18.15:13593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/beck.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPkgAABdI"] [Sat Aug 29 05:07:13.306583 2026] [security2:error] [pid 1018003:tid 1018152] [client 40.83.93.50:20808] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/1.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPkwAABbk"] [Sat Aug 29 05:07:13.306687 2026] [security2:error] [pid 1018003:tid 1018152] [client 40.83.93.50:20808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/1.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPkwAABbk"] [Sat Aug 29 05:07:13.307907 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.158.54.35:17546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-access.php"] [unique_id "apK9YddHPfW2QFvhmL7cDwAAAEo"] [Sat Aug 29 05:07:13.324285 2026] [security2:error] [pid 1028675:tid 1028927] [client 93.123.109.228:39282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9YddHPfW2QFvhmL7cEwAAAHU"] [Sat Aug 29 05:07:13.341382 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.104.62:20656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-logo.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPlQAABfU"] [Sat Aug 29 05:07:13.346544 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.139.37.240:20872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/ac.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPlgAABdg"] [Sat Aug 29 05:07:13.347643 2026] [security2:error] [pid 1028675:tid 1028830] [client 158.158.54.35:29679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/theme.php"] [unique_id "apK9YddHPfW2QFvhmL7cGgAAABQ"] [Sat Aug 29 05:07:13.353872 2026] [security2:error] [pid 1018003:tid 1018224] [client 20.48.250.41:60719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/kbfr.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPmAAABgE"] [Sat Aug 29 05:07:13.357789 2026] [security2:error] [pid 1028675:tid 1028819] [client 20.104.49.130:52315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/amax.php"] [unique_id "apK9YddHPfW2QFvhmL7cHQAAAAk"] [Sat Aug 29 05:07:13.359947 2026] [security2:error] [pid 1018003:tid 1018267] [client 52.139.37.240:14510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/breads1.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPmgAABis"] [Sat Aug 29 05:07:13.376041 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.104.68.135:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "apK9YddHPfW2QFvhmL7cIAAAAEk"] [Sat Aug 29 05:07:13.388119 2026] [security2:error] [pid 1028675:tid 1028935] [client 20.104.18.15:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/simple.php"] [unique_id "apK9YddHPfW2QFvhmL7cIgAAAH0"] [Sat Aug 29 05:07:13.395954 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.196.209.81:15172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/gecko-new.php"] [unique_id "apK9YddHPfW2QFvhmL7cJAAAAG0"] [Sat Aug 29 05:07:13.396501 2026] [security2:error] [pid 1028675:tid 1028909] [client 20.104.18.15:36649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apK9YddHPfW2QFvhmL7cJQAAAGM"] [Sat Aug 29 05:07:13.400091 2026] [security2:error] [pid 1018003:tid 1018262] [client 52.139.37.240:32094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/v.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPngAABiY"] [Sat Aug 29 05:07:13.402868 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.48.160.90:51203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/cd.php"] [unique_id "apK9YddHPfW2QFvhmL7cJwAAAGQ"] [Sat Aug 29 05:07:13.416464 2026] [security2:error] [pid 1028675:tid 1028847] [client 158.23.147.79:30607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9YddHPfW2QFvhmL7cKgAAACU"] [Sat Aug 29 05:07:13.418120 2026] [security2:error] [pid 1018003:tid 1018182] [client 4.205.62.107:21582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/wp-konfig.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPnwAABdc"] [Sat Aug 29 05:07:13.420889 2026] [security2:error] [pid 1018003:tid 1018217] [client 93.123.109.228:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9YTAh5Y1i2tUxg4EPoAAABfo"] [Sat Aug 29 05:07:13.445267 2026] [security2:error] [pid 1018003:tid 1018275] [client 68.155.159.216:64485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/file5.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPoQAABjM"] [Sat Aug 29 05:07:13.447700 2026] [security2:error] [pid 1028675:tid 1028888] [client 20.104.104.62:10494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/see.php"] [unique_id "apK9YddHPfW2QFvhmL7cLwAAAE4"] [Sat Aug 29 05:07:13.449208 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.104.18.15:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/t3.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPowAABbw"] [Sat Aug 29 05:07:13.454333 2026] [security2:error] [pid 1028675:tid 1028928] [client 20.196.209.81:22458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9YddHPfW2QFvhmL7cMAAAAHY"] [Sat Aug 29 05:07:13.462972 2026] [security2:error] [pid 1028675:tid 1028881] [client 68.155.159.216:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9YddHPfW2QFvhmL7cMQAAAEc"] [Sat Aug 29 05:07:13.468055 2026] [security2:error] [pid 1028675:tid 1028914] [client 195.178.110.247:38202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.liatbehr.com"] [uri "/index.php"] [unique_id "apK9YddHPfW2QFvhmL7cNAAAAGg"] [Sat Aug 29 05:07:13.471559 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.197.61.180:13840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPpAAABi4"] [Sat Aug 29 05:07:13.498618 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.203.141.11:1352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/403.php"] [unique_id "apK9YddHPfW2QFvhmL7cOQAAAFk"] [Sat Aug 29 05:07:13.507961 2026] [security2:error] [pid 1028675:tid 1028813] [client 20.48.250.41:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wp-act.php"] [unique_id "apK9YddHPfW2QFvhmL7cOwAAAAM"] [Sat Aug 29 05:07:13.510647 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.104.104.62:42714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/siln.php"] [unique_id "apK9YddHPfW2QFvhmL7cPAAAAAQ"] [Sat Aug 29 05:07:13.521579 2026] [security2:error] [pid 1028675:tid 1028879] [client 93.123.109.228:39204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/test.php"] [unique_id "apK9YddHPfW2QFvhmL7cQAAAAEU"] [Sat Aug 29 05:07:13.529988 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.151.200.44:47357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/sao.php"] [unique_id "apK9YddHPfW2QFvhmL7cQQAAABs"] [Sat Aug 29 05:07:13.535715 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.18.15:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/xty.php"] [unique_id "apK9YddHPfW2QFvhmL7cRAAAAEQ"] [Sat Aug 29 05:07:13.536404 2026] [security2:error] [pid 1018003:tid 1018226] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9YTAh5Y1i2tUxg4EPpwAABgM"] [Sat Aug 29 05:07:13.546617 2026] [security2:error] [pid 1028675:tid 1028849] [client 52.139.37.240:21127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/ctex1.php"] [unique_id "apK9YddHPfW2QFvhmL7cRgAAACc"] [Sat Aug 29 05:07:13.547550 2026] [security2:error] [pid 1018003:tid 1018219] [client 93.123.109.228:39510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9YTAh5Y1i2tUxg4EPqQAABfw"] [Sat Aug 29 05:07:13.556083 2026] [security2:error] [pid 1018003:tid 1018277] [client 52.139.37.240:14478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/must.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPqgAABjU"] [Sat Aug 29 05:07:13.556424 2026] [security2:error] [pid 1028675:tid 1028855] [client 20.104.49.130:34554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/srontol.php"] [unique_id "apK9YddHPfW2QFvhmL7cSAAAAC0"] [Sat Aug 29 05:07:13.560313 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.48.160.90:51661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/luuf.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPqwAABfY"] [Sat Aug 29 05:07:13.560786 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.18.15:36630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/sao.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPrAAABh8"] [Sat Aug 29 05:07:13.576306 2026] [security2:error] [pid 1028675:tid 1028853] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9YddHPfW2QFvhmL7cTwAAACs"] [Sat Aug 29 05:07:13.588500 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.104.68.135:19322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-content/uploads/de_fb_uploads/b.php"] [unique_id "apK9YddHPfW2QFvhmL7cVAAAAFc"] [Sat Aug 29 05:07:13.592834 2026] [security2:error] [pid 1028675:tid 1028815] [client 52.139.37.240:32117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9YddHPfW2QFvhmL7cVQAAAAU"] [Sat Aug 29 05:07:13.598347 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.104.62:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/horeg.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPrgAABd0"] [Sat Aug 29 05:07:13.601927 2026] [security2:error] [pid 1028675:tid 1028861] [client 93.123.109.228:39408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9YddHPfW2QFvhmL7cVwAAADM"] [Sat Aug 29 05:07:13.607217 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.18.15:13655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/wp.php"] [unique_id "apK9YddHPfW2QFvhmL7cWAAAAD0"] [Sat Aug 29 05:07:13.642084 2026] [security2:error] [pid 1028675:tid 1028851] [client 195.178.110.247:65012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.liatbehr.com"] [uri "/index.php"] [unique_id "apK9YddHPfW2QFvhmL7cWgAAACk"] [Sat Aug 29 05:07:13.643619 2026] [security2:error] [pid 1028675:tid 1028712] [remote 47.128.48.166:23412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.glamrus.rocks"] [uri "/robots.txt"] [unique_id "apK9YddHPfW2QFvhmL7cWwAAZR8"] [Sat Aug 29 05:07:13.659798 2026] [security2:error] [pid 1028675:tid 1028912] [client 93.123.109.228:39282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9YddHPfW2QFvhmL7cXAAAAGY"] [Sat Aug 29 05:07:13.664250 2026] [security2:error] [pid 1028675:tid 1028874] [client 168.107.94.195:51625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9YddHPfW2QFvhmL7cXwAAAEA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:13.667011 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.48.250.41:59272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/24.php"] [unique_id "apK9YddHPfW2QFvhmL7cYQAAAHU"] [Sat Aug 29 05:07:13.684174 2026] [security2:error] [pid 1018003:tid 1018236] [client 93.123.109.228:39330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9YTAh5Y1i2tUxg4EPsAAABgw"] [Sat Aug 29 05:07:13.693468 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.104.104.62:20811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-config-sample.php"] [unique_id "apK9YddHPfW2QFvhmL7cZgAAADU"] [Sat Aug 29 05:07:13.701561 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.18.15:36553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/dapa.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPtAAABc8"] [Sat Aug 29 05:07:13.712730 2026] [security2:error] [pid 1018003:tid 1018265] [client 68.155.159.216:33752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPtgAABik"] [Sat Aug 29 05:07:13.723746 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.48.160.90:51605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/fex.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPuAAABhA"] [Sat Aug 29 05:07:13.729675 2026] [security2:error] [pid 1018003:tid 1018244] [client 103.240.76.112:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPuQAABhQ"] [Sat Aug 29 05:07:13.729815 2026] [security2:error] [pid 1018003:tid 1018244] [client 103.240.76.112:43339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPuQAABhQ"] [Sat Aug 29 05:07:13.736847 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.147.79:32718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPugAABfU"] [Sat Aug 29 05:07:13.740266 2026] [security2:error] [pid 1028675:tid 1028830] [client 52.139.37.240:21171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/defaults.php"] [unique_id "apK9YddHPfW2QFvhmL7cbwAAABQ"] [Sat Aug 29 05:07:13.740816 2026] [security2:error] [pid 1028675:tid 1028923] [client 40.83.93.50:9274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/wxo.php"] [unique_id "apK9YddHPfW2QFvhmL7ccAAAAHE"] [Sat Aug 29 05:07:13.741551 2026] [security2:error] [pid 1028675:tid 1028909] [client 20.104.104.62:10660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/basic.php"] [unique_id "apK9YddHPfW2QFvhmL7ccQAAAGM"] [Sat Aug 29 05:07:13.745520 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.18.15:13594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/abcd.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPvQAABdI"] [Sat Aug 29 05:07:13.746298 2026] [security2:error] [pid 1028675:tid 1028847] [client 68.155.159.216:12165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9YddHPfW2QFvhmL7cdQAAACU"] [Sat Aug 29 05:07:13.749133 2026] [security2:error] [pid 1028675:tid 1028835] [client 4.205.62.107:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/gecko-litespeed.php"] [unique_id "apK9YddHPfW2QFvhmL7cegAAABk"] [Sat Aug 29 05:07:13.754328 2026] [security2:error] [pid 1028675:tid 1028905] [client 20.104.18.15:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/sallu.php"] [unique_id "apK9YddHPfW2QFvhmL7cewAAAF8"] [Sat Aug 29 05:07:13.764048 2026] [security2:error] [pid 1018003:tid 1018170] [client 158.158.54.35:10617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPvgAABcs"] [Sat Aug 29 05:07:13.767966 2026] [security2:error] [pid 1028675:tid 1028930] [client 68.155.159.216:63815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9YddHPfW2QFvhmL7cgAAAAHg"] [Sat Aug 29 05:07:13.772598 2026] [security2:error] [pid 1028675:tid 1028842] [client 4.205.62.107:22034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/dd.php"] [unique_id "apK9YddHPfW2QFvhmL7cggAAACA"] [Sat Aug 29 05:07:13.775056 2026] [security2:error] [pid 1018003:tid 1018258] [client 40.83.93.50:20825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/about.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPwAAABiI"] [Sat Aug 29 05:07:13.777072 2026] [security2:error] [pid 1028675:tid 1028900] [client 68.155.159.216:2026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/file5.php"] [unique_id "apK9YddHPfW2QFvhmL7chQAAAFo"] [Sat Aug 29 05:07:13.785499 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.68.135:2948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPwQAABeQ"] [Sat Aug 29 05:07:13.786659 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.104.49.130:43010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/srontol.php"] [unique_id "apK9YddHPfW2QFvhmL7cigAAACI"] [Sat Aug 29 05:07:13.791660 2026] [security2:error] [pid 1018003:tid 1018189] [client 4.205.62.107:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/cache-compat.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPwgAABd4"] [Sat Aug 29 05:07:13.797210 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.196.209.81:14729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/wp-admin.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPwwAABg4"] [Sat Aug 29 05:07:13.798143 2026] [security2:error] [pid 1028675:tid 1028721] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/php-info.php"] [unique_id "apK9YddHPfW2QFvhmL7ciwAAayg"] [Sat Aug 29 05:07:13.805622 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.158.54.35:15191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/classwithtostring.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPxAAABb4"] [Sat Aug 29 05:07:13.824283 2026] [security2:error] [pid 1028675:tid 1028872] [client 158.23.147.79:35717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9YddHPfW2QFvhmL7cjQAAAD4"] [Sat Aug 29 05:07:13.827216 2026] [security2:error] [pid 1028675:tid 1028741] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/php.php"] [unique_id "apK9YddHPfW2QFvhmL7cjgAAazw"] [Sat Aug 29 05:07:13.829373 2026] [security2:error] [pid 1028675:tid 1028725] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/php_info.php"] [unique_id "apK9YddHPfW2QFvhmL7cjwAAayw"] [Sat Aug 29 05:07:13.852247 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.196.209.81:15533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPxgAABjE"] [Sat Aug 29 05:07:13.853680 2026] [security2:error] [pid 1018003:tid 1018191] [client 93.123.109.228:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9YTAh5Y1i2tUxg4EPxwAABeA"] [Sat Aug 29 05:07:13.857452 2026] [security2:error] [pid 1028675:tid 1028814] [client 93.123.109.228:39312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9YddHPfW2QFvhmL7ckQAAAAQ"] [Sat Aug 29 05:07:13.863137 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.160.90:49420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/l.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPyAAABd8"] [Sat Aug 29 05:07:13.865296 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:60781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/155.php"] [unique_id "apK9YddHPfW2QFvhmL7ckwAAAHM"] [Sat Aug 29 05:07:13.866074 2026] [security2:error] [pid 1028675:tid 1028737] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/phpinfo.php"] [unique_id "apK9YddHPfW2QFvhmL7clAAARTg"] [Sat Aug 29 05:07:13.879767 2026] [security2:error] [pid 1018003:tid 1018275] [client 93.123.109.228:39288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9YTAh5Y1i2tUxg4EPygAABjM"] [Sat Aug 29 05:07:13.882826 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.18.15:13692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/nofile.php"] [unique_id "apK9YddHPfW2QFvhmL7clwAAAEQ"] [Sat Aug 29 05:07:13.894783 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.104.62:10868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/monso.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPzAAABeE"] [Sat Aug 29 05:07:13.908629 2026] [security2:error] [pid 1018003:tid 1018194] [client 68.155.159.216:49204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPzgAABeM"] [Sat Aug 29 05:07:13.928410 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.147.79:26617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9YTAh5Y1i2tUxg4EPzwAABgM"] [Sat Aug 29 05:07:13.951043 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.104.18.15:4981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/codex.php"] [unique_id "apK9YTAh5Y1i2tUxg4EP0AAABdQ"] [Sat Aug 29 05:07:13.966278 2026] [autoindex:error] [pid 1018003:tid 1018162] [client 205.210.31.8:57570] AH01276: Cannot serve directory /home3/umuqmhmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:07:13.976303 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.18.15:36696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-content/l.php"] [unique_id "apK9YTAh5Y1i2tUxg4EP0wAABh8"] [Sat Aug 29 05:07:13.981116 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.104.104.62:20836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/blog/fw.php"] [unique_id "apK9YddHPfW2QFvhmL7csgAAAHc"] [Sat Aug 29 05:07:13.983420 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.203.141.11:11236] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.xbdorthodontics.com"] [uri "/1.php"] [unique_id "apK9YddHPfW2QFvhmL7cswAAAE8"] [Sat Aug 29 05:07:13.983500 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.203.141.11:11236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/1.php"] [unique_id "apK9YddHPfW2QFvhmL7cswAAAE8"] [Sat Aug 29 05:07:13.986717 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.68.135:11686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9YTAh5Y1i2tUxg4EP1AAABek"] [Sat Aug 29 05:07:14.011099 2026] [security2:error] [pid 1028675:tid 1028857] [client 93.123.109.228:39312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9YtdHPfW2QFvhmL7ctwAAAC8"] [Sat Aug 29 05:07:14.013458 2026] [security2:error] [pid 1028675:tid 1028833] [client 20.48.160.90:51676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/xr.php"] [unique_id "apK9YtdHPfW2QFvhmL7cuAAAABc"] [Sat Aug 29 05:07:14.020395 2026] [security2:error] [pid 1028675:tid 1028748] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/public/phpinfo.php"] [unique_id "apK9YtdHPfW2QFvhmL7cugAAXEM"] [Sat Aug 29 05:07:14.021918 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.104.18.15:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/run.php"] [unique_id "apK9YtdHPfW2QFvhmL7cuwAAACs"] [Sat Aug 29 05:07:14.023450 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.48.250.41:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/file.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP1wAABfA"] [Sat Aug 29 05:07:14.024199 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.104.104.62:52085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/f-401.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP2AAABd0"] [Sat Aug 29 05:07:14.029603 2026] [security2:error] [pid 1018003:tid 1018184] [client 93.123.109.228:39288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/wp-config.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP2gAABdk"] [Sat Aug 29 05:07:14.044948 2026] [security2:error] [pid 1028675:tid 1028815] [client 168.107.94.195:52043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9YtdHPfW2QFvhmL7cvQAAAAU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:14.048869 2026] [security2:error] [pid 1028675:tid 1028936] [client 93.123.109.228:39326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/wp-config.php.bak"] [unique_id "apK9YtdHPfW2QFvhmL7cvgAAAH4"] [Sat Aug 29 05:07:14.057379 2026] [security2:error] [pid 1018003:tid 1018271] [client 93.123.109.228:39094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/wp-config.php.new"] [unique_id "apK9YjAh5Y1i2tUxg4EP2wAABi8"] [Sat Aug 29 05:07:14.057809 2026] [security2:error] [pid 1028675:tid 1028871] [client 93.123.109.228:39434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/wp-config.php.old"] [unique_id "apK9YtdHPfW2QFvhmL7cwAAAAD0"] [Sat Aug 29 05:07:14.069716 2026] [security2:error] [pid 1028675:tid 1028839] [client 68.155.159.216:50349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/x.php"] [unique_id "apK9YtdHPfW2QFvhmL7cwgAAAB0"] [Sat Aug 29 05:07:14.070626 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.104.104.62:10859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/rce.php"] [unique_id "apK9YtdHPfW2QFvhmL7cwwAAAC4"] [Sat Aug 29 05:07:14.074093 2026] [security2:error] [pid 1018003:tid 1018202] [client 68.155.159.216:30699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP3AAABes"] [Sat Aug 29 05:07:14.113522 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.147.79:25572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP3gAABhA"] [Sat Aug 29 05:07:14.127964 2026] [security2:error] [pid 1028675:tid 1028873] [client 20.104.18.15:5064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/5656.php"] [unique_id "apK9YtdHPfW2QFvhmL7cyQAAAD8"] [Sat Aug 29 05:07:14.132850 2026] [security2:error] [pid 1028675:tid 1028824] [client 93.123.109.228:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.fellowsofmythgar.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9YtdHPfW2QFvhmL7cywAAAA4"] [Sat Aug 29 05:07:14.137303 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.104.18.15:36626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-admin/w.php"] [unique_id "apK9YtdHPfW2QFvhmL7czgAAAEk"] [Sat Aug 29 05:07:14.163410 2026] [security2:error] [pid 1018003:tid 1018267] [client 158.23.147.79:17457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP4AAABis"] [Sat Aug 29 05:07:14.175930 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.197.61.180:7908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/inputs.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP4QAABjU"] [Sat Aug 29 05:07:14.176916 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.104.18.15:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/new.php"] [unique_id "apK9YtdHPfW2QFvhmL7c1QAAACg"] [Sat Aug 29 05:07:14.184295 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.147.79:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/asd.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP4wAABd4"] [Sat Aug 29 05:07:14.203081 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.48.250.41:60705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apK9YtdHPfW2QFvhmL7c2QAAAFQ"] [Sat Aug 29 05:07:14.205517 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.104.68.135:2964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/PHPMailer/index.php"] [unique_id "apK9YtdHPfW2QFvhmL7c2gAAAG4"] [Sat Aug 29 05:07:14.209546 2026] [security2:error] [pid 1018003:tid 1018190] [client 4.205.62.107:56014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/upload.form.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP5QAABd8"] [Sat Aug 29 05:07:14.210055 2026] [http2:warn] [pid 1017536:tid 1017791] [client 57.141.14.6:58642] h2_stream(1017536-30-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:07:14.213454 2026] [security2:error] [pid 1028675:tid 1028828] [client 158.158.54.35:7276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9YtdHPfW2QFvhmL7c3AAAABI"] [Sat Aug 29 05:07:14.215844 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.104.62:10827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/exec.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP5gAABjM"] [Sat Aug 29 05:07:14.228946 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.196.209.81:2036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/wp-configs.php"] [unique_id "apK9YtdHPfW2QFvhmL7c3gAAAFg"] [Sat Aug 29 05:07:14.249743 2026] [security2:error] [pid 1028675:tid 1028903] [client 40.83.93.50:13592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/admin-header.php"] [unique_id "apK9YtdHPfW2QFvhmL7c4QAAAF0"] [Sat Aug 29 05:07:14.250758 2026] [security2:error] [pid 1028675:tid 1028885] [client 158.158.54.35:15200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/news.php"] [unique_id "apK9YtdHPfW2QFvhmL7c4gAAAEs"] [Sat Aug 29 05:07:14.256763 2026] [security2:error] [pid 1028675:tid 1028912] [client 20.196.209.81:20723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/languages/index.php"] [unique_id "apK9YtdHPfW2QFvhmL7c5QAAAGY"] [Sat Aug 29 05:07:14.268517 2026] [security2:error] [pid 1028675:tid 1028904] [client 4.205.62.107:8974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/public/rip.php.php"] [unique_id "apK9YtdHPfW2QFvhmL7c5gAAAF4"] [Sat Aug 29 05:07:14.287141 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.147.79:30667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP6AAABbw"] [Sat Aug 29 05:07:14.290916 2026] [security2:error] [pid 1018003:tid 1018194] [client 20.104.104.62:64757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-optionss.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP6QAABeM"] [Sat Aug 29 05:07:14.305614 2026] [security2:error] [pid 1028675:tid 1028891] [client 35.194.208.44:43844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/app/.env"] [unique_id "apK9YtdHPfW2QFvhmL7c7AAAAFE"] [Sat Aug 29 05:07:14.306214 2026] [security2:error] [pid 1018003:tid 1018258] [client 35.194.208.44:43898] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK9YjAh5Y1i2tUxg4EP7QAABiI"] [Sat Aug 29 05:07:14.306424 2026] [security2:error] [pid 1018003:tid 1018170] [client 35.194.208.44:43842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/root/.env"] [unique_id "apK9YjAh5Y1i2tUxg4EP6gAABcs"] [Sat Aug 29 05:07:14.306621 2026] [security2:error] [pid 1018003:tid 1018221] [client 35.194.208.44:43838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/.env"] [unique_id "apK9YjAh5Y1i2tUxg4EP7AAABf4"] [Sat Aug 29 05:07:14.309036 2026] [security2:error] [pid 1028675:tid 1028830] [client 35.194.208.44:43858] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9YtdHPfW2QFvhmL7c7wAAABQ"] [Sat Aug 29 05:07:14.310046 2026] [security2:error] [pid 1028675:tid 1028923] [client 35.194.208.44:43884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apK9YtdHPfW2QFvhmL7c8QAAAHE"] [Sat Aug 29 05:07:14.310196 2026] [security2:error] [pid 1028675:tid 1028909] [client 35.194.208.44:43916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/.env"] [unique_id "apK9YtdHPfW2QFvhmL7c7QAAAGM"] [Sat Aug 29 05:07:14.310904 2026] [core:error] [pid 1028675:tid 1028847] [client 35.194.208.44:43924] AH10244: invalid URI path (/@fs/../../.env?raw??) [Sat Aug 29 05:07:14.311525 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.18.15:13641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/inx.php"] [unique_id "apK9YtdHPfW2QFvhmL7c8wAAAEQ"] [Sat Aug 29 05:07:14.312736 2026] [security2:error] [pid 1018003:tid 1018186] [client 35.194.208.44:43904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apK9YjAh5Y1i2tUxg4EP7gAABds"] [Sat Aug 29 05:07:14.313241 2026] [security2:error] [pid 1018003:tid 1018186] [client 35.194.208.44:43904] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apK9YjAh5Y1i2tUxg4EP7gAABds"] [Sat Aug 29 05:07:14.313958 2026] [security2:error] [pid 1028675:tid 1028819] [client 35.194.208.44:43850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/src/.env"] [unique_id "apK9YtdHPfW2QFvhmL7c9AAAAAk"] [Sat Aug 29 05:07:14.318635 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.18.15:5034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/w3lls.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP8wAABfw"] [Sat Aug 29 05:07:14.322550 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.48.160.90:51693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/Q3.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP9gAABfk"] [Sat Aug 29 05:07:14.322850 2026] [security2:error] [pid 1018003:tid 1018157] [client 35.194.208.44:43990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/root/.aws/credentials.backup"] [unique_id "apK9YjAh5Y1i2tUxg4EP9QAABb4"] [Sat Aug 29 05:07:14.326572 2026] [security2:error] [pid 1018003:tid 1018224] [client 40.83.93.50:7504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/as.php"] [unique_id "apK9YjAh5Y1i2tUxg4EP-wAABgE"] [Sat Aug 29 05:07:14.328051 2026] [security2:error] [pid 1018003:tid 1018266] [client 35.194.208.44:44004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/root/.aws/credentials.bak"] [unique_id "apK9YjAh5Y1i2tUxg4EP-QAABio"] [Sat Aug 29 05:07:14.328154 2026] [security2:error] [pid 1018003:tid 1018266] [client 35.194.208.44:44004] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/root/.aws/credentials.bak"] [unique_id "apK9YjAh5Y1i2tUxg4EP-QAABio"] [Sat Aug 29 05:07:14.330687 2026] [security2:error] [pid 1028675:tid 1028851] [client 60.243.207.176:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9YtdHPfW2QFvhmL7dAQAAACk"] [Sat Aug 29 05:07:14.330779 2026] [security2:error] [pid 1028675:tid 1028851] [client 60.243.207.176:62464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9YtdHPfW2QFvhmL7dAQAAACk"] [Sat Aug 29 05:07:14.339144 2026] [security2:error] [pid 1028675:tid 1028914] [client 35.194.208.44:44062] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/home/www-data/.aws/credentials"] [unique_id "apK9YtdHPfW2QFvhmL7dBwAAAGg"] [Sat Aug 29 05:07:14.361121 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.18.15:36604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-content/k.php"] [unique_id "apK9YtdHPfW2QFvhmL7dDgAAAHo"] [Sat Aug 29 05:07:14.376563 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.104.104.62:44569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/dbc.php"] [unique_id "apK9YtdHPfW2QFvhmL7dDwAAAHc"] [Sat Aug 29 05:07:14.386599 2026] [security2:error] [pid 1028675:tid 1028845] [client 68.155.159.216:24524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9YtdHPfW2QFvhmL7dFAAAACM"] [Sat Aug 29 05:07:14.426745 2026] [security2:error] [pid 1018003:tid 1018207] [client 168.107.94.195:52508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQBwAABfA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:14.445505 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.48.250.41:59321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/06.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQCAAABdk"] [Sat Aug 29 05:07:14.459969 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.104.18.15:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/fpwch.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQCQAABc8"] [Sat Aug 29 05:07:14.462990 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.104.104.62:42719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/hq.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQCgAABhw"] [Sat Aug 29 05:07:14.471152 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.48.160.90:49530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/Q1.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQCwAABgk"] [Sat Aug 29 05:07:14.478885 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.104.18.15:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/vpn.php"] [unique_id "apK9YtdHPfW2QFvhmL7dIwAAAGw"] [Sat Aug 29 05:07:14.480181 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.68.135:11689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/SimplePie/autoload_classmap.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQDAAABgw"] [Sat Aug 29 05:07:14.504239 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.104.104.62:40226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/work.php"] [unique_id "apK9YtdHPfW2QFvhmL7dJgAAADM"] [Sat Aug 29 05:07:14.520611 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.104.104.62:10463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/wp-wlx.php"] [unique_id "apK9YtdHPfW2QFvhmL7dKQAAAB0"] [Sat Aug 29 05:07:14.523773 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.147.79:30475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQDQAABik"] [Sat Aug 29 05:07:14.545795 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.104.18.15:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/os.php"] [unique_id "apK9YtdHPfW2QFvhmL7dKgAAAEA"] [Sat Aug 29 05:07:14.557753 2026] [security2:error] [pid 1028675:tid 1028824] [client 4.205.62.107:21622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/25.php"] [unique_id "apK9YtdHPfW2QFvhmL7dLAAAAA4"] [Sat Aug 29 05:07:14.598346 2026] [core:error] [pid 1028675:tid 1028850] [client 20.203.141.11:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:14.598370 2026] [core:error] [pid 1028675:tid 1028850] [client 20.203.141.11:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:14.606440 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.203.141.11:45475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/s.php"] [unique_id "apK9YtdHPfW2QFvhmL7dNQAAAG4"] [Sat Aug 29 05:07:14.607636 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.48.160.90:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/nz.php"] [unique_id "apK9YtdHPfW2QFvhmL7dNgAAAB8"] [Sat Aug 29 05:07:14.632216 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.196.209.81:14781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/essexec.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQEQAABi8"] [Sat Aug 29 05:07:14.633968 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.48.250.41:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/class.php"] [unique_id "apK9YtdHPfW2QFvhmL7dOwAAAF0"] [Sat Aug 29 05:07:14.636618 2026] [security2:error] [pid 1018003:tid 1018164] [client 127.0.0.1:40300] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "apK9YjAh5Y1i2tUxg4EP_AAABcU"] [Sat Aug 29 05:07:14.636647 2026] [security2:error] [pid 1028675:tid 1028900] [client 35.194.208.44:43986] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/root/.aws/config"] [unique_id "apK9YtdHPfW2QFvhmL7c_gAAAFo"] [Sat Aug 29 05:07:14.641494 2026] [security2:error] [pid 1028675:tid 1028922] [client 20.104.18.15:13708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/shiny.php"] [unique_id "apK9YtdHPfW2QFvhmL7dPQAAAHA"] [Sat Aug 29 05:07:14.649558 2026] [security2:error] [pid 1028675:tid 1028904] [client 68.155.159.216:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/radio.php"] [unique_id "apK9YtdHPfW2QFvhmL7dPgAAAF4"] [Sat Aug 29 05:07:14.656797 2026] [security2:error] [pid 1028675:tid 1028810] [client 20.196.209.81:15540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/languages/min.php"] [unique_id "apK9YtdHPfW2QFvhmL7dQAAAAAA"] [Sat Aug 29 05:07:14.660865 2026] [security2:error] [pid 1028675:tid 1028871] [client 158.158.54.35:17987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/bthil.php"] [unique_id "apK9YtdHPfW2QFvhmL7dQQAAAD0"] [Sat Aug 29 05:07:14.666145 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.104.104.62:10832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/attack.php"] [unique_id "apK9YtdHPfW2QFvhmL7dQgAAAHI"] [Sat Aug 29 05:07:14.679288 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.104.68.135:11661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9YtdHPfW2QFvhmL7dRQAAACE"] [Sat Aug 29 05:07:14.695215 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.158.54.35:15193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/about/function.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQFgAABhA"] [Sat Aug 29 05:07:14.697075 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.18.15:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/domvf.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQFwAABhY"] [Sat Aug 29 05:07:14.705628 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.104.104.62:40241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-config-pantheon.php"] [unique_id "apK9YtdHPfW2QFvhmL7dSwAAAGE"] [Sat Aug 29 05:07:14.724977 2026] [security2:error] [pid 1018003:tid 1018183] [client 40.83.93.50:13627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/admin.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQGQAABdg"] [Sat Aug 29 05:07:14.758856 2026] [security2:error] [pid 1028675:tid 1028819] [client 52.139.37.240:15294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/up.php"] [unique_id "apK9YtdHPfW2QFvhmL7dUwAAAAk"] [Sat Aug 29 05:07:14.761249 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.48.160.90:49476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/sg.php"] [unique_id "apK9YtdHPfW2QFvhmL7dVAAAADA"] [Sat Aug 29 05:07:14.761930 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.104.18.15:36620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/htio.php"] [unique_id "apK9YtdHPfW2QFvhmL7dVQAAAAg"] [Sat Aug 29 05:07:14.764661 2026] [security2:error] [pid 1028675:tid 1028816] [client 127.0.0.1:40362] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "apK9YtdHPfW2QFvhmL7dBQAAAAY"] [Sat Aug 29 05:07:14.764718 2026] [security2:error] [pid 1028675:tid 1028844] [client 35.194.208.44:44018] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/home/node/.aws/config"] [unique_id "apK9YtdHPfW2QFvhmL7dAwAAACI"] [Sat Aug 29 05:07:14.772528 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.250.41:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/8.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQGgAABf4"] [Sat Aug 29 05:07:14.795120 2026] [security2:error] [pid 1028675:tid 1028855] [client 52.139.37.240:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apK9YtdHPfW2QFvhmL7dWgAAAC0"] [Sat Aug 29 05:07:14.799338 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.104.62:36974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/mh.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQGwAABfw"] [Sat Aug 29 05:07:14.808275 2026] [security2:error] [pid 1018003:tid 1018224] [client 168.107.94.195:52769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQHAAABgE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:14.813778 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.104.104.62:10461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/file66.php"] [unique_id "apK9YtdHPfW2QFvhmL7dXgAAAC8"] [Sat Aug 29 05:07:14.818491 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:33587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQHQAABco"] [Sat Aug 29 05:07:14.842578 2026] [security2:error] [pid 1018003:tid 1018185] [client 158.23.147.79:32714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQHwAABdo"] [Sat Aug 29 05:07:14.845818 2026] [security2:error] [pid 1028675:tid 1028813] [client 40.83.93.50:7429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/room.php"] [unique_id "apK9YtdHPfW2QFvhmL7dYQAAAAM"] [Sat Aug 29 05:07:14.861703 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.18.15:13680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/goods.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQIQAABc0"] [Sat Aug 29 05:07:14.875212 2026] [security2:error] [pid 1028675:tid 1028859] [client 68.155.159.216:65031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/cong.php"] [unique_id "apK9YtdHPfW2QFvhmL7dZwAAADE"] [Sat Aug 29 05:07:14.886686 2026] [security2:error] [pid 1028675:tid 1028936] [client 4.205.62.107:24979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/goods.php"] [unique_id "apK9YtdHPfW2QFvhmL7daQAAAH4"] [Sat Aug 29 05:07:14.891843 2026] [security2:error] [pid 1028675:tid 1028896] [client 68.155.159.216:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/file88.php"] [unique_id "apK9YtdHPfW2QFvhmL7dagAAAFY"] [Sat Aug 29 05:07:14.895043 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.48.160.90:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/hypo.php"] [unique_id "apK9YtdHPfW2QFvhmL7dawAAAAE"] [Sat Aug 29 05:07:14.902522 2026] [security2:error] [pid 1028675:tid 1028861] [client 4.205.62.107:22520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/doc.php"] [unique_id "apK9YtdHPfW2QFvhmL7dbQAAADM"] [Sat Aug 29 05:07:14.908068 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.250.41:62508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/0x0x.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQJgAABes"] [Sat Aug 29 05:07:14.929999 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.197.61.180:7203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQKAAABi4"] [Sat Aug 29 05:07:14.943256 2026] [security2:error] [pid 1028675:tid 1028824] [client 158.23.147.79:35784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9YtdHPfW2QFvhmL7dcwAAAA4"] [Sat Aug 29 05:07:14.944548 2026] [security2:error] [pid 1018003:tid 1018174] [client 52.139.37.240:21402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/domains.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQKgAABc8"] [Sat Aug 29 05:07:14.945097 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.104.104.62:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/f2r4.php"] [unique_id "apK9YtdHPfW2QFvhmL7ddAAAAA8"] [Sat Aug 29 05:07:14.948281 2026] [security2:error] [pid 1018003:tid 1018256] [client 4.205.62.107:51459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/fff.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQKwAABiA"] [Sat Aug 29 05:07:14.948952 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.104.104.62:10825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/zafir1.php"] [unique_id "apK9YtdHPfW2QFvhmL7ddQAAADU"] [Sat Aug 29 05:07:14.951148 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.68.135:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/blocks/buttons/index.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQLAAABis"] [Sat Aug 29 05:07:14.965179 2026] [security2:error] [pid 1028675:tid 1028854] [client 158.23.147.79:53804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/content.php"] [unique_id "apK9YtdHPfW2QFvhmL7ddwAAACw"] [Sat Aug 29 05:07:14.999813 2026] [security2:error] [pid 1018003:tid 1018268] [client 52.139.37.240:32085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9YjAh5Y1i2tUxg4EQMAAABiw"] [Sat Aug 29 05:07:15.016878 2026] [security2:error] [pid 1028675:tid 1028890] [client 68.155.159.216:49184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/admin.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dfAAAAFA"] [Sat Aug 29 05:07:15.029640 2026] [security2:error] [pid 1018003:tid 1018194] [client 114.119.157.112:63075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_reviews_write.php/products_id/626/osCsid/6b7db4fe5228fd82276a6609e8cbfe98"] [unique_id "apK9YzAh5Y1i2tUxg4EQMwAABeM"], referer: http://www.classiclightingusa.com/catalog/product_info.php/products_id/626/osCsid/6b7db4fe5228fd82276a6609e8cbfe98 [Sat Aug 29 05:07:15.038805 2026] [security2:error] [pid 1018003:tid 1018221] [client 20.48.160.90:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/Hd.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQNAAABf4"] [Sat Aug 29 05:07:15.039148 2026] [security2:error] [pid 1018003:tid 1018156] [client 52.139.37.240:14951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-content/155.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQNQAABb0"] [Sat Aug 29 05:07:15.053224 2026] [security2:error] [pid 1018003:tid 1018219] [client 103.168.67.159:40306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQNgAABfw"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:07:15.056207 2026] [security2:error] [pid 1018003:tid 1018152] [client 20.196.209.81:20688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/languages/pk.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQNwAABbk"] [Sat Aug 29 05:07:15.057539 2026] [security2:error] [pid 1028675:tid 1028912] [client 158.23.147.79:26553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/goat.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dggAAAGY"] [Sat Aug 29 05:07:15.065575 2026] [security2:error] [pid 1028675:tid 1028911] [client 20.196.209.81:2041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/hello.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dhQAAAGU"] [Sat Aug 29 05:07:15.065821 2026] [security2:error] [pid 1028675:tid 1028917] [client 68.155.159.216:64416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/file88.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dhAAAAGs"] [Sat Aug 29 05:07:15.067057 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.48.250.41:59379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/166.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQOAAABdA"] [Sat Aug 29 05:07:15.090392 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.104.62:10657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/console.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQOQAABio"] [Sat Aug 29 05:07:15.107830 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.49.130:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/wp-blogs.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQOgAABew"] [Sat Aug 29 05:07:15.117412 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.203.141.11:27951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/test1.php"] [unique_id "apK9Y9dHPfW2QFvhmL7diwAAAH8"] [Sat Aug 29 05:07:15.131488 2026] [core:error] [pid 1018003:tid 1018277] [client 158.158.54.35:34259] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:15.131503 2026] [core:error] [pid 1018003:tid 1018277] [client 158.158.54.35:34259] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:15.143040 2026] [security2:error] [pid 1018003:tid 1018157] [client 52.139.37.240:20785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/dropdown.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQPAAABb4"] [Sat Aug 29 05:07:15.143276 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.104.62:20829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-xmlx.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQPQAABf8"] [Sat Aug 29 05:07:15.145028 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.104.62:42656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/sadis.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQPgAABek"] [Sat Aug 29 05:07:15.146952 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.104.68.135:3694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/css/autoload_classmap.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQPwAABgY"] [Sat Aug 29 05:07:15.184655 2026] [security2:error] [pid 1028675:tid 1028843] [client 68.155.159.216:30706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/makeasmtp.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dlQAAACE"] [Sat Aug 29 05:07:15.187645 2026] [security2:error] [pid 1028675:tid 1028878] [client 168.107.94.195:53103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dlgAAAEQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:15.193041 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:50235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/x.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQQQAABgk"] [Sat Aug 29 05:07:15.193934 2026] [security2:error] [pid 1028675:tid 1028866] [client 146.70.194.254:40496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.194.70.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/xmlrpc.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dkwAAADg"] [Sat Aug 29 05:07:15.200773 2026] [security2:error] [pid 1028675:tid 1028900] [client 40.83.93.50:13584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dnAAAAFo"] [Sat Aug 29 05:07:15.212513 2026] [security2:error] [pid 1028675:tid 1028814] [client 103.171.189.88:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dmwAAAAQ"] [Sat Aug 29 05:07:15.212631 2026] [security2:error] [pid 1028675:tid 1028814] [client 103.171.189.88:57692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dmwAAAAQ"] [Sat Aug 29 05:07:15.219552 2026] [security2:error] [pid 1028675:tid 1028823] [client 158.23.147.79:25596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9Y9dHPfW2QFvhmL7doAAAAA0"] [Sat Aug 29 05:07:15.226858 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.104.62:10824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/blnux.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dogAAACk"] [Sat Aug 29 05:07:15.232014 2026] [security2:error] [pid 1028675:tid 1028929] [client 68.155.159.216:33734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dowAAAHc"] [Sat Aug 29 05:07:15.235054 2026] [security2:error] [pid 1018003:tid 1018184] [client 52.139.37.240:15273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-update.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQQgAABdk"] [Sat Aug 29 05:07:15.236517 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.48.250.41:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/h2a2ck.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dpAAAACM"] [Sat Aug 29 05:07:15.259135 2026] [security2:error] [pid 1028675:tid 1028819] [client 52.139.37.240:32759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/wp-index.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dqwAAAAk"] [Sat Aug 29 05:07:15.274018 2026] [security2:error] [pid 1028675:tid 1028836] [client 158.23.147.79:17508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9Y9dHPfW2QFvhmL7drgAAABo"] [Sat Aug 29 05:07:15.287253 2026] [security2:error] [pid 1028675:tid 1028833] [client 158.158.54.35:18046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/cv.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dtAAAABc"] [Sat Aug 29 05:07:15.289642 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.23.147.79:50095] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.samueljamesmcgrath.com"] [uri "/1.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQRAAABg4"] [Sat Aug 29 05:07:15.289731 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.23.147.79:50095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/1.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQRAAABg4"] [Sat Aug 29 05:07:15.309589 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.160.90:51277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/im.php"] [unique_id "apK9Y9dHPfW2QFvhmL7duQAAAHM"] [Sat Aug 29 05:07:15.333483 2026] [security2:error] [pid 1018003:tid 1018196] [client 52.139.37.240:21134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/files/index.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQRQAABeU"] [Sat Aug 29 05:07:15.353116 2026] [security2:error] [pid 1018003:tid 1018164] [client 4.205.62.107:55993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/aws_auth.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQRwAABcU"] [Sat Aug 29 05:07:15.354121 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.104.62:52049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/xcre1.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQSAAABcI"] [Sat Aug 29 05:07:15.361398 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.104.104.62:10486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/pentest.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQSQAABdw"] [Sat Aug 29 05:07:15.364339 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.250.41:62473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/error_log.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQSgAABdc"] [Sat Aug 29 05:07:15.368101 2026] [security2:error] [pid 1018003:tid 1018213] [client 68.155.159.216:12272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/images/index.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQTAAABfY"] [Sat Aug 29 05:07:15.391324 2026] [security2:error] [pid 1028675:tid 1028840] [client 158.23.147.79:30513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/goat1.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dwwAAAB4"] [Sat Aug 29 05:07:15.419708 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.68.135:2994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/index.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQTgAABds"] [Sat Aug 29 05:07:15.424198 2026] [security2:error] [pid 1028675:tid 1028909] [client 40.83.93.50:7998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/class-wp-cmd.php"] [unique_id "apK9Y9dHPfW2QFvhmL7dxgAAAGM"] [Sat Aug 29 05:07:15.424731 2026] [security2:error] [pid 1018003:tid 1018246] [client 52.139.37.240:14975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/xmrlpc.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQTwAABhY"] [Sat Aug 29 05:07:15.450228 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.139.37.240:32096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/ww2.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQUAAABdg"] [Sat Aug 29 05:07:15.450446 2026] [security2:error] [pid 1028675:tid 1028905] [client 20.48.160.90:51275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/fc.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d0AAAAF8"] [Sat Aug 29 05:07:15.451912 2026] [security2:error] [pid 1018003:tid 1018192] [client 4.205.62.107:9171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/h.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQUQAABeE"] [Sat Aug 29 05:07:15.454584 2026] [security2:error] [pid 1028675:tid 1028879] [client 20.196.209.81:22055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.corinaandbrian.strangeworx.com"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d0wAAAEU"] [Sat Aug 29 05:07:15.467093 2026] [security2:error] [pid 1028675:tid 1028913] [client 20.196.209.81:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/fi2.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d2QAAAGc"] [Sat Aug 29 05:07:15.489580 2026] [security2:error] [pid 1028675:tid 1028854] [client 68.155.159.216:24483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d3AAAACw"] [Sat Aug 29 05:07:15.496180 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.104.104.62:10458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/6y7t.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d3QAAABk"] [Sat Aug 29 05:07:15.520709 2026] [security2:error] [pid 1028675:tid 1028773] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/test.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d4gAAG1w"] [Sat Aug 29 05:07:15.539963 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.48.250.41:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/403.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d5AAAADw"] [Sat Aug 29 05:07:15.558972 2026] [security2:error] [pid 1028675:tid 1028872] [client 68.155.159.216:60721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d5gAAAD4"] [Sat Aug 29 05:07:15.566601 2026] [security2:error] [pid 1028675:tid 1028885] [client 168.107.94.195:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d6QAAAEs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:15.575307 2026] [security2:error] [pid 1028675:tid 1028936] [client 158.158.54.35:28357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/admin.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d6gAAAH4"] [Sat Aug 29 05:07:15.610883 2026] [security2:error] [pid 1028675:tid 1028873] [client 20.203.141.11:9001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/ws.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d7gAAAD8"] [Sat Aug 29 05:07:15.614917 2026] [security2:error] [pid 1028675:tid 1028906] [client 20.104.68.135:3709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d8AAAAGA"] [Sat Aug 29 05:07:15.631911 2026] [security2:error] [pid 1028675:tid 1028892] [client 158.23.147.79:30485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d8QAAAFI"] [Sat Aug 29 05:07:15.633500 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.104.62:10482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/0xs.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQVwAABew"] [Sat Aug 29 05:07:15.640226 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.48.160.90:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/ke.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQWAAABgc"] [Sat Aug 29 05:07:15.643191 2026] [security2:error] [pid 1028675:tid 1028877] [client 20.104.104.62:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/pwp-.myluv.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d9AAAAEM"] [Sat Aug 29 05:07:15.658603 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.197.61.180:13854] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "likesareus.com"] [uri "/1.php7"] [unique_id "apK9YzAh5Y1i2tUxg4EQWgAABcs"] [Sat Aug 29 05:07:15.658708 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.197.61.180:13854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/1.php7"] [unique_id "apK9YzAh5Y1i2tUxg4EQWgAABcs"] [Sat Aug 29 05:07:15.668255 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.48.250.41:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/cytyr.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d9wAAAAs"] [Sat Aug 29 05:07:15.670337 2026] [security2:error] [pid 1018003:tid 1018277] [client 185.104.184.230:55228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK9YzAh5Y1i2tUxg4EQXAAABjU"] [Sat Aug 29 05:07:15.673374 2026] [security2:error] [pid 1028675:tid 1028920] [client 40.83.93.50:21219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/cache/min/1/wp-content/admin.php"] [unique_id "apK9Y9dHPfW2QFvhmL7d-AAAAG4"] [Sat Aug 29 05:07:15.711690 2026] [security2:error] [pid 1018003:tid 1018200] [client 4.205.62.107:21913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/nlnub.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQXgAABek"] [Sat Aug 29 05:07:15.756109 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.158.54.35:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-content/packed.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQXwAABco"] [Sat Aug 29 05:07:15.766583 2026] [security2:error] [pid 1018003:tid 1018191] [client 197.219.150.206:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQYAAABeA"] [Sat Aug 29 05:07:15.766692 2026] [security2:error] [pid 1018003:tid 1018191] [client 197.219.150.206:61968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQYAAABeA"] [Sat Aug 29 05:07:15.769582 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.104.62:10842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/waf.php"] [unique_id "apK9Y9dHPfW2QFvhmL7eCAAAAHo"] [Sat Aug 29 05:07:15.810386 2026] [security2:error] [pid 1028675:tid 1028928] [client 20.104.68.135:19291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/pomo/wp-conflg.php"] [unique_id "apK9Y9dHPfW2QFvhmL7eCgAAAHY"] [Sat Aug 29 05:07:15.823083 2026] [security2:error] [pid 1028675:tid 1028915] [client 20.104.104.62:42637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/motu.php"] [unique_id "apK9Y9dHPfW2QFvhmL7eDgAAAGk"] [Sat Aug 29 05:07:15.836179 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.48.160.90:51649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/tf.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQZAAABiY"] [Sat Aug 29 05:07:15.842644 2026] [security2:error] [pid 1018003:tid 1018202] [client 57.141.14.21:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK9YzAh5Y1i2tUxg4EQZQAABes"] [Sat Aug 29 05:07:15.848727 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.48.250.41:62517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/galer.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQZwAABdk"] [Sat Aug 29 05:07:15.888386 2026] [autoindex:error] [pid 1018003:tid 1018225] [client 192.145.125.70:43636] AH01276: Cannot serve directory /home3/zbvtvpmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:07:15.895555 2026] [security2:error] [pid 1028675:tid 1028908] [client 20.104.104.62:10483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/bnnof6.php"] [unique_id "apK9Y9dHPfW2QFvhmL7eHgAAAGI"] [Sat Aug 29 05:07:15.925887 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.196.209.81:15202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/1p.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQaQAABd0"] [Sat Aug 29 05:07:15.927063 2026] [security2:error] [pid 1028675:tid 1028862] [client 68.155.159.216:33732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9Y9dHPfW2QFvhmL7eJwAAADQ"] [Sat Aug 29 05:07:15.950772 2026] [security2:error] [pid 1018003:tid 1018266] [client 149.34.210.141:40283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQawAABio"] [Sat Aug 29 05:07:15.950877 2026] [security2:error] [pid 1018003:tid 1018266] [client 149.34.210.141:40283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQawAABio"] [Sat Aug 29 05:07:15.951348 2026] [security2:error] [pid 1018003:tid 1018271] [client 168.107.94.195:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQbAAABi8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:15.965849 2026] [security2:error] [pid 1018003:tid 1018161] [client 158.23.147.79:32745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQbQAABcI"] [Sat Aug 29 05:07:15.970938 2026] [security2:error] [pid 1018003:tid 1018258] [client 40.83.93.50:7547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/disagreed.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQbwAABiI"] [Sat Aug 29 05:07:15.980228 2026] [security2:error] [pid 1028675:tid 1028876] [client 68.155.159.216:65140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9Y9dHPfW2QFvhmL7eLgAAAEI"] [Sat Aug 29 05:07:15.983861 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.48.250.41:60774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/baixy.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQcAAABcA"] [Sat Aug 29 05:07:15.989418 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:1968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/NewFile.php/"] [unique_id "apK9YzAh5Y1i2tUxg4EQcQAABdc"] [Sat Aug 29 05:07:15.997908 2026] [security2:error] [pid 1018003:tid 1018194] [client 185.104.184.230:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQcgAABeM"] [Sat Aug 29 05:07:15.999593 2026] [security2:error] [pid 1018003:tid 1018166] [client 20.48.160.90:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/px.php"] [unique_id "apK9YzAh5Y1i2tUxg4EQcwAABcc"] [Sat Aug 29 05:07:16.012845 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.104.104.62:20840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wihp1.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eNQAAAAg"] [Sat Aug 29 05:07:16.024855 2026] [core:error] [pid 1028675:tid 1028895] [client 158.158.54.35:20600] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.024870 2026] [core:error] [pid 1028675:tid 1028895] [client 158.158.54.35:20600] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.025757 2026] [security2:error] [pid 1028675:tid 1028830] [client 4.205.62.107:26655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/loxi-o.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eOgAAABQ"] [Sat Aug 29 05:07:16.028774 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.104.62:10837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/ah24.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQdQAABh8"] [Sat Aug 29 05:07:16.034172 2026] [security2:error] [pid 1018003:tid 1018275] [client 192.145.125.70:43636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZDAh5Y1i2tUxg4EQdgAABjM"] [Sat Aug 29 05:07:16.051293 2026] [security2:error] [pid 1028675:tid 1028863] [client 158.23.147.79:35815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/classwithtostring.php"] [unique_id "apK9ZNdHPfW2QFvhmL7ePgAAADU"] [Sat Aug 29 05:07:16.073847 2026] [security2:error] [pid 1018003:tid 1018172] [client 4.205.62.107:22055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/fun.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQdwAABc0"] [Sat Aug 29 05:07:16.083812 2026] [security2:error] [pid 1018003:tid 1018169] [client 4.205.62.107:58447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/sadd.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQeAAABco"] [Sat Aug 29 05:07:16.087984 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.104.104.62:36950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/wefile.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eQgAAAG0"] [Sat Aug 29 05:07:16.093754 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.104.68.135:3695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-includes/rest-api/fields/index.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQeQAABeA"] [Sat Aug 29 05:07:16.110014 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.151.200.44:47325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/uuu.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eRQAAAD4"] [Sat Aug 29 05:07:16.120489 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.250.41:60708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ava.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQegAABgM"] [Sat Aug 29 05:07:16.122135 2026] [security2:error] [pid 1028675:tid 1028885] [client 68.155.159.216:49214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/xmlrpc.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eRgAAAEs"] [Sat Aug 29 05:07:16.131159 2026] [security2:error] [pid 1028675:tid 1028936] [client 158.23.147.79:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eRwAAAH4"] [Sat Aug 29 05:07:16.137223 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.48.160.90:51677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/jg.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eSQAAAF0"] [Sat Aug 29 05:07:16.149770 2026] [security2:error] [pid 1028675:tid 1028905] [client 40.83.93.50:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eTAAAAF8"] [Sat Aug 29 05:07:16.153713 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.203.141.11:11223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-themes.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQewAABdw"] [Sat Aug 29 05:07:16.176593 2026] [security2:error] [pid 1018003:tid 1018219] [client 34.81.157.26:40434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/root/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQfQAABfw"] [Sat Aug 29 05:07:16.177104 2026] [security2:error] [pid 1028675:tid 1028715] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ffcbranson.com"] [uri "/wp-config.php.bak"] [unique_id "apK9ZNdHPfW2QFvhmL7eUwAAXCI"] [Sat Aug 29 05:07:16.177342 2026] [security2:error] [pid 1028675:tid 1028709] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/wp-config.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eUgAAXBw"] [Sat Aug 29 05:07:16.177659 2026] [security2:error] [pid 1018003:tid 1018190] [client 34.81.157.26:40422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQfgAABd8"] [Sat Aug 29 05:07:16.178669 2026] [security2:error] [pid 1018003:tid 1018152] [client 34.81.157.26:40462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/app/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQfwAABbk"] [Sat Aug 29 05:07:16.178872 2026] [security2:error] [pid 1018003:tid 1018256] [client 34.81.157.26:40490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apK9ZDAh5Y1i2tUxg4EQgQAABiA"] [Sat Aug 29 05:07:16.178912 2026] [security2:error] [pid 1018003:tid 1018183] [client 34.81.157.26:40480] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/proc/self/environ"] [unique_id "apK9ZDAh5Y1i2tUxg4EQgAAABdg"] [Sat Aug 29 05:07:16.182293 2026] [security2:error] [pid 1028675:tid 1028913] [client 34.81.157.26:40512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "apK9ZNdHPfW2QFvhmL7eVQAAAGc"] [Sat Aug 29 05:07:16.182467 2026] [security2:error] [pid 1018003:tid 1018179] [client 34.81.157.26:40498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQhQAABdQ"] [Sat Aug 29 05:07:16.182488 2026] [core:error] [pid 1018003:tid 1018177] [client 34.81.157.26:40518] AH10244: invalid URI path (/@fs/../../.env?raw??) [Sat Aug 29 05:07:16.182738 2026] [security2:error] [pid 1028675:tid 1028706] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ffcbranson.com"] [uri "/wp-config.php.new"] [unique_id "apK9ZNdHPfW2QFvhmL7eVwAAXBk"] [Sat Aug 29 05:07:16.183232 2026] [security2:error] [pid 1028675:tid 1028850] [client 68.155.159.216:65144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/NewFile.php/"] [unique_id "apK9ZNdHPfW2QFvhmL7eWQAAACg"] [Sat Aug 29 05:07:16.186402 2026] [security2:error] [pid 1018003:tid 1018195] [client 34.81.157.26:40486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQigAABeQ"] [Sat Aug 29 05:07:16.186976 2026] [security2:error] [pid 1018003:tid 1018216] [client 34.81.157.26:40450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/src/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQjAAABfk"] [Sat Aug 29 05:07:16.187885 2026] [security2:error] [pid 1028675:tid 1028891] [client 20.104.104.62:10565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/ztv.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eXwAAAFE"] [Sat Aug 29 05:07:16.190017 2026] [security2:error] [pid 1018003:tid 1018252] [client 34.81.157.26:40588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/root/.aws/credentials.backup"] [unique_id "apK9ZDAh5Y1i2tUxg4EQkAAABhw"] [Sat Aug 29 05:07:16.192976 2026] [security2:error] [pid 1028675:tid 1028820] [client 34.81.157.26:40614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/root/.aws/credentials.bak"] [unique_id "apK9ZNdHPfW2QFvhmL7eYwAAAAo"] [Sat Aug 29 05:07:16.194843 2026] [security2:error] [pid 1018003:tid 1018277] [client 34.81.157.26:40650] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/home/ubuntu/.aws/config"] [unique_id "apK9ZDAh5Y1i2tUxg4EQmAAABjU"] [Sat Aug 29 05:07:16.199188 2026] [core:error] [pid 1028675:tid 1028843] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.199204 2026] [core:error] [pid 1028675:tid 1028843] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.208869 2026] [core:error] [pid 1028675:tid 1028928] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.208883 2026] [core:error] [pid 1028675:tid 1028928] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.210957 2026] [security2:error] [pid 1028675:tid 1028883] [client 158.158.54.35:22003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-admin/js/index.php"] [unique_id "apK9ZNdHPfW2QFvhmL7edwAAAEk"] [Sat Aug 29 05:07:16.213878 2026] [core:error] [pid 1028675:tid 1028836] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.213894 2026] [core:error] [pid 1028675:tid 1028836] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.215559 2026] [core:error] [pid 1018003:tid 1018159] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.215573 2026] [core:error] [pid 1018003:tid 1018159] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.216648 2026] [core:error] [pid 1028675:tid 1028855] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.216665 2026] [core:error] [pid 1028675:tid 1028855] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.216685 2026] [core:error] [pid 1028675:tid 1028882] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.216691 2026] [core:error] [pid 1028675:tid 1028882] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.216967 2026] [core:error] [pid 1028675:tid 1028833] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.216979 2026] [core:error] [pid 1028675:tid 1028833] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.218112 2026] [core:error] [pid 1028675:tid 1028916] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.218125 2026] [core:error] [pid 1028675:tid 1028916] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.218495 2026] [security2:error] [pid 1028675:tid 1028710] [remote 93.123.109.228:51634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ffcbranson.com"] [uri "/wp-config.php.old"] [unique_id "apK9ZNdHPfW2QFvhmL7efQAAFR0"] [Sat Aug 29 05:07:16.221883 2026] [core:error] [pid 1028675:tid 1028857] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.221936 2026] [core:error] [pid 1028675:tid 1028867] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.222095 2026] [core:error] [pid 1028675:tid 1028857] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.222110 2026] [core:error] [pid 1028675:tid 1028867] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.222826 2026] [core:error] [pid 1028675:tid 1028925] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.222842 2026] [core:error] [pid 1028675:tid 1028925] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.223339 2026] [core:error] [pid 1018003:tid 1018213] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.223349 2026] [core:error] [pid 1018003:tid 1018213] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.223617 2026] [core:error] [pid 1028675:tid 1028832] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.223629 2026] [core:error] [pid 1028675:tid 1028832] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.223835 2026] [core:error] [pid 1028675:tid 1028877] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.223843 2026] [core:error] [pid 1028675:tid 1028877] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.223941 2026] [security2:error] [pid 1028675:tid 1028877] [client 34.81.157.26:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "apK9ZNdHPfW2QFvhmL7egQAAAEM"] [Sat Aug 29 05:07:16.226507 2026] [security2:error] [pid 1028675:tid 1028888] [client 34.81.157.26:40634] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/home/node/.aws/credentials"] [unique_id "apK9ZNdHPfW2QFvhmL7eYgAAAE4"] [Sat Aug 29 05:07:16.227044 2026] [core:error] [pid 1018003:tid 1018234] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.227062 2026] [core:error] [pid 1018003:tid 1018234] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.227278 2026] [core:error] [pid 1028675:tid 1028815] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.227280 2026] [core:error] [pid 1028675:tid 1028908] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.227292 2026] [core:error] [pid 1028675:tid 1028815] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.227297 2026] [core:error] [pid 1028675:tid 1028908] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.227786 2026] [core:error] [pid 1028675:tid 1028881] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.227801 2026] [core:error] [pid 1028675:tid 1028881] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.228276 2026] [core:error] [pid 1028675:tid 1028884] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.228287 2026] [core:error] [pid 1028675:tid 1028884] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.230171 2026] [core:error] [pid 1028675:tid 1028811] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.230183 2026] [core:error] [pid 1028675:tid 1028811] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.233495 2026] [core:error] [pid 1028675:tid 1028931] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.233508 2026] [core:error] [pid 1028675:tid 1028931] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.281797 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.48.160.90:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/yj.php"] [unique_id "apK9ZNdHPfW2QFvhmL7ekwAAACg"] [Sat Aug 29 05:07:16.290202 2026] [security2:error] [pid 1018003:tid 1018172] [client 68.155.159.216:30716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQoAAABc0"] [Sat Aug 29 05:07:16.304964 2026] [core:error] [pid 1028675:tid 1028845] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.304982 2026] [core:error] [pid 1028675:tid 1028845] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:16.326330 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.48.250.41:62474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/gdn.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQoQAABcQ"] [Sat Aug 29 05:07:16.328215 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.196.209.81:15184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/Njima.php"] [unique_id "apK9ZNdHPfW2QFvhmL7elwAAAAQ"] [Sat Aug 29 05:07:16.330100 2026] [security2:error] [pid 1028675:tid 1028883] [client 168.107.94.195:54418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ZNdHPfW2QFvhmL7emAAAAEk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:16.338475 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.104.104.62:10668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/kure.php"] [unique_id "apK9ZNdHPfW2QFvhmL7emQAAACY"] [Sat Aug 29 05:07:16.338860 2026] [security2:error] [pid 1028675:tid 1028825] [client 68.155.159.216:33783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apK9ZNdHPfW2QFvhmL7emwAAAA8"] [Sat Aug 29 05:07:16.352902 2026] [security2:error] [pid 1028675:tid 1028833] [client 158.23.147.79:25521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/plugins.php"] [unique_id "apK9ZNdHPfW2QFvhmL7enwAAABc"] [Sat Aug 29 05:07:16.380413 2026] [security2:error] [pid 1028675:tid 1028926] [client 20.197.61.180:7737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/ds.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eoQAAAHQ"] [Sat Aug 29 05:07:16.380413 2026] [security2:error] [pid 1018003:tid 1018166] [client 158.23.147.79:17476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/cong.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQpAAABcc"] [Sat Aug 29 05:07:16.396055 2026] [security2:error] [pid 1028675:tid 1028924] [client 158.23.147.79:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/ws.php"] [unique_id "apK9ZNdHPfW2QFvhmL7epAAAAHI"] [Sat Aug 29 05:07:16.422314 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.48.160.90:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/zi.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eqAAAAGQ"] [Sat Aug 29 05:07:16.430617 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.104.68.135:3677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-links-opml.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eqQAAADU"] [Sat Aug 29 05:07:16.432785 2026] [security2:error] [pid 1018003:tid 1018221] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQpgAABf4"] [Sat Aug 29 05:07:16.469478 2026] [security2:error] [pid 1028675:tid 1028830] [client 20.48.250.41:62505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/f2.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eqwAAABQ"] [Sat Aug 29 05:07:16.471353 2026] [security2:error] [pid 1028675:tid 1028875] [client 158.158.54.35:20347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/lock360.php"] [unique_id "apK9ZNdHPfW2QFvhmL7erAAAAEE"] [Sat Aug 29 05:07:16.471803 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.104.104.62:44591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/cafe.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQqAAABew"] [Sat Aug 29 05:07:16.472656 2026] [security2:error] [pid 1028675:tid 1028819] [client 40.83.93.50:7517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/class_api.php"] [unique_id "apK9ZNdHPfW2QFvhmL7erQAAAAk"] [Sat Aug 29 05:07:16.479191 2026] [security2:error] [pid 1028675:tid 1028930] [client 93.123.109.228:44884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9ZNdHPfW2QFvhmL7esAAAAHg"] [Sat Aug 29 05:07:16.481191 2026] [security2:error] [pid 1018003:tid 1018192] [client 68.155.159.216:12266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQqQAABeE"] [Sat Aug 29 05:07:16.491958 2026] [security2:error] [pid 1018003:tid 1018164] [client 4.205.62.107:56059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/hiquido.com/index.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQqwAABcU"] [Sat Aug 29 05:07:16.492893 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.104.62:52061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/EM.php"] [unique_id "apK9ZNdHPfW2QFvhmL7etQAAACk"] [Sat Aug 29 05:07:16.512344 2026] [security2:error] [pid 1018003:tid 1018183] [client 68.155.159.216:52750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/goat.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQrAAABdg"] [Sat Aug 29 05:07:16.563982 2026] [security2:error] [pid 1028675:tid 1028920] [client 158.23.147.79:48162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/images/index.php"] [unique_id "apK9ZNdHPfW2QFvhmL7euwAAAG4"] [Sat Aug 29 05:07:16.565975 2026] [security2:error] [pid 1028675:tid 1028903] [client 93.123.109.228:44944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9ZNdHPfW2QFvhmL7evAAAAF0"] [Sat Aug 29 05:07:16.569998 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.48.160.90:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/ue.php"] [unique_id "apK9ZNdHPfW2QFvhmL7evQAAAHU"] [Sat Aug 29 05:07:16.591353 2026] [security2:error] [pid 1028675:tid 1028889] [client 4.205.62.107:8977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/mamzi.php"] [unique_id "apK9ZNdHPfW2QFvhmL7evwAAAE8"] [Sat Aug 29 05:07:16.627424 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.48.250.41:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/grsiuk.php"] [unique_id "apK9ZNdHPfW2QFvhmL7exAAAACs"] [Sat Aug 29 05:07:16.627664 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.104.68.135:11674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/wp-signup.php"] [unique_id "apK9ZNdHPfW2QFvhmL7exQAAAGg"] [Sat Aug 29 05:07:16.629124 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.104.104.62:10492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/eval.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQrgAABjM"] [Sat Aug 29 05:07:16.630873 2026] [security2:error] [pid 1018003:tid 1018271] [client 93.123.109.228:44950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQrwAABi8"] [Sat Aug 29 05:07:16.633384 2026] [security2:error] [pid 1028675:tid 1028830] [client 20.203.141.11:23121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-trackback.php"] [unique_id "apK9ZNdHPfW2QFvhmL7exwAAABQ"] [Sat Aug 29 05:07:16.647305 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.104.104.62:42632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/ca4.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQsAAABhA"] [Sat Aug 29 05:07:16.648402 2026] [security2:error] [pid 1018003:tid 1018101] [remote 136.108.15.119:30694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tonewarpstudio-com-br.tonewarp.com"] [uri "/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQsQAF_1A"] [Sat Aug 29 05:07:16.650024 2026] [security2:error] [pid 1028675:tid 1028919] [client 40.83.93.50:13694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/config.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eygAAAG0"] [Sat Aug 29 05:07:16.650461 2026] [security2:error] [pid 1018003:tid 1018200] [client 93.123.109.228:44904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9ZDAh5Y1i2tUxg4EQsgAABek"] [Sat Aug 29 05:07:16.657097 2026] [security2:error] [pid 1028675:tid 1028897] [client 192.145.125.70:43644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.125.145.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbv.tvp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eywAAAFc"] [Sat Aug 29 05:07:16.658884 2026] [security2:error] [pid 1028675:tid 1028902] [client 61.9.8.223:4029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eyQAAAFw"] [Sat Aug 29 05:07:16.658977 2026] [security2:error] [pid 1028675:tid 1028902] [client 61.9.8.223:4029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9ZNdHPfW2QFvhmL7eyQAAAFw"] [Sat Aug 29 05:07:16.659622 2026] [security2:error] [pid 1028675:tid 1028891] [client 93.123.109.228:44874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9ZNdHPfW2QFvhmL7ezAAAAFE"] [Sat Aug 29 05:07:16.668657 2026] [security2:error] [pid 1028675:tid 1028895] [client 20.104.104.62:20627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-blog.php"] [unique_id "apK9ZNdHPfW2QFvhmL7ezQAAAFU"] [Sat Aug 29 05:07:16.676204 2026] [security2:error] [pid 1018003:tid 1018170] [client 158.23.147.79:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQswAABcs"] [Sat Aug 29 05:07:16.691934 2026] [security2:error] [pid 1028675:tid 1028860] [client 185.104.184.230:55252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZNdHPfW2QFvhmL7e0AAAADI"] [Sat Aug 29 05:07:16.695084 2026] [security2:error] [pid 1028675:tid 1028849] [client 158.158.54.35:21953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/core.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e0gAAACc"] [Sat Aug 29 05:07:16.709855 2026] [security2:error] [pid 1028675:tid 1028825] [client 168.107.94.195:54861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e1QAAAA8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:16.716031 2026] [security2:error] [pid 1028675:tid 1028836] [client 93.123.109.228:44944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9ZNdHPfW2QFvhmL7e1wAAABo"] [Sat Aug 29 05:07:16.718033 2026] [security2:error] [pid 1028675:tid 1028882] [client 93.123.109.228:44930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9ZNdHPfW2QFvhmL7e2AAAAEg"] [Sat Aug 29 05:07:16.722849 2026] [security2:error] [pid 1028675:tid 1028855] [client 20.48.160.90:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/nv.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e2QAAAC0"] [Sat Aug 29 05:07:16.725451 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.196.209.81:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/configs.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQtQAABdA"] [Sat Aug 29 05:07:16.727576 2026] [security2:error] [pid 1018003:tid 1018244] [client 68.155.159.216:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/ans.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQtgAABhQ"] [Sat Aug 29 05:07:16.751712 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.23.147.79:30568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQuQAABdw"] [Sat Aug 29 05:07:16.757570 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.104.104.62:10652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/sao.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e3wAAACU"] [Sat Aug 29 05:07:16.767749 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.151.200.44:47408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/private.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e4AAAAFI"] [Sat Aug 29 05:07:16.816295 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.104.104.62:41793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/x0x.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e5gAAAHI"] [Sat Aug 29 05:07:16.819179 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.48.250.41:62571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wp-scr1pts.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e6AAAAC4"] [Sat Aug 29 05:07:16.822415 2026] [security2:error] [pid 1018003:tid 1018185] [client 146.70.194.254:44246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZDAh5Y1i2tUxg4EQvgAABdo"] [Sat Aug 29 05:07:16.865789 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.68.135:11695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/xmlrpc.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQvAAABiU"] [Sat Aug 29 05:07:16.866455 2026] [security2:error] [pid 1018003:tid 1018159] [client 4.205.62.107:22282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/mga.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQvwAABcA"] [Sat Aug 29 05:07:16.867929 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.48.160.90:49483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/jw.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQwAAABdI"] [Sat Aug 29 05:07:16.870210 2026] [security2:error] [pid 1028675:tid 1028910] [client 93.123.109.228:44930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9ZNdHPfW2QFvhmL7e7AAAAGQ"] [Sat Aug 29 05:07:16.871919 2026] [security2:error] [pid 1028675:tid 1028863] [client 93.123.109.228:44944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/.env.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e7QAAADU"] [Sat Aug 29 05:07:16.888467 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.104.104.62:10878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/uuu.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e7wAAABk"] [Sat Aug 29 05:07:16.926407 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.49.130:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/static.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQwgAABik"] [Sat Aug 29 05:07:16.927060 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.158.54.35:14921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-conflg.php"] [unique_id "apK9ZDAh5Y1i2tUxg4EQwwAABio"] [Sat Aug 29 05:07:16.959645 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.48.250.41:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/num.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e9wAAADg"] [Sat Aug 29 05:07:16.960806 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.104.104.62:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.beraluzgroup.com"] [uri "/fesa.php"] [unique_id "apK9ZNdHPfW2QFvhmL7e-QAAABI"] [Sat Aug 29 05:07:16.967414 2026] [security2:error] [pid 1018003:tid 1018213] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9ZDAh5Y1i2tUxg4EQxAAABfY"] [Sat Aug 29 05:07:16.976201 2026] [security2:error] [pid 1018003:tid 1018270] [client 93.123.109.228:44904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9ZDAh5Y1i2tUxg4EQxwAABi4"] [Sat Aug 29 05:07:16.998690 2026] [security2:error] [pid 1018003:tid 1018234] [client 185.104.184.230:55266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZDAh5Y1i2tUxg4EQygAABgo"] [Sat Aug 29 05:07:17.002985 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.104.104.62:64717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-utchershill.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQywAABi8"] [Sat Aug 29 05:07:17.004197 2026] [core:error] [pid 1028675:tid 1028870] [client 5.255.231.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:17.004213 2026] [core:error] [pid 1028675:tid 1028870] [client 5.255.231.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:17.021007 2026] [security2:error] [pid 1028675:tid 1028936] [client 20.48.160.90:51618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/or.php"] [unique_id "apK9ZddHPfW2QFvhmL7fAgAAAH4"] [Sat Aug 29 05:07:17.024828 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.104.104.62:10849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/private.php"] [unique_id "apK9ZddHPfW2QFvhmL7fAwAAAF0"] [Sat Aug 29 05:07:17.060817 2026] [security2:error] [pid 1018003:tid 1018224] [client 68.155.159.216:33767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-login.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQzAAABgE"] [Sat Aug 29 05:07:17.062398 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.104.68.135:11711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.68.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lisakayguitar.com"] [uri "/yas.php"] [unique_id "apK9ZddHPfW2QFvhmL7fBgAAAB4"] [Sat Aug 29 05:07:17.062464 2026] [security2:error] [pid 1018003:tid 1018182] [client 40.83.93.50:7455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/aksinet.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQzQAABdc"] [Sat Aug 29 05:07:17.071990 2026] [security2:error] [pid 1018003:tid 1018222] [client 158.23.147.79:32664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQzgAABf8"] [Sat Aug 29 05:07:17.086559 2026] [security2:error] [pid 1018003:tid 1018230] [client 68.155.159.216:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQzwAABgY"] [Sat Aug 29 05:07:17.089686 2026] [security2:error] [pid 1028675:tid 1028899] [client 168.107.94.195:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ZddHPfW2QFvhmL7fDQAAAFk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:17.111146 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.48.250.41:62532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/a4.php"] [unique_id "apK9ZddHPfW2QFvhmL7fEQAAAG0"] [Sat Aug 29 05:07:17.117225 2026] [security2:error] [pid 1028675:tid 1028888] [client 40.83.93.50:20809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/cong.php"] [unique_id "apK9ZddHPfW2QFvhmL7fEwAAAE4"] [Sat Aug 29 05:07:17.130548 2026] [security2:error] [pid 1028675:tid 1028917] [client 93.123.109.228:44830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9ZddHPfW2QFvhmL7fFQAAAGs"] [Sat Aug 29 05:07:17.137974 2026] [security2:error] [pid 1018003:tid 1018273] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ0QAABjE"] [Sat Aug 29 05:07:17.150198 2026] [security2:error] [pid 1018003:tid 1018275] [client 158.158.54.35:24189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/admin/function.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ0gAABjM"] [Sat Aug 29 05:07:17.162316 2026] [security2:error] [pid 1018003:tid 1018244] [client 4.205.62.107:26659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/f35.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ1AAABhQ"] [Sat Aug 29 05:07:17.168382 2026] [security2:error] [pid 1028675:tid 1028883] [client 93.123.109.228:44806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9ZddHPfW2QFvhmL7fGwAAAEk"] [Sat Aug 29 05:07:17.176368 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.160.90:51259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/ile56.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ1QAABfU"] [Sat Aug 29 05:07:17.188342 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.23.147.79:35211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/install.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ1gAABdw"] [Sat Aug 29 05:07:17.202351 2026] [security2:error] [pid 1028675:tid 1028820] [client 20.104.104.62:10846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/lfi.php"] [unique_id "apK9ZddHPfW2QFvhmL7fHwAAAAo"] [Sat Aug 29 05:07:17.213677 2026] [security2:error] [pid 1028675:tid 1028882] [client 4.205.62.107:22448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/bb.php"] [unique_id "apK9ZddHPfW2QFvhmL7fIAAAAEg"] [Sat Aug 29 05:07:17.216237 2026] [security2:error] [pid 1018003:tid 1018240] [client 20.196.209.81:11266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/disagraeed.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ2AAABhA"] [Sat Aug 29 05:07:17.221730 2026] [security2:error] [pid 1018003:tid 1018256] [client 4.205.62.107:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/app_dev.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ2QAABiA"] [Sat Aug 29 05:07:17.227300 2026] [security2:error] [pid 1018003:tid 1018161] [client 68.155.159.216:49212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/atomlib.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ2gAABcI"] [Sat Aug 29 05:07:17.248909 2026] [security2:error] [pid 1028675:tid 1028813] [client 158.23.147.79:61608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/goat.php"] [unique_id "apK9ZddHPfW2QFvhmL7fJgAAAAM"] [Sat Aug 29 05:07:17.252067 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.104.104.62:20714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-log.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ2wAABhw"] [Sat Aug 29 05:07:17.265946 2026] [autoindex:error] [pid 1018003:tid 1018186] [client 192.145.125.70:43652] AH01276: Cannot serve directory /home3/zbvtvpmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:07:17.267985 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.48.250.41:59381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/tfm.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ3QAABdQ"] [Sat Aug 29 05:07:17.277082 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.104.49.130:51499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/worksec.php"] [unique_id "apK9ZddHPfW2QFvhmL7fKwAAAGE"] [Sat Aug 29 05:07:17.293470 2026] [security2:error] [pid 1018003:tid 1018219] [client 111.235.68.106:28209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ3wAABfw"] [Sat Aug 29 05:07:17.293613 2026] [security2:error] [pid 1018003:tid 1018219] [client 111.235.68.106:28209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ3wAABfw"] [Sat Aug 29 05:07:17.299115 2026] [security2:error] [pid 1028675:tid 1028924] [client 185.104.184.230:55282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZddHPfW2QFvhmL7fLwAAAHI"] [Sat Aug 29 05:07:17.307919 2026] [security2:error] [pid 1028675:tid 1028832] [client 20.203.141.11:5769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/222.php"] [unique_id "apK9ZddHPfW2QFvhmL7fMQAAABY"] [Sat Aug 29 05:07:17.335266 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.197.61.180:8935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/GOD.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ4gAABco"] [Sat Aug 29 05:07:17.338653 2026] [security2:error] [pid 1028675:tid 1028887] [client 158.23.184.117:4275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/update/da222.php"] [unique_id "apK9ZddHPfW2QFvhmL7fNQAAAE0"] [Sat Aug 29 05:07:17.347781 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.104.104.62:10853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/quoys.php"] [unique_id "apK9ZddHPfW2QFvhmL7fNwAAAGQ"] [Sat Aug 29 05:07:17.373297 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.158.54.35:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/123.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ4wAABc8"] [Sat Aug 29 05:07:17.382249 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.48.160.90:51227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/emmh.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ5QAABcU"] [Sat Aug 29 05:07:17.396155 2026] [security2:error] [pid 1028675:tid 1028933] [client 171.61.160.196:13018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9ZddHPfW2QFvhmL7fOwAAAHs"] [Sat Aug 29 05:07:17.396283 2026] [security2:error] [pid 1028675:tid 1028933] [client 171.61.160.196:13018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9ZddHPfW2QFvhmL7fOwAAAHs"] [Sat Aug 29 05:07:17.412178 2026] [security2:error] [pid 1018003:tid 1018238] [client 192.145.125.70:43652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ5wAABg4"] [Sat Aug 29 05:07:17.435832 2026] [core:error] [pid 1018003:tid 1018189] [client 20.104.104.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:17.435849 2026] [core:error] [pid 1018003:tid 1018189] [client 20.104.104.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:17.449673 2026] [security2:error] [pid 1018003:tid 1018196] [client 68.155.159.216:33644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/file.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ6wAABeU"] [Sat Aug 29 05:07:17.456006 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.48.250.41:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/Geforce.php"] [unique_id "apK9ZddHPfW2QFvhmL7fPwAAAEE"] [Sat Aug 29 05:07:17.463559 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.147.79:25356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ7AAABgo"] [Sat Aug 29 05:07:17.474897 2026] [security2:error] [pid 1028675:tid 1028851] [client 168.107.94.195:55862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ZddHPfW2QFvhmL7fRQAAACk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:17.475721 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.151.200.44:46629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/lfi.php"] [unique_id "apK9ZddHPfW2QFvhmL7fRgAAAAU"] [Sat Aug 29 05:07:17.485161 2026] [security2:error] [pid 1018003:tid 1018183] [client 158.23.184.117:4289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/xmr.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ7gAABdg"] [Sat Aug 29 05:07:17.487555 2026] [security2:error] [pid 1028675:tid 1028915] [client 158.23.147.79:17425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9ZddHPfW2QFvhmL7fRwAAAGk"] [Sat Aug 29 05:07:17.489041 2026] [security2:error] [pid 1028675:tid 1028842] [client 20.104.104.62:10873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/vbbn.php"] [unique_id "apK9ZddHPfW2QFvhmL7fSAAAACA"] [Sat Aug 29 05:07:17.540266 2026] [security2:error] [pid 1028675:tid 1028885] [client 158.23.147.79:30616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9ZddHPfW2QFvhmL7fUQAAAEs"] [Sat Aug 29 05:07:17.550035 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.48.160.90:51261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/em.php"] [unique_id "apK9ZddHPfW2QFvhmL7fUgAAAEY"] [Sat Aug 29 05:07:17.556564 2026] [security2:error] [pid 1018003:tid 1018195] [client 40.83.93.50:7949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/alfa-rex1.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ8AAABeQ"] [Sat Aug 29 05:07:17.588316 2026] [security2:error] [pid 1028675:tid 1028830] [client 68.155.159.216:12267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9ZddHPfW2QFvhmL7fVAAAABQ"] [Sat Aug 29 05:07:17.589993 2026] [security2:error] [pid 1028675:tid 1028837] [client 185.104.184.230:55294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZddHPfW2QFvhmL7fVQAAABs"] [Sat Aug 29 05:07:17.593630 2026] [security2:error] [pid 1018003:tid 1018184] [client 40.83.93.50:22832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/content.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ8gAABdk"] [Sat Aug 29 05:07:17.612114 2026] [security2:error] [pid 1028675:tid 1028822] [client 20.196.209.81:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/add_actualites.php"] [unique_id "apK9ZddHPfW2QFvhmL7fVwAAAAw"] [Sat Aug 29 05:07:17.625899 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.104.62:10681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/rfi.php"] [unique_id "apK9ZddHPfW2QFvhmL7fWQAAAFw"] [Sat Aug 29 05:07:17.633111 2026] [security2:error] [pid 1028675:tid 1028899] [client 158.23.184.117:4269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9ZddHPfW2QFvhmL7fXAAAAFk"] [Sat Aug 29 05:07:17.634435 2026] [security2:error] [pid 1028675:tid 1028908] [client 158.158.54.35:23341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/admin/index.php"] [unique_id "apK9ZddHPfW2QFvhmL7fXQAAAGI"] [Sat Aug 29 05:07:17.636738 2026] [security2:error] [pid 1018003:tid 1018207] [client 68.155.159.216:52776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ8wAABfA"] [Sat Aug 29 05:07:17.642605 2026] [security2:error] [pid 1028675:tid 1028928] [client 4.205.62.107:53133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ws79.php"] [unique_id "apK9ZddHPfW2QFvhmL7fXwAAAHY"] [Sat Aug 29 05:07:17.665790 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.48.250.41:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/click.php"] [unique_id "apK9ZddHPfW2QFvhmL7fYgAAAD4"] [Sat Aug 29 05:07:17.686173 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.48.160.90:51303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/dvve.php"] [unique_id "apK9ZddHPfW2QFvhmL7fawAAAFI"] [Sat Aug 29 05:07:17.694895 2026] [security2:error] [pid 1028675:tid 1028878] [client 158.23.147.79:48251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/index.php"] [unique_id "apK9ZddHPfW2QFvhmL7fbQAAAEQ"] [Sat Aug 29 05:07:17.728303 2026] [security2:error] [pid 1028675:tid 1028836] [client 103.162.125.59:56288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9ZddHPfW2QFvhmL7fcgAAABo"] [Sat Aug 29 05:07:17.728457 2026] [security2:error] [pid 1028675:tid 1028836] [client 103.162.125.59:56288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9ZddHPfW2QFvhmL7fcgAAABo"] [Sat Aug 29 05:07:17.742486 2026] [security2:error] [pid 1018003:tid 1018217] [client 93.123.109.228:44950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/.wp-config.php.swp"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ-AAABfo"] [Sat Aug 29 05:07:17.761561 2026] [security2:error] [pid 1028675:tid 1028849] [client 68.155.159.216:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9ZddHPfW2QFvhmL7fdQAAACc"] [Sat Aug 29 05:07:17.762816 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.104.104.62:10861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/tajj.php"] [unique_id "apK9ZddHPfW2QFvhmL7fdgAAAE0"] [Sat Aug 29 05:07:17.777886 2026] [security2:error] [pid 1028675:tid 1028924] [client 158.23.184.117:4225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/wp-act.php"] [unique_id "apK9ZddHPfW2QFvhmL7feAAAAHI"] [Sat Aug 29 05:07:17.780560 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.104.49.130:48545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/jp.php"] [unique_id "apK9ZddHPfW2QFvhmL7fegAAADA"] [Sat Aug 29 05:07:17.786325 2026] [security2:error] [pid 1028675:tid 1028873] [client 20.203.141.11:11258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/x.php"] [unique_id "apK9ZddHPfW2QFvhmL7fewAAAD8"] [Sat Aug 29 05:07:17.803277 2026] [security2:error] [pid 1018003:tid 1018185] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ-gAABdo"] [Sat Aug 29 05:07:17.803303 2026] [security2:error] [pid 1028675:tid 1028933] [client 158.23.147.79:26469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9ZddHPfW2QFvhmL7ffwAAAHs"] [Sat Aug 29 05:07:17.815302 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.158.54.35:16897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/yanz.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EQ_gAABcQ"] [Sat Aug 29 05:07:17.824221 2026] [security2:error] [pid 1028675:tid 1028867] [client 93.123.109.228:44874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9ZddHPfW2QFvhmL7fhAAAADk"] [Sat Aug 29 05:07:17.824274 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.48.160.90:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/doo.php"] [unique_id "apK9ZddHPfW2QFvhmL7fhQAAADI"] [Sat Aug 29 05:07:17.855478 2026] [security2:error] [pid 1028675:tid 1028826] [client 158.23.147.79:30567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9ZddHPfW2QFvhmL7fkAAAABA"] [Sat Aug 29 05:07:17.858393 2026] [security2:error] [pid 1018003:tid 1018177] [client 168.107.94.195:56341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ZTAh5Y1i2tUxg4ERAAAABdI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:17.891530 2026] [security2:error] [pid 1028675:tid 1028858] [client 185.104.184.230:55300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZddHPfW2QFvhmL7fpQAAADA"] [Sat Aug 29 05:07:17.893575 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.104.104.62:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/grsiuk.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EREAAABcE"] [Sat Aug 29 05:07:17.894217 2026] [security2:error] [pid 1028675:tid 1028858] [client 93.123.109.228:45012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9ZddHPfW2QFvhmL7fpgAAADA"] [Sat Aug 29 05:07:17.894605 2026] [security2:error] [pid 1028675:tid 1028857] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9ZddHPfW2QFvhmL7fqAAAAC8"] [Sat Aug 29 05:07:17.894848 2026] [security2:error] [pid 1028675:tid 1028929] [client 93.123.109.228:44962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9ZddHPfW2QFvhmL7fqQAAAHc"] [Sat Aug 29 05:07:17.908596 2026] [security2:error] [pid 1028675:tid 1028867] [client 93.123.109.228:44806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9ZddHPfW2QFvhmL7fsQAAADk"] [Sat Aug 29 05:07:17.919008 2026] [security2:error] [pid 1028675:tid 1028828] [client 93.123.109.228:44940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9ZddHPfW2QFvhmL7ftgAAABI"] [Sat Aug 29 05:07:17.924640 2026] [security2:error] [pid 1028675:tid 1028820] [client 158.23.184.117:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/fff.php"] [unique_id "apK9ZddHPfW2QFvhmL7ftwAAAAo"] [Sat Aug 29 05:07:17.925169 2026] [security2:error] [pid 1018003:tid 1018230] [client 158.173.241.137:41129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.241.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.com"] [uri "/suggest.php"] [unique_id "apK9ZTAh5Y1i2tUxg4EREwAABgY"], referer: https://mikelait.com/suggest.php?page=Our+Family+Genealogy+Pages [Sat Aug 29 05:07:17.947442 2026] [security2:error] [pid 1028675:tid 1028902] [client 93.123.109.228:44946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9ZddHPfW2QFvhmL7fuwAAAFw"] [Sat Aug 29 05:07:17.952748 2026] [security2:error] [pid 1018003:tid 1018159] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9ZTAh5Y1i2tUxg4ERGAAABcA"] [Sat Aug 29 05:07:17.960852 2026] [security2:error] [pid 1018003:tid 1018219] [client 4.205.62.107:9198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/admin.php"] [unique_id "apK9ZTAh5Y1i2tUxg4ERGwAABfw"] [Sat Aug 29 05:07:17.960868 2026] [security2:error] [pid 1018003:tid 1018265] [client 68.155.159.216:51569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/worksec.php"] [unique_id "apK9ZTAh5Y1i2tUxg4ERHAAABik"] [Sat Aug 29 05:07:17.962775 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.48.160.90:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/adminer-4.6.6.php"] [unique_id "apK9ZddHPfW2QFvhmL7fwAAAACg"] [Sat Aug 29 05:07:18.007780 2026] [security2:error] [pid 1018003:tid 1018195] [client 4.205.62.107:22030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/ccou.php"] [unique_id "apK9ZjAh5Y1i2tUxg4EROgAABeQ"] [Sat Aug 29 05:07:18.008109 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.196.209.81:15178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/alfanew.php7"] [unique_id "apK9ZtdHPfW2QFvhmL7fzQAAAGw"] [Sat Aug 29 05:07:18.014177 2026] [security2:error] [pid 1028675:tid 1028901] [client 192.145.125.70:43662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZtdHPfW2QFvhmL7f1AAAAFs"] [Sat Aug 29 05:07:18.014400 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.48.250.41:59368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ms.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERPAAABcM"] [Sat Aug 29 05:07:18.026216 2026] [security2:error] [pid 1028675:tid 1028930] [client 20.104.104.62:10475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/ahy66.php"] [unique_id "apK9ZtdHPfW2QFvhmL7f1gAAAHg"] [Sat Aug 29 05:07:18.029049 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.151.200.44:47311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/quoys.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERPwAABio"] [Sat Aug 29 05:07:18.063218 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.197.61.180:8934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/ggfi.php"] [unique_id "apK9ZtdHPfW2QFvhmL7f5QAAAEo"] [Sat Aug 29 05:07:18.070735 2026] [security2:error] [pid 1018003:tid 1018191] [client 158.23.184.117:2578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-content/uploads/my.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERRQAABeA"] [Sat Aug 29 05:07:18.082794 2026] [security2:error] [pid 1018003:tid 1018212] [client 40.83.93.50:22818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/core.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERRwAABfU"] [Sat Aug 29 05:07:18.092301 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.23.184.117:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERSQAABjU"] [Sat Aug 29 05:07:18.100193 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.48.160.90:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/gelap1.php"] [unique_id "apK9ZtdHPfW2QFvhmL7f7wAAACI"] [Sat Aug 29 05:07:18.108550 2026] [security2:error] [pid 1028675:tid 1028867] [client 158.23.184.117:11942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp.php"] [unique_id "apK9ZtdHPfW2QFvhmL7f8AAAADk"] [Sat Aug 29 05:07:18.112864 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.158.54.35:24174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/storage/rip.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERSwAABgc"] [Sat Aug 29 05:07:18.149052 2026] [security2:error] [pid 1018003:tid 1018163] [client 158.23.184.117:63787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/term.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERUAAABcQ"] [Sat Aug 29 05:07:18.149950 2026] [security2:error] [pid 1018003:tid 1018252] [client 40.83.93.50:7472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/headerg.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERUQAABhw"] [Sat Aug 29 05:07:18.164410 2026] [security2:error] [pid 1018003:tid 1018161] [client 68.155.159.216:38577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/dropdown.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERVAAABcI"] [Sat Aug 29 05:07:18.165244 2026] [security2:error] [pid 1028675:tid 1028872] [client 158.23.184.117:30257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/al.php"] [unique_id "apK9ZtdHPfW2QFvhmL7f-wAAAD4"] [Sat Aug 29 05:07:18.177506 2026] [security2:error] [pid 1028675:tid 1028833] [client 158.23.147.79:32675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9ZtdHPfW2QFvhmL7f_QAAABc"] [Sat Aug 29 05:07:18.182535 2026] [security2:error] [pid 1018003:tid 1018266] [client 68.155.159.216:33788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERVwAABio"] [Sat Aug 29 05:07:18.198694 2026] [security2:error] [pid 1028675:tid 1028848] [client 68.155.159.216:1993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/dropdown.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gBAAAACY"] [Sat Aug 29 05:07:18.202592 2026] [security2:error] [pid 1028675:tid 1028913] [client 185.104.184.230:55310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZtdHPfW2QFvhmL7gBwAAAGc"] [Sat Aug 29 05:07:18.203301 2026] [security2:error] [pid 1018003:tid 1018203] [client 68.155.159.216:51397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/goat1.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERXAAABew"] [Sat Aug 29 05:07:18.216853 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.184.117:2600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/themes/uploads/config.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERXgAABiA"] [Sat Aug 29 05:07:18.235308 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.48.160.90:51680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/rsjlrria.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gEQAAADg"] [Sat Aug 29 05:07:18.238804 2026] [security2:error] [pid 1028675:tid 1028890] [client 168.107.94.195:56800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gEgAAAFA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:18.246470 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.104.104.62:10860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/gaje.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gFwAAACM"] [Sat Aug 29 05:07:18.253010 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.184.117:12079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/xmlrpc.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERYQAABbw"] [Sat Aug 29 05:07:18.255891 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.203.141.11:11262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/new.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gGwAAABs"] [Sat Aug 29 05:07:18.269495 2026] [security2:error] [pid 1018003:tid 1018160] [client 158.23.184.117:4244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/robots.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERYwAABcE"] [Sat Aug 29 05:07:18.275191 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.158.54.35:20296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/autoload_classmap.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERZAAABik"] [Sat Aug 29 05:07:18.288086 2026] [security2:error] [pid 1028675:tid 1028931] [client 93.123.109.228:44806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gIwAAAHk"] [Sat Aug 29 05:07:18.292210 2026] [security2:error] [pid 1028675:tid 1028846] [client 213.202.253.4:63026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/postnews.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gJAAAACQ"], referer: www.google.com [Sat Aug 29 05:07:18.300822 2026] [security2:error] [pid 1028675:tid 1028849] [client 4.205.62.107:65526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/api.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gJgAAACc"] [Sat Aug 29 05:07:18.303157 2026] [security2:error] [pid 1028675:tid 1028839] [client 68.155.159.216:65029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/dropdown.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gJwAAAB0"] [Sat Aug 29 05:07:18.303851 2026] [security2:error] [pid 1018003:tid 1018277] [client 68.155.159.216:50359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERZgAABjU"] [Sat Aug 29 05:07:18.346684 2026] [security2:error] [pid 1028675:tid 1028923] [client 158.23.147.79:35825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gKwAAAHE"] [Sat Aug 29 05:07:18.350976 2026] [security2:error] [pid 1028675:tid 1028935] [client 68.155.159.216:49273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/lv.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gLQAAAH0"] [Sat Aug 29 05:07:18.356595 2026] [core:error] [pid 1028675:tid 1028880] [client 57.141.14.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:18.356613 2026] [core:error] [pid 1028675:tid 1028880] [client 57.141.14.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:18.359315 2026] [security2:error] [pid 1018003:tid 1018189] [client 4.205.62.107:58381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/thui.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERbAAABd4"] [Sat Aug 29 05:07:18.364956 2026] [security2:error] [pid 1028675:tid 1028842] [client 93.123.109.228:44930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9ZtdHPfW2QFvhmL7gMwAAACA"] [Sat Aug 29 05:07:18.365816 2026] [security2:error] [pid 1028675:tid 1028825] [client 4.205.62.107:22452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/06.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gNAAAAA8"] [Sat Aug 29 05:07:18.387700 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.48.160.90:51708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/AxAo.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gNwAAABI"] [Sat Aug 29 05:07:18.390286 2026] [security2:error] [pid 1028675:tid 1028891] [client 20.104.104.62:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/wp-admin/zwso.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gOAAAAFE"] [Sat Aug 29 05:07:18.429173 2026] [security2:error] [pid 1028675:tid 1028882] [client 68.155.159.216:30612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gPwAAAEg"] [Sat Aug 29 05:07:18.464831 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.48.250.41:60672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/zxekqlxb.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gQAAAAG8"] [Sat Aug 29 05:07:18.486065 2026] [security2:error] [pid 1018003:tid 1018163] [client 74.7.241.159:44960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "anescoavtech.com"] [uri "/robots.txt"] [unique_id "apK9ZjAh5Y1i2tUxg4ERcAAABcQ"] [Sat Aug 29 05:07:18.514606 2026] [security2:error] [pid 1028675:tid 1028813] [client 20.104.104.62:40250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/web-setting.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gRgAAAAM"] [Sat Aug 29 05:07:18.516235 2026] [security2:error] [pid 1028675:tid 1028836] [client 185.104.184.230:55324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZtdHPfW2QFvhmL7gRwAAABo"] [Sat Aug 29 05:07:18.519106 2026] [security2:error] [pid 1028675:tid 1028901] [client 93.123.109.228:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/admin/phpinfo.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gSAAAAFs"] [Sat Aug 29 05:07:18.525192 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.104.104.62:10659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/Contrller.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gSQAAAAs"] [Sat Aug 29 05:07:18.545604 2026] [security2:error] [pid 1018003:tid 1018174] [client 20.48.160.90:51255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/class17.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERcgAABc8"] [Sat Aug 29 05:07:18.551367 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.196.209.81:11287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/xmlrpc.php0"] [unique_id "apK9ZtdHPfW2QFvhmL7gUAAAAEk"] [Sat Aug 29 05:07:18.551404 2026] [security2:error] [pid 1028675:tid 1028917] [client 52.139.37.240:21139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tikiwithray.com"] [uri "/flower.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gUQAAAGs"] [Sat Aug 29 05:07:18.553073 2026] [security2:error] [pid 1028675:tid 1028876] [client 93.123.109.228:44874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/admin_phpinfo.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gUgAAAEI"] [Sat Aug 29 05:07:18.562063 2026] [security2:error] [pid 1018003:tid 1018216] [client 93.123.109.228:44904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9ZjAh5Y1i2tUxg4ERcwAABfk"] [Sat Aug 29 05:07:18.569366 2026] [security2:error] [pid 1028675:tid 1028892] [client 40.83.93.50:13597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/db-status.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gVAAAAFI"] [Sat Aug 29 05:07:18.569712 2026] [security2:error] [pid 1028675:tid 1028915] [client 158.23.147.79:25422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/goat1.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gVQAAAGk"] [Sat Aug 29 05:07:18.575928 2026] [security2:error] [pid 1028675:tid 1028866] [client 93.123.109.228:44962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9ZtdHPfW2QFvhmL7gWAAAADg"] [Sat Aug 29 05:07:18.588649 2026] [security2:error] [pid 1028675:tid 1028896] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9ZtdHPfW2QFvhmL7gWwAAAFY"] [Sat Aug 29 05:07:18.609614 2026] [security2:error] [pid 1028675:tid 1028837] [client 158.23.147.79:17443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gXwAAABs"] [Sat Aug 29 05:07:18.612574 2026] [security2:error] [pid 1018003:tid 1018225] [client 192.145.125.70:43668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZjAh5Y1i2tUxg4ERdAAABgI"] [Sat Aug 29 05:07:18.616125 2026] [security2:error] [pid 1028675:tid 1028851] [client 68.155.159.216:24499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/classwithtostring.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gYAAAACk"] [Sat Aug 29 05:07:18.619299 2026] [security2:error] [pid 1028675:tid 1028819] [client 168.107.94.195:57211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gYgAAAAk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:18.632137 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.48.250.41:62523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/init.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gZQAAAFQ"] [Sat Aug 29 05:07:18.632371 2026] [security2:error] [pid 1028675:tid 1028884] [client 93.123.109.228:44858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9ZtdHPfW2QFvhmL7gZAAAAEo"] [Sat Aug 29 05:07:18.633604 2026] [security2:error] [pid 1018003:tid 1018187] [client 52.139.37.240:14950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/about/function.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERdgAABdw"] [Sat Aug 29 05:07:18.649371 2026] [security2:error] [pid 1018003:tid 1018246] [client 158.23.147.79:30498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERdwAABhY"] [Sat Aug 29 05:07:18.650744 2026] [security2:error] [pid 1028675:tid 1028872] [client 158.158.54.35:23325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/zoom1.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gZwAAAD4"] [Sat Aug 29 05:07:18.653458 2026] [security2:error] [pid 1028675:tid 1028845] [client 52.139.37.240:32068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/7logs.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gaAAAACM"] [Sat Aug 29 05:07:18.661306 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.104.104.62:10488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/Zeiss.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gagAAAEA"] [Sat Aug 29 05:07:18.693388 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.48.160.90:51302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/okxoby.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gcAAAAFc"] [Sat Aug 29 05:07:18.719750 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.203.141.11:1256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/menu.php"] [unique_id "apK9ZjAh5Y1i2tUxg4EReQAABcA"] [Sat Aug 29 05:07:18.734803 2026] [security2:error] [pid 1028675:tid 1028812] [client 40.83.93.50:7977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/meta.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gcQAAAAI"] [Sat Aug 29 05:07:18.743374 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.158.54.35:16916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/bi.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERfAAABcM"] [Sat Aug 29 05:07:18.747371 2026] [security2:error] [pid 1028675:tid 1028911] [client 68.155.159.216:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gdAAAAGU"] [Sat Aug 29 05:07:18.754974 2026] [security2:error] [pid 1028675:tid 1028881] [client 180.190.5.40:50576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.5.190.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcrl.tech"] [uri "/xmlrpc.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gdwAAAEc"] [Sat Aug 29 05:07:18.755046 2026] [security2:error] [pid 1028675:tid 1028881] [client 180.190.5.40:50576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mcrl.tech"] [uri "/xmlrpc.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gdwAAAEc"] [Sat Aug 29 05:07:18.772596 2026] [security2:error] [pid 1018003:tid 1018256] [client 93.123.109.228:44984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/api/info.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERfQAABiA"] [Sat Aug 29 05:07:18.780370 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.197.61.180:13883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/alfa-rex.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gfgAAAGQ"] [Sat Aug 29 05:07:18.783064 2026] [security2:error] [pid 1028675:tid 1028882] [client 20.104.49.130:57492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/about.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gfwAAAEg"] [Sat Aug 29 05:07:18.792635 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.104.62:10758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/ww2.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERfgAABeU"] [Sat Aug 29 05:07:18.794433 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.23.147.79:48194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/mah.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERfwAABek"] [Sat Aug 29 05:07:18.797860 2026] [security2:error] [pid 1028675:tid 1028916] [client 4.205.62.107:56048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/public/wp-blog.php"] [unique_id "apK9ZtdHPfW2QFvhmL7ggQAAAGo"] [Sat Aug 29 05:07:18.812693 2026] [security2:error] [pid 1028675:tid 1028914] [client 93.123.109.228:44884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/api/phpinfo.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gggAAAGg"] [Sat Aug 29 05:07:18.814655 2026] [security2:error] [pid 1028675:tid 1028912] [client 185.104.184.230:41998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZtdHPfW2QFvhmL7ggwAAAGY"] [Sat Aug 29 05:07:18.816976 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.151.200.44:47395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/vbbn.php"] [unique_id "apK9ZtdHPfW2QFvhmL7ghAAAAFk"] [Sat Aug 29 05:07:18.824728 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.104.104.62:64704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/wp-ettoyag.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERgAAABcs"] [Sat Aug 29 05:07:18.828948 2026] [security2:error] [pid 1018003:tid 1018271] [client 52.139.37.240:14964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/an.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERgQAABi8"] [Sat Aug 29 05:07:18.831815 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.48.160.90:51283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/esuutzzx.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERggAABgw"] [Sat Aug 29 05:07:18.843684 2026] [security2:error] [pid 1028675:tid 1028847] [client 52.139.37.240:32741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/ac.php"] [unique_id "apK9ZtdHPfW2QFvhmL7ghwAAACU"] [Sat Aug 29 05:07:18.892073 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.48.250.41:60726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/term.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERhAAABfU"] [Sat Aug 29 05:07:18.928503 2026] [security2:error] [pid 1028675:tid 1028933] [client 68.155.159.216:6030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/makeasmtp.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gkAAAAHs"] [Sat Aug 29 05:07:18.929950 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.104.62:10822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/anz.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERhgAABiU"] [Sat Aug 29 05:07:18.947780 2026] [security2:error] [pid 1028675:tid 1028873] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9ZtdHPfW2QFvhmL7glgAAAD8"] [Sat Aug 29 05:07:18.965575 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.23.147.79:30403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERiAAABdk"] [Sat Aug 29 05:07:18.979864 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.196.209.81:15174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/content.php"] [unique_id "apK9ZjAh5Y1i2tUxg4ERiQAABgk"] [Sat Aug 29 05:07:18.992711 2026] [security2:error] [pid 1028675:tid 1028877] [client 20.48.160.90:49512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/replace.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gngAAAEM"] [Sat Aug 29 05:07:18.997326 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.104.49.130:60779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/av.php"] [unique_id "apK9ZtdHPfW2QFvhmL7gnwAAADQ"] [Sat Aug 29 05:07:19.000010 2026] [security2:error] [pid 1028675:tid 1028837] [client 168.107.94.195:57545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ZtdHPfW2QFvhmL7goAAAABs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:19.008500 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.49.130:30069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/browse.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gpAAAAD0"] [Sat Aug 29 05:07:19.015572 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.147.79:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERigAABd4"] [Sat Aug 29 05:07:19.032480 2026] [security2:error] [pid 1028675:tid 1028872] [client 93.123.109.228:44842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7gpgAAAD4"] [Sat Aug 29 05:07:19.038579 2026] [security2:error] [pid 1028675:tid 1028915] [client 52.139.37.240:52221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/ctex1.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gqAAAAGk"] [Sat Aug 29 05:07:19.042932 2026] [security2:error] [pid 1018003:tid 1018231] [client 52.139.37.240:14974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/asw.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERjAAABgc"] [Sat Aug 29 05:07:19.049622 2026] [security2:error] [pid 1028675:tid 1028813] [client 40.83.93.50:20815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/disagrsxr.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gqgAAAAM"] [Sat Aug 29 05:07:19.064377 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.104.104.62:10666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/bge.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gqwAAAAU"] [Sat Aug 29 05:07:19.074592 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.48.250.41:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/aaa.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERjgAABho"] [Sat Aug 29 05:07:19.086883 2026] [security2:error] [pid 1028675:tid 1028897] [client 68.155.159.216:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/file17.php"] [unique_id "apK9Z9dHPfW2QFvhmL7grgAAAFc"] [Sat Aug 29 05:07:19.108787 2026] [security2:error] [pid 1018003:tid 1018244] [client 185.104.184.230:59442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZzAh5Y1i2tUxg4ERjwAABhQ"] [Sat Aug 29 05:07:19.133088 2026] [security2:error] [pid 1018003:tid 1018088] [remote 74.7.227.189:42320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pinnacleforms.com"] [uri "/jInventoryRpt.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERkAAGHEM"], referer: https://mail.pinnacleforms.com/ [Sat Aug 29 05:07:19.143961 2026] [security2:error] [pid 1028675:tid 1028881] [client 4.205.62.107:22485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/rum.or.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gtQAAAEc"] [Sat Aug 29 05:07:19.147304 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.48.160.90:51689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/gulu.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERkQAABf8"] [Sat Aug 29 05:07:19.148856 2026] [security2:error] [pid 1028675:tid 1028841] [client 4.205.62.107:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/g3.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gtwAAAB8"] [Sat Aug 29 05:07:19.150687 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.104.104.62:40224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/venom.php"] [unique_id "apK9Z9dHPfW2QFvhmL7guQAAACw"] [Sat Aug 29 05:07:19.195678 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.158.54.35:29676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/cc.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERkgAABh8"] [Sat Aug 29 05:07:19.196166 2026] [security2:error] [pid 1028675:tid 1028901] [client 192.145.125.70:43684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9Z9dHPfW2QFvhmL7gvwAAAFs"] [Sat Aug 29 05:07:19.206220 2026] [security2:error] [pid 1028675:tid 1028855] [client 68.155.159.216:51478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/x.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gwgAAAC0"] [Sat Aug 29 05:07:19.212666 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.203.141.11:11247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERlQAABis"] [Sat Aug 29 05:07:19.229494 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.48.250.41:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/xsox.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERlwAABec"] [Sat Aug 29 05:07:19.230641 2026] [security2:error] [pid 1018003:tid 1018217] [client 40.83.93.50:7537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/dxc.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERmQAABfo"] [Sat Aug 29 05:07:19.232729 2026] [security2:error] [pid 1028675:tid 1028910] [client 52.139.37.240:32016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/defaults.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gxQAAAGQ"] [Sat Aug 29 05:07:19.235302 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.104.104.62:10669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/wp-ana.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gyAAAACg"] [Sat Aug 29 05:07:19.236715 2026] [security2:error] [pid 1028675:tid 1028882] [client 52.139.37.240:14484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/item.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gygAAAEg"] [Sat Aug 29 05:07:19.237030 2026] [security2:error] [pid 1028675:tid 1028833] [client 93.123.109.228:44988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7gyQAAABc"] [Sat Aug 29 05:07:19.241563 2026] [security2:error] [pid 1028675:tid 1028923] [client 158.158.54.35:17648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/txets.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gywAAAHE"] [Sat Aug 29 05:07:19.246964 2026] [security2:error] [pid 1028675:tid 1028856] [client 39.44.3.46:64334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.3.44.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mihp.net"] [uri "/xmlrpc.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gxgAAAC4"] [Sat Aug 29 05:07:19.247047 2026] [security2:error] [pid 1028675:tid 1028856] [client 39.44.3.46:64334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mihp.net"] [uri "/xmlrpc.php"] [unique_id "apK9Z9dHPfW2QFvhmL7gxgAAAC4"] [Sat Aug 29 05:07:19.254656 2026] [security2:error] [pid 1018003:tid 1018152] [client 93.123.109.228:44904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9ZzAh5Y1i2tUxg4ERmgAABbk"] [Sat Aug 29 05:07:19.262562 2026] [security2:error] [pid 1018003:tid 1018159] [client 68.155.159.216:38564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/.well-known/index.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERmwAABcA"] [Sat Aug 29 05:07:19.268038 2026] [security2:error] [pid 1018003:tid 1018190] [client 39.44.3.46:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.3.44.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mihp.net"] [uri "/xmlrpc.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERlgAABd8"] [Sat Aug 29 05:07:19.268151 2026] [security2:error] [pid 1018003:tid 1018190] [client 39.44.3.46:64335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mihp.net"] [uri "/xmlrpc.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERlgAABd8"] [Sat Aug 29 05:07:19.283700 2026] [security2:error] [pid 1018003:tid 1018240] [client 158.23.147.79:32717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/lock.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERnAAABhA"] [Sat Aug 29 05:07:19.290767 2026] [security2:error] [pid 1018003:tid 1018166] [client 146.70.194.254:44262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZzAh5Y1i2tUxg4ERnQAABcc"] [Sat Aug 29 05:07:19.320202 2026] [security2:error] [pid 1028675:tid 1028903] [client 68.155.159.216:51270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g1QAAAF0"] [Sat Aug 29 05:07:19.326158 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.48.160.90:51641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/gtghklk.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g1gAAAC8"] [Sat Aug 29 05:07:19.365843 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.104.104.62:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/secret.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g3QAAAFg"] [Sat Aug 29 05:07:19.377931 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.104.49.130:60962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/1xmomo.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g4gAAAGw"] [Sat Aug 29 05:07:19.379133 2026] [security2:error] [pid 1028675:tid 1028819] [client 168.107.94.195:58010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g4wAAAAk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:19.409221 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.196.209.81:1736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/wxo.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERoAAABcM"] [Sat Aug 29 05:07:19.409651 2026] [security2:error] [pid 1018003:tid 1018258] [client 68.155.159.216:65145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/.well-known/index.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERoQAABiI"] [Sat Aug 29 05:07:19.413115 2026] [security2:error] [pid 1018003:tid 1018172] [client 185.104.184.230:59452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZzAh5Y1i2tUxg4ERogAABc0"] [Sat Aug 29 05:07:19.429393 2026] [security2:error] [pid 1028675:tid 1028731] [remote 43.135.153.177:56822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.153.135.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woosigns.com"] [uri "/xmlrpc.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g5wAAMzI"] [Sat Aug 29 05:07:19.429599 2026] [security2:error] [pid 1028675:tid 1028861] [client 43.135.153.177:56822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "woosigns.com"] [uri "/xmlrpc.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g5wAAMzI"] [Sat Aug 29 05:07:19.435715 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.139.37.240:14705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/jga.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERpQAABdg"] [Sat Aug 29 05:07:19.436682 2026] [security2:error] [pid 1028675:tid 1028877] [client 52.139.37.240:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/domains.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g6wAAAEM"] [Sat Aug 29 05:07:19.439868 2026] [security2:error] [pid 1028675:tid 1028904] [client 4.205.62.107:65467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/temp.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g7AAAAF4"] [Sat Aug 29 05:07:19.454481 2026] [security2:error] [pid 1028675:tid 1028835] [client 68.155.159.216:50342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/log-mama/function.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g7gAAABk"] [Sat Aug 29 05:07:19.466604 2026] [security2:error] [pid 1028675:tid 1028845] [client 20.48.250.41:62591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/lkui.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g8AAAACM"] [Sat Aug 29 05:07:19.467197 2026] [security2:error] [pid 1028675:tid 1028874] [client 158.23.147.79:35810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g8QAAAEA"] [Sat Aug 29 05:07:19.500283 2026] [security2:error] [pid 1028675:tid 1028885] [client 4.205.62.107:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/session.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g9gAAAEs"] [Sat Aug 29 05:07:19.502550 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.48.250.41:35459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g-AAAAHc"] [Sat Aug 29 05:07:19.508528 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.104.104.62:20860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/vuln.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERpgAABdc"] [Sat Aug 29 05:07:19.510148 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.160.90:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/comand.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERpwAABjU"] [Sat Aug 29 05:07:19.511773 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.23.147.79:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERqAAABjU"] [Sat Aug 29 05:07:19.515884 2026] [security2:error] [pid 1018003:tid 1018238] [client 4.205.62.107:22430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/otuz1.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERqQAABg4"] [Sat Aug 29 05:07:19.517330 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.104.62:10676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/pro.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERqgAABco"] [Sat Aug 29 05:07:19.529721 2026] [security2:error] [pid 1028675:tid 1028927] [client 40.83.93.50:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/f35.php"] [unique_id "apK9Z9dHPfW2QFvhmL7g_AAAAHU"] [Sat Aug 29 05:07:19.529724 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.197.61.180:9704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/cookie.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERqwAABfw"] [Sat Aug 29 05:07:19.551842 2026] [security2:error] [pid 1018003:tid 1018184] [client 68.155.159.216:30626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERrAAABdk"] [Sat Aug 29 05:07:19.574914 2026] [security2:error] [pid 1018003:tid 1018177] [client 87.219.197.128:62320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERrgAABdI"] [Sat Aug 29 05:07:19.575006 2026] [security2:error] [pid 1018003:tid 1018177] [client 87.219.197.128:62320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERrgAABdI"] [Sat Aug 29 05:07:19.587105 2026] [security2:error] [pid 1028675:tid 1028936] [client 93.123.109.228:44894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hAQAAAH4"] [Sat Aug 29 05:07:19.594496 2026] [security2:error] [pid 1028675:tid 1028891] [client 93.123.109.228:44988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hAgAAAFE"] [Sat Aug 29 05:07:19.595492 2026] [security2:error] [pid 1028675:tid 1028854] [client 93.123.109.228:44946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hAwAAACw"] [Sat Aug 29 05:07:19.600523 2026] [security2:error] [pid 1018003:tid 1018273] [client 40.83.93.50:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERsAAABjE"] [Sat Aug 29 05:07:19.601736 2026] [security2:error] [pid 1018003:tid 1018179] [client 20.48.250.41:60699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERsQAABdQ"] [Sat Aug 29 05:07:19.605242 2026] [security2:error] [pid 1028675:tid 1028928] [client 93.123.109.228:44842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hBAAAAHY"] [Sat Aug 29 05:07:19.619984 2026] [security2:error] [pid 1028675:tid 1028878] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hBQAAAEQ"] [Sat Aug 29 05:07:19.631873 2026] [security2:error] [pid 1018003:tid 1018156] [client 52.139.37.240:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/dropdown.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERtAAABb0"] [Sat Aug 29 05:07:19.639783 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.48.160.90:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERtQAABcI"] [Sat Aug 29 05:07:19.644989 2026] [security2:error] [pid 1028675:tid 1028831] [client 158.158.54.35:34293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/files/index.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hCAAAABU"] [Sat Aug 29 05:07:19.645189 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.104.104.62:10467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/999.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERtgAABh8"] [Sat Aug 29 05:07:19.651197 2026] [security2:error] [pid 1018003:tid 1018250] [client 52.139.37.240:14498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/mac.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERuAAABho"] [Sat Aug 29 05:07:19.673320 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.48.250.41:35471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hCgAAAGg"] [Sat Aug 29 05:07:19.683596 2026] [security2:error] [pid 1018003:tid 1018164] [client 158.23.147.79:25416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERuQAABcU"] [Sat Aug 29 05:07:19.708802 2026] [security2:error] [pid 1018003:tid 1018152] [client 185.104.184.230:59460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZzAh5Y1i2tUxg4ERuwAABbk"] [Sat Aug 29 05:07:19.727512 2026] [security2:error] [pid 1018003:tid 1018231] [client 40.83.93.50:7978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/wp-2019.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERvQAABgc"] [Sat Aug 29 05:07:19.760130 2026] [security2:error] [pid 1028675:tid 1028930] [client 168.107.94.195:58282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hGgAAAHg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:19.768411 2026] [security2:error] [pid 1028675:tid 1028913] [client 93.123.109.228:44946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hGwAAAGc"] [Sat Aug 29 05:07:19.773896 2026] [security2:error] [pid 1028675:tid 1028821] [client 93.123.109.228:44842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hHQAAAAs"] [Sat Aug 29 05:07:19.779250 2026] [security2:error] [pid 1018003:tid 1018170] [client 93.123.109.228:44904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9ZzAh5Y1i2tUxg4ERvwAABcs"] [Sat Aug 29 05:07:19.779753 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.48.250.41:60733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/motu.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hIAAAAFo"] [Sat Aug 29 05:07:19.780724 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.48.160.90:51691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hIQAAACI"] [Sat Aug 29 05:07:19.783883 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.104.104.62:10875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/sef.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hIwAAADw"] [Sat Aug 29 05:07:19.790310 2026] [security2:error] [pid 1028675:tid 1028883] [client 68.155.159.216:24512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/install.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hJgAAAEk"] [Sat Aug 29 05:07:19.799414 2026] [security2:error] [pid 1018003:tid 1018175] [client 192.145.125.70:43700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9ZzAh5Y1i2tUxg4ERwQAABdA"] [Sat Aug 29 05:07:19.803843 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.104.104.62:40228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/V5.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hKAAAAC8"] [Sat Aug 29 05:07:19.810759 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.48.250.41:35457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ff1.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hKgAAAGs"] [Sat Aug 29 05:07:19.826499 2026] [security2:error] [pid 1028675:tid 1028848] [client 52.139.37.240:32744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/files/index.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hLgAAACY"] [Sat Aug 29 05:07:19.836988 2026] [security2:error] [pid 1028675:tid 1028912] [client 20.196.209.81:2002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/as.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hMQAAAGY"] [Sat Aug 29 05:07:19.841880 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.203.141.11:22443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/lite.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hMgAAABs"] [Sat Aug 29 05:07:19.915102 2026] [security2:error] [pid 1028675:tid 1028877] [client 20.104.104.62:10665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/admin123.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hOgAAAEM"] [Sat Aug 29 05:07:19.916389 2026] [security2:error] [pid 1028675:tid 1028902] [client 93.123.109.228:44940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hOQAAAFw"] [Sat Aug 29 05:07:19.927380 2026] [security2:error] [pid 1028675:tid 1028872] [client 93.123.109.228:44930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9Z9dHPfW2QFvhmL7hPAAAAD4"] [Sat Aug 29 05:07:19.929962 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.48.250.41:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/Ov-Simple1.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hPgAAABA"] [Sat Aug 29 05:07:19.938935 2026] [security2:error] [pid 1028675:tid 1028845] [client 4.205.62.107:53279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/php-details.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hPwAAACM"] [Sat Aug 29 05:07:19.948392 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.48.250.41:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hQgAAAA4"] [Sat Aug 29 05:07:19.951064 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.48.160.90:49517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/edit.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hQwAAAEs"] [Sat Aug 29 05:07:19.954284 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.48.250.41:35103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/t.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hRQAAAB4"] [Sat Aug 29 05:07:19.967318 2026] [security2:error] [pid 1028675:tid 1028811] [client 158.23.147.79:26515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hRgAAAAE"] [Sat Aug 29 05:07:19.991613 2026] [security2:error] [pid 1028675:tid 1028847] [client 93.123.109.228:45012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hRwAAACU"] [Sat Aug 29 05:07:19.999715 2026] [security2:error] [pid 1028675:tid 1028862] [client 40.83.93.50:20856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/index.php"] [unique_id "apK9Z9dHPfW2QFvhmL7hSAAAADQ"] [Sat Aug 29 05:07:20.021176 2026] [security2:error] [pid 1018003:tid 1018187] [client 185.104.184.230:59468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9aDAh5Y1i2tUxg4ERxgAABdw"] [Sat Aug 29 05:07:20.050739 2026] [security2:error] [pid 1018003:tid 1018256] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9ZzAh5Y1i2tUxg4ERwwAGIBw"] [Sat Aug 29 05:07:20.051389 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.104.104.62:10654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/7h.php"] [unique_id "apK9aDAh5Y1i2tUxg4ERyAAABgo"] [Sat Aug 29 05:07:20.068909 2026] [security2:error] [pid 1028675:tid 1028928] [client 68.155.159.216:6057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9aNdHPfW2QFvhmL7hTgAAAHY"] [Sat Aug 29 05:07:20.083559 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.48.250.41:60700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/wp-blogs.php"] [unique_id "apK9aDAh5Y1i2tUxg4ERyQAABjU"] [Sat Aug 29 05:07:20.087694 2026] [security2:error] [pid 1018003:tid 1018238] [client 158.158.54.35:23349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-content/themes/about.php"] [unique_id "apK9aDAh5Y1i2tUxg4ERygAABg4"] [Sat Aug 29 05:07:20.088069 2026] [security2:error] [pid 1028675:tid 1028931] [client 40.83.93.50:24536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/options-general.php"] [unique_id "apK9aNdHPfW2QFvhmL7hUQAAAHk"] [Sat Aug 29 05:07:20.096323 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.250.41:35128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/erty.php"] [unique_id "apK9aDAh5Y1i2tUxg4ERzAAABco"] [Sat Aug 29 05:07:20.096713 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.48.160.90:51207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/tqkdqbbv.php"] [unique_id "apK9aNdHPfW2QFvhmL7hUwAAAHo"] [Sat Aug 29 05:07:20.098401 2026] [security2:error] [pid 1028675:tid 1028889] [client 158.158.54.35:34830] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/1.php7"] [unique_id "apK9aNdHPfW2QFvhmL7hVAAAAE8"] [Sat Aug 29 05:07:20.098475 2026] [security2:error] [pid 1028675:tid 1028889] [client 158.158.54.35:34830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/1.php7"] [unique_id "apK9aNdHPfW2QFvhmL7hVAAAAE8"] [Sat Aug 29 05:07:20.099789 2026] [security2:error] [pid 1028675:tid 1028916] [client 20.48.250.41:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9aNdHPfW2QFvhmL7hVQAAAGo"] [Sat Aug 29 05:07:20.100548 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.147.79:30538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9aDAh5Y1i2tUxg4ERzQAABfw"] [Sat Aug 29 05:07:20.125396 2026] [security2:error] [pid 1028675:tid 1028830] [client 93.123.109.228:44946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/aws.php"] [unique_id "apK9aNdHPfW2QFvhmL7hVgAAABQ"] [Sat Aug 29 05:07:20.136704 2026] [security2:error] [pid 1018003:tid 1018226] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9aDAh5Y1i2tUxg4ERzwAABgM"] [Sat Aug 29 05:07:20.140567 2026] [security2:error] [pid 1028675:tid 1028910] [client 168.107.94.195:58682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9aNdHPfW2QFvhmL7hWwAAAGQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:20.168450 2026] [security2:error] [pid 1028675:tid 1028836] [client 93.123.109.228:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/config.inc.php"] [unique_id "apK9aNdHPfW2QFvhmL7hYAAAABo"] [Sat Aug 29 05:07:20.194287 2026] [security2:error] [pid 1028675:tid 1028923] [client 93.123.109.228:44972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/config.php"] [unique_id "apK9aNdHPfW2QFvhmL7hYwAAAHE"] [Sat Aug 29 05:07:20.196674 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.104.104.62:10675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/wp-gzone.php"] [unique_id "apK9aNdHPfW2QFvhmL7hZAAAAFo"] [Sat Aug 29 05:07:20.199995 2026] [security2:error] [pid 1028675:tid 1028870] [client 68.155.159.216:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9aNdHPfW2QFvhmL7hZgAAADw"] [Sat Aug 29 05:07:20.230312 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.48.250.41:35104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/0x.php"] [unique_id "apK9aNdHPfW2QFvhmL7hbQAAAHs"] [Sat Aug 29 05:07:20.233207 2026] [security2:error] [pid 1028675:tid 1028859] [client 20.48.250.41:62475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/mini.php"] [unique_id "apK9aNdHPfW2QFvhmL7hbgAAADE"] [Sat Aug 29 05:07:20.233628 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.48.250.41:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ff1.php"] [unique_id "apK9aNdHPfW2QFvhmL7hbwAAAF0"] [Sat Aug 29 05:07:20.252682 2026] [security2:error] [pid 1028675:tid 1028846] [client 20.197.61.180:13824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/NewFile.php"] [unique_id "apK9aNdHPfW2QFvhmL7hdAAAACQ"] [Sat Aug 29 05:07:20.256690 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.49.130:45741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/init.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER0QAABiw"] [Sat Aug 29 05:07:20.266806 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.196.209.81:11327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/room.php"] [unique_id "apK9aNdHPfW2QFvhmL7hdwAAAG0"] [Sat Aug 29 05:07:20.273721 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.48.160.90:51280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/kjyehoxl.php"] [unique_id "apK9aNdHPfW2QFvhmL7heAAAAFQ"] [Sat Aug 29 05:07:20.278151 2026] [security2:error] [pid 1028675:tid 1028832] [client 4.205.62.107:22505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/xmy.php"] [unique_id "apK9aNdHPfW2QFvhmL7hegAAABY"] [Sat Aug 29 05:07:20.283643 2026] [security2:error] [pid 1028675:tid 1028828] [client 40.83.93.50:7960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/menu.php"] [unique_id "apK9aNdHPfW2QFvhmL7hewAAABI"] [Sat Aug 29 05:07:20.289569 2026] [security2:error] [pid 1028675:tid 1028820] [client 93.123.109.228:44894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/env.php"] [unique_id "apK9aNdHPfW2QFvhmL7hfAAAAAo"] [Sat Aug 29 05:07:20.300137 2026] [security2:error] [pid 1028675:tid 1028902] [client 4.205.62.107:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/cloud.php"] [unique_id "apK9aNdHPfW2QFvhmL7hfQAAAFw"] [Sat Aug 29 05:07:20.300722 2026] [security2:error] [pid 1028675:tid 1028872] [client 93.123.109.228:44988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/module.config.php"] [unique_id "apK9aNdHPfW2QFvhmL7hfgAAAD4"] [Sat Aug 29 05:07:20.310118 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.203.141.11:8986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/term.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER1AAABdI"] [Sat Aug 29 05:07:20.315934 2026] [security2:error] [pid 1028675:tid 1028813] [client 68.155.159.216:51493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/x.php"] [unique_id "apK9aNdHPfW2QFvhmL7hfwAAAAM"] [Sat Aug 29 05:07:20.322553 2026] [security2:error] [pid 1028675:tid 1028909] [client 93.123.109.228:45030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/nexmo.php"] [unique_id "apK9aNdHPfW2QFvhmL7hgQAAAGM"] [Sat Aug 29 05:07:20.329865 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.104.104.62:10634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/str.php"] [unique_id "apK9aNdHPfW2QFvhmL7hggAAAB4"] [Sat Aug 29 05:07:20.351713 2026] [security2:error] [pid 1028675:tid 1028924] [client 68.155.159.216:33617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9aNdHPfW2QFvhmL7hhQAAAHI"] [Sat Aug 29 05:07:20.361443 2026] [security2:error] [pid 1018003:tid 1018174] [client 103.185.242.143:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER1gAABc8"] [Sat Aug 29 05:07:20.361544 2026] [security2:error] [pid 1018003:tid 1018174] [client 103.185.242.143:65330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER1gAABc8"] [Sat Aug 29 05:07:20.362820 2026] [security2:error] [pid 1028675:tid 1028867] [client 68.155.159.216:38570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9aNdHPfW2QFvhmL7hhgAAADk"] [Sat Aug 29 05:07:20.371732 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.48.250.41:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/t.php"] [unique_id "apK9aNdHPfW2QFvhmL7hhwAAAHU"] [Sat Aug 29 05:07:20.372349 2026] [security2:error] [pid 1028675:tid 1028812] [client 93.123.109.228:45004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/config/stripe.php"] [unique_id "apK9aNdHPfW2QFvhmL7hiAAAAAI"] [Sat Aug 29 05:07:20.375957 2026] [security2:error] [pid 1028675:tid 1028879] [client 20.48.250.41:58405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/amp.php"] [unique_id "apK9aNdHPfW2QFvhmL7hiQAAAEU"] [Sat Aug 29 05:07:20.390816 2026] [security2:error] [pid 1028675:tid 1028911] [client 158.23.147.79:32736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/index/function.php"] [unique_id "apK9aNdHPfW2QFvhmL7hjAAAAGU"] [Sat Aug 29 05:07:20.394345 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.48.250.41:35470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/66.php"] [unique_id "apK9aNdHPfW2QFvhmL7hjQAAACE"] [Sat Aug 29 05:07:20.396421 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.104.104.62:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/v5.php"] [unique_id "apK9aNdHPfW2QFvhmL7hjwAAAGw"] [Sat Aug 29 05:07:20.396488 2026] [security2:error] [pid 1028675:tid 1028914] [client 192.145.125.70:43702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9aNdHPfW2QFvhmL7hjgAAAGg"] [Sat Aug 29 05:07:20.416516 2026] [security2:error] [pid 1028675:tid 1028854] [client 185.104.184.230:59472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9aNdHPfW2QFvhmL7hkAAAACw"] [Sat Aug 29 05:07:20.418501 2026] [security2:error] [pid 1028675:tid 1028891] [client 158.23.147.79:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9aNdHPfW2QFvhmL7hkQAAAFE"] [Sat Aug 29 05:07:20.432717 2026] [security2:error] [pid 1028675:tid 1028853] [client 68.155.159.216:51463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9aNdHPfW2QFvhmL7hkwAAACs"] [Sat Aug 29 05:07:20.465328 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.104.104.62:10646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/mega.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER2gAABfA"] [Sat Aug 29 05:07:20.468435 2026] [autoindex:error] [pid 1028675:tid 1028752] [remote 87.58.197.202:2000] AH01276: Cannot serve directory /home3/zmymhfmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:07:20.472003 2026] [security2:error] [pid 1028675:tid 1028926] [client 20.48.160.90:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/llyuxaqd.php"] [unique_id "apK9aNdHPfW2QFvhmL7hmQAAAHQ"] [Sat Aug 29 05:07:20.488339 2026] [security2:error] [pid 1028675:tid 1028885] [client 40.83.93.50:22796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/install.php"] [unique_id "apK9aNdHPfW2QFvhmL7hnwAAAEs"] [Sat Aug 29 05:07:20.489854 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.151.200.44:46641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/rfi.php"] [unique_id "apK9aNdHPfW2QFvhmL7hoQAAADw"] [Sat Aug 29 05:07:20.516758 2026] [security2:error] [pid 1028675:tid 1028903] [client 68.155.159.216:65136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9aNdHPfW2QFvhmL7howAAAF0"] [Sat Aug 29 05:07:20.521145 2026] [security2:error] [pid 1028675:tid 1028892] [client 168.107.94.195:59139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9aNdHPfW2QFvhmL7hpAAAAFI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:20.522718 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.48.250.41:49031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/erty.php"] [unique_id "apK9aNdHPfW2QFvhmL7hpQAAAFI"] [Sat Aug 29 05:07:20.546642 2026] [security2:error] [pid 1028675:tid 1028819] [client 20.48.250.41:35475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/f35.php"] [unique_id "apK9aNdHPfW2QFvhmL7hqgAAAAk"] [Sat Aug 29 05:07:20.553510 2026] [security2:error] [pid 1028675:tid 1028873] [client 158.158.54.35:28388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/disagraeosc.php"] [unique_id "apK9aNdHPfW2QFvhmL7hrQAAAD8"] [Sat Aug 29 05:07:20.562586 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.49.130:60979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/sym.php"] [unique_id "apK9aNdHPfW2QFvhmL7hrgAAADI"] [Sat Aug 29 05:07:20.563608 2026] [security2:error] [pid 1028675:tid 1028814] [client 158.158.54.35:22447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9aNdHPfW2QFvhmL7hrwAAAAQ"] [Sat Aug 29 05:07:20.567338 2026] [security2:error] [pid 1018003:tid 1018246] [client 68.155.159.216:50214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/bk/index.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER3QAABhY"] [Sat Aug 29 05:07:20.580044 2026] [security2:error] [pid 1018003:tid 1018159] [client 4.205.62.107:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/fm.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER3gAABcA"] [Sat Aug 29 05:07:20.581687 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.147.79:35812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER3wAABbk"] [Sat Aug 29 05:07:20.588506 2026] [security2:error] [pid 1028675:tid 1028818] [client 40.83.93.50:5645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/options.php"] [unique_id "apK9aNdHPfW2QFvhmL7htgAAAAg"] [Sat Aug 29 05:07:20.593609 2026] [security2:error] [pid 1028675:tid 1028904] [client 93.123.109.228:44940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9aNdHPfW2QFvhmL7huAAAAF4"] [Sat Aug 29 05:07:20.602048 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.104.104.62:10869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/ww3.php"] [unique_id "apK9aNdHPfW2QFvhmL7huQAAAB4"] [Sat Aug 29 05:07:20.618692 2026] [security2:error] [pid 1018003:tid 1018240] [client 93.123.109.228:44904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9aDAh5Y1i2tUxg4ER4AAABhA"] [Sat Aug 29 05:07:20.619200 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.48.160.90:51246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/nbwxolou.php"] [unique_id "apK9aNdHPfW2QFvhmL7hugAAAA4"] [Sat Aug 29 05:07:20.619944 2026] [security2:error] [pid 1028675:tid 1028874] [client 20.48.250.41:60695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/cc13.php"] [unique_id "apK9aNdHPfW2QFvhmL7huwAAAEA"] [Sat Aug 29 05:07:20.635525 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.23.147.79:50092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER4QAABew"] [Sat Aug 29 05:07:20.636966 2026] [security2:error] [pid 1018003:tid 1018196] [client 4.205.62.107:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/saml.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER4gAABeU"] [Sat Aug 29 05:07:20.639011 2026] [security2:error] [pid 1028675:tid 1028927] [client 93.123.109.228:45052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9aNdHPfW2QFvhmL7hvQAAAHU"] [Sat Aug 29 05:07:20.658208 2026] [security2:error] [pid 1028675:tid 1028866] [client 4.205.62.107:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/filesystems.php"] [unique_id "apK9aNdHPfW2QFvhmL7hvwAAADg"] [Sat Aug 29 05:07:20.668012 2026] [security2:error] [pid 1028675:tid 1028925] [client 93.123.109.228:45084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9aNdHPfW2QFvhmL7hwAAAAHM"] [Sat Aug 29 05:07:20.681159 2026] [security2:error] [pid 1028675:tid 1028922] [client 93.123.109.228:45074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9aNdHPfW2QFvhmL7hwwAAAHA"] [Sat Aug 29 05:07:20.690773 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.48.250.41:49135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/0x.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER5QAABdg"] [Sat Aug 29 05:07:20.704393 2026] [security2:error] [pid 1018003:tid 1018262] [client 93.123.109.228:45042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9aDAh5Y1i2tUxg4ER5wAABiY"] [Sat Aug 29 05:07:20.704971 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.250.41:35114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/wen.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER6AAABdc"] [Sat Aug 29 05:07:20.706604 2026] [security2:error] [pid 1018003:tid 1018256] [client 68.155.159.216:12172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER6QAABiA"] [Sat Aug 29 05:07:20.719601 2026] [security2:error] [pid 1028675:tid 1028850] [client 185.104.184.230:59486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bjx.okj.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9aNdHPfW2QFvhmL7hywAAACg"] [Sat Aug 29 05:07:20.728864 2026] [security2:error] [pid 1028675:tid 1028926] [client 93.123.109.228:44974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9aNdHPfW2QFvhmL7hzQAAAHQ"] [Sat Aug 29 05:07:20.731576 2026] [security2:error] [pid 1028675:tid 1028820] [client 20.196.209.81:15182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/class-wp-cmd.php"] [unique_id "apK9aNdHPfW2QFvhmL7hzgAAAAo"] [Sat Aug 29 05:07:20.741736 2026] [security2:error] [pid 1028675:tid 1028923] [client 93.123.109.228:44858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9aNdHPfW2QFvhmL7h0AAAAHE"] [Sat Aug 29 05:07:20.744993 2026] [security2:error] [pid 1028675:tid 1028885] [client 20.104.104.62:10637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/sko.php"] [unique_id "apK9aNdHPfW2QFvhmL7h0QAAAEs"] [Sat Aug 29 05:07:20.768844 2026] [security2:error] [pid 1018003:tid 1018231] [client 35.194.208.44:45026] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/home/ubuntu/.env"] [unique_id "apK9aDAh5Y1i2tUxg4ER7AAABgc"] [Sat Aug 29 05:07:20.770147 2026] [security2:error] [pid 1028675:tid 1028811] [client 35.194.208.44:45056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/usr/src/app/.env"] [unique_id "apK9aNdHPfW2QFvhmL7h1gAAAAE"] [Sat Aug 29 05:07:20.771081 2026] [security2:error] [pid 1028675:tid 1028862] [client 35.194.208.44:45034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/var/www/.env"] [unique_id "apK9aNdHPfW2QFvhmL7h2AAAADQ"] [Sat Aug 29 05:07:20.771383 2026] [security2:error] [pid 1018003:tid 1018190] [client 35.194.208.44:45040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/var/www/html/.env"] [unique_id "apK9aDAh5Y1i2tUxg4ER7gAABd8"] [Sat Aug 29 05:07:20.773626 2026] [security2:error] [pid 1028675:tid 1028933] [client 158.23.147.79:30529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/images/index.php"] [unique_id "apK9aNdHPfW2QFvhmL7h2gAAAHs"] [Sat Aug 29 05:07:20.777570 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.250.41:58456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/aa.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER8QAABcE"] [Sat Aug 29 05:07:20.783012 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.48.160.90:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/nsxeubyv.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER8gAABdk"] [Sat Aug 29 05:07:20.802891 2026] [security2:error] [pid 1028675:tid 1028871] [client 146.70.194.254:44276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9aNdHPfW2QFvhmL7h5AAAAD0"] [Sat Aug 29 05:07:20.804739 2026] [security2:error] [pid 1028675:tid 1028908] [client 40.83.93.50:7466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/alfa.php"] [unique_id "apK9aNdHPfW2QFvhmL7h5QAAAGI"] [Sat Aug 29 05:07:20.815197 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:25462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/network/index.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER9wAABb4"] [Sat Aug 29 05:07:20.827187 2026] [security2:error] [pid 1028675:tid 1028846] [client 20.203.141.11:12480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/.trash7206/index.php"] [unique_id "apK9aNdHPfW2QFvhmL7h6gAAACQ"] [Sat Aug 29 05:07:20.844072 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.48.250.41:35131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/inc.php"] [unique_id "apK9aNdHPfW2QFvhmL7h6wAAACk"] [Sat Aug 29 05:07:20.845918 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.48.250.41:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/66.php"] [unique_id "apK9aNdHPfW2QFvhmL7h7QAAAFQ"] [Sat Aug 29 05:07:20.853781 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.151.200.44:47411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/tajj.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER-QAABb0"] [Sat Aug 29 05:07:20.863593 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.203.141.11:24065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/config.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER-gAABdw"] [Sat Aug 29 05:07:20.864398 2026] [security2:error] [pid 1018003:tid 1018270] [client 52.139.37.240:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9aDAh5Y1i2tUxg4ER-wAABi4"] [Sat Aug 29 05:07:20.901861 2026] [security2:error] [pid 1028675:tid 1028879] [client 168.107.94.195:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9aNdHPfW2QFvhmL7h9gAAAEU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:20.902014 2026] [security2:error] [pid 1028675:tid 1028911] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9aNdHPfW2QFvhmL7h9QAAAGU"] [Sat Aug 29 05:07:20.903377 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.104.104.62:10574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/zoz.php"] [unique_id "apK9aNdHPfW2QFvhmL7h9wAAAB8"] [Sat Aug 29 05:07:20.932838 2026] [security2:error] [pid 1028675:tid 1028928] [client 93.123.109.228:44940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9aNdHPfW2QFvhmL7h_gAAAHY"] [Sat Aug 29 05:07:20.933958 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.48.160.90:51681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/zfqipfss.php"] [unique_id "apK9aNdHPfW2QFvhmL7iAAAAABA"] [Sat Aug 29 05:07:20.936887 2026] [security2:error] [pid 1028675:tid 1028876] [client 20.48.250.41:62489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/s1.php"] [unique_id "apK9aNdHPfW2QFvhmL7iAQAAAEI"] [Sat Aug 29 05:07:20.938624 2026] [security2:error] [pid 1028675:tid 1028925] [client 158.23.147.79:48139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-blog-header.php"] [unique_id "apK9aNdHPfW2QFvhmL7iAgAAAHM"] [Sat Aug 29 05:07:20.938886 2026] [security2:error] [pid 1028675:tid 1028839] [client 57.141.14.32:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/acheter/page/19/"] [unique_id "apK9aNdHPfW2QFvhmL7h_AAAAB0"] [Sat Aug 29 05:07:20.945438 2026] [security2:error] [pid 1018003:tid 1018207] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9aDAh5Y1i2tUxg4ER_gAABfA"] [Sat Aug 29 05:07:20.947831 2026] [security2:error] [pid 1028675:tid 1028890] [client 93.123.109.228:44962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9aNdHPfW2QFvhmL7iAwAAAFA"] [Sat Aug 29 05:07:20.971970 2026] [core:error] [pid 1028675:tid 1028856] [client 40.83.93.50:20834] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:20.971988 2026] [core:error] [pid 1028675:tid 1028856] [client 40.83.93.50:20834] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:20.983002 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.197.61.180:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/config.php"] [unique_id "apK9aNdHPfW2QFvhmL7iCAAAAAs"] [Sat Aug 29 05:07:20.987218 2026] [security2:error] [pid 1028675:tid 1028778] [remote 52.167.144.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9aNdHPfW2QFvhmL7iCQAAR2E"] [Sat Aug 29 05:07:20.992785 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.48.250.41:35077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/6bcwiqwj.php"] [unique_id "apK9aNdHPfW2QFvhmL7iCwAAAEQ"] [Sat Aug 29 05:07:20.992948 2026] [security2:error] [pid 1028675:tid 1028889] [client 192.145.125.70:43710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK9aNdHPfW2QFvhmL7iDAAAAE8"] [Sat Aug 29 05:07:21.007911 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.158.54.35:16128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-logs.php"] [unique_id "apK9addHPfW2QFvhmL7iDgAAAEo"] [Sat Aug 29 05:07:21.018139 2026] [security2:error] [pid 1028675:tid 1028836] [client 93.123.109.228:44930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9addHPfW2QFvhmL7iDwAAABo"] [Sat Aug 29 05:07:21.020887 2026] [security2:error] [pid 1028675:tid 1028836] [client 20.104.104.62:20820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/Unknown45.php"] [unique_id "apK9addHPfW2QFvhmL7iEQAAABo"] [Sat Aug 29 05:07:21.023930 2026] [security2:error] [pid 1028675:tid 1028885] [client 93.123.109.228:45074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9addHPfW2QFvhmL7iEgAAAEs"] [Sat Aug 29 05:07:21.036269 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.48.250.41:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/f35.php"] [unique_id "apK9addHPfW2QFvhmL7iFQAAADQ"] [Sat Aug 29 05:07:21.042500 2026] [security2:error] [pid 1018003:tid 1018217] [client 52.139.37.240:32758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plumplumscheese.com"] [uri "/flower.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESAwAABfo"] [Sat Aug 29 05:07:21.061445 2026] [security2:error] [pid 1028675:tid 1028843] [client 40.83.93.50:24514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/panel.php"] [unique_id "apK9addHPfW2QFvhmL7iGgAAACE"] [Sat Aug 29 05:07:21.063514 2026] [security2:error] [pid 1028675:tid 1028921] [client 52.139.37.240:14674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9addHPfW2QFvhmL7iGwAAAG8"] [Sat Aug 29 05:07:21.065827 2026] [security2:error] [pid 1028675:tid 1028877] [client 20.48.160.90:49447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "highqualitytea.com"] [uri "/zrjuyoos.php"] [unique_id "apK9addHPfW2QFvhmL7iHAAAAEM"] [Sat Aug 29 05:07:21.068538 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.48.250.41:59360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/0byte.php"] [unique_id "apK9addHPfW2QFvhmL7iHQAAADI"] [Sat Aug 29 05:07:21.070656 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.158.54.35:16831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-admin/index.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESBAAABho"] [Sat Aug 29 05:07:21.071139 2026] [security2:error] [pid 1028675:tid 1028814] [client 4.205.62.107:53254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/routes.php"] [unique_id "apK9addHPfW2QFvhmL7iHwAAAAQ"] [Sat Aug 29 05:07:21.073234 2026] [security2:error] [pid 1028675:tid 1028814] [client 158.23.147.79:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/dropdown.php"] [unique_id "apK9addHPfW2QFvhmL7iIQAAAAQ"] [Sat Aug 29 05:07:21.087635 2026] [security2:error] [pid 1028675:tid 1028909] [client 20.151.200.44:46646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/grsiuk.php"] [unique_id "apK9addHPfW2QFvhmL7iJQAAAGM"] [Sat Aug 29 05:07:21.093351 2026] [security2:error] [pid 1028675:tid 1028837] [client 127.0.0.1:40528] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "apK9aNdHPfW2QFvhmL7h-gAAABs"] [Sat Aug 29 05:07:21.093623 2026] [security2:error] [pid 1028675:tid 1028914] [client 35.194.208.44:45056] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/app/aws-exports.js"] [unique_id "apK9aNdHPfW2QFvhmL7h-AAAAGg"] [Sat Aug 29 05:07:21.129123 2026] [security2:error] [pid 1018003:tid 1018271] [client 93.123.109.228:45128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/info.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESBwAABi8"] [Sat Aug 29 05:07:21.129392 2026] [security2:error] [pid 1018003:tid 1018175] [client 93.123.109.228:44904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/infophp.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESBgAABdA"] [Sat Aug 29 05:07:21.136445 2026] [security2:error] [pid 1028675:tid 1028915] [client 20.48.250.41:35085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/easy.php"] [unique_id "apK9addHPfW2QFvhmL7iLAAAAGk"] [Sat Aug 29 05:07:21.155683 2026] [security2:error] [pid 1028675:tid 1028823] [client 20.196.209.81:11319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/disagreed.php"] [unique_id "apK9addHPfW2QFvhmL7iLQAAAA0"] [Sat Aug 29 05:07:21.156031 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.104.49.130:30078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/002.php"] [unique_id "apK9addHPfW2QFvhmL7iLwAAABA"] [Sat Aug 29 05:07:21.156079 2026] [security2:error] [pid 1028675:tid 1028876] [client 93.123.109.228:45064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/infos.php"] [unique_id "apK9addHPfW2QFvhmL7iLgAAAEI"] [Sat Aug 29 05:07:21.174952 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.48.250.41:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/wen.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESCgAABiI"] [Sat Aug 29 05:07:21.176755 2026] [security2:error] [pid 1028675:tid 1028929] [client 93.123.109.228:44930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9addHPfW2QFvhmL7iMQAAAHc"] [Sat Aug 29 05:07:21.187262 2026] [security2:error] [pid 1028675:tid 1028890] [client 93.123.109.228:44962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9addHPfW2QFvhmL7iMwAAAFA"] [Sat Aug 29 05:07:21.190437 2026] [security2:error] [pid 1028675:tid 1028887] [client 68.155.159.216:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9addHPfW2QFvhmL7iNAAAAE0"] [Sat Aug 29 05:07:21.209453 2026] [http2:warn] [pid 1018003:tid 1018272] [client 57.141.14.67:61602] h2_stream(1018003-14-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:07:21.228217 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.250.41:59305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/xr.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESDQAABdc"] [Sat Aug 29 05:07:21.229787 2026] [security2:error] [pid 1028675:tid 1028937] [client 93.123.109.228:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9addHPfW2QFvhmL7iOAAAAH8"] [Sat Aug 29 05:07:21.247205 2026] [security2:error] [pid 1028675:tid 1028910] [client 68.155.159.216:33778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/file5.php"] [unique_id "apK9addHPfW2QFvhmL7iPAAAAGQ"] [Sat Aug 29 05:07:21.248274 2026] [security2:error] [pid 1028675:tid 1028850] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9addHPfW2QFvhmL7iOwAAACg"] [Sat Aug 29 05:07:21.258523 2026] [security2:error] [pid 1028675:tid 1028825] [client 93.123.109.228:44974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9addHPfW2QFvhmL7iPQAAAA8"] [Sat Aug 29 05:07:21.269929 2026] [security2:error] [pid 1028675:tid 1028931] [client 52.139.37.240:14673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/zafir1.php"] [unique_id "apK9addHPfW2QFvhmL7iQAAAAHk"] [Sat Aug 29 05:07:21.285610 2026] [security2:error] [pid 1028675:tid 1028920] [client 40.83.93.50:7989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK9addHPfW2QFvhmL7iQgAAAG4"] [Sat Aug 29 05:07:21.294389 2026] [security2:error] [pid 1028675:tid 1028811] [client 93.123.109.228:45052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9addHPfW2QFvhmL7iQwAAAAE"] [Sat Aug 29 05:07:21.299306 2026] [security2:error] [pid 1018003:tid 1018252] [client 20.203.141.11:11266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/wk/index.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESDgAABhw"] [Sat Aug 29 05:07:21.301548 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:2040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/.well-known/index.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESDwAABd8"] [Sat Aug 29 05:07:21.302650 2026] [security2:error] [pid 1018003:tid 1018277] [client 168.107.94.195:59860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESEAAABjU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:21.308112 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.48.250.41:49039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/inc.php"] [unique_id "apK9addHPfW2QFvhmL7iRgAAADA"] [Sat Aug 29 05:07:21.345686 2026] [security2:error] [pid 1018003:tid 1018238] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/new/.env"] [unique_id "apK9aTAh5Y1i2tUxg4ESEQAABg4"] [Sat Aug 29 05:07:21.347233 2026] [security2:error] [pid 1028675:tid 1028888] [client 93.123.109.228:45178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/node-api/.env"] [unique_id "apK9addHPfW2QFvhmL7iSwAAAE4"] [Sat Aug 29 05:07:21.354599 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.104.49.130:48586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/wp-css.php"] [unique_id "apK9addHPfW2QFvhmL7iTAAAACE"] [Sat Aug 29 05:07:21.365251 2026] [security2:error] [pid 1028675:tid 1028846] [client 93.123.109.228:45074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apK9addHPfW2QFvhmL7iTQAAACQ"] [Sat Aug 29 05:07:21.366080 2026] [security2:error] [pid 1018003:tid 1018191] [client 20.203.141.11:1279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESEgAABeA"] [Sat Aug 29 05:07:21.368587 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.48.250.41:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/h02ugyh.php"] [unique_id "apK9addHPfW2QFvhmL7iTgAAAG8"] [Sat Aug 29 05:07:21.372466 2026] [security2:error] [pid 1028675:tid 1028877] [client 93.123.109.228:44830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/node/api/.env"] [unique_id "apK9addHPfW2QFvhmL7iTwAAAEM"] [Sat Aug 29 05:07:21.387465 2026] [security2:error] [pid 1018003:tid 1018157] [client 93.123.109.228:45042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/node/backend/.env"] [unique_id "apK9aTAh5Y1i2tUxg4ESEwAABb4"] [Sat Aug 29 05:07:21.391383 2026] [security2:error] [pid 1028675:tid 1028894] [client 93.123.109.228:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/nodeapi/.env"] [unique_id "apK9addHPfW2QFvhmL7iUgAAAFQ"] [Sat Aug 29 05:07:21.391663 2026] [security2:error] [pid 1028675:tid 1028898] [client 93.123.109.228:45084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/nodeweb/.env"] [unique_id "apK9addHPfW2QFvhmL7iUQAAAFg"] [Sat Aug 29 05:07:21.394702 2026] [security2:error] [pid 1028675:tid 1028930] [client 20.48.250.41:35100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/fresh3.php"] [unique_id "apK9addHPfW2QFvhmL7iUwAAAHg"] [Sat Aug 29 05:07:21.420428 2026] [security2:error] [pid 1028675:tid 1028914] [client 93.123.109.228:44974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/old/.env"] [unique_id "apK9addHPfW2QFvhmL7iWgAAAGg"] [Sat Aug 29 05:07:21.421219 2026] [security2:error] [pid 1028675:tid 1028883] [client 4.205.62.107:21608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/ms-edit.php"] [unique_id "apK9addHPfW2QFvhmL7iWwAAAEk"] [Sat Aug 29 05:07:21.436404 2026] [security2:error] [pid 1028675:tid 1028842] [client 68.155.159.216:51511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9addHPfW2QFvhmL7iXwAAACA"] [Sat Aug 29 05:07:21.443694 2026] [security2:error] [pid 1028675:tid 1028924] [client 20.48.250.41:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/6bcwiqwj.php"] [unique_id "apK9addHPfW2QFvhmL7iZQAAAHI"] [Sat Aug 29 05:07:21.446191 2026] [security2:error] [pid 1028675:tid 1028924] [client 93.123.109.228:45052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/opt/.env"] [unique_id "apK9addHPfW2QFvhmL7iZgAAAHI"] [Sat Aug 29 05:07:21.450846 2026] [security2:error] [pid 1028675:tid 1028885] [client 40.83.93.50:20834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9addHPfW2QFvhmL7iZwAAAEs"] [Sat Aug 29 05:07:21.453844 2026] [security2:error] [pid 1028675:tid 1028913] [client 158.158.54.35:29633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-admin/css/about.php"] [unique_id "apK9addHPfW2QFvhmL7iaAAAAGc"] [Sat Aug 29 05:07:21.468470 2026] [security2:error] [pid 1028675:tid 1028897] [client 68.155.159.216:38580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/radio.php"] [unique_id "apK9addHPfW2QFvhmL7iagAAAFc"] [Sat Aug 29 05:07:21.481425 2026] [security2:error] [pid 1028675:tid 1028818] [client 52.139.37.240:14675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/abc.php"] [unique_id "apK9addHPfW2QFvhmL7ibgAAAAg"] [Sat Aug 29 05:07:21.494905 2026] [security2:error] [pid 1028675:tid 1028826] [client 68.155.159.216:49158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9addHPfW2QFvhmL7icQAAABA"] [Sat Aug 29 05:07:21.526312 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.48.250.41:35489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/bgymj.php"] [unique_id "apK9addHPfW2QFvhmL7iewAAAC4"] [Sat Aug 29 05:07:21.526949 2026] [security2:error] [pid 1028675:tid 1028912] [client 158.158.54.35:16782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/radio.php"] [unique_id "apK9addHPfW2QFvhmL7ifAAAAGY"] [Sat Aug 29 05:07:21.535592 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.48.250.41:60798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/xxw.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESFwAABb0"] [Sat Aug 29 05:07:21.546331 2026] [security2:error] [pid 1028675:tid 1028880] [client 4.205.62.107:9014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/f35.php"] [unique_id "apK9addHPfW2QFvhmL7ifwAAAEY"] [Sat Aug 29 05:07:21.550364 2026] [security2:error] [pid 1028675:tid 1028902] [client 40.83.93.50:5232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/pk.php"] [unique_id "apK9addHPfW2QFvhmL7igAAAAFw"] [Sat Aug 29 05:07:21.550400 2026] [security2:error] [pid 1028675:tid 1028819] [client 68.155.159.216:51878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9addHPfW2QFvhmL7igQAAAAk"] [Sat Aug 29 05:07:21.563758 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.196.209.81:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/class_api.php"] [unique_id "apK9addHPfW2QFvhmL7ihQAAACc"] [Sat Aug 29 05:07:21.569729 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.48.250.41:49123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/easy.php"] [unique_id "apK9addHPfW2QFvhmL7iiAAAAH8"] [Sat Aug 29 05:07:21.593050 2026] [security2:error] [pid 1018003:tid 1018188] [client 192.145.125.70:43718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9aTAh5Y1i2tUxg4ESGAAABd0"] [Sat Aug 29 05:07:21.626237 2026] [security2:error] [pid 1028675:tid 1028857] [client 68.155.159.216:65054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/radio.php"] [unique_id "apK9addHPfW2QFvhmL7ikgAAAC8"] [Sat Aug 29 05:07:21.657409 2026] [security2:error] [pid 1018003:tid 1018230] [client 20.48.250.41:35115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ws69.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESGQAABgY"] [Sat Aug 29 05:07:21.670107 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.48.250.41:59273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/bolt.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESGgAABfk"] [Sat Aug 29 05:07:21.680391 2026] [security2:error] [pid 1028675:tid 1028836] [client 52.139.37.240:14972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/c1.php"] [unique_id "apK9addHPfW2QFvhmL7ilQAAABo"] [Sat Aug 29 05:07:21.682918 2026] [security2:error] [pid 1018003:tid 1018236] [client 68.155.159.216:50203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.bistrobrew.com"] [uri "/first.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESHAAABgw"] [Sat Aug 29 05:07:21.687567 2026] [security2:error] [pid 1028675:tid 1028843] [client 93.123.109.228:45178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/php.php"] [unique_id "apK9addHPfW2QFvhmL7ilgAAACE"] [Sat Aug 29 05:07:21.687760 2026] [security2:error] [pid 1028675:tid 1028830] [client 93.123.109.228:44930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/php-info.php"] [unique_id "apK9addHPfW2QFvhmL7ilwAAABQ"] [Sat Aug 29 05:07:21.695095 2026] [security2:error] [pid 1028675:tid 1028921] [client 158.23.147.79:35839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-login.php"] [unique_id "apK9addHPfW2QFvhmL7imAAAAG8"] [Sat Aug 29 05:07:21.697693 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.197.61.180:7883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/22.php"] [unique_id "apK9addHPfW2QFvhmL7imgAAAB8"] [Sat Aug 29 05:07:21.698542 2026] [security2:error] [pid 1028675:tid 1028877] [client 168.107.94.195:60305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9addHPfW2QFvhmL7imwAAAEM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:21.703275 2026] [security2:error] [pid 1018003:tid 1018224] [client 93.123.109.228:45042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/php_info.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESHQAABgE"] [Sat Aug 29 05:07:21.713854 2026] [security2:error] [pid 1018003:tid 1018161] [client 4.205.62.107:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/tinyfilemanager.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESHgAABcI"] [Sat Aug 29 05:07:21.719221 2026] [security2:error] [pid 1028675:tid 1028909] [client 93.123.109.228:45180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/phpinfo.php"] [unique_id "apK9addHPfW2QFvhmL7inQAAAGM"] [Sat Aug 29 05:07:21.721883 2026] [security2:error] [pid 1028675:tid 1028926] [client 158.23.147.79:17452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9addHPfW2QFvhmL7ingAAAHQ"] [Sat Aug 29 05:07:21.730380 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.48.250.41:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/fresh3.php"] [unique_id "apK9addHPfW2QFvhmL7ioQAAABI"] [Sat Aug 29 05:07:21.749105 2026] [security2:error] [pid 1028675:tid 1028935] [client 93.123.109.228:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/portal/.env"] [unique_id "apK9addHPfW2QFvhmL7ipQAAAH0"] [Sat Aug 29 05:07:21.754977 2026] [security2:error] [pid 1028675:tid 1028924] [client 158.23.147.79:50068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/cong.php"] [unique_id "apK9addHPfW2QFvhmL7iqAAAAHI"] [Sat Aug 29 05:07:21.766801 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.203.141.11:13622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/admin.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESIAAABi4"] [Sat Aug 29 05:07:21.774603 2026] [security2:error] [pid 1028675:tid 1028818] [client 4.205.62.107:58445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/aws_settings.php"] [unique_id "apK9addHPfW2QFvhmL7irAAAAAg"] [Sat Aug 29 05:07:21.789273 2026] [security2:error] [pid 1028675:tid 1028927] [client 20.48.250.41:35134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ccs.php"] [unique_id "apK9addHPfW2QFvhmL7irgAAAHU"] [Sat Aug 29 05:07:21.791412 2026] [security2:error] [pid 1028675:tid 1028823] [client 20.151.200.44:47361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/ahy66.php"] [unique_id "apK9addHPfW2QFvhmL7irwAAAA0"] [Sat Aug 29 05:07:21.799186 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:59279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/rtx.php"] [unique_id "apK9addHPfW2QFvhmL7isAAAAHM"] [Sat Aug 29 05:07:21.811931 2026] [security2:error] [pid 1028675:tid 1028856] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apK9addHPfW2QFvhmL7isgAAAC4"] [Sat Aug 29 05:07:21.814393 2026] [security2:error] [pid 1018003:tid 1018233] [client 4.205.62.107:22424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/server_info.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESIgAABgk"] [Sat Aug 29 05:07:21.817411 2026] [security2:error] [pid 1028675:tid 1028912] [client 93.123.109.228:44940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/product/.env"] [unique_id "apK9addHPfW2QFvhmL7iswAAAGY"] [Sat Aug 29 05:07:21.824003 2026] [security2:error] [pid 1028675:tid 1028839] [client 68.155.159.216:12186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9addHPfW2QFvhmL7itAAAAB0"] [Sat Aug 29 05:07:21.830191 2026] [security2:error] [pid 1028675:tid 1028816] [client 93.123.109.228:45052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apK9addHPfW2QFvhmL7itQAAAAY"] [Sat Aug 29 05:07:21.846414 2026] [security2:error] [pid 1028675:tid 1028937] [client 93.123.109.228:45164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/project/.env"] [unique_id "apK9addHPfW2QFvhmL7iuQAAAH8"] [Sat Aug 29 05:07:21.855867 2026] [security2:error] [pid 1028675:tid 1028861] [client 93.123.109.228:45200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/public-api/.env"] [unique_id "apK9addHPfW2QFvhmL7iugAAADM"] [Sat Aug 29 05:07:21.870014 2026] [security2:error] [pid 1028675:tid 1028825] [client 93.123.109.228:45162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/public/.env"] [unique_id "apK9addHPfW2QFvhmL7ivgAAAA8"] [Sat Aug 29 05:07:21.870738 2026] [security2:error] [pid 1028675:tid 1028931] [client 93.123.109.228:45074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/public/phpinfo.php"] [unique_id "apK9addHPfW2QFvhmL7ivwAAAHk"] [Sat Aug 29 05:07:21.874059 2026] [security2:error] [pid 1028675:tid 1028811] [client 158.23.147.79:30626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9addHPfW2QFvhmL7iwgAAAAE"] [Sat Aug 29 05:07:21.874727 2026] [security2:error] [pid 1028675:tid 1028822] [client 52.139.37.240:14669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/index.php/feed/atom/"] [unique_id "apK9addHPfW2QFvhmL7iwwAAAAw"] [Sat Aug 29 05:07:21.878302 2026] [security2:error] [pid 1018003:tid 1018185] [client 103.168.67.159:49990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9aTAh5Y1i2tUxg4ESJAAABdo"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:07:21.887591 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.48.250.41:49097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/bgymj.php"] [unique_id "apK9addHPfW2QFvhmL7ixAAAAD0"] [Sat Aug 29 05:07:21.890746 2026] [security2:error] [pid 1028675:tid 1028866] [client 93.123.109.228:44830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/public_html/.env"] [unique_id "apK9addHPfW2QFvhmL7ixQAAADg"] [Sat Aug 29 05:07:21.900424 2026] [security2:error] [pid 1028675:tid 1028845] [client 40.83.93.50:7531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/inputs.php"] [unique_id "apK9addHPfW2QFvhmL7ixgAAACM"] [Sat Aug 29 05:07:21.902474 2026] [security2:error] [pid 1028675:tid 1028911] [client 195.178.110.247:5386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lifeandmemorycenter.com"] [uri "/index.php"] [unique_id "apK9addHPfW2QFvhmL7ixwAAAGU"] [Sat Aug 29 05:07:21.915125 2026] [security2:error] [pid 1028675:tid 1028913] [client 158.158.54.35:16137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/system_log.php"] [unique_id "apK9addHPfW2QFvhmL7iyQAAAGc"] [Sat Aug 29 05:07:21.915771 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.203.141.11:24065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-good.php"] [unique_id "apK9addHPfW2QFvhmL7iygAAAAQ"] [Sat Aug 29 05:07:21.929618 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.48.250.41:35102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/mar.php"] [unique_id "apK9addHPfW2QFvhmL7izQAAAFo"] [Sat Aug 29 05:07:21.930293 2026] [security2:error] [pid 1028675:tid 1028895] [client 93.123.109.228:45084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/qa/.env"] [unique_id "apK9addHPfW2QFvhmL7iywAAAFU"] [Sat Aug 29 05:07:21.933609 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.48.250.41:60737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/ckk.php"] [unique_id "apK9addHPfW2QFvhmL7izgAAAEo"] [Sat Aug 29 05:07:21.934322 2026] [security2:error] [pid 1028675:tid 1028915] [client 40.83.93.50:20828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/languages/chosen.php"] [unique_id "apK9addHPfW2QFvhmL7izwAAAGk"] [Sat Aug 29 05:07:21.952611 2026] [security2:error] [pid 1028675:tid 1028836] [client 68.155.159.216:24404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9addHPfW2QFvhmL7i0QAAABo"] [Sat Aug 29 05:07:21.983244 2026] [security2:error] [pid 1028675:tid 1028887] [client 158.158.54.35:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/item.php"] [unique_id "apK9addHPfW2QFvhmL7i1gAAAE0"] [Sat Aug 29 05:07:21.992745 2026] [security2:error] [pid 1028675:tid 1028846] [client 158.23.147.79:25509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9addHPfW2QFvhmL7i2AAAACQ"] [Sat Aug 29 05:07:22.006246 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.196.209.81:11286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/aksinet.php"] [unique_id "apK9atdHPfW2QFvhmL7i3AAAACs"] [Sat Aug 29 05:07:22.028575 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.48.250.41:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ws69.php"] [unique_id "apK9atdHPfW2QFvhmL7i4AAAABI"] [Sat Aug 29 05:07:22.032309 2026] [security2:error] [pid 1018003:tid 1018152] [client 40.83.93.50:24523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/plugin-install.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESJwAABbk"] [Sat Aug 29 05:07:22.035427 2026] [security2:error] [pid 1028675:tid 1028883] [client 158.23.147.79:48132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apK9atdHPfW2QFvhmL7i4wAAAEk"] [Sat Aug 29 05:07:22.071202 2026] [security2:error] [pid 1028675:tid 1028897] [client 158.23.147.79:61595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9atdHPfW2QFvhmL7i5wAAAFc"] [Sat Aug 29 05:07:22.074772 2026] [security2:error] [pid 1028675:tid 1028926] [client 52.139.37.240:14661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/root.php"] [unique_id "apK9atdHPfW2QFvhmL7i6AAAAHQ"] [Sat Aug 29 05:07:22.077692 2026] [security2:error] [pid 1028675:tid 1028881] [client 195.178.110.247:48656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lifeandmemorycenter.com"] [uri "/index.php"] [unique_id "apK9atdHPfW2QFvhmL7i6QAAAEc"] [Sat Aug 29 05:07:22.078928 2026] [security2:error] [pid 1028675:tid 1028879] [client 168.107.94.195:60673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9atdHPfW2QFvhmL7i6gAAAEU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:22.087872 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:62560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ochentayuno.com"] [uri "/R57.php"] [unique_id "apK9atdHPfW2QFvhmL7i7gAAAHM"] [Sat Aug 29 05:07:22.113701 2026] [security2:error] [pid 1028675:tid 1028816] [client 20.48.250.41:35120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ccu.php"] [unique_id "apK9atdHPfW2QFvhmL7i9AAAAAY"] [Sat Aug 29 05:07:22.121672 2026] [security2:error] [pid 1028675:tid 1028928] [client 146.70.194.254:44288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/website/wp-includes/wlwmanifest.xml"] [unique_id "apK9atdHPfW2QFvhmL7i9QAAAHY"] [Sat Aug 29 05:07:22.165303 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.48.250.41:49125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ccs.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESLQAABik"] [Sat Aug 29 05:07:22.178467 2026] [security2:error] [pid 1028675:tid 1028825] [client 158.23.147.79:26456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/sad/about.php"] [unique_id "apK9atdHPfW2QFvhmL7jAAAAAA8"] [Sat Aug 29 05:07:22.192735 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.151.200.44:46539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/gaje.php"] [unique_id "apK9atdHPfW2QFvhmL7jCwAAAAU"] [Sat Aug 29 05:07:22.197158 2026] [security2:error] [pid 1028675:tid 1028862] [client 192.145.125.70:43732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9atdHPfW2QFvhmL7jDgAAADQ"] [Sat Aug 29 05:07:22.212983 2026] [security2:error] [pid 1028675:tid 1028929] [client 4.205.62.107:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/aww.php"] [unique_id "apK9atdHPfW2QFvhmL7jEQAAAHc"] [Sat Aug 29 05:07:22.234118 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.203.141.11:38617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/php8.php"] [unique_id "apK9atdHPfW2QFvhmL7jFQAAAAg"] [Sat Aug 29 05:07:22.262459 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.48.250.41:35093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ak.php"] [unique_id "apK9atdHPfW2QFvhmL7jGgAAACU"] [Sat Aug 29 05:07:22.269075 2026] [security2:error] [pid 1028675:tid 1028915] [client 93.123.109.228:45084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/s3/.env.bak"] [unique_id "apK9atdHPfW2QFvhmL7jHQAAAGk"] [Sat Aug 29 05:07:22.274449 2026] [security2:error] [pid 1028675:tid 1028811] [client 52.139.37.240:14626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/shell.php"] [unique_id "apK9atdHPfW2QFvhmL7jHwAAAAE"] [Sat Aug 29 05:07:22.301901 2026] [security2:error] [pid 1018003:tid 1018160] [client 20.48.250.41:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/mar.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESMwAABcE"] [Sat Aug 29 05:07:22.327801 2026] [security2:error] [pid 1028675:tid 1028875] [client 158.23.147.79:30613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9atdHPfW2QFvhmL7jJQAAAEE"] [Sat Aug 29 05:07:22.333806 2026] [security2:error] [pid 1018003:tid 1018219] [client 68.155.159.216:65071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/radio.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESNQAABfw"] [Sat Aug 29 05:07:22.340861 2026] [core:error] [pid 1028675:tid 1028898] [client 195.178.110.60:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.340879 2026] [core:error] [pid 1028675:tid 1028898] [client 195.178.110.60:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.377892 2026] [security2:error] [pid 1028675:tid 1028822] [client 40.83.93.50:7958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK9atdHPfW2QFvhmL7jNgAAAAw"] [Sat Aug 29 05:07:22.389107 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.203.141.11:1368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESOAAABis"] [Sat Aug 29 05:07:22.393177 2026] [security2:error] [pid 1028675:tid 1028913] [client 158.158.54.35:29647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/24.php"] [unique_id "apK9atdHPfW2QFvhmL7jOAAAAGc"] [Sat Aug 29 05:07:22.401924 2026] [security2:error] [pid 1028675:tid 1028901] [client 20.48.250.41:35466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/lib.php"] [unique_id "apK9atdHPfW2QFvhmL7jOQAAAFs"] [Sat Aug 29 05:07:22.405268 2026] [security2:error] [pid 1028675:tid 1028820] [client 40.83.93.50:13628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/languages/index.php"] [unique_id "apK9atdHPfW2QFvhmL7jOwAAAAo"] [Sat Aug 29 05:07:22.405705 2026] [security2:error] [pid 1028675:tid 1028824] [client 93.123.109.228:45162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env"] [unique_id "apK9atdHPfW2QFvhmL7jOgAAAA4"] [Sat Aug 29 05:07:22.413225 2026] [security2:error] [pid 1028675:tid 1028867] [client 93.123.109.228:44858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/server/api/.env"] [unique_id "apK9atdHPfW2QFvhmL7jPAAAADk"] [Sat Aug 29 05:07:22.423510 2026] [security2:error] [pid 1028675:tid 1028813] [client 68.155.159.216:1932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9atdHPfW2QFvhmL7jPgAAAAM"] [Sat Aug 29 05:07:22.431133 2026] [security2:error] [pid 1028675:tid 1028897] [client 93.123.109.228:44830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/server/backend/.env"] [unique_id "apK9atdHPfW2QFvhmL7jPwAAAFc"] [Sat Aug 29 05:07:22.435482 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.48.250.41:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ccu.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESOQAABb0"] [Sat Aug 29 05:07:22.435500 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.196.209.81:11296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/alfa-rex1.php"] [unique_id "apK9atdHPfW2QFvhmL7jQgAAACE"] [Sat Aug 29 05:07:22.457317 2026] [security2:error] [pid 1028675:tid 1028927] [client 68.155.159.216:33650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9atdHPfW2QFvhmL7jRQAAAHU"] [Sat Aug 29 05:07:22.458940 2026] [security2:error] [pid 1028675:tid 1028823] [client 168.107.94.195:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9atdHPfW2QFvhmL7jRgAAAA0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:22.460128 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.104.49.130:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/classwithtostring.php"] [unique_id "apK9atdHPfW2QFvhmL7jRwAAAHM"] [Sat Aug 29 05:07:22.463127 2026] [security2:error] [pid 1018003:tid 1018179] [client 52.139.37.240:14679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESOgAABdQ"] [Sat Aug 29 05:07:22.469957 2026] [security2:error] [pid 1028675:tid 1028856] [client 195.178.110.101:36650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/index.php"] [unique_id "apK9atdHPfW2QFvhmL7jSAAAAC4"] [Sat Aug 29 05:07:22.476928 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.197.61.180:7711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/bak.phps"] [unique_id "apK9ajAh5Y1i2tUxg4ESOwAABgc"] [Sat Aug 29 05:07:22.493689 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.158.54.35:22456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/t.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESPAAABdk"] [Sat Aug 29 05:07:22.506610 2026] [security2:error] [pid 1028675:tid 1028880] [client 40.83.93.50:5673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/plugins/img/themes/plugins/maintenance.php"] [unique_id "apK9atdHPfW2QFvhmL7jTQAAAEY"] [Sat Aug 29 05:07:22.536713 2026] [security2:error] [pid 1028675:tid 1028825] [client 158.23.147.79:32643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/.well-known/content.php"] [unique_id "apK9atdHPfW2QFvhmL7jTwAAAA8"] [Sat Aug 29 05:07:22.546138 2026] [security2:error] [pid 1028675:tid 1028858] [client 68.155.159.216:51785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/log-mama/function.php"] [unique_id "apK9atdHPfW2QFvhmL7jUQAAADA"] [Sat Aug 29 05:07:22.546704 2026] [security2:error] [pid 1028675:tid 1028871] [client 93.123.109.228:45052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apK9atdHPfW2QFvhmL7jUgAAAD0"] [Sat Aug 29 05:07:22.547796 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.49.130:30036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/jp.php"] [unique_id "apK9atdHPfW2QFvhmL7jUwAAAEQ"] [Sat Aug 29 05:07:22.552364 2026] [security2:error] [pid 1028675:tid 1028936] [client 93.123.109.228:45192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apK9atdHPfW2QFvhmL7jVAAAAH4"] [Sat Aug 29 05:07:22.575265 2026] [security2:error] [pid 1028675:tid 1028845] [client 68.155.159.216:56513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9atdHPfW2QFvhmL7jXAAAACM"] [Sat Aug 29 05:07:22.575857 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.48.250.41:35458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/wp-style.php"] [unique_id "apK9atdHPfW2QFvhmL7jXQAAAFo"] [Sat Aug 29 05:07:22.588051 2026] [security2:error] [pid 1028675:tid 1028919] [client 4.205.62.107:22428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/sys.php"] [unique_id "apK9atdHPfW2QFvhmL7jYQAAAG0"] [Sat Aug 29 05:07:22.603590 2026] [security2:error] [pid 1028675:tid 1028836] [client 68.155.159.216:49229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/content.php"] [unique_id "apK9atdHPfW2QFvhmL7jYwAAABo"] [Sat Aug 29 05:07:22.611411 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.48.250.41:49112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ak.php"] [unique_id "apK9atdHPfW2QFvhmL7jZAAAAB8"] [Sat Aug 29 05:07:22.641996 2026] [security2:error] [pid 1028675:tid 1028894] [client 93.123.109.228:45164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/shared/.env"] [unique_id "apK9atdHPfW2QFvhmL7jagAAAFQ"] [Sat Aug 29 05:07:22.646715 2026] [security2:error] [pid 1028675:tid 1028898] [client 93.123.109.228:44974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/shop/.env"] [unique_id "apK9atdHPfW2QFvhmL7jbQAAAFg"] [Sat Aug 29 05:07:22.653799 2026] [security2:error] [pid 1028675:tid 1028859] [client 34.81.157.26:35528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/home/ubuntu/.env"] [unique_id "apK9atdHPfW2QFvhmL7jcAAAADE"] [Sat Aug 29 05:07:22.667301 2026] [security2:error] [pid 1018003:tid 1018174] [client 34.81.157.26:35544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/var/www/html/.env"] [unique_id "apK9ajAh5Y1i2tUxg4ESQAAABc8"] [Sat Aug 29 05:07:22.668311 2026] [security2:error] [pid 1028675:tid 1028861] [client 34.81.157.26:35540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/var/www/.env"] [unique_id "apK9atdHPfW2QFvhmL7jegAAADM"] [Sat Aug 29 05:07:22.669465 2026] [security2:error] [pid 1028675:tid 1028903] [client 34.81.157.26:35556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/usr/src/app/.env"] [unique_id "apK9atdHPfW2QFvhmL7jewAAAF0"] [Sat Aug 29 05:07:22.671100 2026] [security2:error] [pid 1028675:tid 1028899] [client 34.81.157.26:35552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/app/terraform.tfstate"] [unique_id "apK9atdHPfW2QFvhmL7jfAAAAFk"] [Sat Aug 29 05:07:22.671478 2026] [security2:error] [pid 1028675:tid 1028931] [client 34.81.157.26:35564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/root/terraform.tfstate"] [unique_id "apK9atdHPfW2QFvhmL7jfwAAAHk"] [Sat Aug 29 05:07:22.671964 2026] [security2:error] [pid 1028675:tid 1028910] [client 52.139.37.240:14687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK9atdHPfW2QFvhmL7jgAAAAGQ"] [Sat Aug 29 05:07:22.685002 2026] [core:error] [pid 1018003:tid 1018224] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.685018 2026] [core:error] [pid 1018003:tid 1018224] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.685613 2026] [security2:error] [pid 1028675:tid 1028820] [client 20.104.49.130:43041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/static.php"] [unique_id "apK9atdHPfW2QFvhmL7jiAAAAAo"] [Sat Aug 29 05:07:22.691962 2026] [security2:error] [pid 1028675:tid 1028867] [client 4.205.62.107:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/params.php"] [unique_id "apK9atdHPfW2QFvhmL7jigAAADk"] [Sat Aug 29 05:07:22.706290 2026] [core:error] [pid 1028675:tid 1028813] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.706307 2026] [core:error] [pid 1028675:tid 1028813] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.719352 2026] [security2:error] [pid 1028675:tid 1028879] [client 20.151.200.44:47406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/wp-admin/zwso.php"] [unique_id "apK9atdHPfW2QFvhmL7jjwAAAEU"] [Sat Aug 29 05:07:22.720590 2026] [security2:error] [pid 1018003:tid 1018226] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env"] [unique_id "apK9ajAh5Y1i2tUxg4ESRAAABgM"] [Sat Aug 29 05:07:22.724015 2026] [core:error] [pid 1018003:tid 1018186] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.724036 2026] [core:error] [pid 1018003:tid 1018186] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.728311 2026] [core:error] [pid 1028675:tid 1028914] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.728326 2026] [core:error] [pid 1028675:tid 1028914] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.728757 2026] [core:error] [pid 1028675:tid 1028927] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.728772 2026] [core:error] [pid 1028675:tid 1028927] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.730044 2026] [core:error] [pid 1018003:tid 1018246] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.730055 2026] [core:error] [pid 1018003:tid 1018246] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.737173 2026] [core:error] [pid 1018003:tid 1018159] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.737191 2026] [core:error] [pid 1018003:tid 1018159] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.738532 2026] [security2:error] [pid 1018003:tid 1018217] [client 68.155.159.216:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESSAAABfo"] [Sat Aug 29 05:07:22.742140 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.48.250.41:49127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/lib.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESSQAABho"] [Sat Aug 29 05:07:22.803250 2026] [security2:error] [pid 1018003:tid 1018261] [client 192.145.125.70:43738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9ajAh5Y1i2tUxg4ESSwAABiU"] [Sat Aug 29 05:07:22.828653 2026] [security2:error] [pid 1028675:tid 1028848] [client 158.23.147.79:17468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/radio.php"] [unique_id "apK9atdHPfW2QFvhmL7joQAAACY"] [Sat Aug 29 05:07:22.839420 2026] [security2:error] [pid 1018003:tid 1018183] [client 168.107.94.195:61423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESTQAABdg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:22.842267 2026] [security2:error] [pid 1028675:tid 1028811] [client 93.123.109.228:45200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/srv/.env"] [unique_id "apK9atdHPfW2QFvhmL7jowAAAAE"] [Sat Aug 29 05:07:22.851050 2026] [core:error] [pid 1028675:tid 1028897] [client 158.158.54.35:20565] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.851065 2026] [core:error] [pid 1028675:tid 1028897] [client 158.158.54.35:20565] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:22.853277 2026] [security2:error] [pid 1018003:tid 1018195] [client 4.205.62.107:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/05.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESTgAABeQ"] [Sat Aug 29 05:07:22.861893 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.48.250.41:35123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/browse.php"] [unique_id "apK9atdHPfW2QFvhmL7jpQAAAGE"] [Sat Aug 29 05:07:22.862250 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.147.79:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESTwAABik"] [Sat Aug 29 05:07:22.863238 2026] [security2:error] [pid 1018003:tid 1018207] [client 40.83.93.50:11679] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/1.php7"] [unique_id "apK9ajAh5Y1i2tUxg4ESUQAABfA"] [Sat Aug 29 05:07:22.863335 2026] [security2:error] [pid 1018003:tid 1018207] [client 40.83.93.50:11679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/1.php7"] [unique_id "apK9ajAh5Y1i2tUxg4ESUQAABfA"] [Sat Aug 29 05:07:22.863445 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.196.209.81:14731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/headerg.php"] [unique_id "apK9atdHPfW2QFvhmL7jpgAAACw"] [Sat Aug 29 05:07:22.863898 2026] [security2:error] [pid 1018003:tid 1018182] [client 93.123.109.228:45138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apK9ajAh5Y1i2tUxg4ESUAAABdc"] [Sat Aug 29 05:07:22.865603 2026] [security2:error] [pid 1028675:tid 1028855] [client 20.203.141.11:33714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/install.php"] [unique_id "apK9atdHPfW2QFvhmL7jpwAAAC0"] [Sat Aug 29 05:07:22.869045 2026] [security2:error] [pid 1028675:tid 1028830] [client 93.123.109.228:45052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apK9atdHPfW2QFvhmL7jqAAAABQ"] [Sat Aug 29 05:07:22.871308 2026] [security2:error] [pid 1028675:tid 1028895] [client 52.139.37.240:14477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-header-json.php"] [unique_id "apK9atdHPfW2QFvhmL7jqQAAAFU"] [Sat Aug 29 05:07:22.879139 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.203.141.11:5779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/abcd.php"] [unique_id "apK9atdHPfW2QFvhmL7jqgAAAB4"] [Sat Aug 29 05:07:22.879247 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.48.250.41:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/wp-style.php"] [unique_id "apK9atdHPfW2QFvhmL7jqwAAAFg"] [Sat Aug 29 05:07:22.895056 2026] [security2:error] [pid 1018003:tid 1018155] [client 40.83.93.50:13606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/languages/min.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESUwAABbw"] [Sat Aug 29 05:07:22.915516 2026] [security2:error] [pid 1018003:tid 1018234] [client 4.205.62.107:58375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/aws-credentials.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESVAAABgo"] [Sat Aug 29 05:07:22.919846 2026] [security2:error] [pid 1028675:tid 1028859] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/stg/.env"] [unique_id "apK9atdHPfW2QFvhmL7jsAAAADE"] [Sat Aug 29 05:07:22.925302 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.151.200.44:47353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/Contrller.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESVQAABcM"] [Sat Aug 29 05:07:22.935565 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:12215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/nf_tracking.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESVgAABco"] [Sat Aug 29 05:07:22.960989 2026] [security2:error] [pid 1018003:tid 1018271] [client 158.158.54.35:17594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/i.php"] [unique_id "apK9ajAh5Y1i2tUxg4ESVwAABi8"] [Sat Aug 29 05:07:22.966933 2026] [security2:error] [pid 1028675:tid 1028892] [client 4.205.62.107:22421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/87.php"] [unique_id "apK9atdHPfW2QFvhmL7jugAAAFI"] [Sat Aug 29 05:07:22.991196 2026] [security2:error] [pid 1028675:tid 1028824] [client 158.23.147.79:30640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9atdHPfW2QFvhmL7jvwAAAA4"] [Sat Aug 29 05:07:22.993068 2026] [security2:error] [pid 1028675:tid 1028896] [client 213.202.253.4:65104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/postnews.php"] [unique_id "apK9atdHPfW2QFvhmL7jwAAAAFY"], referer: www.google.com [Sat Aug 29 05:07:23.000460 2026] [security2:error] [pid 1028675:tid 1028842] [client 93.123.109.228:45200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apK9atdHPfW2QFvhmL7jwgAAACA"] [Sat Aug 29 05:07:23.004260 2026] [security2:error] [pid 1018003:tid 1018164] [client 40.83.93.50:5689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/security.php"] [unique_id "apK9azAh5Y1i2tUxg4ESWgAABcU"] [Sat Aug 29 05:07:23.023234 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.48.250.41:49072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/browse.php"] [unique_id "apK9azAh5Y1i2tUxg4ESXAAABjE"] [Sat Aug 29 05:07:23.071763 2026] [security2:error] [pid 1028675:tid 1028880] [client 93.123.109.228:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apK9a9dHPfW2QFvhmL7jzAAAAEY"] [Sat Aug 29 05:07:23.085674 2026] [security2:error] [pid 1018003:tid 1018157] [client 52.139.37.240:14677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/zup.php"] [unique_id "apK9azAh5Y1i2tUxg4ESXgAABb4"] [Sat Aug 29 05:07:23.123700 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.23.147.79:25564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9azAh5Y1i2tUxg4ESXwAABgc"] [Sat Aug 29 05:07:23.150475 2026] [security2:error] [pid 1028675:tid 1028825] [client 93.123.109.228:44858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/test.php"] [unique_id "apK9a9dHPfW2QFvhmL7j3QAAAA8"] [Sat Aug 29 05:07:23.153170 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.48.250.41:49026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/zoo.php"] [unique_id "apK9a9dHPfW2QFvhmL7j3wAAADA"] [Sat Aug 29 05:07:23.153929 2026] [security2:error] [pid 1028675:tid 1028815] [client 93.123.109.228:45148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apK9a9dHPfW2QFvhmL7j3gAAAAU"] [Sat Aug 29 05:07:23.153993 2026] [security2:error] [pid 1028675:tid 1028908] [client 158.23.147.79:48150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/user/index.php"] [unique_id "apK9a9dHPfW2QFvhmL7j4AAAAGI"] [Sat Aug 29 05:07:23.158347 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.104.49.130:46559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/about.php"] [unique_id "apK9a9dHPfW2QFvhmL7j4QAAACg"] [Sat Aug 29 05:07:23.160338 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.48.250.41:35465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/zoo.php"] [unique_id "apK9azAh5Y1i2tUxg4ESYAAABcQ"] [Sat Aug 29 05:07:23.173171 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.151.200.44:46627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/Zeiss.php"] [unique_id "apK9a9dHPfW2QFvhmL7j4gAAABA"] [Sat Aug 29 05:07:23.198440 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.49.130:60968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/fling.php"] [unique_id "apK9a9dHPfW2QFvhmL7j5QAAAEQ"] [Sat Aug 29 05:07:23.206890 2026] [security2:error] [pid 1028675:tid 1028901] [client 20.197.61.180:7929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/install.php"] [unique_id "apK9a9dHPfW2QFvhmL7j5gAAAFs"] [Sat Aug 29 05:07:23.211282 2026] [security2:error] [pid 1028675:tid 1028936] [client 93.123.109.228:44962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/user/.env"] [unique_id "apK9a9dHPfW2QFvhmL7j5wAAAH4"] [Sat Aug 29 05:07:23.233290 2026] [security2:error] [pid 1028675:tid 1028900] [client 93.123.109.228:44974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/v1/.env"] [unique_id "apK9a9dHPfW2QFvhmL7j6gAAAFo"] [Sat Aug 29 05:07:23.240947 2026] [security2:error] [pid 1028675:tid 1028860] [client 168.107.94.195:61800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9a9dHPfW2QFvhmL7j6wAAADI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:23.256604 2026] [security2:error] [pid 1018003:tid 1018174] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/v2/.env"] [unique_id "apK9azAh5Y1i2tUxg4ESZAAABc8"] [Sat Aug 29 05:07:23.258667 2026] [security2:error] [pid 1028675:tid 1028759] [remote 136.108.23.170:55262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thesmartpm.com"] [uri "/.env"] [unique_id "apK9a9dHPfW2QFvhmL7j7gAAIU4"] [Sat Aug 29 05:07:23.260733 2026] [security2:error] [pid 1028675:tid 1028835] [client 93.123.109.228:45052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/v3/.env"] [unique_id "apK9a9dHPfW2QFvhmL7j8AAAABk"] [Sat Aug 29 05:07:23.281410 2026] [security2:error] [pid 1028675:tid 1028911] [client 52.139.37.240:14707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/a9.php"] [unique_id "apK9a9dHPfW2QFvhmL7j9AAAAGU"] [Sat Aug 29 05:07:23.283176 2026] [security2:error] [pid 1028675:tid 1028861] [client 158.23.147.79:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/admin.php"] [unique_id "apK9a9dHPfW2QFvhmL7j9QAAADM"] [Sat Aug 29 05:07:23.295439 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.48.250.41:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/elp.php"] [unique_id "apK9a9dHPfW2QFvhmL7j9gAAACs"] [Sat Aug 29 05:07:23.298386 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.158.54.35:31481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apK9azAh5Y1i2tUxg4ESZQAABdk"] [Sat Aug 29 05:07:23.329602 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.196.209.81:15180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/meta.php"] [unique_id "apK9a9dHPfW2QFvhmL7j-AAAAAs"] [Sat Aug 29 05:07:23.337425 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.203.141.11:3035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/ioxi-o.php"] [unique_id "apK9a9dHPfW2QFvhmL7j-gAAAD0"] [Sat Aug 29 05:07:23.355408 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.203.141.11:1368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-access.php"] [unique_id "apK9azAh5Y1i2tUxg4ESZwAABgw"] [Sat Aug 29 05:07:23.365774 2026] [security2:error] [pid 1028675:tid 1028880] [client 4.205.62.107:56056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/maxro.php"] [unique_id "apK9a9dHPfW2QFvhmL7j_wAAAEY"] [Sat Aug 29 05:07:23.366509 2026] [security2:error] [pid 1028675:tid 1028881] [client 68.155.159.216:33745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/file88.php"] [unique_id "apK9a9dHPfW2QFvhmL7kAAAAAEc"] [Sat Aug 29 05:07:23.376150 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.48.250.41:35075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/elp.php"] [unique_id "apK9a9dHPfW2QFvhmL7kAwAAAF4"] [Sat Aug 29 05:07:23.380114 2026] [security2:error] [pid 1028675:tid 1028919] [client 40.83.93.50:20840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/languages/pk.php"] [unique_id "apK9a9dHPfW2QFvhmL7kBgAAAG0"] [Sat Aug 29 05:07:23.402390 2026] [security2:error] [pid 1028675:tid 1028849] [client 192.145.125.70:43742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9a9dHPfW2QFvhmL7kCAAAACc"] [Sat Aug 29 05:07:23.428125 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.48.250.41:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/666.php"] [unique_id "apK9azAh5Y1i2tUxg4ESaQAABd4"] [Sat Aug 29 05:07:23.430052 2026] [security2:error] [pid 1028675:tid 1028858] [client 93.123.109.228:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apK9a9dHPfW2QFvhmL7kCwAAADA"] [Sat Aug 29 05:07:23.434237 2026] [security2:error] [pid 1028675:tid 1028842] [client 158.158.54.35:22439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/deepseek_d.php"] [unique_id "apK9a9dHPfW2QFvhmL7kDQAAACA"] [Sat Aug 29 05:07:23.438317 2026] [security2:error] [pid 1028675:tid 1028920] [client 40.83.93.50:7516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/ds.php"] [unique_id "apK9a9dHPfW2QFvhmL7kDgAAAG4"] [Sat Aug 29 05:07:23.442892 2026] [security2:error] [pid 1028675:tid 1028925] [client 68.155.159.216:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9a9dHPfW2QFvhmL7kDwAAAHM"] [Sat Aug 29 05:07:23.446802 2026] [security2:error] [pid 1028675:tid 1028866] [client 93.123.109.228:44940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apK9a9dHPfW2QFvhmL7kEAAAADg"] [Sat Aug 29 05:07:23.454827 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.147.79:30507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9azAh5Y1i2tUxg4ESagAABeE"] [Sat Aug 29 05:07:23.494326 2026] [security2:error] [pid 1028675:tid 1028825] [client 52.139.37.240:14693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/admin/index.php"] [unique_id "apK9a9dHPfW2QFvhmL7kEgAAAA8"] [Sat Aug 29 05:07:23.502077 2026] [security2:error] [pid 1028675:tid 1028918] [client 40.83.93.50:5679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9a9dHPfW2QFvhmL7kEwAAAGw"] [Sat Aug 29 05:07:23.511636 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.48.250.41:35083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/666.php"] [unique_id "apK9azAh5Y1i2tUxg4ESbAAABeU"] [Sat Aug 29 05:07:23.515778 2026] [security2:error] [pid 1028675:tid 1028847] [client 158.23.147.79:53847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/dropdown.php"] [unique_id "apK9a9dHPfW2QFvhmL7kFwAAACU"] [Sat Aug 29 05:07:23.523885 2026] [security2:error] [pid 1018003:tid 1018261] [client 93.123.109.228:45138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/web/.env"] [unique_id "apK9azAh5Y1i2tUxg4ESbQAABiU"] [Sat Aug 29 05:07:23.529101 2026] [security2:error] [pid 1028675:tid 1028818] [client 68.155.159.216:2044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/radio.php"] [unique_id "apK9a9dHPfW2QFvhmL7kGAAAAAg"] [Sat Aug 29 05:07:23.561678 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.48.250.41:49036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/knmt.php"] [unique_id "apK9a9dHPfW2QFvhmL7kHQAAAE0"] [Sat Aug 29 05:07:23.575070 2026] [security2:error] [pid 1028675:tid 1028860] [client 68.155.159.216:33615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-admin.php"] [unique_id "apK9a9dHPfW2QFvhmL7kHwAAADI"] [Sat Aug 29 05:07:23.622644 2026] [security2:error] [pid 1028675:tid 1028911] [client 168.107.94.195:62169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9a9dHPfW2QFvhmL7kKQAAAGU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:23.645294 2026] [security2:error] [pid 1028675:tid 1028819] [client 20.48.250.41:35121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/knmt.php"] [unique_id "apK9a9dHPfW2QFvhmL7kLAAAAAk"] [Sat Aug 29 05:07:23.646412 2026] [security2:error] [pid 1018003:tid 1018207] [client 93.123.109.228:44822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/website/.env"] [unique_id "apK9azAh5Y1i2tUxg4ESbwAABfA"] [Sat Aug 29 05:07:23.648756 2026] [security2:error] [pid 1028675:tid 1028899] [client 158.23.147.79:32735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/cong.php"] [unique_id "apK9a9dHPfW2QFvhmL7kLQAAAFk"] [Sat Aug 29 05:07:23.652366 2026] [security2:error] [pid 1028675:tid 1028823] [client 68.155.159.216:51475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/.well-knownold/index.php"] [unique_id "apK9a9dHPfW2QFvhmL7kLgAAAA0"] [Sat Aug 29 05:07:23.679396 2026] [security2:error] [pid 1018003:tid 1018155] [client 68.155.159.216:38541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/makeasmtp.php"] [unique_id "apK9azAh5Y1i2tUxg4EScAAABbw"] [Sat Aug 29 05:07:23.690092 2026] [security2:error] [pid 1028675:tid 1028867] [client 52.139.37.240:14682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/makeasmtp.php"] [unique_id "apK9a9dHPfW2QFvhmL7kMAAAADk"] [Sat Aug 29 05:07:23.690867 2026] [security2:error] [pid 1028675:tid 1028856] [client 93.123.109.228:45148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ffcbranson.com"] [uri "/wp-config.php"] [unique_id "apK9a9dHPfW2QFvhmL7kMQAAAC4"] [Sat Aug 29 05:07:23.692784 2026] [security2:error] [pid 1028675:tid 1028857] [client 20.48.250.41:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/sbhu.php"] [unique_id "apK9a9dHPfW2QFvhmL7kMwAAAC8"] [Sat Aug 29 05:07:23.694665 2026] [security2:error] [pid 1028675:tid 1028821] [client 93.123.109.228:44830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ffcbranson.com"] [uri "/wp-config.php.bak"] [unique_id "apK9a9dHPfW2QFvhmL7kNAAAAAs"] [Sat Aug 29 05:07:23.709286 2026] [security2:error] [pid 1018003:tid 1018162] [client 68.155.159.216:49326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9azAh5Y1i2tUxg4EScgAABcM"] [Sat Aug 29 05:07:23.714213 2026] [security2:error] [pid 1028675:tid 1028876] [client 93.123.109.228:45192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ffcbranson.com"] [uri "/wp-config.php.old"] [unique_id "apK9a9dHPfW2QFvhmL7kNgAAAEI"] [Sat Aug 29 05:07:23.722051 2026] [security2:error] [pid 1018003:tid 1018175] [client 4.205.62.107:22473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/phpsysinfo.php"] [unique_id "apK9azAh5Y1i2tUxg4EScwAABdA"] [Sat Aug 29 05:07:23.729703 2026] [security2:error] [pid 1028675:tid 1028880] [client 93.123.109.228:45162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.ffcbranson.com"] [uri "/wp-config.php.new"] [unique_id "apK9a9dHPfW2QFvhmL7kNwAAAEY"] [Sat Aug 29 05:07:23.742957 2026] [security2:error] [pid 1028675:tid 1028904] [client 68.155.159.216:30714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9a9dHPfW2QFvhmL7kOAAAAF4"] [Sat Aug 29 05:07:23.748268 2026] [core:error] [pid 1028675:tid 1028843] [client 158.158.54.35:14971] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:23.748283 2026] [core:error] [pid 1028675:tid 1028843] [client 158.158.54.35:14971] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:23.750782 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.196.209.81:11295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/dxc.php"] [unique_id "apK9azAh5Y1i2tUxg4ESdAAABik"] [Sat Aug 29 05:07:23.752676 2026] [security2:error] [pid 1028675:tid 1028849] [client 93.123.109.228:45086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.ffcbranson.com"] [uri "/___proxy_subdomain_cpcontacts/wp-content/mysql.sql"] [unique_id "apK9a9dHPfW2QFvhmL7kPAAAACc"] [Sat Aug 29 05:07:23.816005 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:35491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/sbhu.php"] [unique_id "apK9a9dHPfW2QFvhmL7kRQAAAHM"] [Sat Aug 29 05:07:23.817965 2026] [security2:error] [pid 1028675:tid 1028866] [client 52.138.0.157:5655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/sm.php"] [unique_id "apK9a9dHPfW2QFvhmL7kRwAAADg"] [Sat Aug 29 05:07:23.825378 2026] [security2:error] [pid 1018003:tid 1018256] [client 20.203.141.11:5763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apK9azAh5Y1i2tUxg4ESdgAABiA"] [Sat Aug 29 05:07:23.837612 2026] [security2:error] [pid 1028675:tid 1028922] [client 20.48.250.41:49060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/a332.php"] [unique_id "apK9a9dHPfW2QFvhmL7kSgAAAHA"] [Sat Aug 29 05:07:23.839489 2026] [security2:error] [pid 1018003:tid 1018262] [client 68.155.159.216:64488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/makeasmtp.php"] [unique_id "apK9azAh5Y1i2tUxg4ESdwAABiY"] [Sat Aug 29 05:07:23.840582 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.203.141.11:27666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/xmlrpc.php"] [unique_id "apK9azAh5Y1i2tUxg4ESeAAABdc"] [Sat Aug 29 05:07:23.845718 2026] [security2:error] [pid 1028675:tid 1028826] [client 4.205.62.107:9185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/debug.php"] [unique_id "apK9a9dHPfW2QFvhmL7kSwAAABA"] [Sat Aug 29 05:07:23.875959 2026] [security2:error] [pid 1028675:tid 1028901] [client 158.23.147.79:35775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9a9dHPfW2QFvhmL7kTAAAAFs"] [Sat Aug 29 05:07:23.877160 2026] [security2:error] [pid 1018003:tid 1018169] [client 40.83.93.50:20855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kellyandjohn.strangeworx.com"] [uri "/wp-content/languages/plugins/about.php"] [unique_id "apK9azAh5Y1i2tUxg4ESeQAABco"] [Sat Aug 29 05:07:23.887914 2026] [security2:error] [pid 1028675:tid 1028837] [client 52.139.37.240:14944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/paku.php"] [unique_id "apK9a9dHPfW2QFvhmL7kTgAAABs"] [Sat Aug 29 05:07:23.898881 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.104.49.130:58084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/wen.php"] [unique_id "apK9a9dHPfW2QFvhmL7kTwAAAAg"] [Sat Aug 29 05:07:23.925282 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.197.61.180:7176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/colour.php"] [unique_id "apK9azAh5Y1i2tUxg4ESewAABgo"] [Sat Aug 29 05:07:23.936396 2026] [security2:error] [pid 1028675:tid 1028845] [client 158.23.147.79:17518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9a9dHPfW2QFvhmL7kUAAAACM"] [Sat Aug 29 05:07:23.949532 2026] [security2:error] [pid 1028675:tid 1028842] [client 40.83.93.50:7491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/GOD.php"] [unique_id "apK9a9dHPfW2QFvhmL7kUgAAACA"] [Sat Aug 29 05:07:23.976323 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.48.250.41:35081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/a332.php"] [unique_id "apK9a9dHPfW2QFvhmL7kVAAAAG8"] [Sat Aug 29 05:07:23.993731 2026] [security2:error] [pid 1028675:tid 1028900] [client 4.205.62.107:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/wp-blog.php"] [unique_id "apK9a9dHPfW2QFvhmL7kVgAAAFo"] [Sat Aug 29 05:07:23.999580 2026] [security2:error] [pid 1018003:tid 1018172] [client 192.145.125.70:43756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9azAh5Y1i2tUxg4ESfAAABc0"] [Sat Aug 29 05:07:24.003110 2026] [security2:error] [pid 1028675:tid 1028907] [client 168.107.94.195:62652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9bNdHPfW2QFvhmL7kWAAAAGE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:24.010789 2026] [security2:error] [pid 1028675:tid 1028873] [client 40.83.93.50:24533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/system.php"] [unique_id "apK9bNdHPfW2QFvhmL7kWQAAAD8"] [Sat Aug 29 05:07:24.020228 2026] [security2:error] [pid 1028675:tid 1028846] [client 52.138.0.157:40985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/shell.php"] [unique_id "apK9bNdHPfW2QFvhmL7kWgAAACQ"] [Sat Aug 29 05:07:24.026128 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.158.54.35:21990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESfQAABdw"] [Sat Aug 29 05:07:24.031584 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.48.250.41:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ws66.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESfwAABew"] [Sat Aug 29 05:07:24.037330 2026] [security2:error] [pid 1018003:tid 1018163] [client 68.155.159.216:12113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wzy.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESgAAABcQ"] [Sat Aug 29 05:07:24.047394 2026] [security2:error] [pid 1028675:tid 1028833] [client 103.72.85.95:30722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.85.72.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mocoex.com"] [uri "/xmlrpc.php"] [unique_id "apK9a9dHPfW2QFvhmL7kVwAAABc"] [Sat Aug 29 05:07:24.047522 2026] [security2:error] [pid 1028675:tid 1028833] [client 103.72.85.95:30722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mocoex.com"] [uri "/xmlrpc.php"] [unique_id "apK9a9dHPfW2QFvhmL7kVwAAABc"] [Sat Aug 29 05:07:24.048328 2026] [security2:error] [pid 1028675:tid 1028897] [client 158.23.147.79:49999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apK9bNdHPfW2QFvhmL7kWwAAAFc"] [Sat Aug 29 05:07:24.051694 2026] [security2:error] [pid 1028675:tid 1028875] [client 4.205.62.107:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/umgebung.php"] [unique_id "apK9bNdHPfW2QFvhmL7kXAAAAEE"] [Sat Aug 29 05:07:24.084343 2026] [security2:error] [pid 1028675:tid 1028854] [client 52.139.37.240:15284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/rtx.php"] [unique_id "apK9bNdHPfW2QFvhmL7kXwAAACw"] [Sat Aug 29 05:07:24.106242 2026] [security2:error] [pid 1028675:tid 1028894] [client 4.205.62.107:22381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/kedi.php"] [unique_id "apK9bNdHPfW2QFvhmL7kYAAAAFQ"] [Sat Aug 29 05:07:24.111741 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.48.250.41:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ws66.php"] [unique_id "apK9bNdHPfW2QFvhmL7kYQAAABk"] [Sat Aug 29 05:07:24.113387 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.151.200.44:46625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/ww2.php"] [unique_id "apK9bNdHPfW2QFvhmL7kYgAAAEk"] [Sat Aug 29 05:07:24.129204 2026] [security2:error] [pid 1028675:tid 1028813] [client 68.155.159.216:24515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9bNdHPfW2QFvhmL7kYwAAAAM"] [Sat Aug 29 05:07:24.148402 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.196.209.81:11299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/wp-2019.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESgQAABd0"] [Sat Aug 29 05:07:24.199124 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.48.250.41:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ws68.php"] [unique_id "apK9bNdHPfW2QFvhmL7kZgAAAAs"] [Sat Aug 29 05:07:24.203057 2026] [core:error] [pid 1028675:tid 1028887] [client 158.158.54.35:31474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:24.203076 2026] [core:error] [pid 1028675:tid 1028887] [client 158.158.54.35:31474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:24.214063 2026] [security2:error] [pid 1028675:tid 1028912] [client 103.240.76.112:50335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9bNdHPfW2QFvhmL7kaAAAAGY"] [Sat Aug 29 05:07:24.214195 2026] [security2:error] [pid 1028675:tid 1028912] [client 103.240.76.112:50335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9bNdHPfW2QFvhmL7kaAAAAGY"] [Sat Aug 29 05:07:24.214380 2026] [security2:error] [pid 1028675:tid 1028903] [client 52.138.0.157:5646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/simple.php"] [unique_id "apK9bNdHPfW2QFvhmL7kaQAAAF0"] [Sat Aug 29 05:07:24.218235 2026] [security2:error] [pid 1028675:tid 1028880] [client 68.155.159.216:51236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/bk/index.php"] [unique_id "apK9bNdHPfW2QFvhmL7kagAAAEY"] [Sat Aug 29 05:07:24.230609 2026] [security2:error] [pid 1018003:tid 1018198] [client 158.23.147.79:25587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESgwAABec"] [Sat Aug 29 05:07:24.244555 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.48.250.41:35095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ws68.php"] [unique_id "apK9bDAh5Y1i2tUxg4EShAAABgM"] [Sat Aug 29 05:07:24.280185 2026] [security2:error] [pid 1018003:tid 1018161] [client 52.139.37.240:15271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/update/da222.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESiAAABcI"] [Sat Aug 29 05:07:24.297295 2026] [security2:error] [pid 1028675:tid 1028839] [client 146.70.194.254:44292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9bNdHPfW2QFvhmL7kcwAAAB0"] [Sat Aug 29 05:07:24.310104 2026] [security2:error] [pid 1028675:tid 1028937] [client 68.155.159.216:6029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9bNdHPfW2QFvhmL7kdAAAAH8"] [Sat Aug 29 05:07:24.310388 2026] [autoindex:error] [pid 1018003:tid 1018025] [remote 87.58.197.202:58006] AH01276: Cannot serve directory /home3/tffvbdmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:07:24.314012 2026] [security2:error] [pid 1028675:tid 1028819] [client 20.203.141.11:23162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9bNdHPfW2QFvhmL7kdQAAAAk"] [Sat Aug 29 05:07:24.314059 2026] [security2:error] [pid 1028675:tid 1028823] [client 20.203.141.11:22324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/filemanager.php"] [unique_id "apK9bNdHPfW2QFvhmL7kdgAAAA0"] [Sat Aug 29 05:07:24.330163 2026] [security2:error] [pid 1018003:tid 1018212] [client 158.23.184.117:12066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/update/da222.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESiwAABfU"] [Sat Aug 29 05:07:24.342600 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.48.250.41:49081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/users.php"] [unique_id "apK9bNdHPfW2QFvhmL7keAAAACg"] [Sat Aug 29 05:07:24.384855 2026] [security2:error] [pid 1018003:tid 1018152] [client 158.23.147.79:26502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/admin.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESjAAABbk"] [Sat Aug 29 05:07:24.401218 2026] [security2:error] [pid 1028675:tid 1028837] [client 168.107.94.195:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9bNdHPfW2QFvhmL7kfAAAABs"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:24.405446 2026] [security2:error] [pid 1028675:tid 1028826] [client 52.138.0.157:19601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin.php"] [unique_id "apK9bNdHPfW2QFvhmL7kfQAAABA"] [Sat Aug 29 05:07:24.414141 2026] [security2:error] [pid 1028675:tid 1028933] [client 20.48.250.41:35028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/users.php"] [unique_id "apK9bNdHPfW2QFvhmL7kfgAAAHs"] [Sat Aug 29 05:07:24.425868 2026] [security2:error] [pid 1028675:tid 1028888] [client 158.23.184.117:12084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/update/da222.php"] [unique_id "apK9bNdHPfW2QFvhmL7kfwAAAE4"] [Sat Aug 29 05:07:24.449911 2026] [security2:error] [pid 1028675:tid 1028909] [client 40.83.93.50:7499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/ggfi.php"] [unique_id "apK9bNdHPfW2QFvhmL7kgAAAAGM"] [Sat Aug 29 05:07:24.470837 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.49.130:47867] ModSecurity: Access denied with connection close (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1032"] [id "900036"] [msg "Wordpress BOT exploit :: No UA/Referer"] [hostname "mail.flatlandsfoto.com"] [uri "/wp-login.php"] [unique_id "apK9bNdHPfW2QFvhmL7kgQAAAHo"] [Sat Aug 29 05:07:24.473964 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.48.250.41:49110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/bzjdlofz.php"] [unique_id "apK9bNdHPfW2QFvhmL7kggAAAG8"] [Sat Aug 29 05:07:24.473999 2026] [security2:error] [pid 1028675:tid 1028848] [client 158.23.184.117:12037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/xmr.php"] [unique_id "apK9bNdHPfW2QFvhmL7kgwAAACY"] [Sat Aug 29 05:07:24.483290 2026] [security2:error] [pid 1018003:tid 1018159] [client 40.83.93.50:5212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/test.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESjQAABcA"] [Sat Aug 29 05:07:24.484113 2026] [security2:error] [pid 1028675:tid 1028746] [remote 136.108.23.170:55262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.thesmartpm.com"] [uri "/.env.backup"] [unique_id "apK9bNdHPfW2QFvhmL7khQAAWkE"] [Sat Aug 29 05:07:24.484459 2026] [security2:error] [pid 1028675:tid 1028757] [remote 136.108.23.170:55262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.thesmartpm.com"] [uri "/.env.bak"] [unique_id "apK9bNdHPfW2QFvhmL7khgAAWkw"] [Sat Aug 29 05:07:24.500757 2026] [security2:error] [pid 1018003:tid 1018175] [client 20.104.49.130:34525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/crgio.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESjwAABdA"] [Sat Aug 29 05:07:24.516081 2026] [security2:error] [pid 1028675:tid 1028855] [client 4.205.62.107:55996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/brc.php"] [unique_id "apK9bNdHPfW2QFvhmL7kiQAAAC0"] [Sat Aug 29 05:07:24.544747 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.48.250.41:35105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/bzjdlofz.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESkAAABfw"] [Sat Aug 29 05:07:24.561902 2026] [security2:error] [pid 1028675:tid 1028930] [client 158.23.147.79:30520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/nf_tracking.php"] [unique_id "apK9bNdHPfW2QFvhmL7kiwAAAHg"] [Sat Aug 29 05:07:24.569602 2026] [security2:error] [pid 1028675:tid 1028897] [client 158.23.184.117:11930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/xmr.php"] [unique_id "apK9bNdHPfW2QFvhmL7kjAAAAFc"] [Sat Aug 29 05:07:24.573125 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.196.209.81:1996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/menu.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESkwAABfA"] [Sat Aug 29 05:07:24.583500 2026] [security2:error] [pid 1018003:tid 1018191] [client 52.139.37.240:14922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-admin/min.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESlAAABeA"] [Sat Aug 29 05:07:24.592930 2026] [security2:error] [pid 1028675:tid 1028908] [client 192.145.125.70:50392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9bNdHPfW2QFvhmL7kjgAAAGI"] [Sat Aug 29 05:07:24.594053 2026] [security2:error] [pid 1028675:tid 1028765] [remote 136.108.23.170:55262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.thesmartpm.com"] [uri "/.env.old"] [unique_id "apK9bNdHPfW2QFvhmL7kjQAAP1Q"] [Sat Aug 29 05:07:24.600197 2026] [security2:error] [pid 1018003:tid 1018183] [client 52.138.0.157:19615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESlQAABdg"] [Sat Aug 29 05:07:24.603414 2026] [security2:error] [pid 1028675:tid 1028763] [remote 136.108.23.170:55262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thesmartpm.com"] [uri "/config/.env"] [unique_id "apK9bNdHPfW2QFvhmL7kkAAAP1I"] [Sat Aug 29 05:07:24.619367 2026] [security2:error] [pid 1018003:tid 1018271] [client 158.23.184.117:12084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESlgAABi8"] [Sat Aug 29 05:07:24.622280 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.48.250.41:49069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/selesai.php"] [unique_id "apK9bNdHPfW2QFvhmL7kkQAAAGQ"] [Sat Aug 29 05:07:24.624515 2026] [security2:error] [pid 1028675:tid 1028822] [client 158.158.54.35:22181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "apK9bNdHPfW2QFvhmL7kkgAAAAw"] [Sat Aug 29 05:07:24.636243 2026] [security2:error] [pid 1028675:tid 1028926] [client 68.155.159.216:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9bNdHPfW2QFvhmL7kkwAAAHQ"] [Sat Aug 29 05:07:24.640964 2026] [security2:error] [pid 1028675:tid 1028773] [remote 136.108.23.170:55262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thesmartpm.com"] [uri "/api/.env"] [unique_id "apK9bNdHPfW2QFvhmL7klQAAP1w"] [Sat Aug 29 05:07:24.641037 2026] [security2:error] [pid 1028675:tid 1028754] [remote 136.108.23.170:55262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thesmartpm.com"] [uri "/backend/.env"] [unique_id "apK9bNdHPfW2QFvhmL7klAAAP0k"] [Sat Aug 29 05:07:24.660871 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.197.61.180:13066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/OK.php"] [unique_id "apK9bNdHPfW2QFvhmL7klgAAAAg"] [Sat Aug 29 05:07:24.668164 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.104.18.15:12170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESlwAABis"] [Sat Aug 29 05:07:24.680841 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.48.250.41:35472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/selesai.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESmQAABb0"] [Sat Aug 29 05:07:24.687061 2026] [security2:error] [pid 1028675:tid 1028912] [client 68.155.159.216:33707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9bNdHPfW2QFvhmL7kmQAAAGY"] [Sat Aug 29 05:07:24.690589 2026] [security2:error] [pid 1018003:tid 1018190] [client 158.158.54.35:14940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESmwAABd8"] [Sat Aug 29 05:07:24.701559 2026] [security2:error] [pid 1018003:tid 1018157] [client 158.23.147.79:53130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/sad/about.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESnAAABb4"] [Sat Aug 29 05:07:24.717603 2026] [security2:error] [pid 1018003:tid 1018277] [client 158.23.184.117:11737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESnQAABjU"] [Sat Aug 29 05:07:24.719968 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.151.200.44:45475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/anz.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESngAABc0"] [Sat Aug 29 05:07:24.755083 2026] [security2:error] [pid 1028675:tid 1028923] [client 158.23.147.79:32647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9bNdHPfW2QFvhmL7kngAAAHE"] [Sat Aug 29 05:07:24.760205 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.48.250.41:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/shlo.php"] [unique_id "apK9bNdHPfW2QFvhmL7koAAAAAU"] [Sat Aug 29 05:07:24.760406 2026] [security2:error] [pid 1028675:tid 1028916] [client 68.155.159.216:51258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9bNdHPfW2QFvhmL7knwAAAGo"] [Sat Aug 29 05:07:24.766898 2026] [security2:error] [pid 1028675:tid 1028816] [client 158.23.184.117:11962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/wp-act.php"] [unique_id "apK9bNdHPfW2QFvhmL7koQAAAAY"] [Sat Aug 29 05:07:24.779713 2026] [security2:error] [pid 1018003:tid 1018179] [client 52.139.37.240:14968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESnwAABdQ"] [Sat Aug 29 05:07:24.781113 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.203.141.11:27951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/bthil.php"] [unique_id "apK9bNdHPfW2QFvhmL7kogAAAFk"] [Sat Aug 29 05:07:24.781641 2026] [security2:error] [pid 1028675:tid 1028931] [client 20.203.141.11:38177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/wp-content/themes/admin.php"] [unique_id "apK9bNdHPfW2QFvhmL7kpAAAAHk"] [Sat Aug 29 05:07:24.781897 2026] [security2:error] [pid 1028675:tid 1028920] [client 168.107.94.195:63534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9bNdHPfW2QFvhmL7kowAAAG4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:24.799399 2026] [security2:error] [pid 1028675:tid 1028879] [client 52.138.0.157:10516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/includes/about.php"] [unique_id "apK9bNdHPfW2QFvhmL7kpQAAAEU"] [Sat Aug 29 05:07:24.815803 2026] [security2:error] [pid 1028675:tid 1028878] [client 20.104.18.15:12284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9bNdHPfW2QFvhmL7kpgAAAEQ"] [Sat Aug 29 05:07:24.829756 2026] [security2:error] [pid 1028675:tid 1028826] [client 68.155.159.216:49186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/goat.php"] [unique_id "apK9bNdHPfW2QFvhmL7kpwAAABA"] [Sat Aug 29 05:07:24.861669 2026] [security2:error] [pid 1028675:tid 1028814] [client 158.23.184.117:12062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/wp-act.php"] [unique_id "apK9bNdHPfW2QFvhmL7kqAAAAAQ"] [Sat Aug 29 05:07:24.865185 2026] [security2:error] [pid 1028675:tid 1028909] [client 4.205.62.107:22361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/sgd.php"] [unique_id "apK9bNdHPfW2QFvhmL7kqgAAAGM"] [Sat Aug 29 05:07:24.877008 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.48.250.41:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/shlo.php"] [unique_id "apK9bNdHPfW2QFvhmL7kqwAAAAE"] [Sat Aug 29 05:07:24.903296 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.48.250.41:49025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/asax.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESoAAABh8"] [Sat Aug 29 05:07:24.919976 2026] [security2:error] [pid 1028675:tid 1028845] [client 158.23.184.117:11959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/fff.php"] [unique_id "apK9bNdHPfW2QFvhmL7krgAAACM"] [Sat Aug 29 05:07:24.945266 2026] [security2:error] [pid 1028675:tid 1028900] [client 68.155.159.216:65109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9bNdHPfW2QFvhmL7krwAAAFo"] [Sat Aug 29 05:07:24.950575 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.104.18.15:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/ap.php"] [unique_id "apK9bNdHPfW2QFvhmL7ksAAAAGE"] [Sat Aug 29 05:07:24.989948 2026] [security2:error] [pid 1018003:tid 1018174] [client 52.139.37.240:15243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESogAABc8"] [Sat Aug 29 05:07:24.992649 2026] [security2:error] [pid 1028675:tid 1028888] [client 20.196.209.81:15218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/alfa.php"] [unique_id "apK9bNdHPfW2QFvhmL7ksgAAAE4"] [Sat Aug 29 05:07:24.995658 2026] [security2:error] [pid 1028675:tid 1028897] [client 158.23.147.79:35201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9bNdHPfW2QFvhmL7ktAAAAFc"] [Sat Aug 29 05:07:24.996609 2026] [security2:error] [pid 1018003:tid 1018167] [client 52.138.0.157:20514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/js/index.php"] [unique_id "apK9bDAh5Y1i2tUxg4ESowAABcg"] [Sat Aug 29 05:07:25.025911 2026] [security2:error] [pid 1028675:tid 1028937] [client 60.243.207.176:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.207.243.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9bddHPfW2QFvhmL7kuQAAAH8"] [Sat Aug 29 05:07:25.026219 2026] [security2:error] [pid 1028675:tid 1028937] [client 60.243.207.176:63046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lindamcvayart.com"] [uri "/xmlrpc.php"] [unique_id "apK9bddHPfW2QFvhmL7kuQAAAH8"] [Sat Aug 29 05:07:25.039279 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.48.250.41:35503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/asax.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESpQAABds"] [Sat Aug 29 05:07:25.042699 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.23.147.79:17421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/login.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESpgAABdk"] [Sat Aug 29 05:07:25.045656 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.48.250.41:49131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/fetch.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESpwAABio"] [Sat Aug 29 05:07:25.055790 2026] [security2:error] [pid 1028675:tid 1028872] [client 158.23.184.117:11912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/fff.php"] [unique_id "apK9bddHPfW2QFvhmL7kvAAAAD4"] [Sat Aug 29 05:07:25.064383 2026] [security2:error] [pid 1028675:tid 1028824] [client 68.155.159.216:16255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/themes.php"] [unique_id "apK9bddHPfW2QFvhmL7kvwAAAA4"] [Sat Aug 29 05:07:25.066073 2026] [security2:error] [pid 1028675:tid 1028883] [client 158.23.184.117:11935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9bddHPfW2QFvhmL7kwAAAAEk"] [Sat Aug 29 05:07:25.082992 2026] [security2:error] [pid 1018003:tid 1018224] [client 158.158.54.35:24129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/assets/images/doc.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESqgAABgE"] [Sat Aug 29 05:07:25.117046 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.104.49.130:30068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/classwithtostring.php"] [unique_id "apK9bddHPfW2QFvhmL7kxgAAABI"] [Sat Aug 29 05:07:25.117362 2026] [security2:error] [pid 1018003:tid 1018162] [client 20.104.18.15:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/media.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESqwAABcM"] [Sat Aug 29 05:07:25.128376 2026] [security2:error] [pid 1028675:tid 1028825] [client 4.205.62.107:24989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/erty.php"] [unique_id "apK9bddHPfW2QFvhmL7kxwAAAA8"] [Sat Aug 29 05:07:25.130061 2026] [security2:error] [pid 1028675:tid 1028892] [client 40.83.93.50:5662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/user/f35.php"] [unique_id "apK9bddHPfW2QFvhmL7kyAAAAFI"] [Sat Aug 29 05:07:25.138818 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.158.54.35:16901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/num.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESrAAABgM"] [Sat Aug 29 05:07:25.143030 2026] [security2:error] [pid 1018003:tid 1018159] [client 68.155.159.216:12175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESrQAABcA"] [Sat Aug 29 05:07:25.147129 2026] [security2:error] [pid 1018003:tid 1018175] [client 4.205.62.107:53362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/dialog.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESrgAABdA"] [Sat Aug 29 05:07:25.147240 2026] [security2:error] [pid 1028675:tid 1028812] [client 40.83.93.50:11682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/alfa-rex.php"] [unique_id "apK9bddHPfW2QFvhmL7kywAAAAI"] [Sat Aug 29 05:07:25.149193 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.147.79:50051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESrwAABbw"] [Sat Aug 29 05:07:25.149195 2026] [security2:error] [pid 1028675:tid 1028923] [client 158.23.147.79:30489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wzy.php"] [unique_id "apK9bddHPfW2QFvhmL7kzQAAAHE"] [Sat Aug 29 05:07:25.161457 2026] [security2:error] [pid 1028675:tid 1028916] [client 168.107.94.195:63876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9bddHPfW2QFvhmL7kzgAAAGo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:25.181529 2026] [security2:error] [pid 1028675:tid 1028877] [client 192.145.125.70:50408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9bddHPfW2QFvhmL7kzwAAAEM"] [Sat Aug 29 05:07:25.181630 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.48.250.41:35135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/fetch.php"] [unique_id "apK9bddHPfW2QFvhmL7k0AAAAB0"] [Sat Aug 29 05:07:25.187028 2026] [security2:error] [pid 1028675:tid 1028853] [client 52.139.37.240:14971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK9bddHPfW2QFvhmL7k0QAAACs"] [Sat Aug 29 05:07:25.189395 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.48.250.41:49089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/vx.php"] [unique_id "apK9bddHPfW2QFvhmL7k0wAAAG4"] [Sat Aug 29 05:07:25.189452 2026] [security2:error] [pid 1028675:tid 1028931] [client 4.205.62.107:58486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/wp-content/db-status.php"] [unique_id "apK9bddHPfW2QFvhmL7k0gAAAHk"] [Sat Aug 29 05:07:25.215719 2026] [security2:error] [pid 1028675:tid 1028816] [client 158.23.184.117:12078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/robots.php"] [unique_id "apK9bddHPfW2QFvhmL7k1gAAAAY"] [Sat Aug 29 05:07:25.215971 2026] [security2:error] [pid 1018003:tid 1018219] [client 158.23.184.117:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/.tmb/dropdown.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESsAAABfw"] [Sat Aug 29 05:07:25.240865 2026] [security2:error] [pid 1028675:tid 1028922] [client 4.205.62.107:22150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wp-content/maintenance.php"] [unique_id "apK9bddHPfW2QFvhmL7k1wAAAHA"] [Sat Aug 29 05:07:25.244934 2026] [security2:error] [pid 1018003:tid 1018271] [client 68.155.159.216:24542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESsQAABi8"] [Sat Aug 29 05:07:25.247426 2026] [security2:error] [pid 1028675:tid 1028901] [client 20.104.18.15:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/adminfuns.php"] [unique_id "apK9bddHPfW2QFvhmL7k2AAAAFs"] [Sat Aug 29 05:07:25.253196 2026] [security2:error] [pid 1018003:tid 1018213] [client 20.203.141.11:22278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/wp-admin/css/admin.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESswAABfY"] [Sat Aug 29 05:07:25.268375 2026] [http2:warn] [pid 1017536:tid 1017764] [client 57.141.14.63:59328] h2_stream(1017536-342-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:07:25.271689 2026] [security2:error] [pid 1028675:tid 1028814] [client 158.23.147.79:48355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/plugins.php"] [unique_id "apK9bddHPfW2QFvhmL7k2wAAAAQ"] [Sat Aug 29 05:07:25.315940 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.48.250.41:35476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/vx.php"] [unique_id "apK9bTAh5Y1i2tUxg4EStQAABco"] [Sat Aug 29 05:07:25.318708 2026] [security2:error] [pid 1028675:tid 1028845] [client 52.138.0.157:27807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9bddHPfW2QFvhmL7k3QAAACM"] [Sat Aug 29 05:07:25.324215 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.184.117:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/Ov-Simple1.php"] [unique_id "apK9bTAh5Y1i2tUxg4EStgAABiA"] [Sat Aug 29 05:07:25.342841 2026] [security2:error] [pid 1028675:tid 1028833] [client 158.23.147.79:25408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9bddHPfW2QFvhmL7k5AAAABc"] [Sat Aug 29 05:07:25.360835 2026] [security2:error] [pid 1028675:tid 1028811] [client 158.23.184.117:30022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/alfa.php"] [unique_id "apK9bddHPfW2QFvhmL7k5QAAAAE"] [Sat Aug 29 05:07:25.362419 2026] [security2:error] [pid 1018003:tid 1018268] [client 158.23.184.117:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/.well-known/install.php"] [unique_id "apK9bTAh5Y1i2tUxg4EStwAABiw"] [Sat Aug 29 05:07:25.362821 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.184.117:11336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/robots.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESuAAABdc"] [Sat Aug 29 05:07:25.365361 2026] [security2:error] [pid 1028675:tid 1028919] [client 68.155.159.216:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9bddHPfW2QFvhmL7k5gAAAG0"] [Sat Aug 29 05:07:25.373808 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.48.250.41:49047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/global.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESuQAABd8"] [Sat Aug 29 05:07:25.373944 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.104.49.130:57711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marketingmagicsecrets.com"] [uri "/sxxb.php"] [unique_id "apK9bddHPfW2QFvhmL7k6AAAAEc"] [Sat Aug 29 05:07:25.378404 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.197.61.180:13885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "likesareus.com"] [uri "/aaa.php"] [unique_id "apK9bddHPfW2QFvhmL7k6QAAAEY"] [Sat Aug 29 05:07:25.386196 2026] [security2:error] [pid 1028675:tid 1028902] [client 68.155.159.216:51398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nillpower.com"] [uri "/first.php"] [unique_id "apK9bddHPfW2QFvhmL7k6wAAAFw"] [Sat Aug 29 05:07:25.388550 2026] [security2:error] [pid 1028675:tid 1028928] [client 20.196.209.81:14479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/feed-rss2-queue.php"] [unique_id "apK9bddHPfW2QFvhmL7k7AAAAHY"] [Sat Aug 29 05:07:25.388722 2026] [security2:error] [pid 1028675:tid 1028855] [client 158.23.184.117:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/av.php"] [unique_id "apK9bddHPfW2QFvhmL7k7QAAAC0"] [Sat Aug 29 05:07:25.417712 2026] [security2:error] [pid 1028675:tid 1028860] [client 158.23.184.117:11945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/app.php"] [unique_id "apK9bddHPfW2QFvhmL7k8AAAADI"] [Sat Aug 29 05:07:25.425602 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.104.18.15:12179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/classwithtostring.php"] [unique_id "apK9bddHPfW2QFvhmL7k8QAAAEk"] [Sat Aug 29 05:07:25.428891 2026] [security2:error] [pid 1028675:tid 1028861] [client 68.155.159.216:5952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9bddHPfW2QFvhmL7k8gAAADM"] [Sat Aug 29 05:07:25.431814 2026] [security2:error] [pid 1028675:tid 1028937] [client 158.23.184.117:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/.well-known/install.php"] [unique_id "apK9bddHPfW2QFvhmL7k8wAAAH8"] [Sat Aug 29 05:07:25.451170 2026] [security2:error] [pid 1018003:tid 1018163] [client 20.203.141.11:11205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/cv.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESugAABcQ"] [Sat Aug 29 05:07:25.467992 2026] [security2:error] [pid 1028675:tid 1028872] [client 158.23.184.117:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/atomlib.php"] [unique_id "apK9bddHPfW2QFvhmL7k9AAAAD4"] [Sat Aug 29 05:07:25.481651 2026] [security2:error] [pid 1028675:tid 1028918] [client 52.139.37.240:15286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9bddHPfW2QFvhmL7k9QAAAGw"] [Sat Aug 29 05:07:25.497063 2026] [security2:error] [pid 1028675:tid 1028854] [client 158.23.147.79:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9bddHPfW2QFvhmL7k9gAAACw"] [Sat Aug 29 05:07:25.506199 2026] [security2:error] [pid 1028675:tid 1028912] [client 20.48.250.41:48964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/fs.php"] [unique_id "apK9bddHPfW2QFvhmL7k-AAAAGY"] [Sat Aug 29 05:07:25.509041 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.23.184.117:30040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/as.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESuwAABdQ"] [Sat Aug 29 05:07:25.516102 2026] [security2:error] [pid 1028675:tid 1028908] [client 52.138.0.157:20519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/network/admin.php"] [unique_id "apK9bddHPfW2QFvhmL7k-gAAAGI"] [Sat Aug 29 05:07:25.529711 2026] [security2:error] [pid 1028675:tid 1028825] [client 158.23.184.117:11756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/.well-known/install.php"] [unique_id "apK9bddHPfW2QFvhmL7k-wAAAA8"] [Sat Aug 29 05:07:25.531070 2026] [security2:error] [pid 1028675:tid 1028870] [client 158.158.54.35:17593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/bgymj.php"] [unique_id "apK9bddHPfW2QFvhmL7k_AAAADw"] [Sat Aug 29 05:07:25.534370 2026] [security2:error] [pid 1018003:tid 1018233] [client 68.155.159.216:33679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/NewFile.php/"] [unique_id "apK9bTAh5Y1i2tUxg4ESvwAABgk"] [Sat Aug 29 05:07:25.542480 2026] [security2:error] [pid 1028675:tid 1028839] [client 168.107.94.195:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9bddHPfW2QFvhmL7k_QAAAB0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:25.559146 2026] [security2:error] [pid 1028675:tid 1028903] [client 68.155.159.216:65114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/login.php"] [unique_id "apK9bddHPfW2QFvhmL7k_gAAAF0"] [Sat Aug 29 05:07:25.560035 2026] [security2:error] [pid 1018003:tid 1018166] [client 158.23.184.117:12087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/wp-admin/about.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESwAAABcc"] [Sat Aug 29 05:07:25.564909 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.184.117:12064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/aaa.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESwQAABhw"] [Sat Aug 29 05:07:25.584563 2026] [security2:error] [pid 1018003:tid 1018184] [client 158.23.184.117:2586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-includes/ID3/file.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESwwAABdk"] [Sat Aug 29 05:07:25.585042 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.104.18.15:12283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK9bddHPfW2QFvhmL7lAQAAACg"] [Sat Aug 29 05:07:25.594023 2026] [core:error] [pid 1028675:tid 1028828] [client 158.158.54.35:29663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.594039 2026] [core:error] [pid 1028675:tid 1028828] [client 158.158.54.35:29663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.598896 2026] [security2:error] [pid 1028675:tid 1028926] [client 40.83.93.50:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/user/min.php"] [unique_id "apK9bddHPfW2QFvhmL7lAwAAAHQ"] [Sat Aug 29 05:07:25.608208 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.48.250.41:35485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/global.php"] [unique_id "apK9bddHPfW2QFvhmL7lBQAAABA"] [Sat Aug 29 05:07:25.610299 2026] [security2:error] [pid 1028675:tid 1028819] [client 158.23.184.117:39967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/edit.php"] [unique_id "apK9bddHPfW2QFvhmL7lBgAAAAk"] [Sat Aug 29 05:07:25.628756 2026] [security2:error] [pid 1028675:tid 1028814] [client 158.23.184.117:4363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/wp-admin/about.php"] [unique_id "apK9bddHPfW2QFvhmL7lBwAAAAQ"] [Sat Aug 29 05:07:25.647458 2026] [security2:error] [pid 1018003:tid 1018200] [client 40.83.93.50:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/cookie.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESxAAABek"] [Sat Aug 29 05:07:25.650775 2026] [security2:error] [pid 1028675:tid 1028837] [client 158.23.184.117:30256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/aa.php"] [unique_id "apK9bddHPfW2QFvhmL7lCAAAABs"] [Sat Aug 29 05:07:25.654125 2026] [security2:error] [pid 1028675:tid 1028840] [client 4.205.62.107:56050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/vx.php"] [unique_id "apK9bddHPfW2QFvhmL7lCQAAAB4"] [Sat Aug 29 05:07:25.662187 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.250.41:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ioxi.php"] [unique_id "apK9bTAh5Y1i2tUxg4ESxQAABes"] [Sat Aug 29 05:07:25.670718 2026] [security2:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9bTAh5Y1i2tUxg4ESxgAGIiA"] [Sat Aug 29 05:07:25.683150 2026] [security2:error] [pid 1028675:tid 1028858] [client 158.23.147.79:30633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/ans.php"] [unique_id "apK9bddHPfW2QFvhmL7lDgAAADA"] [Sat Aug 29 05:07:25.687544 2026] [security2:error] [pid 1028675:tid 1028847] [client 52.139.37.240:14690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-info.php"] [unique_id "apK9bddHPfW2QFvhmL7lDwAAACU"] [Sat Aug 29 05:07:25.692467 2026] [security2:error] [pid 1028675:tid 1028867] [client 103.171.189.88:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.189.171.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9bddHPfW2QFvhmL7lEAAAADk"] [Sat Aug 29 05:07:25.692556 2026] [security2:error] [pid 1028675:tid 1028867] [client 103.171.189.88:58262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9bddHPfW2QFvhmL7lEAAAADk"] [Sat Aug 29 05:07:25.702903 2026] [security2:error] [pid 1018003:tid 1018170] [client 158.23.184.117:12032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/wp-content/backup.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES0QAABcs"] [Sat Aug 29 05:07:25.710099 2026] [security2:error] [pid 1028675:tid 1028844] [client 52.138.0.157:20516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-conflg/function.php"] [unique_id "apK9bddHPfW2QFvhmL7lEgAAACI"] [Sat Aug 29 05:07:25.724378 2026] [security2:error] [pid 1018003:tid 1018221] [client 158.23.184.117:11936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/wp-admin/about.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES0gAABf4"] [Sat Aug 29 05:07:25.729370 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.203.141.11:22275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/adminfuns.php"] [unique_id "apK9bddHPfW2QFvhmL7lEwAAAG4"] [Sat Aug 29 05:07:25.729600 2026] [security2:error] [pid 1028675:tid 1028925] [client 158.23.184.117:2770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reed-white.bistrobrew.com"] [uri "/wp-admin/css/fff.php"] [unique_id "apK9bddHPfW2QFvhmL7lFAAAAHM"] [Sat Aug 29 05:07:25.739205 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.739217 2026] [core:error] [pid 1018003:tid 1018155] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.741936 2026] [security2:error] [pid 1028675:tid 1028928] [client 68.155.159.216:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/makeasmtp.php"] [unique_id "apK9bddHPfW2QFvhmL7lFQAAAHY"] [Sat Aug 29 05:07:25.748121 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.748133 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.757145 2026] [security2:error] [pid 1028675:tid 1028811] [client 158.23.184.117:63783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/7.php"] [unique_id "apK9bddHPfW2QFvhmL7lFgAAAAE"] [Sat Aug 29 05:07:25.758129 2026] [security2:error] [pid 1028675:tid 1028860] [client 158.23.184.117:11954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/hehe.php"] [unique_id "apK9bddHPfW2QFvhmL7lFwAAADI"] [Sat Aug 29 05:07:25.766277 2026] [security2:error] [pid 1018003:tid 1018248] [client 192.145.125.70:50418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zbv.tvp.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK9bTAh5Y1i2tUxg4ES1QAABhg"] [Sat Aug 29 05:07:25.773886 2026] [security2:error] [pid 1018003:tid 1018189] [client 158.23.184.117:4392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/wp-content/backup.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES1gAABd4"] [Sat Aug 29 05:07:25.780371 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.780384 2026] [core:error] [pid 1028675:tid 1028824] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.781504 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.781518 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.786521 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.786533 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.789250 2026] [security2:error] [pid 1018003:tid 1018217] [client 20.48.250.41:35132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/fs.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES2AAABfo"] [Sat Aug 29 05:07:25.789603 2026] [security2:error] [pid 1028675:tid 1028876] [client 68.155.159.216:33595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/lock.php"] [unique_id "apK9bddHPfW2QFvhmL7lIAAAAEI"] [Sat Aug 29 05:07:25.789902 2026] [security2:error] [pid 1028675:tid 1028894] [client 68.155.159.216:38590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9bddHPfW2QFvhmL7lIQAAAFQ"] [Sat Aug 29 05:07:25.789929 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.789937 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.804008 2026] [security2:error] [pid 1018003:tid 1018275] [client 20.48.250.41:49141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/bootstrap.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES2QAABjM"] [Sat Aug 29 05:07:25.816301 2026] [security2:error] [pid 1018003:tid 1018028] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9bTAh5Y1i2tUxg4ES3AAGIgc"] [Sat Aug 29 05:07:25.817603 2026] [security2:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/*update.cgi*"] [unique_id "apK9bTAh5Y1i2tUxg4ES4QAGIj8"] [Sat Aug 29 05:07:25.820091 2026] [core:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.820104 2026] [core:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.821439 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.196.209.81:1868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/inputs.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES4gAABeU"] [Sat Aug 29 05:07:25.825207 2026] [security2:error] [pid 1018003:tid 1018169] [client 20.104.18.15:12219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES4wAABco"] [Sat Aug 29 05:07:25.849625 2026] [security2:error] [pid 1028675:tid 1028897] [client 158.23.184.117:11333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/.well-known/aa.php"] [unique_id "apK9bddHPfW2QFvhmL7lKQAAAFc"] [Sat Aug 29 05:07:25.855027 2026] [security2:error] [pid 1028675:tid 1028903] [client 158.23.147.79:32740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/index.php"] [unique_id "apK9bddHPfW2QFvhmL7lLAAAAF0"] [Sat Aug 29 05:07:25.855597 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.855609 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.855914 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.855924 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.856089 2026] [core:error] [pid 1028675:tid 1028899] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.856097 2026] [core:error] [pid 1028675:tid 1028899] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.859550 2026] [core:error] [pid 1028675:tid 1028871] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.859561 2026] [core:error] [pid 1028675:tid 1028871] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.863748 2026] [core:error] [pid 1018003:tid 1018156] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.863760 2026] [core:error] [pid 1018003:tid 1018156] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.863813 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.863821 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.864376 2026] [core:error] [pid 1028675:tid 1028828] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.864388 2026] [core:error] [pid 1028675:tid 1028828] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:25.864957 2026] [security2:error] [pid 1018003:tid 1018265] [client 158.23.184.117:12077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/wp-content/backup.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES5wAABik"] [Sat Aug 29 05:07:25.866549 2026] [security2:error] [pid 1028675:tid 1028890] [client 158.23.184.117:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/abc.php"] [unique_id "apK9bddHPfW2QFvhmL7lMAAAAFA"] [Sat Aug 29 05:07:25.877429 2026] [security2:error] [pid 1018003:tid 1018277] [client 20.104.49.130:57495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.wirearte.com"] [uri "/666.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES6AAABjU"] [Sat Aug 29 05:07:25.879863 2026] [security2:error] [pid 1018003:tid 1018231] [client 68.155.159.216:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES6QAABgc"] [Sat Aug 29 05:07:25.880776 2026] [security2:error] [pid 1028675:tid 1028889] [client 52.139.37.240:14666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK9bddHPfW2QFvhmL7lMQAAAE8"] [Sat Aug 29 05:07:25.900797 2026] [security2:error] [pid 1028675:tid 1028853] [client 158.23.184.117:63794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/black.php"] [unique_id "apK9bddHPfW2QFvhmL7lMgAAACs"] [Sat Aug 29 05:07:25.903819 2026] [security2:error] [pid 1028675:tid 1028816] [client 158.23.184.117:11908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-includes/PHPMailer.php"] [unique_id "apK9bddHPfW2QFvhmL7lMwAAAAY"] [Sat Aug 29 05:07:25.907857 2026] [security2:error] [pid 1018003:tid 1018256] [client 52.138.0.157:5634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES6gAABiA"] [Sat Aug 29 05:07:25.921136 2026] [security2:error] [pid 1018003:tid 1018234] [client 158.23.184.117:4413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/.well-known/aa.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES6wAABgo"] [Sat Aug 29 05:07:25.924642 2026] [security2:error] [pid 1028675:tid 1028867] [client 168.107.94.195:64605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9bddHPfW2QFvhmL7lNAAAADk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:25.929701 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.203.141.11:35218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-content/packed.php"] [unique_id "apK9bddHPfW2QFvhmL7lNQAAACE"] [Sat Aug 29 05:07:25.936207 2026] [security2:error] [pid 1018003:tid 1018101] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.docker/.env"] [unique_id "apK9bTAh5Y1i2tUxg4ES7AAGH1A"] [Sat Aug 29 05:07:25.941285 2026] [security2:error] [pid 1018003:tid 1018167] [client 68.155.159.216:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES7QAABcg"] [Sat Aug 29 05:07:25.950707 2026] [security2:error] [pid 1028675:tid 1028877] [client 158.23.147.79:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/admin.php"] [unique_id "apK9bddHPfW2QFvhmL7lOQAAAEM"] [Sat Aug 29 05:07:25.954099 2026] [security2:error] [pid 1028675:tid 1028930] [client 20.48.250.41:49091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/export.php"] [unique_id "apK9bddHPfW2QFvhmL7lPAAAAHg"] [Sat Aug 29 05:07:25.970818 2026] [ssl:error] [pid 1018003:tid 1018195] [client 3.233.59.216:17923] AH02032: Hostname host2038.hostmonster.com (default host as no SNI was provided) and hostname webdisk.evecreative.co provided via HTTP have no compatible SSL setup for policy 'secure' [Sat Aug 29 05:07:25.979106 2026] [security2:error] [pid 1028675:tid 1028870] [client 158.158.54.35:17581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9bddHPfW2QFvhmL7lQgAAADw"] [Sat Aug 29 05:07:25.982767 2026] [security2:error] [pid 1018003:tid 1018086] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "apK9bTAh5Y1i2tUxg4ES8gAGGkE"] [Sat Aug 29 05:07:25.990828 2026] [security2:error] [pid 1018003:tid 1018200] [client 20.104.18.15:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK9bTAh5Y1i2tUxg4ES9gAABek"] [Sat Aug 29 05:07:25.995296 2026] [security2:error] [pid 1028675:tid 1028859] [client 20.48.250.41:35086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ioxi.php"] [unique_id "apK9bddHPfW2QFvhmL7lSAAAADE"] [Sat Aug 29 05:07:26.000983 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.23.184.117:11940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9bjAh5Y1i2tUxg4ES-QAABfk"] [Sat Aug 29 05:07:26.013344 2026] [security2:error] [pid 1028675:tid 1028919] [client 158.23.184.117:11734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/.well-known/aa.php"] [unique_id "apK9btdHPfW2QFvhmL7lSgAAAG0"] [Sat Aug 29 05:07:26.014046 2026] [security2:error] [pid 1018003:tid 1018252] [client 158.23.184.117:30251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/av.php"] [unique_id "apK9bjAh5Y1i2tUxg4ES-wAABhw"] [Sat Aug 29 05:07:26.019406 2026] [security2:error] [pid 1018003:tid 1018080] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.docker/laravel/app/.env"] [unique_id "apK9bjAh5Y1i2tUxg4ES_wAGGjs"] [Sat Aug 29 05:07:26.019791 2026] [security2:error] [pid 1018003:tid 1018188] [client 4.205.62.107:21627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/fleen.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETAAAABd0"] [Sat Aug 29 05:07:26.021951 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.021968 2026] [core:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.022844 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.022866 2026] [core:error] [pid 1028675:tid 1028855] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.025367 2026] [core:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.025380 2026] [core:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.026536 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.026554 2026] [core:error] [pid 1028675:tid 1028911] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.027026 2026] [core:error] [pid 1028675:tid 1028811] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.027041 2026] [core:error] [pid 1028675:tid 1028811] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.037384 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.037398 2026] [core:error] [pid 1018003:tid 1018174] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.047796 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.23.184.117:63801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/wp-blog-header.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETBQAABdI"] [Sat Aug 29 05:07:26.052513 2026] [core:error] [pid 1018003:tid 1018222] [client 158.158.54.35:15169] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.052531 2026] [core:error] [pid 1018003:tid 1018222] [client 158.158.54.35:15169] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.055424 2026] [core:error] [pid 1028675:tid 1028918] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.055448 2026] [core:error] [pid 1028675:tid 1028918] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.070559 2026] [security2:error] [pid 1018003:tid 1018163] [client 40.83.93.50:5640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/users.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETBwAABcQ"] [Sat Aug 29 05:07:26.072248 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.072267 2026] [core:error] [pid 1028675:tid 1028887] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.082453 2026] [security2:error] [pid 1028675:tid 1028860] [client 158.23.184.117:11909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "apK9btdHPfW2QFvhmL7lUQAAADI"] [Sat Aug 29 05:07:26.082573 2026] [security2:error] [pid 1028675:tid 1028914] [client 158.23.184.117:4251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9btdHPfW2QFvhmL7lUwAAAGg"] [Sat Aug 29 05:07:26.082613 2026] [security2:error] [pid 1028675:tid 1028932] [client 52.139.37.240:14513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/ws49.php"] [unique_id "apK9btdHPfW2QFvhmL7lUgAAAHo"] [Sat Aug 29 05:07:26.085944 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.48.250.41:49024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/gk.php"] [unique_id "apK9btdHPfW2QFvhmL7lVAAAAEE"] [Sat Aug 29 05:07:26.115418 2026] [security2:error] [pid 1018003:tid 1018106] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.env.bak"] [unique_id "apK9bjAh5Y1i2tUxg4ETCQAF4FU"] [Sat Aug 29 05:07:26.115576 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.115593 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.116934 2026] [security2:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "apK9bjAh5Y1i2tUxg4ETCwAF4Fs"] [Sat Aug 29 05:07:26.125372 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.104.18.15:12276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/wsd.php"] [unique_id "apK9btdHPfW2QFvhmL7lWQAAAF4"] [Sat Aug 29 05:07:26.139735 2026] [security2:error] [pid 1028675:tid 1028917] [client 146.70.194.254:59624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9btdHPfW2QFvhmL7lWgAAAGs"] [Sat Aug 29 05:07:26.146407 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.146425 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.160859 2026] [security2:error] [pid 1028675:tid 1028927] [client 158.23.184.117:30067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/autoload_classmap.php"] [unique_id "apK9btdHPfW2QFvhmL7lWwAAAHU"] [Sat Aug 29 05:07:26.163738 2026] [security2:error] [pid 1028675:tid 1028901] [client 158.23.184.117:11769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "apK9btdHPfW2QFvhmL7lXAAAAFs"] [Sat Aug 29 05:07:26.164695 2026] [security2:error] [pid 1028675:tid 1028890] [client 158.23.147.79:17474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/hehehehe.php"] [unique_id "apK9btdHPfW2QFvhmL7lXgAAAFA"] [Sat Aug 29 05:07:26.176251 2026] [security2:error] [pid 1028675:tid 1028845] [client 68.155.159.216:16077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/wp-mail.php"] [unique_id "apK9btdHPfW2QFvhmL7lXwAAACM"] [Sat Aug 29 05:07:26.177116 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.177131 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.185170 2026] [security2:error] [pid 1028675:tid 1028858] [client 52.138.0.157:10498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-content/themes/fitnessbase/404.php"] [unique_id "apK9btdHPfW2QFvhmL7lYAAAADA"] [Sat Aug 29 05:07:26.188177 2026] [security2:error] [pid 1028675:tid 1028896] [client 40.83.93.50:11709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/config.php"] [unique_id "apK9btdHPfW2QFvhmL7lYQAAAFY"] [Sat Aug 29 05:07:26.196335 2026] [security2:error] [pid 1018003:tid 1018125] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/.env.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETEwAF4Gg"] [Sat Aug 29 05:07:26.197601 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.48.250.41:35483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/bootstrap.php"] [unique_id "apK9btdHPfW2QFvhmL7lYwAAACs"] [Sat Aug 29 05:07:26.204392 2026] [security2:error] [pid 1028675:tid 1028815] [client 158.23.184.117:12057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9btdHPfW2QFvhmL7lZQAAAAU"] [Sat Aug 29 05:07:26.204512 2026] [security2:error] [pid 1018003:tid 1018097] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.env.old"] [unique_id "apK9bjAh5Y1i2tUxg4ETFgAF4Ew"] [Sat Aug 29 05:07:26.226710 2026] [security2:error] [pid 1018003:tid 1018207] [client 20.203.141.11:3053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/goods.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETGAAABfA"] [Sat Aug 29 05:07:26.227798 2026] [security2:error] [pid 1028675:tid 1028889] [client 158.23.184.117:11731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dubeyko.com"] [uri "/admin/alfa-rex.php"] [unique_id "apK9btdHPfW2QFvhmL7laQAAAE8"] [Sat Aug 29 05:07:26.243425 2026] [security2:error] [pid 1028675:tid 1028859] [client 158.23.184.117:39969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cworthy.net"] [uri "/2.php"] [unique_id "apK9btdHPfW2QFvhmL7lbAAAADE"] [Sat Aug 29 05:07:26.243983 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.48.250.41:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/logs1.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETGgAABdc"] [Sat Aug 29 05:07:26.253761 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.104.18.15:12178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/bulet.php"] [unique_id "apK9btdHPfW2QFvhmL7lbwAAAGQ"] [Sat Aug 29 05:07:26.268273 2026] [security2:error] [pid 1018003:tid 1018190] [client 4.205.62.107:26625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/wp-config.backup.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETHgAABd8"] [Sat Aug 29 05:07:26.275262 2026] [security2:error] [pid 1018003:tid 1018140] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.env.swp"] [unique_id "apK9bjAh5Y1i2tUxg4ETIAAF4Hc"] [Sat Aug 29 05:07:26.276039 2026] [security2:error] [pid 1028675:tid 1028888] [client 52.139.37.240:14708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/xxx.php"] [unique_id "apK9btdHPfW2QFvhmL7lcQAAAE4"] [Sat Aug 29 05:07:26.279317 2026] [security2:error] [pid 1028675:tid 1028840] [client 20.196.209.81:1890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/class-walker-category-dropdown-class.php"] [unique_id "apK9btdHPfW2QFvhmL7lcgAAAB4"] [Sat Aug 29 05:07:26.282332 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.282346 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.284535 2026] [security2:error] [pid 1028675:tid 1028884] [client 158.23.184.117:4384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lumbeesolar.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9btdHPfW2QFvhmL7ldAAAAEo"] [Sat Aug 29 05:07:26.284938 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.284949 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.286572 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.286586 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.286940 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.286950 2026] [core:error] [pid 1018003:tid 1018212] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.287576 2026] [security2:error] [pid 1028675:tid 1028836] [client 20.104.49.130:46556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.likesareus.com"] [uri "/666.php"] [unique_id "apK9btdHPfW2QFvhmL7ldgAAABo"] [Sat Aug 29 05:07:26.295507 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.295519 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.304697 2026] [security2:error] [pid 1028675:tid 1028824] [client 158.23.184.117:30057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mikelait.managemymood.com"] [uri "/asus.php"] [unique_id "apK9btdHPfW2QFvhmL7ldwAAAA4"] [Sat Aug 29 05:07:26.305845 2026] [security2:error] [pid 1018003:tid 1018187] [client 168.107.94.195:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETJgAABdw"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:26.315756 2026] [core:error] [pid 1028675:tid 1028856] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.315768 2026] [core:error] [pid 1028675:tid 1028856] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.323888 2026] [security2:error] [pid 1028675:tid 1028846] [client 158.23.184.117:12044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.it-methods.com"] [uri "/wp-content/plugins/alfa-rex.php"] [unique_id "apK9btdHPfW2QFvhmL7leQAAACQ"] [Sat Aug 29 05:07:26.327685 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.327698 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.331689 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.48.250.41:35018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/export.php"] [unique_id "apK9btdHPfW2QFvhmL7lfQAAAHc"] [Sat Aug 29 05:07:26.333171 2026] [security2:error] [pid 1028675:tid 1028819] [client 4.205.62.107:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/file59.php"] [unique_id "apK9btdHPfW2QFvhmL7lfgAAAAk"] [Sat Aug 29 05:07:26.340465 2026] [core:error] [pid 1028675:tid 1028923] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.340477 2026] [core:error] [pid 1028675:tid 1028923] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.348535 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.348550 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.351694 2026] [core:error] [pid 1018003:tid 1018255] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.351707 2026] [core:error] [pid 1018003:tid 1018255] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.355009 2026] [core:error] [pid 1028675:tid 1028861] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.355027 2026] [core:error] [pid 1028675:tid 1028861] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.378857 2026] [security2:error] [pid 1018003:tid 1018203] [client 52.138.0.157:20495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETLAAABew"] [Sat Aug 29 05:07:26.379275 2026] [security2:error] [pid 1028675:tid 1028847] [client 4.205.62.107:22392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/upload.form.php"] [unique_id "apK9btdHPfW2QFvhmL7lhQAAACU"] [Sat Aug 29 05:07:26.381676 2026] [security2:error] [pid 1018003:tid 1018216] [client 158.23.147.79:48291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETLQAABfk"] [Sat Aug 29 05:07:26.393867 2026] [security2:error] [pid 1028675:tid 1028896] [client 4.205.62.107:9008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/doc.php"] [unique_id "apK9btdHPfW2QFvhmL7lhgAAAFY"] [Sat Aug 29 05:07:26.395438 2026] [security2:error] [pid 1028675:tid 1028843] [client 158.23.184.117:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enveso.com"] [uri "/test.php"] [unique_id "apK9btdHPfW2QFvhmL7lhwAAACE"] [Sat Aug 29 05:07:26.398093 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.48.250.41:49055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/inege.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETLwAABd0"] [Sat Aug 29 05:07:26.399077 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.399091 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.419501 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.203.141.11:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-admin/js/index.php"] [unique_id "apK9btdHPfW2QFvhmL7ligAAAH8"] [Sat Aug 29 05:07:26.443785 2026] [security2:error] [pid 1018003:tid 1018270] [client 158.23.147.79:25497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/images/index.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETMAAABi4"] [Sat Aug 29 05:07:26.453629 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.18.15:12264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/av.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETMwAABhY"] [Sat Aug 29 05:07:26.455910 2026] [security2:error] [pid 1028675:tid 1028859] [client 20.104.18.15:19417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9btdHPfW2QFvhmL7ljgAAADE"] [Sat Aug 29 05:07:26.456323 2026] [security2:error] [pid 1018003:tid 1018155] [client 149.34.210.141:34037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETNQAABbw"] [Sat Aug 29 05:07:26.456423 2026] [security2:error] [pid 1018003:tid 1018155] [client 149.34.210.141:34037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "playandlearntherapy.com"] [uri "/xmlrpc.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETNQAABbw"] [Sat Aug 29 05:07:26.464156 2026] [security2:error] [pid 1018003:tid 1018119] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.env~"] [unique_id "apK9bjAh5Y1i2tUxg4ETOAAF_mI"] [Sat Aug 29 05:07:26.471068 2026] [security2:error] [pid 1028675:tid 1028811] [client 195.178.110.247:5414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lifesosweet.com"] [uri "/index.php"] [unique_id "apK9btdHPfW2QFvhmL7lkQAAAAE"] [Sat Aug 29 05:07:26.471106 2026] [security2:error] [pid 1028675:tid 1028911] [client 68.155.159.216:30693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/asd.php"] [unique_id "apK9btdHPfW2QFvhmL7lkAAAAGU"] [Sat Aug 29 05:07:26.474502 2026] [security2:error] [pid 1018003:tid 1018192] [client 52.139.37.240:14718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/0x.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETOQAABeE"] [Sat Aug 29 05:07:26.501442 2026] [security2:error] [pid 1018003:tid 1018123] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.git/config.old"] [unique_id "apK9bjAh5Y1i2tUxg4ETPAAF_mY"] [Sat Aug 29 05:07:26.502389 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.158.54.35:16132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETPQAABcg"] [Sat Aug 29 05:07:26.507029 2026] [security2:error] [pid 1018003:tid 1018026] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.git/config~"] [unique_id "apK9bjAh5Y1i2tUxg4ETPgAF_gU"] [Sat Aug 29 05:07:26.538977 2026] [core:error] [pid 1028675:tid 1028884] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.538993 2026] [core:error] [pid 1028675:tid 1028884] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.540679 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.540694 2026] [core:error] [pid 1028675:tid 1028876] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.541956 2026] [core:error] [pid 1028675:tid 1028918] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.541970 2026] [core:error] [pid 1028675:tid 1028918] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.545619 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.545631 2026] [core:error] [pid 1028675:tid 1028822] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.549692 2026] [core:error] [pid 1028675:tid 1028836] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.549703 2026] [core:error] [pid 1028675:tid 1028836] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.550231 2026] [security2:error] [pid 1028675:tid 1028830] [client 68.155.159.216:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9btdHPfW2QFvhmL7lnQAAABQ"] [Sat Aug 29 05:07:26.550915 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.48.250.41:49139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/wp-link10.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETRQAABd4"] [Sat Aug 29 05:07:26.565321 2026] [security2:error] [pid 1018003:tid 1018147] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/.git/config.bak"] [unique_id "apK9bjAh5Y1i2tUxg4ETSAAF_n4"] [Sat Aug 29 05:07:26.570317 2026] [core:error] [pid 1028675:tid 1028842] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.570329 2026] [core:error] [pid 1028675:tid 1028842] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.577815 2026] [security2:error] [pid 1028675:tid 1028844] [client 40.83.93.50:5202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/wp-cron.php"] [unique_id "apK9btdHPfW2QFvhmL7logAAACI"] [Sat Aug 29 05:07:26.580720 2026] [security2:error] [pid 1028675:tid 1028850] [client 158.158.54.35:22148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-load.php"] [unique_id "apK9btdHPfW2QFvhmL7lowAAACg"] [Sat Aug 29 05:07:26.584185 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.104.18.15:19440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9btdHPfW2QFvhmL7lpAAAACc"] [Sat Aug 29 05:07:26.589059 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.48.250.41:35074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/gk.php"] [unique_id "apK9btdHPfW2QFvhmL7lpQAAAC4"] [Sat Aug 29 05:07:26.592955 2026] [security2:error] [pid 1028675:tid 1028821] [client 52.138.0.157:20499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "apK9btdHPfW2QFvhmL7lpgAAAAs"] [Sat Aug 29 05:07:26.618133 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.618148 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.619250 2026] [security2:error] [pid 1028675:tid 1028904] [client 158.23.147.79:26506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/classwithtostring.php"] [unique_id "apK9btdHPfW2QFvhmL7lqQAAAF4"] [Sat Aug 29 05:07:26.622421 2026] [core:error] [pid 1028675:tid 1028871] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.622439 2026] [core:error] [pid 1028675:tid 1028871] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.633455 2026] [security2:error] [pid 1028675:tid 1028908] [client 195.178.110.247:48676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lifesosweet.com"] [uri "/index.php"] [unique_id "apK9btdHPfW2QFvhmL7lqwAAAGI"] [Sat Aug 29 05:07:26.662834 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.662858 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.665911 2026] [security2:error] [pid 1028675:tid 1028867] [client 68.155.159.216:33551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/dropdown.php"] [unique_id "apK9btdHPfW2QFvhmL7lswAAADk"] [Sat Aug 29 05:07:26.667480 2026] [security2:error] [pid 1028675:tid 1028826] [client 52.139.37.240:14692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/CDX1.php"] [unique_id "apK9btdHPfW2QFvhmL7ltgAAABA"] [Sat Aug 29 05:07:26.672239 2026] [security2:error] [pid 1018003:tid 1018202] [client 40.83.93.50:7983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/22.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETTQAABes"] [Sat Aug 29 05:07:26.674766 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.674779 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.680083 2026] [security2:error] [pid 1018003:tid 1018159] [client 68.155.159.216:64456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/hehehehe.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETTwAABcA"] [Sat Aug 29 05:07:26.684368 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.196.209.81:10572] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.hellospringford.wine-garden.com"] [uri "/1.php7"] [unique_id "apK9btdHPfW2QFvhmL7luwAAAFc"] [Sat Aug 29 05:07:26.684440 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.196.209.81:10572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/1.php7"] [unique_id "apK9btdHPfW2QFvhmL7luwAAAFc"] [Sat Aug 29 05:07:26.687501 2026] [security2:error] [pid 1018003:tid 1018196] [client 168.107.94.195:65318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETUAAABeU"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:26.689130 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.48.250.41:49120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ww.php"] [unique_id "apK9btdHPfW2QFvhmL7lvQAAADA"] [Sat Aug 29 05:07:26.700018 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.104.18.15:12248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/images.php"] [unique_id "apK9btdHPfW2QFvhmL7lvwAAACs"] [Sat Aug 29 05:07:26.713721 2026] [core:error] [pid 1028675:tid 1028815] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.713734 2026] [core:error] [pid 1028675:tid 1028815] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.713888 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.713897 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.727529 2026] [security2:error] [pid 1028675:tid 1028879] [client 20.203.141.11:38626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/css.php"] [unique_id "apK9btdHPfW2QFvhmL7lxgAAAEU"] [Sat Aug 29 05:07:26.740244 2026] [security2:error] [pid 1028675:tid 1028911] [client 68.155.159.216:12139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9btdHPfW2QFvhmL7lyQAAAGU"] [Sat Aug 29 05:07:26.749395 2026] [security2:error] [pid 1028675:tid 1028888] [client 57.141.14.67:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK9btdHPfW2QFvhmL7lygAAAE4"] [Sat Aug 29 05:07:26.749927 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.104.18.15:19399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/ap.php"] [unique_id "apK9btdHPfW2QFvhmL7lywAAAFQ"] [Sat Aug 29 05:07:26.760474 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.760490 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.771314 2026] [security2:error] [pid 1028675:tid 1028822] [client 158.23.147.79:30472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/worksec.php"] [unique_id "apK9btdHPfW2QFvhmL7l1AAAAAw"] [Sat Aug 29 05:07:26.782196 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.48.250.41:35106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/logs1.php"] [unique_id "apK9btdHPfW2QFvhmL7l2wAAADI"] [Sat Aug 29 05:07:26.787578 2026] [security2:error] [pid 1018003:tid 1018268] [client 52.138.0.157:5682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-content/uploads/de_fb_uploads/b.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETWwAABiw"] [Sat Aug 29 05:07:26.793453 2026] [security2:error] [pid 1018003:tid 1018277] [client 4.205.62.107:53138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/ty.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETXAAABjU"] [Sat Aug 29 05:07:26.799647 2026] [security2:error] [pid 1028675:tid 1028812] [client 158.23.147.79:30414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9btdHPfW2QFvhmL7l3AAAAAI"] [Sat Aug 29 05:07:26.801025 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.151.200.44:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9btdHPfW2QFvhmL7l3QAAAB0"] [Sat Aug 29 05:07:26.808688 2026] [security2:error] [pid 1028675:tid 1028916] [client 20.104.49.130:47842] ModSecurity: Access denied with connection close (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1032"] [id "900036"] [msg "Wordpress BOT exploit :: No UA/Referer"] [hostname "mail.flatlandsfoto.com"] [uri "/wp-login.php"] [unique_id "apK9btdHPfW2QFvhmL7l3gAAAGo"] [Sat Aug 29 05:07:26.810089 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.810101 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.812900 2026] [core:error] [pid 1028675:tid 1028850] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.812915 2026] [core:error] [pid 1028675:tid 1028850] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.813004 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.813015 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.814168 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.814182 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.817096 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.817108 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.820995 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.104.49.130:36329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/fs.php"] [unique_id "apK9btdHPfW2QFvhmL7l5gAAAD0"] [Sat Aug 29 05:07:26.830800 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.830815 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.840041 2026] [security2:error] [pid 1028675:tid 1028922] [client 20.48.250.41:48993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/w1px.php"] [unique_id "apK9btdHPfW2QFvhmL7l7AAAAHA"] [Sat Aug 29 05:07:26.858575 2026] [security2:error] [pid 1028675:tid 1028861] [client 68.155.159.216:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9btdHPfW2QFvhmL7l7wAAADM"] [Sat Aug 29 05:07:26.863514 2026] [security2:error] [pid 1028675:tid 1028832] [client 52.139.37.240:14694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/akcc.php"] [unique_id "apK9btdHPfW2QFvhmL7l8AAAABY"] [Sat Aug 29 05:07:26.880580 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.880602 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.880720 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.880730 2026] [core:error] [pid 1028675:tid 1028858] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.884740 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.884753 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.886789 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.886806 2026] [core:error] [pid 1028675:tid 1028930] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.887277 2026] [security2:error] [pid 1018003:tid 1018170] [client 68.155.159.216:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETbAAABcs"] [Sat Aug 29 05:07:26.887780 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.887793 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.889052 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.203.141.11:8984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/core.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETbQAABb4"] [Sat Aug 29 05:07:26.889940 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.889953 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.895797 2026] [security2:error] [pid 1028675:tid 1028911] [client 20.104.18.15:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/media.php"] [unique_id "apK9btdHPfW2QFvhmL7l-QAAAGU"] [Sat Aug 29 05:07:26.897202 2026] [security2:error] [pid 1028675:tid 1028892] [client 68.155.159.216:33718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/index/function.php"] [unique_id "apK9btdHPfW2QFvhmL7l-gAAAFI"] [Sat Aug 29 05:07:26.945777 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/ops.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETcAAABi4"] [Sat Aug 29 05:07:26.959333 2026] [core:error] [pid 1028675:tid 1028828] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.959768 2026] [core:error] [pid 1028675:tid 1028828] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.960503 2026] [security2:error] [pid 1018003:tid 1018192] [client 68.155.159.216:18273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETdAAABeE"] [Sat Aug 29 05:07:26.984234 2026] [security2:error] [pid 1018003:tid 1018222] [client 52.138.0.157:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apK9bjAh5Y1i2tUxg4ETdQAABf8"] [Sat Aug 29 05:07:26.989778 2026] [core:error] [pid 1028675:tid 1028914] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:26.989795 2026] [core:error] [pid 1028675:tid 1028914] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.007943 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.007967 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.011489 2026] [security2:error] [pid 1018003:tid 1018231] [client 158.158.54.35:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETewAABgc"] [Sat Aug 29 05:07:27.021839 2026] [security2:error] [pid 1018003:tid 1018213] [client 68.155.159.216:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/images/index.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETfgAABfY"] [Sat Aug 29 05:07:27.028345 2026] [security2:error] [pid 1018003:tid 1018043] [remote 216.73.216.46:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goodtogo-store.sortthru.com"] [uri "/reception-signs/"] [unique_id "apK9bzAh5Y1i2tUxg4ETfQAGFBY"] [Sat Aug 29 05:07:27.044605 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.044626 2026] [core:error] [pid 1028675:tid 1028917] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.045673 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.045673 2026] [core:error] [pid 1028675:tid 1028884] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.045690 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.045694 2026] [core:error] [pid 1028675:tid 1028884] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.046740 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.046755 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.048315 2026] [core:error] [pid 1028675:tid 1028875] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.048327 2026] [core:error] [pid 1028675:tid 1028875] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.062029 2026] [security2:error] [pid 1028675:tid 1028839] [client 52.139.37.240:14952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "apK9b9dHPfW2QFvhmL7mCQAAAB0"] [Sat Aug 29 05:07:27.063590 2026] [security2:error] [pid 1028675:tid 1028872] [client 40.83.93.50:5653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/wp-links-opml.php"] [unique_id "apK9b9dHPfW2QFvhmL7mCgAAAD4"] [Sat Aug 29 05:07:27.067906 2026] [security2:error] [pid 1018003:tid 1018182] [client 168.107.94.195:49343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETgQAABdc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:27.077339 2026] [security2:error] [pid 1028675:tid 1028928] [client 20.104.18.15:12160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/coffexium.php"] [unique_id "apK9b9dHPfW2QFvhmL7mCwAAAHY"] [Sat Aug 29 05:07:27.110830 2026] [security2:error] [pid 1018003:tid 1018265] [client 20.104.18.15:19392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/adminfuns.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETggAABik"] [Sat Aug 29 05:07:27.139731 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.196.209.81:10597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/ds.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETigAABfw"] [Sat Aug 29 05:07:27.142713 2026] [core:error] [pid 1028675:tid 1028879] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.142729 2026] [core:error] [pid 1028675:tid 1028879] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.151973 2026] [security2:error] [pid 1018003:tid 1018238] [client 4.205.62.107:21600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/upload.form.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETjwAABg4"] [Sat Aug 29 05:07:27.157106 2026] [core:error] [pid 1018003:tid 1018255] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.157123 2026] [core:error] [pid 1018003:tid 1018255] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.161318 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.161332 2026] [core:error] [pid 1018003:tid 1018266] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.161717 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.161734 2026] [core:error] [pid 1028675:tid 1028845] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.162046 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.162060 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.164557 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.164568 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.164926 2026] [security2:error] [pid 1028675:tid 1028849] [client 40.83.93.50:7986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/bak.phps"] [unique_id "apK9b9dHPfW2QFvhmL7mFgAAACc"] [Sat Aug 29 05:07:27.166663 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.166676 2026] [core:error] [pid 1018003:tid 1018190] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.176687 2026] [security2:error] [pid 1018003:tid 1018177] [client 158.158.54.35:21991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/a.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETlwAABdI"] [Sat Aug 29 05:07:27.177613 2026] [core:error] [pid 1028675:tid 1028888] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.177625 2026] [core:error] [pid 1028675:tid 1028888] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.180155 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.180167 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.182148 2026] [security2:error] [pid 1018003:tid 1018268] [client 52.138.0.157:27785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETmQAABiw"] [Sat Aug 29 05:07:27.191290 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.191302 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.239438 2026] [security2:error] [pid 1028675:tid 1028937] [client 158.23.147.79:61599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9b9dHPfW2QFvhmL7mGwAAAH8"] [Sat Aug 29 05:07:27.251675 2026] [security2:error] [pid 1028675:tid 1028866] [client 197.219.150.206:62568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.150.219.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9b9dHPfW2QFvhmL7mHAAAADg"] [Sat Aug 29 05:07:27.251788 2026] [security2:error] [pid 1028675:tid 1028866] [client 197.219.150.206:62568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brunas.coach"] [uri "/xmlrpc.php"] [unique_id "apK9b9dHPfW2QFvhmL7mHAAAADg"] [Sat Aug 29 05:07:27.257189 2026] [security2:error] [pid 1028675:tid 1028836] [client 52.139.37.240:14663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/s.php"] [unique_id "apK9b9dHPfW2QFvhmL7mHQAAABo"] [Sat Aug 29 05:07:27.257189 2026] [security2:error] [pid 1018003:tid 1018246] [client 20.104.18.15:19328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/classwithtostring.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETnQAABhY"] [Sat Aug 29 05:07:27.271438 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.18.15:12173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/BDKR28WP.php"] [unique_id "apK9b9dHPfW2QFvhmL7mHgAAAHo"] [Sat Aug 29 05:07:27.274839 2026] [security2:error] [pid 1028675:tid 1028907] [client 158.23.147.79:17448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9b9dHPfW2QFvhmL7mHwAAAGE"] [Sat Aug 29 05:07:27.282696 2026] [security2:error] [pid 1028675:tid 1028812] [client 20.151.200.44:65274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9b9dHPfW2QFvhmL7mIQAAAAI"] [Sat Aug 29 05:07:27.289393 2026] [security2:error] [pid 1028675:tid 1028833] [client 52.139.37.240:19289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/ahax.php"] [unique_id "apK9b9dHPfW2QFvhmL7mIwAAABc"] [Sat Aug 29 05:07:27.290526 2026] [security2:error] [pid 1028675:tid 1028894] [client 61.9.8.52:13583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.8.9.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9b9dHPfW2QFvhmL7mIAAAAFQ"] [Sat Aug 29 05:07:27.290617 2026] [security2:error] [pid 1028675:tid 1028894] [client 61.9.8.52:13583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "yustorres.com"] [uri "/xmlrpc.php"] [unique_id "apK9b9dHPfW2QFvhmL7mIAAAAFQ"] [Sat Aug 29 05:07:27.302583 2026] [security2:error] [pid 1028675:tid 1028896] [client 158.23.147.79:50041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-content/radio.php"] [unique_id "apK9b9dHPfW2QFvhmL7mJQAAAFY"] [Sat Aug 29 05:07:27.314230 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.314244 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.351318 2026] [security2:error] [pid 1028675:tid 1028928] [client 68.155.159.216:24492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-login.php"] [unique_id "apK9b9dHPfW2QFvhmL7mKgAAAHY"] [Sat Aug 29 05:07:27.374545 2026] [security2:error] [pid 1028675:tid 1028841] [client 52.138.0.157:20509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/PHPMailer/index.php"] [unique_id "apK9b9dHPfW2QFvhmL7mKwAAAB8"] [Sat Aug 29 05:07:27.396510 2026] [security2:error] [pid 1028675:tid 1028936] [client 20.203.141.11:11243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/admin/function.php"] [unique_id "apK9b9dHPfW2QFvhmL7mLgAAAH4"] [Sat Aug 29 05:07:27.402150 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.402169 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.402819 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.402832 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.404390 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.404403 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.405743 2026] [security2:error] [pid 1018003:tid 1018207] [client 4.205.62.107:24986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/edit.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETugAABfA"] [Sat Aug 29 05:07:27.407644 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.104.18.15:12277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/sf.php"] [unique_id "apK9b9dHPfW2QFvhmL7mMQAAAFo"] [Sat Aug 29 05:07:27.408219 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.408220 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.104.18.15:19423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/3PJcpMFsD8B.php"] [unique_id "apK9b9dHPfW2QFvhmL7mMgAAACE"] [Sat Aug 29 05:07:27.408231 2026] [core:error] [pid 1018003:tid 1018273] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.408290 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.408298 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.409273 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.409290 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.410733 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.410745 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.421171 2026] [core:error] [pid 1028675:tid 1028820] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.421184 2026] [core:error] [pid 1028675:tid 1028820] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.421329 2026] [core:error] [pid 1028675:tid 1028846] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.421338 2026] [core:error] [pid 1028675:tid 1028846] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.422723 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.422735 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.435823 2026] [core:error] [pid 1028675:tid 1028910] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.435844 2026] [core:error] [pid 1028675:tid 1028910] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.446190 2026] [security2:error] [pid 1028675:tid 1028930] [client 168.107.94.195:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9b9dHPfW2QFvhmL7mOQAAAHg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:27.450096 2026] [security2:error] [pid 1028675:tid 1028863] [client 52.139.37.240:14925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/sagax.php"] [unique_id "apK9b9dHPfW2QFvhmL7mOgAAADU"] [Sat Aug 29 05:07:27.452571 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.452585 2026] [core:error] [pid 1018003:tid 1018233] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.453133 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.453144 2026] [core:error] [pid 1018003:tid 1018172] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.454348 2026] [core:error] [pid 1018003:tid 1018161] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.454367 2026] [core:error] [pid 1018003:tid 1018161] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.456520 2026] [security2:error] [pid 1028675:tid 1028911] [client 158.23.147.79:32741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/about/function.php"] [unique_id "apK9b9dHPfW2QFvhmL7mOwAAAGU"] [Sat Aug 29 05:07:27.459536 2026] [security2:error] [pid 1028675:tid 1028904] [client 158.158.54.35:29663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/gifclass.php"] [unique_id "apK9b9dHPfW2QFvhmL7mPAAAAF4"] [Sat Aug 29 05:07:27.469605 2026] [security2:error] [pid 1028675:tid 1028920] [client 4.205.62.107:58475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/time.php"] [unique_id "apK9b9dHPfW2QFvhmL7mPwAAAG4"] [Sat Aug 29 05:07:27.481698 2026] [security2:error] [pid 1028675:tid 1028845] [client 52.139.37.240:19318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/breads1.php"] [unique_id "apK9b9dHPfW2QFvhmL7mQAAAACM"] [Sat Aug 29 05:07:27.488647 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.488662 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.490602 2026] [security2:error] [pid 1028675:tid 1028890] [client 158.23.147.79:48192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/goat1.php"] [unique_id "apK9b9dHPfW2QFvhmL7mQQAAAFA"] [Sat Aug 29 05:07:27.528256 2026] [security2:error] [pid 1028675:tid 1028830] [client 4.205.62.107:22024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/v3.php"] [unique_id "apK9b9dHPfW2QFvhmL7mQgAAABQ"] [Sat Aug 29 05:07:27.530810 2026] [security2:error] [pid 1028675:tid 1028824] [client 40.83.93.50:5650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/wp-load.php"] [unique_id "apK9b9dHPfW2QFvhmL7mQwAAAA4"] [Sat Aug 29 05:07:27.533406 2026] [security2:error] [pid 1028675:tid 1028932] [client 68.155.159.216:49341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9b9dHPfW2QFvhmL7mRAAAAHo"] [Sat Aug 29 05:07:27.540865 2026] [security2:error] [pid 1018003:tid 1018226] [client 146.70.36.124:49828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apK9bzAh5Y1i2tUxg4ETxAAABgM"] [Sat Aug 29 05:07:27.548003 2026] [security2:error] [pid 1028675:tid 1028894] [client 158.23.147.79:25556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9b9dHPfW2QFvhmL7mRgAAAFQ"] [Sat Aug 29 05:07:27.565267 2026] [security2:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/API/.env"] [unique_id "apK9bzAh5Y1i2tUxg4ETxgAGK0c"] [Sat Aug 29 05:07:27.572283 2026] [core:error] [pid 1028675:tid 1028819] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.572298 2026] [core:error] [pid 1028675:tid 1028819] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.575158 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.196.209.81:10609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/GOD.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETyQAABg4"] [Sat Aug 29 05:07:27.577179 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.104.18.15:12174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/k.php"] [unique_id "apK9b9dHPfW2QFvhmL7mSgAAAEE"] [Sat Aug 29 05:07:27.580167 2026] [core:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.580180 2026] [core:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.582541 2026] [security2:error] [pid 1018003:tid 1018192] [client 20.104.18.15:19449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/5PJcpMFsD8B.php"] [unique_id "apK9bzAh5Y1i2tUxg4ETywAABeE"] [Sat Aug 29 05:07:27.589820 2026] [core:error] [pid 1018003:tid 1018059] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.589837 2026] [core:error] [pid 1018003:tid 1018059] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.590978 2026] [security2:error] [pid 1028675:tid 1028821] [client 68.155.159.216:30690] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/1.php"] [unique_id "apK9b9dHPfW2QFvhmL7mSwAAAAs"] [Sat Aug 29 05:07:27.591054 2026] [security2:error] [pid 1028675:tid 1028821] [client 68.155.159.216:30690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/1.php"] [unique_id "apK9b9dHPfW2QFvhmL7mSwAAAAs"] [Sat Aug 29 05:07:27.599436 2026] [core:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.599451 2026] [core:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.600483 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.600495 2026] [core:error] [pid 1018003:tid 1018030] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.603515 2026] [core:error] [pid 1028675:tid 1028927] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.603527 2026] [core:error] [pid 1028675:tid 1028927] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.609029 2026] [core:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.609043 2026] [core:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.613519 2026] [core:error] [pid 1018003:tid 1018028] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.613531 2026] [core:error] [pid 1018003:tid 1018028] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.614605 2026] [security2:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/APP/.env"] [unique_id "apK9bzAh5Y1i2tUxg4ET0wAGKz8"] [Sat Aug 29 05:07:27.614636 2026] [security2:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/Api/.env"] [unique_id "apK9bzAh5Y1i2tUxg4ET0gAGK0s"] [Sat Aug 29 05:07:27.634799 2026] [security2:error] [pid 1018003:tid 1018248] [client 52.138.0.157:5695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/SimplePie/autoload_classmap.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET1AAABhg"] [Sat Aug 29 05:07:27.635145 2026] [security2:error] [pid 1018003:tid 1018081] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/.wp-config.php.swp"] [unique_id "apK9bzAh5Y1i2tUxg4ET1QAF5Dw"] [Sat Aug 29 05:07:27.638314 2026] [security2:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/ADMIN/.env"] [unique_id "apK9bzAh5Y1i2tUxg4ET1gAF_zc"] [Sat Aug 29 05:07:27.647276 2026] [authz_core:error] [pid 1028675:tid 1028816] [client 43.159.144.16:0] AH01630: client denied by server configuration: /home4/rocworxc/public_html/royalryder/php.ini, referer: http://www.royalryder.com [Sat Aug 29 05:07:27.667455 2026] [security2:error] [pid 1028675:tid 1028847] [client 158.158.54.35:5279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/u.php"] [unique_id "apK9b9dHPfW2QFvhmL7mUwAAACU"] [Sat Aug 29 05:07:27.674116 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.674140 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.677168 2026] [security2:error] [pid 1028675:tid 1028837] [client 52.139.37.240:19281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/must.php"] [unique_id "apK9b9dHPfW2QFvhmL7mVAAAABs"] [Sat Aug 29 05:07:27.717728 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.104.18.15:19448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/4PJcpMFsD8B.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET2gAABfk"] [Sat Aug 29 05:07:27.722837 2026] [security2:error] [pid 1018003:tid 1018271] [client 52.139.37.240:14504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-content/plugins/ftde.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET3AAABi8"] [Sat Aug 29 05:07:27.724283 2026] [security2:error] [pid 1018003:tid 1018207] [client 158.23.147.79:26445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/install.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET3QAABfA"] [Sat Aug 29 05:07:27.728468 2026] [security2:error] [pid 1018003:tid 1018273] [client 4.205.62.107:9159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/atex1.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET3wAABjE"] [Sat Aug 29 05:07:27.728498 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/82.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET3gAABes"] [Sat Aug 29 05:07:27.751717 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.151.200.44:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/baee.php"] [unique_id "apK9b9dHPfW2QFvhmL7mVQAAAFg"] [Sat Aug 29 05:07:27.759994 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.104.49.130:47945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/reop3.php"] [unique_id "apK9b9dHPfW2QFvhmL7mVwAAAHc"] [Sat Aug 29 05:07:27.776033 2026] [security2:error] [pid 1028675:tid 1028840] [client 68.155.159.216:33787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/.well-known/index.php"] [unique_id "apK9b9dHPfW2QFvhmL7mWAAAAB4"] [Sat Aug 29 05:07:27.788124 2026] [security2:error] [pid 1028675:tid 1028923] [client 68.155.159.216:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9b9dHPfW2QFvhmL7mWQAAAHE"] [Sat Aug 29 05:07:27.823909 2026] [security2:error] [pid 1028675:tid 1028925] [client 168.107.94.195:50268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9b9dHPfW2QFvhmL7mWwAAAHM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:27.831041 2026] [security2:error] [pid 1028675:tid 1028879] [client 52.138.0.157:27793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9b9dHPfW2QFvhmL7mXAAAAEU"] [Sat Aug 29 05:07:27.832475 2026] [security2:error] [pid 1028675:tid 1028850] [client 103.168.67.159:50004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9b9dHPfW2QFvhmL7mXQAAACg"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:07:27.842815 2026] [security2:error] [pid 1028675:tid 1028818] [client 146.70.36.124:49832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.36.70.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.airviewconcept.com"] [uri "/xmlrpc.php"] [unique_id "apK9b9dHPfW2QFvhmL7mXgAAAAg"] [Sat Aug 29 05:07:27.847489 2026] [security2:error] [pid 1028675:tid 1028909] [client 68.155.159.216:12208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9b9dHPfW2QFvhmL7mXwAAAGM"] [Sat Aug 29 05:07:27.847827 2026] [security2:error] [pid 1028675:tid 1028926] [client 111.235.68.106:1868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.68.235.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9b9dHPfW2QFvhmL7mYAAAAHQ"] [Sat Aug 29 05:07:27.847912 2026] [security2:error] [pid 1028675:tid 1028926] [client 111.235.68.106:1868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "harvesthouse.ph"] [uri "/xmlrpc.php"] [unique_id "apK9b9dHPfW2QFvhmL7mYAAAAHQ"] [Sat Aug 29 05:07:27.867864 2026] [security2:error] [pid 1018003:tid 1018152] [client 213.202.253.4:63616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/userfuns.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET4gAABbk"], referer: www.google.com [Sat Aug 29 05:07:27.884867 2026] [security2:error] [pid 1018003:tid 1018212] [client 52.139.37.240:19291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/up.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET4wAABfU"] [Sat Aug 29 05:07:27.886939 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.18.15:19335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/wsd.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET5AAABfw"] [Sat Aug 29 05:07:27.896576 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.104.18.15:12266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/dex.php"] [unique_id "apK9b9dHPfW2QFvhmL7mYgAAAGw"] [Sat Aug 29 05:07:27.909098 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.147.79:30537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/x.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET5QAABbw"] [Sat Aug 29 05:07:27.909901 2026] [security2:error] [pid 1018003:tid 1018255] [client 158.23.147.79:30467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET5gAABh8"] [Sat Aug 29 05:07:27.912224 2026] [security2:error] [pid 1018003:tid 1018162] [client 52.139.37.240:14701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET5wAABcM"] [Sat Aug 29 05:07:27.913036 2026] [core:error] [pid 1028675:tid 1028912] [client 158.158.54.35:20553] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.913054 2026] [core:error] [pid 1028675:tid 1028912] [client 158.158.54.35:20553] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:27.926895 2026] [security2:error] [pid 1028675:tid 1028815] [client 40.83.93.50:7434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/install.php"] [unique_id "apK9b9dHPfW2QFvhmL7mZAAAAAU"] [Sat Aug 29 05:07:27.933430 2026] [security2:error] [pid 1018003:tid 1018236] [client 4.205.62.107:53290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET6AAABgw"] [Sat Aug 29 05:07:27.945918 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.203.141.11:23672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/admin/index.php"] [unique_id "apK9b9dHPfW2QFvhmL7mZQAAAB0"] [Sat Aug 29 05:07:27.966335 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:1936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9bzAh5Y1i2tUxg4ET6QAABd8"] [Sat Aug 29 05:07:27.994186 2026] [security2:error] [pid 1028675:tid 1028930] [client 40.83.93.50:5204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "apK9b9dHPfW2QFvhmL7mZwAAAHg"] [Sat Aug 29 05:07:27.995464 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.48.250.41:35052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/inege.php"] [unique_id "apK9b9dHPfW2QFvhmL7maAAAAFA"] [Sat Aug 29 05:07:28.004270 2026] [security2:error] [pid 1028675:tid 1028842] [client 20.196.209.81:14525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/ggfi.php"] [unique_id "apK9cNdHPfW2QFvhmL7maQAAACA"] [Sat Aug 29 05:07:28.022116 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.18.15:19347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/bulet.php"] [unique_id "apK9cNdHPfW2QFvhmL7magAAADI"] [Sat Aug 29 05:07:28.065905 2026] [security2:error] [pid 1028675:tid 1028824] [client 68.155.159.216:33625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/.well-known/content.php"] [unique_id "apK9cNdHPfW2QFvhmL7mbQAAAA4"] [Sat Aug 29 05:07:28.071114 2026] [security2:error] [pid 1018003:tid 1018268] [client 68.155.159.216:18414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/content.php"] [unique_id "apK9cDAh5Y1i2tUxg4ET6wAABiw"] [Sat Aug 29 05:07:28.071520 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.104.49.130:63594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiritofamericatour.org"] [uri "/reviall.php"] [unique_id "apK9cNdHPfW2QFvhmL7mbgAAAGE"] [Sat Aug 29 05:07:28.071677 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.104.62:10563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/mmm.php"] [unique_id "apK9cNdHPfW2QFvhmL7mbwAAAHo"] [Sat Aug 29 05:07:28.072777 2026] [security2:error] [pid 1028675:tid 1028812] [client 68.155.159.216:65094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apK9cNdHPfW2QFvhmL7mcAAAAAI"] [Sat Aug 29 05:07:28.081706 2026] [security2:error] [pid 1028675:tid 1028833] [client 20.104.18.15:12175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/inso.php"] [unique_id "apK9cNdHPfW2QFvhmL7mcgAAABc"] [Sat Aug 29 05:07:28.092336 2026] [http2:warn] [pid 1017536:tid 1017714] [client 57.141.14.73:47554] h2_stream(1017536-369-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:07:28.102114 2026] [security2:error] [pid 1018003:tid 1018203] [client 158.158.54.35:22461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/r.php"] [unique_id "apK9cDAh5Y1i2tUxg4ET7QAABew"] [Sat Aug 29 05:07:28.110843 2026] [security2:error] [pid 1028675:tid 1028899] [client 52.138.0.157:19642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/blocks/buttons/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7mdAAAAFk"] [Sat Aug 29 05:07:28.113315 2026] [security2:error] [pid 1018003:tid 1018226] [client 158.23.147.79:35223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9cDAh5Y1i2tUxg4ET7gAABgM"] [Sat Aug 29 05:07:28.123320 2026] [security2:error] [pid 1028675:tid 1028867] [client 195.178.110.247:5426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lifes-finance.com"] [uri "/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7mdQAAADk"] [Sat Aug 29 05:07:28.129508 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.151.200.44:63403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/d12.php"] [unique_id "apK9cNdHPfW2QFvhmL7megAAAAs"] [Sat Aug 29 05:07:28.133161 2026] [security2:error] [pid 1028675:tid 1028826] [client 68.155.159.216:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7mfAAAABA"] [Sat Aug 29 05:07:28.140146 2026] [security2:error] [pid 1028675:tid 1028804] [remote 136.108.23.170:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.23.108.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thesmartpm.com"] [uri "/apps/wp-login.php"] [unique_id "apK9cNdHPfW2QFvhmL7mdgAAR3s"], referer: https://thesmartpm.com/login [Sat Aug 29 05:07:28.143417 2026] [security2:error] [pid 1028675:tid 1028928] [client 52.139.37.240:19320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-content/155.php"] [unique_id "apK9cNdHPfW2QFvhmL7mfgAAAHY"] [Sat Aug 29 05:07:28.160172 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.104.18.15:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/av.php"] [unique_id "apK9cDAh5Y1i2tUxg4ET8AAABg4"] [Sat Aug 29 05:07:28.176031 2026] [security2:error] [pid 1028675:tid 1028900] [client 114.119.148.1:48865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.enproretail.com"] [uri "/blast-window-film-2"] [unique_id "apK9cNdHPfW2QFvhmL7mkAAAAFo"], referer: http://www.enproretail.com/view-control-window-film-2 [Sat Aug 29 05:07:28.177718 2026] [security2:error] [pid 1028675:tid 1028935] [client 20.104.49.130:63571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/samll.php"] [unique_id "apK9cNdHPfW2QFvhmL7mkQAAAH0"] [Sat Aug 29 05:07:28.181786 2026] [security2:error] [pid 1028675:tid 1028851] [client 52.139.37.240:14936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/z.php"] [unique_id "apK9cNdHPfW2QFvhmL7mkwAAACk"] [Sat Aug 29 05:07:28.206046 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.104.104.62:44597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/advanced.php"] [unique_id "apK9cNdHPfW2QFvhmL7mlgAAAG0"] [Sat Aug 29 05:07:28.206602 2026] [security2:error] [pid 1028675:tid 1028823] [client 168.107.94.195:50668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7mlwAAAA0"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:28.231842 2026] [security2:error] [pid 1018003:tid 1018183] [client 20.104.18.15:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/aa.php"] [unique_id "apK9cDAh5Y1i2tUxg4ET-AAABdg"] [Sat Aug 29 05:07:28.288292 2026] [security2:error] [pid 1028675:tid 1028875] [client 195.178.110.247:48692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lifes-finance.com"] [uri "/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7mmwAAAEE"] [Sat Aug 29 05:07:28.301212 2026] [security2:error] [pid 1028675:tid 1028918] [client 146.70.36.124:49840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9cNdHPfW2QFvhmL7mnQAAAGw"] [Sat Aug 29 05:07:28.306117 2026] [security2:error] [pid 1018003:tid 1018172] [client 4.205.62.107:22410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/aws_auth.php"] [unique_id "apK9cDAh5Y1i2tUxg4ET-gAABc0"] [Sat Aug 29 05:07:28.307248 2026] [security2:error] [pid 1018003:tid 1018231] [client 52.138.0.157:20534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/css/autoload_classmap.php"] [unique_id "apK9cDAh5Y1i2tUxg4ET-wAABgc"] [Sat Aug 29 05:07:28.320928 2026] [security2:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/BACKEND/.env"] [unique_id "apK9cDAh5Y1i2tUxg4ET_AAF6zM"] [Sat Aug 29 05:07:28.322341 2026] [security2:error] [pid 1028675:tid 1028876] [client 20.104.18.15:19398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/images.php"] [unique_id "apK9cNdHPfW2QFvhmL7mnwAAAEI"] [Sat Aug 29 05:07:28.324292 2026] [core:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.324306 2026] [core:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.327147 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.104.104.62:40198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/vinus.php"] [unique_id "apK9cDAh5Y1i2tUxg4ET_wAABcI"] [Sat Aug 29 05:07:28.327220 2026] [security2:error] [pid 1018003:tid 1018074] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/Backend/.env"] [unique_id "apK9cDAh5Y1i2tUxg4ET_gAF6zU"] [Sat Aug 29 05:07:28.329398 2026] [security2:error] [pid 1018003:tid 1018101] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/Be/.env"] [unique_id "apK9cDAh5Y1i2tUxg4EUAAAF61A"] [Sat Aug 29 05:07:28.338211 2026] [security2:error] [pid 1018003:tid 1018155] [client 52.139.37.240:19319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-update.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUAgAABbw"] [Sat Aug 29 05:07:28.341386 2026] [core:error] [pid 1028675:tid 1028921] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.341405 2026] [core:error] [pid 1028675:tid 1028921] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.351571 2026] [security2:error] [pid 1028675:tid 1028824] [client 68.155.159.216:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familytrade.ca"] [uri "/cgi-bin/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7mogAAAA4"] [Sat Aug 29 05:07:28.352626 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.104.104.62:10852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/blox.php"] [unique_id "apK9cNdHPfW2QFvhmL7mowAAAFc"] [Sat Aug 29 05:07:28.365855 2026] [security2:error] [pid 1018003:tid 1018179] [client 158.158.54.35:14927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUBAAABdQ"] [Sat Aug 29 05:07:28.376751 2026] [security2:error] [pid 1028675:tid 1028815] [client 52.139.37.240:15295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/f35.php"] [unique_id "apK9cNdHPfW2QFvhmL7mpQAAAAU"] [Sat Aug 29 05:07:28.385830 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.18.15:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/img.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUBQAABiY"] [Sat Aug 29 05:07:28.391916 2026] [security2:error] [pid 1028675:tid 1028820] [client 35.194.208.44:33238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK9cNdHPfW2QFvhmL7mqAAAAAo"] [Sat Aug 29 05:07:28.391993 2026] [security2:error] [pid 1028675:tid 1028820] [client 35.194.208.44:33238] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK9cNdHPfW2QFvhmL7mqAAAAAo"] [Sat Aug 29 05:07:28.394265 2026] [security2:error] [pid 1028675:tid 1028833] [client 158.23.147.79:17465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-content/admin.php"] [unique_id "apK9cNdHPfW2QFvhmL7mqQAAABc"] [Sat Aug 29 05:07:28.395155 2026] [security2:error] [pid 1028675:tid 1028916] [client 20.104.49.130:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/ab.php"] [unique_id "apK9cNdHPfW2QFvhmL7mrAAAAGo"] [Sat Aug 29 05:07:28.395783 2026] [security2:error] [pid 1018003:tid 1018207] [client 35.194.208.44:33274] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apK9cDAh5Y1i2tUxg4EUCQAABfA"] [Sat Aug 29 05:07:28.395786 2026] [core:error] [pid 1018003:tid 1018271] [client 35.194.208.44:33290] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) [Sat Aug 29 05:07:28.396986 2026] [core:error] [pid 1028675:tid 1028879] [client 35.194.208.44:33296] AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) [Sat Aug 29 05:07:28.399050 2026] [security2:error] [pid 1028675:tid 1028910] [client 35.194.208.44:33304] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apK9cNdHPfW2QFvhmL7mtQAAAGQ"] [Sat Aug 29 05:07:28.401590 2026] [security2:error] [pid 1028675:tid 1028855] [client 35.194.208.44:33236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/root/.ssh/id_rsa"] [unique_id "apK9cNdHPfW2QFvhmL7mtAAAAC0"] [Sat Aug 29 05:07:28.408053 2026] [security2:error] [pid 1018003:tid 1018213] [client 40.83.93.50:11655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/colour.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUFgAABfY"] [Sat Aug 29 05:07:28.409975 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.203.141.11:35204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/storage/rip.php"] [unique_id "apK9cNdHPfW2QFvhmL7mwAAAACc"] [Sat Aug 29 05:07:28.422832 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.422853 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.445493 2026] [security2:error] [pid 1028675:tid 1028911] [client 103.162.125.59:56830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.125.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9cNdHPfW2QFvhmL7myAAAAGU"] [Sat Aug 29 05:07:28.445541 2026] [security2:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/BACK/.env"] [unique_id "apK9cDAh5Y1i2tUxg4EUNgAF6yU"] [Sat Aug 29 05:07:28.445635 2026] [security2:error] [pid 1028675:tid 1028911] [client 103.162.125.59:56830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "colibridiscoveries.com"] [uri "/xmlrpc.php"] [unique_id "apK9cNdHPfW2QFvhmL7myAAAAGU"] [Sat Aug 29 05:07:28.449480 2026] [security2:error] [pid 1018003:tid 1018066] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/BE/.env"] [unique_id "apK9cDAh5Y1i2tUxg4EUNwAF6y0"] [Sat Aug 29 05:07:28.467493 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.467517 2026] [core:error] [pid 1028675:tid 1028912] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.467713 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.467721 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.468287 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.468301 2026] [core:error] [pid 1018003:tid 1018187] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.470883 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.470899 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.477293 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.104.18.15:19431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/ops.php"] [unique_id "apK9cNdHPfW2QFvhmL7m0QAAAGg"] [Sat Aug 29 05:07:28.486583 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.486603 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.488034 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.488052 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.491882 2026] [security2:error] [pid 1028675:tid 1028930] [client 40.83.93.50:5185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "apK9cNdHPfW2QFvhmL7m1gAAAHg"] [Sat Aug 29 05:07:28.493007 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.493020 2026] [core:error] [pid 1018003:tid 1018177] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.498521 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.196.209.81:14501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/alfa-rex.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUQAAABh8"] [Sat Aug 29 05:07:28.503462 2026] [security2:error] [pid 1028675:tid 1028888] [client 20.151.200.44:63346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/yyy.php"] [unique_id "apK9cNdHPfW2QFvhmL7m2AAAAE4"] [Sat Aug 29 05:07:28.506940 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.506962 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.507936 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.104.62:10877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/kcs.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUQQAABb4"] [Sat Aug 29 05:07:28.515040 2026] [security2:error] [pid 1018003:tid 1018252] [client 171.61.160.196:19506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.160.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUQwAABhw"] [Sat Aug 29 05:07:28.515866 2026] [security2:error] [pid 1018003:tid 1018252] [client 171.61.160.196:19506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "culturapopular.cl"] [uri "/xmlrpc.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUQwAABhw"] [Sat Aug 29 05:07:28.530013 2026] [security2:error] [pid 1028675:tid 1028876] [client 52.139.37.240:19306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/xmrlpc.php"] [unique_id "apK9cNdHPfW2QFvhmL7m3AAAAEI"] [Sat Aug 29 05:07:28.545460 2026] [security2:error] [pid 1028675:tid 1028818] [client 4.205.62.107:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/8.php"] [unique_id "apK9cNdHPfW2QFvhmL7m3QAAAAg"] [Sat Aug 29 05:07:28.556785 2026] [security2:error] [pid 1028675:tid 1028826] [client 158.158.54.35:4508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-blog.php"] [unique_id "apK9cNdHPfW2QFvhmL7m3gAAABA"] [Sat Aug 29 05:07:28.573121 2026] [security2:error] [pid 1018003:tid 1018203] [client 52.139.37.240:14680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/file61.php"] [unique_id "apK9cDAh5Y1i2tUxg4EURAAABew"] [Sat Aug 29 05:07:28.575515 2026] [security2:error] [pid 1028675:tid 1028903] [client 52.138.0.157:40973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7m3wAAAF0"] [Sat Aug 29 05:07:28.584521 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.104.18.15:12252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/222.php"] [unique_id "apK9cNdHPfW2QFvhmL7m4QAAACc"] [Sat Aug 29 05:07:28.587492 2026] [security2:error] [pid 1028675:tid 1028844] [client 168.107.94.195:51053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9cNdHPfW2QFvhmL7m4wAAACI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:28.590533 2026] [security2:error] [pid 1018003:tid 1018179] [client 146.70.36.124:49846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apK9cDAh5Y1i2tUxg4EURQAABdQ"] [Sat Aug 29 05:07:28.598092 2026] [security2:error] [pid 1028675:tid 1028935] [client 158.23.147.79:48136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/certificates/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7m7wAAAH0"] [Sat Aug 29 05:07:28.598637 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.151.200.44:47318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/bge.php"] [unique_id "apK9cNdHPfW2QFvhmL7m8AAAAFo"] [Sat Aug 29 05:07:28.604682 2026] [security2:error] [pid 1018003:tid 1018200] [client 4.205.62.107:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/old_phpinfo.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUSAAABek"] [Sat Aug 29 05:07:28.614594 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.104.18.15:19455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/coffexium.php"] [unique_id "apK9cNdHPfW2QFvhmL7m8gAAAFQ"] [Sat Aug 29 05:07:28.642497 2026] [security2:error] [pid 1028675:tid 1028931] [client 68.155.159.216:49224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7m-AAAAHk"] [Sat Aug 29 05:07:28.648123 2026] [security2:error] [pid 1028675:tid 1028898] [client 158.23.147.79:59870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7m-QAAAFg"] [Sat Aug 29 05:07:28.654969 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.104.104.62:10470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/wsz.php"] [unique_id "apK9cNdHPfW2QFvhmL7m-gAAADw"] [Sat Aug 29 05:07:28.657119 2026] [security2:error] [pid 1028675:tid 1028841] [client 158.23.147.79:25508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7m-wAAAB8"] [Sat Aug 29 05:07:28.658897 2026] [security2:error] [pid 1028675:tid 1028866] [client 127.0.0.1:30300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "apK9cNdHPfW2QFvhmL7muAAAADg"] [Sat Aug 29 05:07:28.658928 2026] [security2:error] [pid 1028675:tid 1028846] [client 35.194.208.44:33216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/root/.ssh/id_ed25519"] [unique_id "apK9cNdHPfW2QFvhmL7mqgAAACQ"] [Sat Aug 29 05:07:28.686886 2026] [security2:error] [pid 1018003:tid 1018203] [client 4.205.62.107:22468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/sale.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUTwAABew"] [Sat Aug 29 05:07:28.720351 2026] [core:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.720379 2026] [core:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.724000 2026] [security2:error] [pid 1018003:tid 1018191] [client 127.0.0.1:30346] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "apK9cDAh5Y1i2tUxg4EUEQAABeA"] [Sat Aug 29 05:07:28.724262 2026] [security2:error] [pid 1018003:tid 1018217] [client 35.194.208.44:33362] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bridlingtonpremierleaguedarts.com"] [uri "/@fs/root/.azure/credentials"] [unique_id "apK9cDAh5Y1i2tUxg4EUDQAABfo"] [Sat Aug 29 05:07:28.724980 2026] [security2:error] [pid 1028675:tid 1028848] [client 52.139.37.240:19286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/about/function.php"] [unique_id "apK9cNdHPfW2QFvhmL7nBAAAACY"] [Sat Aug 29 05:07:28.731022 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.731038 2026] [core:error] [pid 1028675:tid 1028916] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.739735 2026] [core:error] [pid 1028675:tid 1028878] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.739751 2026] [core:error] [pid 1028675:tid 1028878] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.743804 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.743819 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.744014 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.744032 2026] [core:error] [pid 1018003:tid 1018213] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.749921 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.749935 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.759818 2026] [core:error] [pid 1028675:tid 1028811] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.759839 2026] [core:error] [pid 1028675:tid 1028811] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.770719 2026] [security2:error] [pid 1028675:tid 1028932] [client 52.139.37.240:14940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/mah.php"] [unique_id "apK9cNdHPfW2QFvhmL7nDAAAAHo"] [Sat Aug 29 05:07:28.774031 2026] [security2:error] [pid 1018003:tid 1018266] [client 52.138.0.157:19588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUZQAABio"] [Sat Aug 29 05:07:28.774330 2026] [security2:error] [pid 1018003:tid 1018238] [client 20.104.104.62:20698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/store.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUZAAABg4"] [Sat Aug 29 05:07:28.775083 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.18.15:12257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/key.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUZgAABdI"] [Sat Aug 29 05:07:28.788098 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.788114 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.788688 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.788701 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.793848 2026] [security2:error] [pid 1028675:tid 1028921] [client 20.104.104.62:44581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/msy.php"] [unique_id "apK9cNdHPfW2QFvhmL7nDwAAAG8"] [Sat Aug 29 05:07:28.796635 2026] [core:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.796655 2026] [core:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.799207 2026] [core:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.799219 2026] [core:error] [pid 1018003:tid 1018128] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.803901 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.803915 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.804802 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.104.18.15:18880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/BDKR28WP.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUcQAABho"] [Sat Aug 29 05:07:28.805480 2026] [core:error] [pid 1018003:tid 1018261] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.805492 2026] [core:error] [pid 1018003:tid 1018261] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.808467 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.808478 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.823641 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.823667 2026] [core:error] [pid 1018003:tid 1018200] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.825262 2026] [security2:error] [pid 1028675:tid 1028832] [client 158.158.54.35:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/css/index.php"] [unique_id "apK9cNdHPfW2QFvhmL7nEQAAABY"] [Sat Aug 29 05:07:28.829212 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.829228 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:28.846012 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.147.79:26444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-content/x/index.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUdAAABiA"] [Sat Aug 29 05:07:28.849374 2026] [security2:error] [pid 1018003:tid 1018120] [remote 35.231.104.225:41784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apK9cDAh5Y1i2tUxg4EUdQAF12M"] [Sat Aug 29 05:07:28.876097 2026] [security2:error] [pid 1028675:tid 1028914] [client 4.205.62.107:8976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/product.php"] [unique_id "apK9cNdHPfW2QFvhmL7nFAAAAGg"] [Sat Aug 29 05:07:28.885827 2026] [security2:error] [pid 1028675:tid 1028846] [client 146.70.36.124:49858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apK9cNdHPfW2QFvhmL7nFQAAACQ"] [Sat Aug 29 05:07:28.910032 2026] [security2:error] [pid 1018003:tid 1018255] [client 20.196.209.81:14486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/cookie.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUdwAABh8"] [Sat Aug 29 05:07:28.919497 2026] [security2:error] [pid 1028675:tid 1028870] [client 52.139.37.240:19288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/an.php"] [unique_id "apK9cNdHPfW2QFvhmL7nFgAAADw"] [Sat Aug 29 05:07:28.920798 2026] [security2:error] [pid 1018003:tid 1018156] [client 40.83.93.50:7982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/OK.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUeAAABb0"] [Sat Aug 29 05:07:28.924101 2026] [security2:error] [pid 1018003:tid 1018170] [client 20.151.200.44:64681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/bgymj.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUeQAABcs"] [Sat Aug 29 05:07:28.937558 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.203.141.11:1369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/zoom1.php"] [unique_id "apK9cNdHPfW2QFvhmL7nFwAAACI"] [Sat Aug 29 05:07:28.939510 2026] [security2:error] [pid 1028675:tid 1028908] [client 20.104.18.15:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/chosen.php"] [unique_id "apK9cNdHPfW2QFvhmL7nGAAAAGI"] [Sat Aug 29 05:07:28.943905 2026] [security2:error] [pid 1028675:tid 1028812] [client 20.104.104.62:10633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/siln.php"] [unique_id "apK9cNdHPfW2QFvhmL7nGQAAAAI"] [Sat Aug 29 05:07:28.950638 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.203.141.11:38641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/w.php"] [unique_id "apK9cNdHPfW2QFvhmL7nGgAAAG4"] [Sat Aug 29 05:07:28.957592 2026] [security2:error] [pid 1018003:tid 1018117] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/_profiler/phpinfo.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUfAAF6WA"] [Sat Aug 29 05:07:28.967756 2026] [security2:error] [pid 1028675:tid 1028930] [client 52.139.37.240:14611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/mini.php"] [unique_id "apK9cNdHPfW2QFvhmL7nHAAAAHg"] [Sat Aug 29 05:07:28.967019 2026] [security2:error] [pid 1028675:tid 1028902] [client 52.138.0.157:20492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/pomo/wp-conflg.php"] [unique_id "apK9cNdHPfW2QFvhmL7nGwAAAFw"] [Sat Aug 29 05:07:28.971023 2026] [security2:error] [pid 1018003:tid 1018213] [client 168.107.94.195:51340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUfgAABfY"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:28.979921 2026] [security2:error] [pid 1018003:tid 1018111] [remote 35.231.104.225:41784] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.qandlcondos.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "apK9cDAh5Y1i2tUxg4EUggAF0lo"] [Sat Aug 29 05:07:28.982568 2026] [security2:error] [pid 1018003:tid 1018266] [client 40.83.93.50:15703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUhgAABio"] [Sat Aug 29 05:07:28.982791 2026] [security2:error] [pid 1018003:tid 1018147] [remote 35.231.104.225:41784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/@fs/var/task/.env"] [unique_id "apK9cDAh5Y1i2tUxg4EUhAAF0n4"] [Sat Aug 29 05:07:28.993455 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.104.18.15:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/sf.php"] [unique_id "apK9cDAh5Y1i2tUxg4EUiQAABiw"] [Sat Aug 29 05:07:29.009441 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.63.81.20:20963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUigAABdo"] [Sat Aug 29 05:07:29.032610 2026] [security2:error] [pid 1028675:tid 1028866] [client 158.158.54.35:22456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/xxx.php"] [unique_id "apK9cddHPfW2QFvhmL7nIwAAADg"] [Sat Aug 29 05:07:29.035968 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.035995 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.043207 2026] [security2:error] [pid 1028675:tid 1028929] [client 158.23.147.79:30445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/x.php"] [unique_id "apK9cddHPfW2QFvhmL7nJQAAAHc"] [Sat Aug 29 05:07:29.045115 2026] [security2:error] [pid 1028675:tid 1028849] [client 158.23.147.79:30546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apK9cddHPfW2QFvhmL7nJgAAACc"] [Sat Aug 29 05:07:29.045150 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.151.200.44:47396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/wp-ana.php"] [unique_id "apK9cddHPfW2QFvhmL7nJwAAAHc"] [Sat Aug 29 05:07:29.054489 2026] [security2:error] [pid 1028675:tid 1028856] [client 68.155.159.216:38578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9cddHPfW2QFvhmL7nKgAAAC4"] [Sat Aug 29 05:07:29.076313 2026] [security2:error] [pid 1028675:tid 1028843] [client 158.23.147.79:32684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9cddHPfW2QFvhmL7nLAAAACE"] [Sat Aug 29 05:07:29.079552 2026] [security2:error] [pid 1018003:tid 1018212] [client 4.205.62.107:56001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/phpi.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUlAAABfU"] [Sat Aug 29 05:07:29.088164 2026] [security2:error] [pid 1028675:tid 1028931] [client 20.104.104.62:10874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/f-401.php"] [unique_id "apK9cddHPfW2QFvhmL7nLgAAAHk"] [Sat Aug 29 05:07:29.094207 2026] [security2:error] [pid 1018003:tid 1018186] [client 68.155.159.216:1992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUlQAABds"] [Sat Aug 29 05:07:29.094302 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.094319 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.094509 2026] [security2:error] [pid 1018003:tid 1018216] [client 20.104.104.62:20683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/unzip.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUlgAABfk"] [Sat Aug 29 05:07:29.095548 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.095560 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.095961 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.095968 2026] [core:error] [pid 1018003:tid 1018202] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.097250 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.097263 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.105767 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.105784 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.112387 2026] [security2:error] [pid 1028675:tid 1028900] [client 52.139.37.240:19285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/asw.php"] [unique_id "apK9cddHPfW2QFvhmL7nMAAAAFo"] [Sat Aug 29 05:07:29.125031 2026] [security2:error] [pid 1028675:tid 1028820] [client 20.104.18.15:12278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/file1221.php"] [unique_id "apK9cddHPfW2QFvhmL7nMgAAAAo"] [Sat Aug 29 05:07:29.131575 2026] [security2:error] [pid 1028675:tid 1028920] [client 20.104.18.15:19416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/k.php"] [unique_id "apK9cddHPfW2QFvhmL7nMwAAAG4"] [Sat Aug 29 05:07:29.149671 2026] [security2:error] [pid 1018003:tid 1018145] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/admin-app/.env"] [unique_id "apK9cTAh5Y1i2tUxg4EUngAF_3w"] [Sat Aug 29 05:07:29.151539 2026] [core:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.151557 2026] [core:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.153546 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.153546 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.153569 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.153574 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.167783 2026] [security2:error] [pid 1018003:tid 1018182] [client 68.155.159.216:18262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUogAABdc"] [Sat Aug 29 05:07:29.173148 2026] [security2:error] [pid 1018003:tid 1018200] [client 52.139.37.240:14965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/v.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUowAABek"] [Sat Aug 29 05:07:29.177643 2026] [security2:error] [pid 1018003:tid 1018271] [client 20.63.81.20:20954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUpAAABi8"] [Sat Aug 29 05:07:29.178909 2026] [security2:error] [pid 1018003:tid 1018248] [client 146.70.36.124:49874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apK9cTAh5Y1i2tUxg4EUpQAABhg"] [Sat Aug 29 05:07:29.179806 2026] [security2:error] [pid 1018003:tid 1018190] [client 68.155.159.216:65058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-content/languages/about.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUpgAABd8"] [Sat Aug 29 05:07:29.180768 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.180788 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.188499 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.188518 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.192484 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.192500 2026] [core:error] [pid 1028675:tid 1028849] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.202087 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.202100 2026] [core:error] [pid 1028675:tid 1028929] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.206062 2026] [security2:error] [pid 1028675:tid 1028842] [client 68.155.159.216:33600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/cong.php"] [unique_id "apK9cddHPfW2QFvhmL7nPQAAACA"] [Sat Aug 29 05:07:29.218328 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.218342 2026] [core:error] [pid 1018003:tid 1018217] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.218959 2026] [security2:error] [pid 1028675:tid 1028889] [client 158.23.147.79:35719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-admin.php"] [unique_id "apK9cddHPfW2QFvhmL7nQAAAAE8"] [Sat Aug 29 05:07:29.225788 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.104.104.62:10647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/hq.php"] [unique_id "apK9cddHPfW2QFvhmL7nQQAAAEY"] [Sat Aug 29 05:07:29.245521 2026] [security2:error] [pid 1028675:tid 1028816] [client 68.155.159.216:51580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apK9cddHPfW2QFvhmL7nQwAAAAY"] [Sat Aug 29 05:07:29.263711 2026] [security2:error] [pid 1028675:tid 1028846] [client 52.138.0.157:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-includes/rest-api/fields/index.php"] [unique_id "apK9cddHPfW2QFvhmL7nTAAAACQ"] [Sat Aug 29 05:07:29.266616 2026] [security2:error] [pid 1018003:tid 1018103] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/admin/phpinfo.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUrQAF8FI"] [Sat Aug 29 05:07:29.270074 2026] [security2:error] [pid 1028675:tid 1028687] [remote 136.108.23.170:55262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thesmartpm.com"] [uri "/.github/.env"] [unique_id "apK9cddHPfW2QFvhmL7nUAAARAc"] [Sat Aug 29 05:07:29.270262 2026] [core:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.270272 2026] [core:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.270472 2026] [core:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.270487 2026] [core:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.279188 2026] [security2:error] [pid 1018003:tid 1018258] [client 20.104.18.15:12236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/nox.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUrgAABiI"] [Sat Aug 29 05:07:29.300369 2026] [security2:error] [pid 1028675:tid 1028821] [client 158.158.54.35:14935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-cron.php"] [unique_id "apK9cddHPfW2QFvhmL7nVQAAAAs"] [Sat Aug 29 05:07:29.305326 2026] [security2:error] [pid 1028675:tid 1028919] [client 52.139.37.240:19323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/item.php"] [unique_id "apK9cddHPfW2QFvhmL7nVwAAAG0"] [Sat Aug 29 05:07:29.306606 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.196.209.81:14467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/NewFile.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUsAAABd4"] [Sat Aug 29 05:07:29.312151 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.63.81.20:20928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/ser.php"] [unique_id "apK9cddHPfW2QFvhmL7nWAAAADg"] [Sat Aug 29 05:07:29.322068 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.104.18.15:19445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/82.php"] [unique_id "apK9cddHPfW2QFvhmL7nWQAAACs"] [Sat Aug 29 05:07:29.331825 2026] [core:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.331841 2026] [core:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.334686 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.48.250.41:35500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/wp-link10.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUsgAABhQ"] [Sat Aug 29 05:07:29.337836 2026] [security2:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/admin_phpinfo.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUtAAFwBc"] [Sat Aug 29 05:07:29.338718 2026] [security2:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/administrator/.env"] [unique_id "apK9cTAh5Y1i2tUxg4EUswAFwFE"] [Sat Aug 29 05:07:29.350981 2026] [security2:error] [pid 1018003:tid 1018184] [client 168.107.94.195:51779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUtQAABdk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:29.363103 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.104.62:10588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/mh.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUtgAABeU"] [Sat Aug 29 05:07:29.367970 2026] [security2:error] [pid 1028675:tid 1028876] [client 52.139.37.240:14495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9cddHPfW2QFvhmL7nWwAAAEI"] [Sat Aug 29 05:07:29.406036 2026] [security2:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/api/.env"] [unique_id "apK9cTAh5Y1i2tUxg4EUuwAGARI"] [Sat Aug 29 05:07:29.406036 2026] [security2:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/api-backend/.env"] [unique_id "apK9cTAh5Y1i2tUxg4EUugAGARY"] [Sat Aug 29 05:07:29.406778 2026] [security2:error] [pid 1018003:tid 1018083] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/api-node/.env"] [unique_id "apK9cTAh5Y1i2tUxg4EUvAAGAT4"] [Sat Aug 29 05:07:29.408166 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.408180 2026] [core:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.408625 2026] [core:error] [pid 1018003:tid 1018037] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.408637 2026] [core:error] [pid 1018003:tid 1018037] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.408725 2026] [core:error] [pid 1018003:tid 1018100] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.408735 2026] [core:error] [pid 1018003:tid 1018100] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.408869 2026] [core:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.408880 2026] [core:error] [pid 1018003:tid 1018135] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.414187 2026] [security2:error] [pid 1018003:tid 1018226] [client 34.81.157.26:30772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apK9cTAh5Y1i2tUxg4EUwgAABgM"] [Sat Aug 29 05:07:29.414490 2026] [security2:error] [pid 1028675:tid 1028907] [client 20.104.18.15:12273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/akismet.php"] [unique_id "apK9cddHPfW2QFvhmL7nZAAAAGE"] [Sat Aug 29 05:07:29.414981 2026] [security2:error] [pid 1018003:tid 1018192] [client 34.81.157.26:30802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apK9cTAh5Y1i2tUxg4EUwwAABeE"] [Sat Aug 29 05:07:29.415118 2026] [security2:error] [pid 1018003:tid 1018246] [client 34.81.157.26:30814] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apK9cTAh5Y1i2tUxg4EUxQAABhY"] [Sat Aug 29 05:07:29.416972 2026] [core:error] [pid 1018003:tid 1018169] [client 34.81.157.26:30836] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) [Sat Aug 29 05:07:29.417013 2026] [security2:error] [pid 1028675:tid 1028815] [client 34.81.157.26:30844] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apK9cddHPfW2QFvhmL7nZwAAAAU"] [Sat Aug 29 05:07:29.417337 2026] [core:error] [pid 1018003:tid 1018265] [client 34.81.157.26:30846] AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) [Sat Aug 29 05:07:29.417696 2026] [security2:error] [pid 1018003:tid 1018273] [client 34.81.157.26:30718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/@fs/root/.ssh/id_rsa"] [unique_id "apK9cTAh5Y1i2tUxg4EUxgAABjE"] [Sat Aug 29 05:07:29.418222 2026] [security2:error] [pid 1028675:tid 1028850] [client 34.81.157.26:30872] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/cgi-sys/404.html"] [unique_id "apK9cddHPfW2QFvhmL7nZgAAACg"] [Sat Aug 29 05:07:29.422488 2026] [security2:error] [pid 1028675:tid 1028881] [client 40.83.93.50:11650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.traceyandstewart.strangeworx.com"] [uri "/aaa.php"] [unique_id "apK9cddHPfW2QFvhmL7nbwAAAEc"] [Sat Aug 29 05:07:29.428111 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.203.141.11:27706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/ahax.php"] [unique_id "apK9cddHPfW2QFvhmL7ndQAAADw"] [Sat Aug 29 05:07:29.429694 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.429707 2026] [core:error] [pid 1018003:tid 1018182] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.432952 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.432968 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.434590 2026] [security2:error] [pid 1018003:tid 1018200] [client 34.81.157.26:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/cgi-sys/404.html"] [unique_id "apK9cTAh5Y1i2tUxg4EUywAABek"] [Sat Aug 29 05:07:29.435157 2026] [core:error] [pid 1028675:tid 1028830] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.435168 2026] [core:error] [pid 1028675:tid 1028830] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.439080 2026] [security2:error] [pid 1018003:tid 1018270] [client 158.23.147.79:50109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU0AAABi4"] [Sat Aug 29 05:07:29.442653 2026] [core:error] [pid 1028675:tid 1028858] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.442668 2026] [core:error] [pid 1028675:tid 1028858] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.443655 2026] [core:error] [pid 1028675:tid 1028884] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.443669 2026] [core:error] [pid 1028675:tid 1028884] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.449048 2026] [security2:error] [pid 1018003:tid 1018236] [client 34.81.157.26:30992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/@fs/home/ubuntu/.oci/config"] [unique_id "apK9cTAh5Y1i2tUxg4EU0QAABgw"] [Sat Aug 29 05:07:29.451258 2026] [security2:error] [pid 1028675:tid 1028832] [client 34.81.157.26:30822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.samueljamesmcgrath.com"] [uri "/___proxy_subdomain_webdisk/cgi-sys/404.html"] [unique_id "apK9cddHPfW2QFvhmL7nYAAAABY"] [Sat Aug 29 05:07:29.455463 2026] [security2:error] [pid 1018003:tid 1018188] [client 4.205.62.107:22020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/hiquido.com/index.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU0gAABd0"] [Sat Aug 29 05:07:29.456010 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.63.81.20:20933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/431.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU1AAABec"] [Sat Aug 29 05:07:29.459088 2026] [core:error] [pid 1028675:tid 1028816] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.459104 2026] [core:error] [pid 1028675:tid 1028816] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.459980 2026] [core:error] [pid 1028675:tid 1028890] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.459990 2026] [core:error] [pid 1028675:tid 1028890] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.461016 2026] [core:error] [pid 1028675:tid 1028896] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.461091 2026] [core:error] [pid 1018003:tid 1018177] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.461175 2026] [core:error] [pid 1028675:tid 1028896] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.461180 2026] [core:error] [pid 1018003:tid 1018177] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.461266 2026] [core:error] [pid 1018003:tid 1018203] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.461272 2026] [core:error] [pid 1018003:tid 1018203] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.461689 2026] [core:error] [pid 1028675:tid 1028902] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.461699 2026] [core:error] [pid 1028675:tid 1028902] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.462686 2026] [core:error] [pid 1028675:tid 1028861] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.462697 2026] [core:error] [pid 1028675:tid 1028861] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.463208 2026] [core:error] [pid 1018003:tid 1018191] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.463217 2026] [core:error] [pid 1018003:tid 1018191] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.463788 2026] [core:error] [pid 1028675:tid 1028821] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.463807 2026] [core:error] [pid 1028675:tid 1028821] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.465098 2026] [core:error] [pid 1028675:tid 1028899] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.465114 2026] [core:error] [pid 1028675:tid 1028899] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.467128 2026] [core:error] [pid 1028675:tid 1028919] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.467143 2026] [core:error] [pid 1028675:tid 1028919] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.469319 2026] [core:error] [pid 1018003:tid 1018162] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.469330 2026] [core:error] [pid 1018003:tid 1018162] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.469992 2026] [core:error] [pid 1018003:tid 1018219] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.470003 2026] [core:error] [pid 1018003:tid 1018219] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.470728 2026] [security2:error] [pid 1028675:tid 1028837] [client 40.83.93.50:24488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-blog-header.php"] [unique_id "apK9cddHPfW2QFvhmL7nkwAAABs"] [Sat Aug 29 05:07:29.470878 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.203.141.11:1365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/txets.php"] [unique_id "apK9cddHPfW2QFvhmL7nlAAAAGs"] [Sat Aug 29 05:07:29.471012 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.48.250.41:35072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ww.php"] [unique_id "apK9cddHPfW2QFvhmL7nlQAAAHc"] [Sat Aug 29 05:07:29.473080 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.104.104.62:64721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/think.php"] [unique_id "apK9cddHPfW2QFvhmL7nlgAAABI"] [Sat Aug 29 05:07:29.474441 2026] [security2:error] [pid 1028675:tid 1028863] [client 146.70.36.124:49886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apK9cddHPfW2QFvhmL7nmAAAADU"] [Sat Aug 29 05:07:29.475698 2026] [core:error] [pid 1028675:tid 1028830] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.475709 2026] [core:error] [pid 1028675:tid 1028830] [client 34.81.157.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.479377 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.18.15:19346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/dex.php"] [unique_id "apK9cddHPfW2QFvhmL7nmQAAADI"] [Sat Aug 29 05:07:29.492807 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.492818 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.498860 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.104.104.62:10624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/f2r4.php"] [unique_id "apK9cddHPfW2QFvhmL7nmwAAAAQ"] [Sat Aug 29 05:07:29.501491 2026] [security2:error] [pid 1018003:tid 1018190] [client 52.139.37.240:19317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/jga.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU2gAABd8"] [Sat Aug 29 05:07:29.513949 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.513960 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.514000 2026] [core:error] [pid 1018003:tid 1018079] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.514015 2026] [core:error] [pid 1018003:tid 1018079] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.515609 2026] [core:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.515622 2026] [core:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.534733 2026] [security2:error] [pid 1028675:tid 1028832] [client 20.151.200.44:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/fh26.php"] [unique_id "apK9cddHPfW2QFvhmL7nnwAAABY"] [Sat Aug 29 05:07:29.536519 2026] [core:error] [pid 1018003:tid 1018075] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.536530 2026] [core:error] [pid 1018003:tid 1018075] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.564630 2026] [security2:error] [pid 1028675:tid 1028901] [client 158.23.147.79:17446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/xmlrpc.php"] [unique_id "apK9cddHPfW2QFvhmL7nngAAAFs"] [Sat Aug 29 05:07:29.565615 2026] [security2:error] [pid 1028675:tid 1028879] [client 52.139.37.240:15279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apK9cddHPfW2QFvhmL7noQAAAEU"] [Sat Aug 29 05:07:29.568496 2026] [core:error] [pid 1028675:tid 1028897] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.568509 2026] [core:error] [pid 1028675:tid 1028897] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.569111 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.569118 2026] [core:error] [pid 1018003:tid 1018244] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.581915 2026] [security2:error] [pid 1018003:tid 1018195] [client 20.104.18.15:12279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/ajax.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU5AAABeQ"] [Sat Aug 29 05:07:29.584575 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.63.81.20:20865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/rxr.php"] [unique_id "apK9cddHPfW2QFvhmL7nowAAAA4"] [Sat Aug 29 05:07:29.604367 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.104.49.130:58193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ericfenniman.com"] [uri "/Jcrop.php"] [unique_id "apK9cddHPfW2QFvhmL7npAAAAGw"] [Sat Aug 29 05:07:29.615657 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.48.250.41:35111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/w1px.php"] [unique_id "apK9cddHPfW2QFvhmL7npQAAAAE"] [Sat Aug 29 05:07:29.617710 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.151.200.44:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/secret.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU5QAABb4"] [Sat Aug 29 05:07:29.629180 2026] [security2:error] [pid 1028675:tid 1028920] [client 52.138.0.157:20483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-links-opml.php"] [unique_id "apK9cddHPfW2QFvhmL7npgAAAG4"] [Sat Aug 29 05:07:29.631654 2026] [security2:error] [pid 1028675:tid 1028912] [client 20.104.104.62:10663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/sadis.php"] [unique_id "apK9cddHPfW2QFvhmL7nqAAAAGY"] [Sat Aug 29 05:07:29.663855 2026] [security2:error] [pid 1028675:tid 1028921] [client 68.155.159.216:6038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/asd.php"] [unique_id "apK9cddHPfW2QFvhmL7nqgAAAG8"] [Sat Aug 29 05:07:29.696349 2026] [security2:error] [pid 1028675:tid 1028849] [client 52.139.37.240:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/mac.php"] [unique_id "apK9cddHPfW2QFvhmL7nqwAAACc"] [Sat Aug 29 05:07:29.699023 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.104.18.15:18905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/inso.php"] [unique_id "apK9cddHPfW2QFvhmL7nrAAAACI"] [Sat Aug 29 05:07:29.706292 2026] [security2:error] [pid 1018003:tid 1018161] [client 20.196.209.81:1899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/config.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU5gAABcI"] [Sat Aug 29 05:07:29.709579 2026] [security2:error] [pid 1028675:tid 1028847] [client 20.104.104.62:20611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/tod.php"] [unique_id "apK9cddHPfW2QFvhmL7nrQAAACU"] [Sat Aug 29 05:07:29.710293 2026] [security2:error] [pid 1028675:tid 1028892] [client 4.205.62.107:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/thui.php"] [unique_id "apK9cddHPfW2QFvhmL7nrgAAAFI"] [Sat Aug 29 05:07:29.719512 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.63.81.20:20950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/csst.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU5wAABec"] [Sat Aug 29 05:07:29.730524 2026] [security2:error] [pid 1028675:tid 1028931] [client 168.107.94.195:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9cddHPfW2QFvhmL7nrwAAAHk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:29.735895 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.104.18.15:12258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/atomlib.php"] [unique_id "apK9cddHPfW2QFvhmL7nsAAAACY"] [Sat Aug 29 05:07:29.738924 2026] [security2:error] [pid 1028675:tid 1028873] [client 4.205.62.107:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/paths.php"] [unique_id "apK9cddHPfW2QFvhmL7nsQAAAD8"] [Sat Aug 29 05:07:29.740807 2026] [security2:error] [pid 1028675:tid 1028896] [client 158.158.54.35:31479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-block.php"] [unique_id "apK9cddHPfW2QFvhmL7nsgAAAFY"] [Sat Aug 29 05:07:29.756061 2026] [security2:error] [pid 1028675:tid 1028881] [client 52.139.37.240:14506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9cddHPfW2QFvhmL7nswAAAEc"] [Sat Aug 29 05:07:29.758408 2026] [security2:error] [pid 1028675:tid 1028917] [client 68.155.159.216:30531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/ws.php"] [unique_id "apK9cddHPfW2QFvhmL7ntAAAAGs"] [Sat Aug 29 05:07:29.762738 2026] [security2:error] [pid 1028675:tid 1028818] [client 68.155.159.216:49153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/dropdown.php"] [unique_id "apK9cddHPfW2QFvhmL7ntQAAAAg"] [Sat Aug 29 05:07:29.768114 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.104.62:44574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/xcre1.php"] [unique_id "apK9cddHPfW2QFvhmL7ntwAAAHo"] [Sat Aug 29 05:07:29.776737 2026] [security2:error] [pid 1028675:tid 1028842] [client 158.158.54.35:24280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/tool.php"] [unique_id "apK9cddHPfW2QFvhmL7nuAAAACA"] [Sat Aug 29 05:07:29.780255 2026] [security2:error] [pid 1028675:tid 1028909] [client 146.70.36.124:49888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9cddHPfW2QFvhmL7nugAAAGM"] [Sat Aug 29 05:07:29.789425 2026] [security2:error] [pid 1018003:tid 1018186] [client 91.92.47.191:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.corrigansbasement.com"] [uri "/wp-config.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU6AAABds"] [Sat Aug 29 05:07:29.799135 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.151.200.44:46648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/pro.php"] [unique_id "apK9cddHPfW2QFvhmL7nvAAAADA"] [Sat Aug 29 05:07:29.800675 2026] [security2:error] [pid 1028675:tid 1028884] [client 20.48.250.41:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/to.php"] [unique_id "apK9cddHPfW2QFvhmL7nvQAAAEo"] [Sat Aug 29 05:07:29.806070 2026] [security2:error] [pid 1018003:tid 1018169] [client 68.155.159.216:52809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-admin/maint/index.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU6QAABco"] [Sat Aug 29 05:07:29.813138 2026] [security2:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/api/info.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU6gAF4Gc"] [Sat Aug 29 05:07:29.820522 2026] [security2:error] [pid 1028675:tid 1028837] [client 52.138.0.157:5642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-signup.php"] [unique_id "apK9cddHPfW2QFvhmL7nvgAAABs"] [Sat Aug 29 05:07:29.821393 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.821407 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.821766 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.821774 2026] [core:error] [pid 1018003:tid 1018033] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.822416 2026] [security2:error] [pid 1028675:tid 1028830] [client 103.168.67.159:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturalkneads.com"] [uri "/wp/index.php"] [unique_id "apK9cddHPfW2QFvhmL7nvwAAABQ"], referer: https://naturalkneads.com/wp/wp-admin/ [Sat Aug 29 05:07:29.823115 2026] [security2:error] [pid 1018003:tid 1018040] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/api/phpinfo.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU8QAF4BM"] [Sat Aug 29 05:07:29.824371 2026] [core:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.824382 2026] [core:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.827448 2026] [core:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.827463 2026] [core:error] [pid 1018003:tid 1018049] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.830721 2026] [core:error] [pid 1018003:tid 1018104] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.830732 2026] [core:error] [pid 1018003:tid 1018104] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.838318 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.18.15:19405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/aa.php"] [unique_id "apK9cddHPfW2QFvhmL7nwQAAACk"] [Sat Aug 29 05:07:29.838816 2026] [security2:error] [pid 1028675:tid 1028846] [client 4.205.62.107:22498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/wp-content/themes/luJMF.php"] [unique_id "apK9cddHPfW2QFvhmL7nwgAAACQ"] [Sat Aug 29 05:07:29.839569 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.839580 2026] [core:error] [pid 1028675:tid 1028832] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.849980 2026] [security2:error] [pid 1028675:tid 1028888] [client 20.63.81.20:20958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apK9cddHPfW2QFvhmL7nxQAAAE4"] [Sat Aug 29 05:07:29.858443 2026] [security2:error] [pid 1018003:tid 1018221] [client 180.190.5.40:50541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.5.190.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcrl.tech"] [uri "/xmlrpc.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU9wAABf4"] [Sat Aug 29 05:07:29.858527 2026] [security2:error] [pid 1018003:tid 1018221] [client 180.190.5.40:50541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mcrl.tech"] [uri "/xmlrpc.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU9wAABf4"] [Sat Aug 29 05:07:29.858809 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.858819 2026] [core:error] [pid 1018003:tid 1018271] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.863896 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.863908 2026] [core:error] [pid 1018003:tid 1018231] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.874883 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.18.15:12165] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.printingbyjoe.com"] [uri "/1.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU-QAABfw"] [Sat Aug 29 05:07:29.874960 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.104.18.15:12165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/1.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU-QAABfw"] [Sat Aug 29 05:07:29.898079 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.104.104.62:10582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/motu.php"] [unique_id "apK9cddHPfW2QFvhmL7nxgAAAD4"] [Sat Aug 29 05:07:29.903052 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.104.18.15:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/blacks.php"] [unique_id "apK9cddHPfW2QFvhmL7nxwAAAF0"] [Sat Aug 29 05:07:29.909945 2026] [security2:error] [pid 1028675:tid 1028879] [client 52.139.37.240:19330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-admin/images/index.php"] [unique_id "apK9cddHPfW2QFvhmL7nyAAAAEU"] [Sat Aug 29 05:07:29.922006 2026] [security2:error] [pid 1018003:tid 1018203] [client 20.203.141.11:38621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/shell.php"] [unique_id "apK9cTAh5Y1i2tUxg4EU_wAABew"] [Sat Aug 29 05:07:29.946691 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.946717 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.947848 2026] [core:error] [pid 1028675:tid 1028825] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.947874 2026] [core:error] [pid 1028675:tid 1028825] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.950164 2026] [security2:error] [pid 1018003:tid 1018174] [client 68.155.159.216:12287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9cTAh5Y1i2tUxg4EVAQAABc8"] [Sat Aug 29 05:07:29.950474 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.950486 2026] [core:error] [pid 1028675:tid 1028821] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.951545 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.951565 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:29.952952 2026] [security2:error] [pid 1028675:tid 1028920] [client 158.23.147.79:26588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9cddHPfW2QFvhmL7n0QAAAG4"] [Sat Aug 29 05:07:29.955152 2026] [security2:error] [pid 1028675:tid 1028899] [client 68.155.159.216:63855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-content/admin.php"] [unique_id "apK9cddHPfW2QFvhmL7n0gAAAFk"] [Sat Aug 29 05:07:29.957300 2026] [security2:error] [pid 1028675:tid 1028921] [client 68.155.159.216:33544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-content/themes/too.php"] [unique_id "apK9cddHPfW2QFvhmL7n0wAAAG8"] [Sat Aug 29 05:07:29.967851 2026] [security2:error] [pid 1028675:tid 1028911] [client 40.83.93.50:5223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-blogs.php"] [unique_id "apK9cddHPfW2QFvhmL7n1AAAAGU"] [Sat Aug 29 05:07:29.975596 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.104.18.15:19422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/img.php"] [unique_id "apK9cddHPfW2QFvhmL7n1QAAACE"] [Sat Aug 29 05:07:29.976740 2026] [security2:error] [pid 1028675:tid 1028849] [client 20.151.200.44:46611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/999.php"] [unique_id "apK9cddHPfW2QFvhmL7n1wAAACc"] [Sat Aug 29 05:07:29.978230 2026] [security2:error] [pid 1028675:tid 1028870] [client 20.63.81.20:20956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apK9cddHPfW2QFvhmL7n2AAAADw"] [Sat Aug 29 05:07:29.981139 2026] [security2:error] [pid 1018003:tid 1018262] [client 20.104.18.15:36637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/gos.php"] [unique_id "apK9cTAh5Y1i2tUxg4EVAwAABiY"] [Sat Aug 29 05:07:29.991468 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.48.250.41:35014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/thui.php"] [unique_id "apK9cTAh5Y1i2tUxg4EVBAAABd4"] [Sat Aug 29 05:07:29.998637 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.48.250.41:49056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/to.php"] [unique_id "apK9cTAh5Y1i2tUxg4EVBQAABiw"] [Sat Aug 29 05:07:30.030032 2026] [security2:error] [pid 1028675:tid 1028812] [client 20.104.104.62:10856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/wefile.php"] [unique_id "apK9ctdHPfW2QFvhmL7n2gAAAAI"] [Sat Aug 29 05:07:30.032719 2026] [security2:error] [pid 1018003:tid 1018156] [client 52.138.0.157:1458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/xmlrpc.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVBgAABb0"] [Sat Aug 29 05:07:30.034404 2026] [security2:error] [pid 1028675:tid 1028931] [client 20.104.18.15:13728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/33.php"] [unique_id "apK9ctdHPfW2QFvhmL7n2wAAAHk"] [Sat Aug 29 05:07:30.034671 2026] [security2:error] [pid 1028675:tid 1028848] [client 52.139.37.240:14668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/wp-index.php"] [unique_id "apK9ctdHPfW2QFvhmL7n3AAAACY"] [Sat Aug 29 05:07:30.038204 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.104.49.130:30017] ModSecurity: Access denied with connection close (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1032"] [id "900036"] [msg "Wordpress BOT exploit :: No UA/Referer"] [hostname "mail.flatlandsfoto.com"] [uri "/wp-login.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVBwAABgk"] [Sat Aug 29 05:07:30.077562 2026] [security2:error] [pid 1028675:tid 1028909] [client 4.205.62.107:8983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/public/wp-blog.php"] [unique_id "apK9ctdHPfW2QFvhmL7n3gAAAGM"] [Sat Aug 29 05:07:30.078138 2026] [security2:error] [pid 1028675:tid 1028856] [client 87.219.197.128:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.197.219.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9ctdHPfW2QFvhmL7n3wAAAC4"] [Sat Aug 29 05:07:30.078264 2026] [security2:error] [pid 1028675:tid 1028856] [client 87.219.197.128:62929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bomchecker.net"] [uri "/xmlrpc.php"] [unique_id "apK9ctdHPfW2QFvhmL7n3wAAAC4"] [Sat Aug 29 05:07:30.082147 2026] [security2:error] [pid 1028675:tid 1028856] [client 146.70.36.124:49898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apK9ctdHPfW2QFvhmL7n4QAAAC4"] [Sat Aug 29 05:07:30.102797 2026] [security2:error] [pid 1028675:tid 1028873] [client 52.139.37.240:19345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9ctdHPfW2QFvhmL7n4wAAAD8"] [Sat Aug 29 05:07:30.104274 2026] [security2:error] [pid 1028675:tid 1028860] [client 20.104.18.15:12198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/samll.php"] [unique_id "apK9ctdHPfW2QFvhmL7n5AAAADI"] [Sat Aug 29 05:07:30.111125 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.63.81.20:20960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9ctdHPfW2QFvhmL7n5QAAAAQ"] [Sat Aug 29 05:07:30.116934 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.18.15:19453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/222.php"] [unique_id "apK9ctdHPfW2QFvhmL7n5gAAACk"] [Sat Aug 29 05:07:30.130841 2026] [security2:error] [pid 1028675:tid 1028925] [client 168.107.94.195:52530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ctdHPfW2QFvhmL7n6AAAAHM"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:30.133239 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.104.104.62:64727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/setor.php"] [unique_id "apK9ctdHPfW2QFvhmL7n6QAAAHM"] [Sat Aug 29 05:07:30.147238 2026] [security2:error] [pid 1028675:tid 1028922] [client 20.104.18.15:36639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/132.php"] [unique_id "apK9ctdHPfW2QFvhmL7n6wAAAHA"] [Sat Aug 29 05:07:30.161841 2026] [security2:error] [pid 1018003:tid 1018192] [client 158.23.147.79:30402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVFAAABeE"] [Sat Aug 29 05:07:30.162792 2026] [security2:error] [pid 1018003:tid 1018273] [client 68.155.159.216:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVFQAABjE"] [Sat Aug 29 05:07:30.172385 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.151.200.44:46621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/sef.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVFwAABgo"] [Sat Aug 29 05:07:30.175512 2026] [security2:error] [pid 1018003:tid 1018200] [client 158.23.147.79:30502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVGQAABek"] [Sat Aug 29 05:07:30.176081 2026] [security2:error] [pid 1028675:tid 1028867] [client 158.23.147.79:32591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ctdHPfW2QFvhmL7n7AAAADk"] [Sat Aug 29 05:07:30.177868 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.104.62:10864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/EM.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVHQAABio"] [Sat Aug 29 05:07:30.178070 2026] [security2:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/apis/.env"] [unique_id "apK9cjAh5Y1i2tUxg4EVGgAF1y4"] [Sat Aug 29 05:07:30.187027 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.104.18.15:13704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/133.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVHgAABfU"] [Sat Aug 29 05:07:30.187164 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.104.18.15:4961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/beck.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVHwAABi4"] [Sat Aug 29 05:07:30.189445 2026] [security2:error] [pid 1028675:tid 1028896] [client 158.158.54.35:16154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apK9ctdHPfW2QFvhmL7n7wAAAFY"] [Sat Aug 29 05:07:30.205390 2026] [security2:error] [pid 1028675:tid 1028842] [client 20.196.209.81:14485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/22.php"] [unique_id "apK9ctdHPfW2QFvhmL7n8AAAACA"] [Sat Aug 29 05:07:30.211977 2026] [security2:error] [pid 1018003:tid 1018244] [client 158.158.54.35:7280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/k.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVIQAABhQ"] [Sat Aug 29 05:07:30.212839 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.48.250.41:35511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/Jcrop.php"] [unique_id "apK9ctdHPfW2QFvhmL7n8QAAAA8"] [Sat Aug 29 05:07:30.225070 2026] [security2:error] [pid 1018003:tid 1018246] [client 52.139.37.240:14702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/ww2.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVIwAABhY"] [Sat Aug 29 05:07:30.227937 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.227954 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.230157 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.230174 2026] [core:error] [pid 1028675:tid 1028920] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.230581 2026] [core:error] [pid 1028675:tid 1028879] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.230597 2026] [core:error] [pid 1028675:tid 1028879] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.236094 2026] [security2:error] [pid 1028675:tid 1028876] [client 52.138.0.157:39716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.0.138.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/yas.php"] [unique_id "apK9ctdHPfW2QFvhmL7n9QAAAEI"] [Sat Aug 29 05:07:30.236972 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.104.18.15:12180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/she11.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVJgAABiU"] [Sat Aug 29 05:07:30.237720 2026] [security2:error] [pid 1018003:tid 1018186] [client 68.155.159.216:2014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVJwAABds"] [Sat Aug 29 05:07:30.242447 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.48.250.41:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/thui.php"] [unique_id "apK9ctdHPfW2QFvhmL7n9gAAAE8"] [Sat Aug 29 05:07:30.245310 2026] [security2:error] [pid 1028675:tid 1028899] [client 20.63.81.20:20967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/haxor.php"] [unique_id "apK9ctdHPfW2QFvhmL7n9wAAAFk"] [Sat Aug 29 05:07:30.246306 2026] [security2:error] [pid 1028675:tid 1028921] [client 4.205.62.107:56024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apK9ctdHPfW2QFvhmL7n-AAAAG8"] [Sat Aug 29 05:07:30.249827 2026] [core:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.249840 2026] [core:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.250788 2026] [core:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.250800 2026] [core:error] [pid 1018003:tid 1018072] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.264559 2026] [security2:error] [pid 1028675:tid 1028859] [client 20.104.18.15:19356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/key.php"] [unique_id "apK9ctdHPfW2QFvhmL7n_AAAADE"] [Sat Aug 29 05:07:30.268001 2026] [security2:error] [pid 1028675:tid 1028847] [client 158.23.147.79:25353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9ctdHPfW2QFvhmL7n_QAAACU"] [Sat Aug 29 05:07:30.285481 2026] [security2:error] [pid 1018003:tid 1018177] [client 68.155.159.216:63841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-content/banners/about.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVLwAABdI"] [Sat Aug 29 05:07:30.288418 2026] [security2:error] [pid 1018003:tid 1018086] [remote 52.167.144.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giantsfans.net"] [uri "/message_board/index.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVMAAF60E"] [Sat Aug 29 05:07:30.292955 2026] [security2:error] [pid 1018003:tid 1018191] [client 68.155.159.216:18386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/goat.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVMQAABeA"] [Sat Aug 29 05:07:30.294662 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.104.49.130:34536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/f35.update.php"] [unique_id "apK9ctdHPfW2QFvhmL7n_wAAAGs"] [Sat Aug 29 05:07:30.296189 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.296203 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.296281 2026] [security2:error] [pid 1018003:tid 1018198] [client 52.139.37.240:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/zafir1.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVMgAABec"] [Sat Aug 29 05:07:30.301034 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.203.141.11:8965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-content/themes/about.php"] [unique_id "apK9ctdHPfW2QFvhmL7oAAAAAHc"] [Sat Aug 29 05:07:30.309103 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.104.104.62:10662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/ca4.php"] [unique_id "apK9ctdHPfW2QFvhmL7oAQAAACI"] [Sat Aug 29 05:07:30.326921 2026] [security2:error] [pid 1028675:tid 1028878] [client 68.155.159.216:33572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/js/index.php"] [unique_id "apK9ctdHPfW2QFvhmL7oAwAAAEQ"] [Sat Aug 29 05:07:30.329021 2026] [security2:error] [pid 1018003:tid 1018174] [client 158.23.147.79:59897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/classwithtostring.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVNAAABc8"] [Sat Aug 29 05:07:30.329925 2026] [security2:error] [pid 1018003:tid 1018256] [client 158.23.147.79:35216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVNQAABiA"] [Sat Aug 29 05:07:30.331206 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.104.18.15:5000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/t3.php"] [unique_id "apK9ctdHPfW2QFvhmL7oBAAAAB0"] [Sat Aug 29 05:07:30.334076 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.104.18.15:13583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/sym.php"] [unique_id "apK9ctdHPfW2QFvhmL7oBQAAAAQ"] [Sat Aug 29 05:07:30.345675 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.345687 2026] [core:error] [pid 1028675:tid 1028937] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.352628 2026] [security2:error] [pid 1018003:tid 1018258] [client 68.155.159.216:51819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVNgAABiI"] [Sat Aug 29 05:07:30.357912 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.357925 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.359504 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.151.200.44:46654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/admin123.php"] [unique_id "apK9ctdHPfW2QFvhmL7oCwAAABk"] [Sat Aug 29 05:07:30.370161 2026] [security2:error] [pid 1028675:tid 1028866] [client 20.63.81.20:20959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/google.php"] [unique_id "apK9ctdHPfW2QFvhmL7oDAAAADg"] [Sat Aug 29 05:07:30.374539 2026] [security2:error] [pid 1028675:tid 1028816] [client 146.70.36.124:49912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9ctdHPfW2QFvhmL7oDQAAAAY"] [Sat Aug 29 05:07:30.400408 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.203.141.11:38601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/elp.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVOQAABf8"] [Sat Aug 29 05:07:30.407731 2026] [security2:error] [pid 1018003:tid 1018066] [remote 35.231.104.225:41798] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.qandlcondos.com"] [uri "/api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9cjAh5Y1i2tUxg4EVOgAFuS0"] [Sat Aug 29 05:07:30.409675 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.18.15:19409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/chosen.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVOwAABeU"] [Sat Aug 29 05:07:30.415503 2026] [security2:error] [pid 1028675:tid 1028841] [client 52.139.37.240:14491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/7logs.php"] [unique_id "apK9ctdHPfW2QFvhmL7oDgAAAB8"] [Sat Aug 29 05:07:30.420855 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.104.18.15:12214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/kerang.php"] [unique_id "apK9ctdHPfW2QFvhmL7oDwAAAF0"] [Sat Aug 29 05:07:30.424403 2026] [security2:error] [pid 1028675:tid 1028898] [client 20.48.250.41:49032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/Jcrop.php"] [unique_id "apK9ctdHPfW2QFvhmL7oEAAAAFg"] [Sat Aug 29 05:07:30.424660 2026] [security2:error] [pid 1028675:tid 1028867] [client 20.48.250.41:35097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/ws58.php"] [unique_id "apK9ctdHPfW2QFvhmL7oEQAAADk"] [Sat Aug 29 05:07:30.432421 2026] [security2:error] [pid 1028675:tid 1028812] [client 40.83.93.50:24457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-comments-post.php"] [unique_id "apK9ctdHPfW2QFvhmL7oEgAAAAI"] [Sat Aug 29 05:07:30.440020 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.104.18.15:36707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/v22.php"] [unique_id "apK9ctdHPfW2QFvhmL7oEwAAAA8"] [Sat Aug 29 05:07:30.448133 2026] [security2:error] [pid 1028675:tid 1028912] [client 20.104.104.62:10642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/x0x.php"] [unique_id "apK9ctdHPfW2QFvhmL7oFAAAAGY"] [Sat Aug 29 05:07:30.449464 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.104.62:64745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/thr.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVPAAABc0"] [Sat Aug 29 05:07:30.463211 2026] [security2:error] [pid 1018003:tid 1018195] [client 68.155.159.216:24477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVPQAABeQ"] [Sat Aug 29 05:07:30.476297 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.104.18.15:13656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/8.php"] [unique_id "apK9ctdHPfW2QFvhmL7oFQAAADM"] [Sat Aug 29 05:07:30.492099 2026] [security2:error] [pid 1028675:tid 1028811] [client 52.139.37.240:19265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/abc.php"] [unique_id "apK9ctdHPfW2QFvhmL7oFgAAAAE"] [Sat Aug 29 05:07:30.494751 2026] [security2:error] [pid 1028675:tid 1028832] [client 20.104.18.15:4996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/wp.php"] [unique_id "apK9ctdHPfW2QFvhmL7oFwAAABY"] [Sat Aug 29 05:07:30.497947 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.63.81.20:20974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apK9ctdHPfW2QFvhmL7oGAAAAE0"] [Sat Aug 29 05:07:30.509815 2026] [security2:error] [pid 1028675:tid 1028899] [client 168.107.94.195:52923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9ctdHPfW2QFvhmL7oHAAAAFk"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:30.541138 2026] [security2:error] [pid 1018003:tid 1018234] [client 20.151.200.44:47412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/7h.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVPwAABgo"] [Sat Aug 29 05:07:30.544199 2026] [security2:error] [pid 1018003:tid 1018138] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/app/.env"] [unique_id "apK9cjAh5Y1i2tUxg4EVQAAF6XU"] [Sat Aug 29 05:07:30.548962 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.104.18.15:12172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/m.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVQQAABio"] [Sat Aug 29 05:07:30.555260 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.48.250.41:49101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/ws58.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVQgAABi4"] [Sat Aug 29 05:07:30.559622 2026] [security2:error] [pid 1028675:tid 1028919] [client 158.23.147.79:49995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/login.php"] [unique_id "apK9ctdHPfW2QFvhmL7oIwAAAG0"] [Sat Aug 29 05:07:30.586339 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.104.18.15:19337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/file1221.php"] [unique_id "apK9ctdHPfW2QFvhmL7oKAAAAGs"] [Sat Aug 29 05:07:30.589985 2026] [security2:error] [pid 1018003:tid 1018236] [client 20.104.104.62:10585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capturephoto.net"] [uri "/fesa.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVSQAABgw"] [Sat Aug 29 05:07:30.596933 2026] [security2:error] [pid 1028675:tid 1028929] [client 4.205.62.107:21893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/ws79.php"] [unique_id "apK9ctdHPfW2QFvhmL7oKQAAAHc"] [Sat Aug 29 05:07:30.601594 2026] [core:error] [pid 1018003:tid 1018188] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.601610 2026] [core:error] [pid 1018003:tid 1018188] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.603983 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.603998 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.604576 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.604590 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.607610 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.607627 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.607831 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.607841 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.609145 2026] [security2:error] [pid 1028675:tid 1028833] [client 20.196.209.81:1990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/bak.phps"] [unique_id "apK9ctdHPfW2QFvhmL7oLAAAABc"] [Sat Aug 29 05:07:30.619142 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.48.250.41:35473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/xs.php"] [unique_id "apK9ctdHPfW2QFvhmL7oLQAAABs"] [Sat Aug 29 05:07:30.622641 2026] [security2:error] [pid 1028675:tid 1028920] [client 158.158.54.35:16186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/m.php"] [unique_id "apK9ctdHPfW2QFvhmL7oLgAAAG4"] [Sat Aug 29 05:07:30.627684 2026] [security2:error] [pid 1028675:tid 1028859] [client 52.139.37.240:15256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/ac.php"] [unique_id "apK9ctdHPfW2QFvhmL7oLwAAADE"] [Sat Aug 29 05:07:30.633138 2026] [security2:error] [pid 1018003:tid 1018182] [client 20.63.81.20:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/robots.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVTgAABdc"] [Sat Aug 29 05:07:30.652575 2026] [security2:error] [pid 1028675:tid 1028855] [client 158.158.54.35:15886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/root.php"] [unique_id "apK9ctdHPfW2QFvhmL7oMAAAAC0"] [Sat Aug 29 05:07:30.658967 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.104.18.15:4998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/abcd.php"] [unique_id "apK9ctdHPfW2QFvhmL7oMQAAADQ"] [Sat Aug 29 05:07:30.662794 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.18.15:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-activate.php"] [unique_id "apK9ctdHPfW2QFvhmL7oMgAAACk"] [Sat Aug 29 05:07:30.667784 2026] [security2:error] [pid 1018003:tid 1018162] [client 158.23.147.79:17506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/atomlib.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVUAAABcM"] [Sat Aug 29 05:07:30.680751 2026] [security2:error] [pid 1018003:tid 1018224] [client 146.70.36.124:49922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9cjAh5Y1i2tUxg4EVWAAABgE"] [Sat Aug 29 05:07:30.684653 2026] [security2:error] [pid 1028675:tid 1028814] [client 52.139.37.240:19293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/c1.php"] [unique_id "apK9ctdHPfW2QFvhmL7oNQAAAAQ"] [Sat Aug 29 05:07:30.689114 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.48.250.41:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/xs.php"] [unique_id "apK9ctdHPfW2QFvhmL7oNwAAAHM"] [Sat Aug 29 05:07:30.689215 2026] [security2:error] [pid 1028675:tid 1028888] [client 20.104.18.15:13754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/goods.php"] [unique_id "apK9ctdHPfW2QFvhmL7oNgAAAE4"] [Sat Aug 29 05:07:30.696779 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.696796 2026] [core:error] [pid 1018003:tid 1018191] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.696970 2026] [core:error] [pid 1028675:tid 1028901] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.696981 2026] [core:error] [pid 1028675:tid 1028901] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.700970 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.151.200.44:47370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/wp-gzone.php"] [unique_id "apK9ctdHPfW2QFvhmL7oOgAAAA4"] [Sat Aug 29 05:07:30.703866 2026] [security2:error] [pid 1018003:tid 1018255] [client 2804:d59:ad19:6200:dd9f:6cc7:2ea4:88c1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "sungrove.org"] [uri "/xmlrpc.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVSgAGH1U"] [Sat Aug 29 05:07:30.705883 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.705895 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.713150 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.713162 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.713424 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.713441 2026] [core:error] [pid 1018003:tid 1018256] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.716857 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.716867 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.717320 2026] [security2:error] [pid 1028675:tid 1028916] [client 158.23.147.79:48284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-admin/network/index.php"] [unique_id "apK9ctdHPfW2QFvhmL7oPgAAAGo"] [Sat Aug 29 05:07:30.746567 2026] [security2:error] [pid 1028675:tid 1028867] [client 20.104.18.15:19336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/nox.php"] [unique_id "apK9ctdHPfW2QFvhmL7oQQAAADk"] [Sat Aug 29 05:07:30.747545 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.104.49.130:50591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.danesquality.com"] [uri "/xwx1.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVXAAABho"] [Sat Aug 29 05:07:30.755170 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.203.141.11:27351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9ctdHPfW2QFvhmL7oQgAAACI"] [Sat Aug 29 05:07:30.761069 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.104.18.15:12168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/fling.php"] [unique_id "apK9ctdHPfW2QFvhmL7oQwAAACg"] [Sat Aug 29 05:07:30.765189 2026] [security2:error] [pid 1018003:tid 1018267] [client 20.63.81.20:20976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVXQAABis"] [Sat Aug 29 05:07:30.770402 2026] [security2:error] [pid 1018003:tid 1018217] [client 68.155.159.216:6140] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/1.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVXgAABfo"] [Sat Aug 29 05:07:30.770505 2026] [security2:error] [pid 1018003:tid 1018217] [client 68.155.159.216:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/1.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVXgAABfo"] [Sat Aug 29 05:07:30.817579 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.104.18.15:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/nofile.php"] [unique_id "apK9ctdHPfW2QFvhmL7oRgAAADA"] [Sat Aug 29 05:07:30.823272 2026] [core:error] [pid 1028675:tid 1028889] [client 34.138.144.127:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.823287 2026] [core:error] [pid 1028675:tid 1028889] [client 34.138.144.127:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.832516 2026] [security2:error] [pid 1028675:tid 1028912] [client 52.139.37.240:15273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/ctex1.php"] [unique_id "apK9ctdHPfW2QFvhmL7oRwAAAGY"] [Sat Aug 29 05:07:30.839520 2026] [security2:error] [pid 1028675:tid 1028826] [client 20.104.104.62:20835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/tmv.php"] [unique_id "apK9ctdHPfW2QFvhmL7oSAAAABA"] [Sat Aug 29 05:07:30.853803 2026] [security2:error] [pid 1028675:tid 1028911] [client 4.205.62.107:24965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/file21.php"] [unique_id "apK9ctdHPfW2QFvhmL7oSQAAAGU"] [Sat Aug 29 05:07:30.857888 2026] [security2:error] [pid 1028675:tid 1028871] [client 20.203.141.11:18189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/wp-content/cong.php"] [unique_id "apK9ctdHPfW2QFvhmL7oSgAAAD0"] [Sat Aug 29 05:07:30.866849 2026] [security2:error] [pid 1018003:tid 1018183] [client 68.155.159.216:30592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVYAAABdg"] [Sat Aug 29 05:07:30.876334 2026] [security2:error] [pid 1018003:tid 1018159] [client 20.104.18.15:36724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-trackback.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVYQAABcA"] [Sat Aug 29 05:07:30.876564 2026] [security2:error] [pid 1028675:tid 1028887] [client 52.139.37.240:19325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/index.php/feed/atom/"] [unique_id "apK9ctdHPfW2QFvhmL7oSwAAAE0"] [Sat Aug 29 05:07:30.879108 2026] [security2:error] [pid 1018003:tid 1018184] [client 4.205.62.107:58484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/css.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVYgAABdk"] [Sat Aug 29 05:07:30.887215 2026] [security2:error] [pid 1028675:tid 1028830] [client 68.155.159.216:49157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/sad/about.php"] [unique_id "apK9ctdHPfW2QFvhmL7oTAAAABQ"] [Sat Aug 29 05:07:30.891721 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.151.200.44:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/fgd.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVYwAABf8"] [Sat Aug 29 05:07:30.893362 2026] [security2:error] [pid 1018003:tid 1018196] [client 20.104.18.15:13595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/ah.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVZgAABeU"] [Sat Aug 29 05:07:30.893502 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.63.81.20:20943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apK9ctdHPfW2QFvhmL7oTQAAAFA"] [Sat Aug 29 05:07:30.895563 2026] [core:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.895580 2026] [core:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.899300 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.104.18.15:12226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/btyuio.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVaAAABc0"] [Sat Aug 29 05:07:30.902408 2026] [security2:error] [pid 1028675:tid 1028903] [client 40.83.93.50:5642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-config.php"] [unique_id "apK9ctdHPfW2QFvhmL7oTgAAAF0"] [Sat Aug 29 05:07:30.918611 2026] [security2:error] [pid 1028675:tid 1028919] [client 68.155.159.216:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/dropdown.php"] [unique_id "apK9ctdHPfW2QFvhmL7oTwAAAG0"] [Sat Aug 29 05:07:30.920007 2026] [security2:error] [pid 1028675:tid 1028881] [client 168.107.94.195:53324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9ctdHPfW2QFvhmL7oUAAAAEc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:30.921931 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.18.15:19330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/akismet.php"] [unique_id "apK9cjAh5Y1i2tUxg4EVawAABgM"] [Sat Aug 29 05:07:30.926431 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.926460 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.929039 2026] [core:error] [pid 1018003:tid 1018109] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.929062 2026] [core:error] [pid 1018003:tid 1018109] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.948815 2026] [security2:error] [pid 1018003:tid 1018094] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/apps/.env"] [unique_id "apK9cjAh5Y1i2tUxg4EVcQAGMUk"] [Sat Aug 29 05:07:30.949005 2026] [security2:error] [pid 1018003:tid 1018140] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/application/.env"] [unique_id "apK9cjAh5Y1i2tUxg4EVcAAGMXc"] [Sat Aug 29 05:07:30.952772 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.952785 2026] [core:error] [pid 1018003:tid 1018146] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.974981 2026] [security2:error] [pid 1018003:tid 1018077] [remote 34.138.144.127:58716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/wp/.env"] [unique_id "apK9cjAh5Y1i2tUxg4EVcwAFvDg"] [Sat Aug 29 05:07:30.979726 2026] [security2:error] [pid 1028675:tid 1028848] [client 4.205.62.107:21914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/packed.php"] [unique_id "apK9ctdHPfW2QFvhmL7oVAAAACY"] [Sat Aug 29 05:07:30.980249 2026] [core:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.980260 2026] [core:error] [pid 1018003:tid 1018120] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.981338 2026] [core:error] [pid 1028675:tid 1028873] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.981363 2026] [core:error] [pid 1028675:tid 1028873] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.981381 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.981391 2026] [core:error] [pid 1018003:tid 1018275] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.983919 2026] [security2:error] [pid 1028675:tid 1028873] [client 146.70.36.124:49928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apK9ctdHPfW2QFvhmL7oVQAAAD8"] [Sat Aug 29 05:07:30.984971 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.984995 2026] [core:error] [pid 1018003:tid 1018246] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.986051 2026] [core:error] [pid 1018003:tid 1018065] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.986064 2026] [core:error] [pid 1018003:tid 1018065] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.989232 2026] [core:error] [pid 1018003:tid 1018117] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.989245 2026] [core:error] [pid 1018003:tid 1018117] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:30.989331 2026] [security2:error] [pid 1028675:tid 1028837] [client 20.104.49.130:43804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apK9ctdHPfW2QFvhmL7oVgAAABs"] [Sat Aug 29 05:07:30.989427 2026] [security2:error] [pid 1018003:tid 1018107] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/@fs/.env"] [unique_id "apK9cjAh5Y1i2tUxg4EVeQAGGFY"] [Sat Aug 29 05:07:31.005091 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.104.18.15:4944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/run.php"] [unique_id "apK9czAh5Y1i2tUxg4EVgQAABes"] [Sat Aug 29 05:07:31.023695 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.104.18.15:36648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/pri.php"] [unique_id "apK9c9dHPfW2QFvhmL7oVwAAADQ"] [Sat Aug 29 05:07:31.025201 2026] [security2:error] [pid 1028675:tid 1028847] [client 52.139.37.240:14492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/defaults.php"] [unique_id "apK9c9dHPfW2QFvhmL7oWAAAACU"] [Sat Aug 29 05:07:31.029667 2026] [security2:error] [pid 1028675:tid 1028842] [client 103.185.242.143:49525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.242.185.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9c9dHPfW2QFvhmL7oWgAAACA"] [Sat Aug 29 05:07:31.029791 2026] [security2:error] [pid 1028675:tid 1028842] [client 103.185.242.143:49525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jamwestcon.com"] [uri "/xmlrpc.php"] [unique_id "apK9c9dHPfW2QFvhmL7oWgAAACA"] [Sat Aug 29 05:07:31.034803 2026] [security2:error] [pid 1028675:tid 1028936] [client 20.104.18.15:13575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/ws55.php"] [unique_id "apK9c9dHPfW2QFvhmL7oWwAAAH4"] [Sat Aug 29 05:07:31.036117 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.63.81.20:20936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apK9c9dHPfW2QFvhmL7oXAAAAAQ"] [Sat Aug 29 05:07:31.040588 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.196.209.81:10581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/install.php"] [unique_id "apK9c9dHPfW2QFvhmL7oXwAAAFo"] [Sat Aug 29 05:07:31.047316 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.104.18.15:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/dehnl.php"] [unique_id "apK9c9dHPfW2QFvhmL7oYAAAAA4"] [Sat Aug 29 05:07:31.061233 2026] [security2:error] [pid 1028675:tid 1028870] [client 158.23.147.79:26463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/includes/index.php"] [unique_id "apK9c9dHPfW2QFvhmL7oZAAAADw"] [Sat Aug 29 05:07:31.062234 2026] [security2:error] [pid 1028675:tid 1028914] [client 68.155.159.216:65072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/xmlrpc.php"] [unique_id "apK9c9dHPfW2QFvhmL7oZQAAAGg"] [Sat Aug 29 05:07:31.068264 2026] [security2:error] [pid 1028675:tid 1028910] [client 68.155.159.216:33541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/radio.php"] [unique_id "apK9c9dHPfW2QFvhmL7oZgAAAGQ"] [Sat Aug 29 05:07:31.071057 2026] [security2:error] [pid 1028675:tid 1028819] [client 158.158.54.35:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "apK9c9dHPfW2QFvhmL7oZwAAAAk"] [Sat Aug 29 05:07:31.071876 2026] [security2:error] [pid 1028675:tid 1028920] [client 52.139.37.240:19282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/root.php"] [unique_id "apK9c9dHPfW2QFvhmL7oaAAAAG4"] [Sat Aug 29 05:07:31.074888 2026] [core:error] [pid 1018003:tid 1018061] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.074904 2026] [core:error] [pid 1018003:tid 1018061] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.076192 2026] [security2:error] [pid 1018003:tid 1018119] [remote 34.138.144.127:58716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.roycehomesales.com"] [uri "/wp-config.php~"] [unique_id "apK9czAh5Y1i2tUxg4EVgwAGHGI"] [Sat Aug 29 05:07:31.113013 2026] [security2:error] [pid 1028675:tid 1028909] [client 158.158.54.35:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/p.php"] [unique_id "apK9c9dHPfW2QFvhmL7obQAAAGM"] [Sat Aug 29 05:07:31.132543 2026] [security2:error] [pid 1028675:tid 1028858] [client 20.151.200.44:47404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/str.php"] [unique_id "apK9c9dHPfW2QFvhmL7ocQAAADA"] [Sat Aug 29 05:07:31.135066 2026] [core:error] [pid 1018003:tid 1018080] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.135084 2026] [core:error] [pid 1018003:tid 1018080] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.139391 2026] [security2:error] [pid 1018003:tid 1018133] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.qandlcondos.com"] [uri "/wp-config.php.old"] [unique_id "apK9czAh5Y1i2tUxg4EVhwAGIHA"] [Sat Aug 29 05:07:31.140264 2026] [security2:error] [pid 1018003:tid 1018113] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/@fs/.env"] [unique_id "apK9czAh5Y1i2tUxg4EVhgAGIFw"] [Sat Aug 29 05:07:31.146717 2026] [security2:error] [pid 1018003:tid 1018032] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/@fs/.env"] [unique_id "apK9czAh5Y1i2tUxg4EViQAF_gs"] [Sat Aug 29 05:07:31.150269 2026] [security2:error] [pid 1018003:tid 1018145] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.qandlcondos.com"] [uri "/wp-config.php.bak"] [unique_id "apK9czAh5Y1i2tUxg4EViwAGInw"] [Sat Aug 29 05:07:31.151644 2026] [security2:error] [pid 1018003:tid 1018130] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/laravel/.env"] [unique_id "apK9czAh5Y1i2tUxg4EVigAGIm0"] [Sat Aug 29 05:07:31.166027 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.104.18.15:19331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/ajax.php"] [unique_id "apK9czAh5Y1i2tUxg4EVjwAABd4"] [Sat Aug 29 05:07:31.167978 2026] [security2:error] [pid 1018003:tid 1018250] [client 20.104.18.15:13687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/drykl.php"] [unique_id "apK9czAh5Y1i2tUxg4EVkAAABho"] [Sat Aug 29 05:07:31.169580 2026] [security2:error] [pid 1018003:tid 1018268] [client 20.63.81.20:20872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apK9czAh5Y1i2tUxg4EVkQAABiw"] [Sat Aug 29 05:07:31.187427 2026] [security2:error] [pid 1018003:tid 1018175] [client 146.70.194.254:59636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/2018/wp-includes/wlwmanifest.xml"] [unique_id "apK9czAh5Y1i2tUxg4EVkwAABdA"] [Sat Aug 29 05:07:31.194595 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.104.18.15:4966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/new.php"] [unique_id "apK9c9dHPfW2QFvhmL7ocwAAAE0"] [Sat Aug 29 05:07:31.215342 2026] [security2:error] [pid 1028675:tid 1028912] [client 52.139.37.240:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/domains.php"] [unique_id "apK9c9dHPfW2QFvhmL7odQAAAGY"] [Sat Aug 29 05:07:31.231463 2026] [security2:error] [pid 1028675:tid 1028823] [client 20.203.141.11:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-admin/index.php"] [unique_id "apK9c9dHPfW2QFvhmL7odgAAAA0"] [Sat Aug 29 05:07:31.240817 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.240833 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.244727 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.244745 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.246175 2026] [core:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.246191 2026] [core:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.248093 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.248115 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.249169 2026] [core:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.249185 2026] [core:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.249902 2026] [core:error] [pid 1018003:tid 1018137] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.249925 2026] [core:error] [pid 1018003:tid 1018137] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.253658 2026] [core:error] [pid 1018003:tid 1018035] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.253673 2026] [core:error] [pid 1018003:tid 1018035] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.253959 2026] [core:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.253968 2026] [core:error] [pid 1018003:tid 1018127] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.254249 2026] [core:error] [pid 1018003:tid 1018045] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.254259 2026] [core:error] [pid 1018003:tid 1018045] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.254497 2026] [core:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.254513 2026] [core:error] [pid 1018003:tid 1018041] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.254743 2026] [core:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.254749 2026] [core:error] [pid 1018003:tid 1018102] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.255150 2026] [core:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.255160 2026] [core:error] [pid 1018003:tid 1018039] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.267447 2026] [security2:error] [pid 1028675:tid 1028830] [client 52.139.37.240:19341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/shell.php"] [unique_id "apK9c9dHPfW2QFvhmL7oeQAAABQ"] [Sat Aug 29 05:07:31.273692 2026] [security2:error] [pid 1018003:tid 1018172] [client 68.155.159.216:56550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9czAh5Y1i2tUxg4EVqAAABc0"] [Sat Aug 29 05:07:31.278617 2026] [security2:error] [pid 1028675:tid 1028833] [client 20.104.18.15:12213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/zoo2.php"] [unique_id "apK9c9dHPfW2QFvhmL7oegAAABc"] [Sat Aug 29 05:07:31.279202 2026] [security2:error] [pid 1028675:tid 1028927] [client 158.23.147.79:30426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9c9dHPfW2QFvhmL7oewAAAHU"] [Sat Aug 29 05:07:31.280612 2026] [security2:error] [pid 1028675:tid 1028818] [client 4.205.62.107:8709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/test.php"] [unique_id "apK9c9dHPfW2QFvhmL7ofAAAAAg"] [Sat Aug 29 05:07:31.286999 2026] [security2:error] [pid 1028675:tid 1028873] [client 146.70.36.124:49944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apK9c9dHPfW2QFvhmL7ofQAAAD8"] [Sat Aug 29 05:07:31.291269 2026] [security2:error] [pid 1028675:tid 1028847] [client 158.23.147.79:32581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-content/themes/index.php"] [unique_id "apK9c9dHPfW2QFvhmL7ofwAAACU"] [Sat Aug 29 05:07:31.294954 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.294968 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.295906 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.295920 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.296059 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.296070 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.296332 2026] [core:error] [pid 1028675:tid 1028859] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.296341 2026] [core:error] [pid 1028675:tid 1028859] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.296404 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.296417 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.301529 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.63.81.20:20880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apK9czAh5Y1i2tUxg4EVqQAABgM"] [Sat Aug 29 05:07:31.301888 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.104.18.15:13589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/backup.php"] [unique_id "apK9c9dHPfW2QFvhmL7ohAAAAFo"] [Sat Aug 29 05:07:31.302812 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.104.18.15:19436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/atomlib.php"] [unique_id "apK9c9dHPfW2QFvhmL7ohQAAAGs"] [Sat Aug 29 05:07:31.316428 2026] [security2:error] [pid 1018003:tid 1018192] [client 168.107.94.195:53844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9czAh5Y1i2tUxg4EVqgAABeE"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:31.325858 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.203.141.11:38166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apK9c9dHPfW2QFvhmL7ohgAAAAs"] [Sat Aug 29 05:07:31.333051 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.18.15:36656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp_blog_footer.php"] [unique_id "apK9c9dHPfW2QFvhmL7ohwAAAFw"] [Sat Aug 29 05:07:31.354989 2026] [security2:error] [pid 1018003:tid 1018083] [remote 34.138.144.127:58716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.roycehomesales.com"] [uri "/wp-config.php.swp"] [unique_id "apK9czAh5Y1i2tUxg4EVrAAF7D4"] [Sat Aug 29 05:07:31.356829 2026] [security2:error] [pid 1018003:tid 1018277] [client 68.155.159.216:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9czAh5Y1i2tUxg4EVrQAABjU"] [Sat Aug 29 05:07:31.357111 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.104.18.15:5055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/inx.php"] [unique_id "apK9c9dHPfW2QFvhmL7oiAAAAGg"] [Sat Aug 29 05:07:31.361247 2026] [core:error] [pid 1018003:tid 1018095] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.361262 2026] [core:error] [pid 1018003:tid 1018095] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.374053 2026] [security2:error] [pid 1028675:tid 1028916] [client 158.23.147.79:25417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9c9dHPfW2QFvhmL7oiQAAAGo"] [Sat Aug 29 05:07:31.376995 2026] [security2:error] [pid 1028675:tid 1028849] [client 40.83.93.50:24456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-configs.php"] [unique_id "apK9c9dHPfW2QFvhmL7oigAAACc"] [Sat Aug 29 05:07:31.378099 2026] [security2:error] [pid 1028675:tid 1028920] [client 4.205.62.107:53280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/myfile.php"] [unique_id "apK9c9dHPfW2QFvhmL7oiwAAAG4"] [Sat Aug 29 05:07:31.396152 2026] [security2:error] [pid 1018003:tid 1018100] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.104.231.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.qandlcondos.com"] [uri "/config.php.bak"] [unique_id "apK9czAh5Y1i2tUxg4EVrgAF-U8"] [Sat Aug 29 05:07:31.396619 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.104.104.62:64732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/terminal.php"] [unique_id "apK9czAh5Y1i2tUxg4EVsAAABb4"] [Sat Aug 29 05:07:31.403658 2026] [security2:error] [pid 1018003:tid 1018037] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.104.231.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.qandlcondos.com"] [uri "/configuration.php.bak"] [unique_id "apK9czAh5Y1i2tUxg4EVrwAF-RA"] [Sat Aug 29 05:07:31.405562 2026] [security2:error] [pid 1018003:tid 1018231] [client 52.139.37.240:14938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/dropdown.php"] [unique_id "apK9czAh5Y1i2tUxg4EVsQAABgc"] [Sat Aug 29 05:07:31.432761 2026] [security2:error] [pid 1028675:tid 1028825] [client 158.23.147.79:35829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/lock.php"] [unique_id "apK9c9dHPfW2QFvhmL7ojAAAAA8"] [Sat Aug 29 05:07:31.433791 2026] [security2:error] [pid 1018003:tid 1018164] [client 20.104.18.15:13568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/indo.php"] [unique_id "apK9czAh5Y1i2tUxg4EVsgAABcU"] [Sat Aug 29 05:07:31.433892 2026] [security2:error] [pid 1028675:tid 1028812] [client 68.155.159.216:33577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-content/index.php"] [unique_id "apK9c9dHPfW2QFvhmL7ojQAAAAI"] [Sat Aug 29 05:07:31.434447 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.104.18.15:19427] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.kozo.com.mx"] [uri "/1.php"] [unique_id "apK9c9dHPfW2QFvhmL7ojgAAACI"] [Sat Aug 29 05:07:31.434513 2026] [security2:error] [pid 1028675:tid 1028844] [client 20.104.18.15:19427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/1.php"] [unique_id "apK9c9dHPfW2QFvhmL7ojgAAACI"] [Sat Aug 29 05:07:31.446984 2026] [security2:error] [pid 1018003:tid 1018273] [client 20.104.18.15:12282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/zoo1.php"] [unique_id "apK9czAh5Y1i2tUxg4EVswAABjE"] [Sat Aug 29 05:07:31.447042 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.63.81.20:20948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apK9c9dHPfW2QFvhmL7ojwAAADM"] [Sat Aug 29 05:07:31.460827 2026] [security2:error] [pid 1018003:tid 1018182] [client 158.23.147.79:37770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/install.php"] [unique_id "apK9czAh5Y1i2tUxg4EVtAAABdc"] [Sat Aug 29 05:07:31.474376 2026] [security2:error] [pid 1018003:tid 1018246] [client 52.139.37.240:19300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-admin/user/index.php"] [unique_id "apK9czAh5Y1i2tUxg4EVtQAABhY"] [Sat Aug 29 05:07:31.478231 2026] [security2:error] [pid 1018003:tid 1018135] [remote 34.138.144.127:58716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/wp-config.old"] [unique_id "apK9czAh5Y1i2tUxg4EVtwAGGHI"] [Sat Aug 29 05:07:31.479195 2026] [core:error] [pid 1018003:tid 1018054] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.479207 2026] [core:error] [pid 1018003:tid 1018054] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.479590 2026] [core:error] [pid 1018003:tid 1018048] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.479607 2026] [core:error] [pid 1018003:tid 1018048] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.479751 2026] [security2:error] [pid 1018003:tid 1018185] [client 20.196.209.81:1889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/colour.php"] [unique_id "apK9czAh5Y1i2tUxg4EVugAABdo"] [Sat Aug 29 05:07:31.479892 2026] [core:error] [pid 1018003:tid 1018078] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.479900 2026] [core:error] [pid 1018003:tid 1018078] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.490752 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.18.15:4947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/vpn.php"] [unique_id "apK9czAh5Y1i2tUxg4EVuwAABec"] [Sat Aug 29 05:07:31.495046 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.104.18.15:36561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/sushi.php"] [unique_id "apK9c9dHPfW2QFvhmL7okAAAAAE"] [Sat Aug 29 05:07:31.514065 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.514079 2026] [core:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.515075 2026] [security2:error] [pid 1028675:tid 1028863] [client 158.158.54.35:34869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/222.php"] [unique_id "apK9c9dHPfW2QFvhmL7okgAAADU"] [Sat Aug 29 05:07:31.552589 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.552608 2026] [core:error] [pid 1028675:tid 1028890] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.554669 2026] [security2:error] [pid 1018003:tid 1018049] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.104.231.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.qandlcondos.com"] [uri "/config/.env.php"] [unique_id "apK9czAh5Y1i2tUxg4EVzgAGCRw"] [Sat Aug 29 05:07:31.555279 2026] [security2:error] [pid 1018003:tid 1018050] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/core/.env"] [unique_id "apK9czAh5Y1i2tUxg4EVzwAGCR0"] [Sat Aug 29 05:07:31.556525 2026] [security2:error] [pid 1018003:tid 1018056] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.104.231.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.qandlcondos.com"] [uri "/.env.php.bak"] [unique_id "apK9czAh5Y1i2tUxg4EV0QAGCSM"] [Sat Aug 29 05:07:31.559920 2026] [security2:error] [pid 1028675:tid 1028819] [client 158.158.54.35:24263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/a1.php"] [unique_id "apK9c9dHPfW2QFvhmL7omwAAAAk"] [Sat Aug 29 05:07:31.563153 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.563168 2026] [core:error] [pid 1018003:tid 1018262] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.563546 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.563554 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.565952 2026] [security2:error] [pid 1028675:tid 1028881] [client 20.104.18.15:13604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/sign.php"] [unique_id "apK9c9dHPfW2QFvhmL7onQAAAEc"] [Sat Aug 29 05:07:31.567551 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.567570 2026] [core:error] [pid 1028675:tid 1028880] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.586151 2026] [core:error] [pid 1028675:tid 1028884] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.586165 2026] [core:error] [pid 1028675:tid 1028884] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.586653 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.104.18.15:12271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/radio.php"] [unique_id "apK9c9dHPfW2QFvhmL7ooAAAACw"] [Sat Aug 29 05:07:31.586966 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.63.81.20:20971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/650.php"] [unique_id "apK9c9dHPfW2QFvhmL7ooQAAACY"] [Sat Aug 29 05:07:31.589255 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.589266 2026] [core:error] [pid 1018003:tid 1018195] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.592043 2026] [security2:error] [pid 1028675:tid 1028927] [client 146.70.36.124:49960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apK9c9dHPfW2QFvhmL7oowAAAHU"] [Sat Aug 29 05:07:31.593038 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.593050 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.596942 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.596953 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.598794 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.598804 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.601422 2026] [security2:error] [pid 1028675:tid 1028813] [client 20.104.18.15:19371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/samll.php"] [unique_id "apK9c9dHPfW2QFvhmL7opwAAAAM"] [Sat Aug 29 05:07:31.609698 2026] [security2:error] [pid 1018003:tid 1018217] [client 52.139.37.240:14927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/files/index.php"] [unique_id "apK9czAh5Y1i2tUxg4EV2AAABfo"] [Sat Aug 29 05:07:31.640321 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.640332 2026] [core:error] [pid 1018003:tid 1018184] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.644388 2026] [security2:error] [pid 1018003:tid 1018226] [client 20.104.104.62:25832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/wp-content/index.php"] [unique_id "apK9czAh5Y1i2tUxg4EV2gAABgM"] [Sat Aug 29 05:07:31.647662 2026] [security2:error] [pid 1028675:tid 1028814] [client 20.104.18.15:36572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/manga.php"] [unique_id "apK9c9dHPfW2QFvhmL7oqAAAAAQ"] [Sat Aug 29 05:07:31.661209 2026] [security2:error] [pid 1028675:tid 1028901] [client 20.104.18.15:4950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/shiny.php"] [unique_id "apK9c9dHPfW2QFvhmL7oqQAAAFs"] [Sat Aug 29 05:07:31.665644 2026] [security2:error] [pid 1028675:tid 1028847] [client 52.139.37.240:19348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "apK9c9dHPfW2QFvhmL7oqgAAACU"] [Sat Aug 29 05:07:31.686668 2026] [core:error] [pid 1018003:tid 1018038] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.roycehomesales.com [Sat Aug 29 05:07:31.686687 2026] [core:error] [pid 1018003:tid 1018038] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.roycehomesales.com [Sat Aug 29 05:07:31.687346 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.687365 2026] [core:error] [pid 1018003:tid 1018055] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.687542 2026] [core:error] [pid 1018003:tid 1018060] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.687552 2026] [core:error] [pid 1018003:tid 1018060] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.689261 2026] [core:error] [pid 1018003:tid 1018087] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.689270 2026] [core:error] [pid 1018003:tid 1018087] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.695187 2026] [security2:error] [pid 1028675:tid 1028875] [client 57.141.14.83:0] ModSecurity: Access denied with code 409 (phase 2). Match of "rx ^/monarx-analyzer.php" against "REQUEST_URI" required. [file "/opt/mod_security/botprotection.conf"] [line "1"] [id "901020"] [msg "TRANSPARENT BOT PROTECTION ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.djiboutifresh.com"] [uri "/cart/"] [unique_id "apK9c9dHPfW2QFvhmL7orAAAAEE"] [Sat Aug 29 05:07:31.696256 2026] [security2:error] [pid 1028675:tid 1028888] [client 168.107.94.195:54202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9c9dHPfW2QFvhmL7orQAAAE4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:31.697175 2026] [security2:error] [pid 1018003:tid 1018024] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/back-api/.env"] [unique_id "apK9czAh5Y1i2tUxg4EV3wAF_gM"] [Sat Aug 29 05:07:31.702691 2026] [security2:error] [pid 1028675:tid 1028853] [client 20.104.18.15:13697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/wnnjpsby.php"] [unique_id "apK9c9dHPfW2QFvhmL7orgAAACs"] [Sat Aug 29 05:07:31.710890 2026] [security2:error] [pid 1018003:tid 1018062] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/back-end/.env"] [unique_id "apK9czAh5Y1i2tUxg4EV4AAF_ik"] [Sat Aug 29 05:07:31.713738 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.713750 2026] [core:error] [pid 1028675:tid 1028826] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.717719 2026] [core:error] [pid 1018003:tid 1018047] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.717731 2026] [core:error] [pid 1018003:tid 1018047] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.721167 2026] [core:error] [pid 1018003:tid 1018030] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.721180 2026] [core:error] [pid 1018003:tid 1018030] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.722048 2026] [core:error] [pid 1018003:tid 1018025] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.722062 2026] [core:error] [pid 1018003:tid 1018025] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.724268 2026] [security2:error] [pid 1028675:tid 1028828] [client 20.203.141.11:25505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/radio.php"] [unique_id "apK9c9dHPfW2QFvhmL7osAAAABI"] [Sat Aug 29 05:07:31.724748 2026] [security2:error] [pid 1028675:tid 1028914] [client 20.63.81.20:20884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/nakrip.php"] [unique_id "apK9c9dHPfW2QFvhmL7osQAAAGg"] [Sat Aug 29 05:07:31.725317 2026] [security2:error] [pid 1018003:tid 1018096] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apK9czAh5Y1i2tUxg4EV5AAF_ks"] [Sat Aug 29 05:07:31.738610 2026] [security2:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apK9czAh5Y1i2tUxg4EV5gAF-So"] [Sat Aug 29 05:07:31.738652 2026] [security2:error] [pid 1018003:tid 1018266] [client 4.205.62.107:22403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/public/wp-blog.php"] [unique_id "apK9czAh5Y1i2tUxg4EV5wAABio"] [Sat Aug 29 05:07:31.741073 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.104.18.15:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/one.php"] [unique_id "apK9c9dHPfW2QFvhmL7osgAAAD4"] [Sat Aug 29 05:07:31.741979 2026] [core:error] [pid 1018003:tid 1018084] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.741993 2026] [core:error] [pid 1018003:tid 1018084] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.756580 2026] [security2:error] [pid 1028675:tid 1028820] [client 68.155.159.216:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin/images/about.php"] [unique_id "apK9c9dHPfW2QFvhmL7otQAAAAo"] [Sat Aug 29 05:07:31.780871 2026] [security2:error] [pid 1028675:tid 1028839] [client 20.203.141.11:27694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/wp-mail.php"] [unique_id "apK9c9dHPfW2QFvhmL7otwAAAB0"] [Sat Aug 29 05:07:31.802300 2026] [security2:error] [pid 1028675:tid 1028861] [client 20.104.18.15:36564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/asdfghj.php"] [unique_id "apK9c9dHPfW2QFvhmL7ougAAADM"] [Sat Aug 29 05:07:31.805538 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.104.18.15:19412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/she11.php"] [unique_id "apK9c9dHPfW2QFvhmL7ovAAAAAE"] [Sat Aug 29 05:07:31.805869 2026] [security2:error] [pid 1028675:tid 1028920] [client 52.139.37.240:14924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ewenclan.com"] [uri "/flower.php"] [unique_id "apK9c9dHPfW2QFvhmL7ovQAAAG4"] [Sat Aug 29 05:07:31.812062 2026] [security2:error] [pid 1028675:tid 1028923] [client 158.23.147.79:17485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/lv.php"] [unique_id "apK9c9dHPfW2QFvhmL7ovwAAAHE"] [Sat Aug 29 05:07:31.816058 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.104.18.15:5022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/goods.php"] [unique_id "apK9c9dHPfW2QFvhmL7owAAAACk"] [Sat Aug 29 05:07:31.819628 2026] [security2:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/backend/.env"] [unique_id "apK9czAh5Y1i2tUxg4EV6wAF12U"] [Sat Aug 29 05:07:31.820258 2026] [security2:error] [pid 1028675:tid 1028887] [client 158.23.147.79:48161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apK9c9dHPfW2QFvhmL7owQAAAE0"] [Sat Aug 29 05:07:31.821189 2026] [core:error] [pid 1018003:tid 1018059] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.821210 2026] [core:error] [pid 1018003:tid 1018059] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.821583 2026] [core:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.821594 2026] [core:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.821716 2026] [core:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.821727 2026] [core:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.836489 2026] [security2:error] [pid 1028675:tid 1028903] [client 20.104.18.15:13748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/gigi.php"] [unique_id "apK9c9dHPfW2QFvhmL7owgAAAF0"] [Sat Aug 29 05:07:31.843576 2026] [core:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.843591 2026] [core:error] [pid 1018003:tid 1018070] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.859185 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.104.104.62:40223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/titid.php"] [unique_id "apK9c9dHPfW2QFvhmL7oxAAAAFA"] [Sat Aug 29 05:07:31.859215 2026] [security2:error] [pid 1028675:tid 1028821] [client 40.83.93.50:5226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-conflg.php"] [unique_id "apK9c9dHPfW2QFvhmL7owwAAAAs"] [Sat Aug 29 05:07:31.859481 2026] [security2:error] [pid 1028675:tid 1028823] [client 20.48.250.41:49066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/zu.php"] [unique_id "apK9c9dHPfW2QFvhmL7oxQAAAA0"] [Sat Aug 29 05:07:31.861043 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.151.200.44:64688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/inject.php"] [unique_id "apK9c9dHPfW2QFvhmL7oxgAAAHo"] [Sat Aug 29 05:07:31.869607 2026] [security2:error] [pid 1028675:tid 1028909] [client 52.139.37.240:19357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-header-json.php"] [unique_id "apK9c9dHPfW2QFvhmL7oyAAAAGM"] [Sat Aug 29 05:07:31.873385 2026] [security2:error] [pid 1028675:tid 1028843] [client 20.63.81.20:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apK9c9dHPfW2QFvhmL7oyQAAACE"] [Sat Aug 29 05:07:31.880850 2026] [security2:error] [pid 1028675:tid 1028854] [client 68.155.159.216:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/ws.php"] [unique_id "apK9c9dHPfW2QFvhmL7ozAAAACw"] [Sat Aug 29 05:07:31.884560 2026] [security2:error] [pid 1028675:tid 1028883] [client 20.196.209.81:14473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/OK.php"] [unique_id "apK9c9dHPfW2QFvhmL7ozQAAAEk"] [Sat Aug 29 05:07:31.896598 2026] [security2:error] [pid 1028675:tid 1028877] [client 20.104.18.15:12200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/503.php"] [unique_id "apK9c9dHPfW2QFvhmL7ozgAAAEM"] [Sat Aug 29 05:07:31.897292 2026] [core:error] [pid 1018003:tid 1018028] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.897305 2026] [core:error] [pid 1018003:tid 1018028] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.897985 2026] [core:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.898001 2026] [core:error] [pid 1018003:tid 1018067] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.898241 2026] [core:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.898251 2026] [core:error] [pid 1018003:tid 1018129] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:31.904529 2026] [security2:error] [pid 1028675:tid 1028927] [client 146.70.36.124:49976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apK9c9dHPfW2QFvhmL7ozwAAAHU"] [Sat Aug 29 05:07:31.909404 2026] [security2:error] [pid 1018003:tid 1018248] [client 20.104.104.62:25608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/wp-content/uploads/admin.php"] [unique_id "apK9czAh5Y1i2tUxg4EV8gAABhg"] [Sat Aug 29 05:07:31.928875 2026] [security2:error] [pid 1018003:tid 1018202] [client 20.48.250.41:35492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/zu.php"] [unique_id "apK9czAh5Y1i2tUxg4EV8wAABes"] [Sat Aug 29 05:07:31.948510 2026] [security2:error] [pid 1028675:tid 1028832] [client 20.151.200.44:47416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/mega.php"] [unique_id "apK9c9dHPfW2QFvhmL7o0wAAABY"] [Sat Aug 29 05:07:31.950691 2026] [security2:error] [pid 1028675:tid 1028842] [client 20.104.18.15:36787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/dragonshell.php"] [unique_id "apK9c9dHPfW2QFvhmL7o1AAAACA"] [Sat Aug 29 05:07:31.959384 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.104.18.15:19441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/kerang.php"] [unique_id "apK9czAh5Y1i2tUxg4EV9gAABd8"] [Sat Aug 29 05:07:31.964724 2026] [security2:error] [pid 1028675:tid 1028863] [client 158.158.54.35:31464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/mini.php"] [unique_id "apK9c9dHPfW2QFvhmL7o1QAAADU"] [Sat Aug 29 05:07:31.971516 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.104.18.15:13618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/info.php/new.php"] [unique_id "apK9c9dHPfW2QFvhmL7o1wAAAHM"] [Sat Aug 29 05:07:31.988874 2026] [security2:error] [pid 1028675:tid 1028929] [client 68.155.159.216:30703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9c9dHPfW2QFvhmL7o4AAAAHc"] [Sat Aug 29 05:07:31.989394 2026] [security2:error] [pid 1028675:tid 1028901] [client 4.205.62.107:24994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/mcebraed.php"] [unique_id "apK9c9dHPfW2QFvhmL7o4QAAAFs"] [Sat Aug 29 05:07:32.004025 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.63.81.20:20962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/xcc.php"] [unique_id "apK9dNdHPfW2QFvhmL7o4gAAAFw"] [Sat Aug 29 05:07:32.008940 2026] [security2:error] [pid 1028675:tid 1028912] [client 158.158.54.35:5300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7o4wAAAGY"] [Sat Aug 29 05:07:32.014079 2026] [security2:error] [pid 1018003:tid 1018256] [client 4.205.62.107:58389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/erty.php"] [unique_id "apK9dDAh5Y1i2tUxg4EV-AAABiA"] [Sat Aug 29 05:07:32.026537 2026] [core:error] [pid 1018003:tid 1018118] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.roycehomesales.com [Sat Aug 29 05:07:32.026554 2026] [core:error] [pid 1018003:tid 1018118] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.roycehomesales.com [Sat Aug 29 05:07:32.027625 2026] [core:error] [pid 1018003:tid 1018099] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.027638 2026] [core:error] [pid 1018003:tid 1018099] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.040755 2026] [core:error] [pid 1018003:tid 1018114] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.051446 2026] [security2:error] [pid 1028675:tid 1028872] [client 68.155.159.216:12248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7o5AAAAD4"] [Sat Aug 29 05:07:32.051748 2026] [security2:error] [pid 1028675:tid 1028837] [client 68.155.159.216:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/sad/about.php"] [unique_id "apK9dNdHPfW2QFvhmL7o5QAAABs"] [Sat Aug 29 05:07:32.052104 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.104.18.15:5100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/alfa.php"] [unique_id "apK9dNdHPfW2QFvhmL7o5gAAAGw"] [Sat Aug 29 05:07:32.064842 2026] [security2:error] [pid 1028675:tid 1028900] [client 52.139.37.240:19344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/zup.php"] [unique_id "apK9dNdHPfW2QFvhmL7o5wAAAFo"] [Sat Aug 29 05:07:32.066182 2026] [security2:error] [pid 1028675:tid 1028850] [client 20.104.18.15:12259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/504.php"] [unique_id "apK9dNdHPfW2QFvhmL7o6AAAACg"] [Sat Aug 29 05:07:32.075065 2026] [security2:error] [pid 1028675:tid 1028876] [client 168.107.94.195:54582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7o6gAAAEI"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:32.085583 2026] [security2:error] [pid 1018003:tid 1018219] [client 20.48.250.41:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/lanka.php"] [unique_id "apK9dDAh5Y1i2tUxg4EV_AAABfw"] [Sat Aug 29 05:07:32.090748 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.104.18.15:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/m.php"] [unique_id "apK9dNdHPfW2QFvhmL7o6wAAAHE"] [Sat Aug 29 05:07:32.105882 2026] [security2:error] [pid 1028675:tid 1028851] [client 20.48.250.41:35050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/lanka.php"] [unique_id "apK9dNdHPfW2QFvhmL7o7QAAACk"] [Sat Aug 29 05:07:32.108005 2026] [security2:error] [pid 1018003:tid 1018076] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/web/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EV_QAFwjc"] [Sat Aug 29 05:07:32.108007 2026] [security2:error] [pid 1018003:tid 1018081] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/public/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EV_gAFwjw"] [Sat Aug 29 05:07:32.117734 2026] [security2:error] [pid 1028675:tid 1028819] [client 4.205.62.107:22048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/phpi.php"] [unique_id "apK9dNdHPfW2QFvhmL7o7gAAAAk"] [Sat Aug 29 05:07:32.118824 2026] [security2:error] [pid 1018003:tid 1018023] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/wp/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EV_wAFzQI"] [Sat Aug 29 05:07:32.123832 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.104.49.130:63613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thepsychicintuitive.allgooddays.org"] [uri "/images.php"] [unique_id "apK9dNdHPfW2QFvhmL7o7wAAAFA"] [Sat Aug 29 05:07:32.144099 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.63.81.20:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWAAAABd4"] [Sat Aug 29 05:07:32.155027 2026] [security2:error] [pid 1028675:tid 1028909] [client 68.155.159.216:51505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7o8QAAAGM"] [Sat Aug 29 05:07:32.168098 2026] [security2:error] [pid 1028675:tid 1028884] [client 68.155.159.216:65090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/atomlib.php"] [unique_id "apK9dNdHPfW2QFvhmL7o8gAAAEo"] [Sat Aug 29 05:07:32.171008 2026] [security2:error] [pid 1028675:tid 1028854] [client 158.23.147.79:50051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/hehehehe.php"] [unique_id "apK9dNdHPfW2QFvhmL7o9AAAACw"] [Sat Aug 29 05:07:32.171898 2026] [security2:error] [pid 1018003:tid 1018072] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/.env.swp"] [unique_id "apK9dDAh5Y1i2tUxg4EWAQAF5DM"] [Sat Aug 29 05:07:32.175953 2026] [security2:error] [pid 1018003:tid 1018074] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/storage/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EWAwAFyzU"] [Sat Aug 29 05:07:32.176039 2026] [security2:error] [pid 1028675:tid 1028877] [client 68.155.159.216:33542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7o9QAAAEM"] [Sat Aug 29 05:07:32.195830 2026] [core:error] [pid 1018003:tid 1018101] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.195843 2026] [core:error] [pid 1018003:tid 1018101] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.197728 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.104.18.15:12268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.printingbyjoe.com"] [uri "/admin.php"] [unique_id "apK9dNdHPfW2QFvhmL7o9gAAADQ"] [Sat Aug 29 05:07:32.198894 2026] [security2:error] [pid 1018003:tid 1018066] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EWBwAFvS0"] [Sat Aug 29 05:07:32.204399 2026] [security2:error] [pid 1018003:tid 1018138] [remote 34.138.144.127:58716] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcalendars.roycehomesales.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9dDAh5Y1i2tUxg4EWCQAF2XU"] [Sat Aug 29 05:07:32.207390 2026] [core:error] [pid 1018003:tid 1018138] [remote 34.138.144.127:58716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.210138 2026] [security2:error] [pid 1028675:tid 1028825] [client 20.203.141.11:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/item.php"] [unique_id "apK9dNdHPfW2QFvhmL7o-AAAAA8"] [Sat Aug 29 05:07:32.217193 2026] [security2:error] [pid 1028675:tid 1028863] [client 20.104.18.15:5012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.enveso.com"] [uri "/33.php"] [unique_id "apK9dNdHPfW2QFvhmL7o-QAAADU"] [Sat Aug 29 05:07:32.219566 2026] [security2:error] [pid 1028675:tid 1028937] [client 20.104.18.15:19339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kozo.com.mx"] [uri "/fling.php"] [unique_id "apK9dNdHPfW2QFvhmL7o-gAAAH8"] [Sat Aug 29 05:07:32.220484 2026] [security2:error] [pid 1028675:tid 1028925] [client 146.70.36.124:49986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apK9dNdHPfW2QFvhmL7o-wAAAHM"] [Sat Aug 29 05:07:32.232842 2026] [core:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.232854 2026] [core:error] [pid 1018003:tid 1018069] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.235973 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.104.104.62:25644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/403.php"] [unique_id "apK9dNdHPfW2QFvhmL7o_AAAAGQ"] [Sat Aug 29 05:07:32.240804 2026] [security2:error] [pid 1018003:tid 1018139] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EWDQAFvXY"] [Sat Aug 29 05:07:32.241161 2026] [core:error] [pid 1018003:tid 1018105] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.241169 2026] [core:error] [pid 1018003:tid 1018105] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.241184 2026] [security2:error] [pid 1018003:tid 1018116] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/be/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EWDgAFvV8"] [Sat Aug 29 05:07:32.242046 2026] [core:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.242055 2026] [core:error] [pid 1018003:tid 1018126] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.243347 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.203.141.11:38647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/wp-content.php"] [unique_id "apK9dNdHPfW2QFvhmL7o_QAAAAE"] [Sat Aug 29 05:07:32.245560 2026] [security2:error] [pid 1018003:tid 1018090] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/beta/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EWDwAFvUU"] [Sat Aug 29 05:07:32.257552 2026] [security2:error] [pid 1018003:tid 1018207] [client 52.139.37.240:19324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/a9.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWEAAABfA"] [Sat Aug 29 05:07:32.267190 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.267204 2026] [core:error] [pid 1028675:tid 1028812] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.268241 2026] [core:error] [pid 1028675:tid 1028814] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.268253 2026] [core:error] [pid 1028675:tid 1028814] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.286782 2026] [security2:error] [pid 1028675:tid 1028911] [client 91.92.47.191:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.corrigansbasement.com"] [uri "/config.php"] [unique_id "apK9dNdHPfW2QFvhmL7pAAAAAGU"] [Sat Aug 29 05:07:32.286988 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.151.200.44:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/ww3.php"] [unique_id "apK9dNdHPfW2QFvhmL7pAQAAAA4"] [Sat Aug 29 05:07:32.315507 2026] [security2:error] [pid 1028675:tid 1028818] [client 20.63.81.20:20877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apK9dNdHPfW2QFvhmL7pAwAAAAg"] [Sat Aug 29 05:07:32.317291 2026] [security2:error] [pid 1018003:tid 1018073] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.qandlcondos.com"] [uri "/wp-config.php~"] [unique_id "apK9dDAh5Y1i2tUxg4EWEgAGDDQ"] [Sat Aug 29 05:07:32.332610 2026] [security2:error] [pid 1018003:tid 1018109] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.qandlcondos.com"] [uri "/wp-config.php.swp"] [unique_id "apK9dDAh5Y1i2tUxg4EWGgAGNVg"] [Sat Aug 29 05:07:32.336929 2026] [security2:error] [pid 1018003:tid 1018098] [remote 35.231.104.225:42404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/wp-config.old"] [unique_id "apK9dDAh5Y1i2tUxg4EWGwAF7E0"] [Sat Aug 29 05:07:32.339451 2026] [security2:error] [pid 1028675:tid 1028848] [client 20.196.209.81:14498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hellospringford.wine-garden.com"] [uri "/aaa.php"] [unique_id "apK9dNdHPfW2QFvhmL7pCgAAACY"] [Sat Aug 29 05:07:32.342544 2026] [security2:error] [pid 1018003:tid 1018162] [client 40.83.93.50:24482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-content.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWHAAABcM"] [Sat Aug 29 05:07:32.348830 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.348845 2026] [core:error] [pid 1028675:tid 1028816] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.349851 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.349866 2026] [core:error] [pid 1028675:tid 1028860] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.350575 2026] [core:error] [pid 1028675:tid 1028904] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.350588 2026] [core:error] [pid 1028675:tid 1028904] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.352517 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.352529 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.354187 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.354199 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.356311 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.356321 2026] [core:error] [pid 1028675:tid 1028872] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.380715 2026] [security2:error] [pid 1028675:tid 1028819] [client 68.155.159.216:38670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/asd.php"] [unique_id "apK9dNdHPfW2QFvhmL7pEwAAAAk"] [Sat Aug 29 05:07:32.387097 2026] [security2:error] [pid 1028675:tid 1028890] [client 158.23.147.79:30411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/log-mama/function.php"] [unique_id "apK9dNdHPfW2QFvhmL7pFAAAAFA"] [Sat Aug 29 05:07:32.388256 2026] [security2:error] [pid 1028675:tid 1028870] [client 52.139.37.240:3387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/aged.php"] [unique_id "apK9dNdHPfW2QFvhmL7pFQAAADw"] [Sat Aug 29 05:07:32.389480 2026] [security2:error] [pid 1028675:tid 1028823] [client 158.23.147.79:32651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/about.php"] [unique_id "apK9dNdHPfW2QFvhmL7pFgAAAA0"] [Sat Aug 29 05:07:32.391003 2026] [security2:error] [pid 1028675:tid 1028932] [client 20.104.18.15:36671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.horseweblog.com"] [uri "/wp-safe.php"] [unique_id "apK9dNdHPfW2QFvhmL7pFwAAAHo"] [Sat Aug 29 05:07:32.411496 2026] [autoindex:error] [pid 1028675:tid 1028909] [client 20.104.18.15:0] AH01276: Cannot serve directory /home3/zenicane/public_html/lunarfestival/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Sat Aug 29 05:07:32.430039 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.104.104.62:25830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/ava.php"] [unique_id "apK9dNdHPfW2QFvhmL7pGgAAAHE"] [Sat Aug 29 05:07:32.435494 2026] [security2:error] [pid 1018003:tid 1018244] [client 20.104.49.130:43634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgbeats.tonewarp.com"] [uri "/f35.update.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWHQAABhQ"] [Sat Aug 29 05:07:32.436060 2026] [security2:error] [pid 1028675:tid 1028871] [client 158.158.54.35:33498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/aa.php"] [unique_id "apK9dNdHPfW2QFvhmL7pGwAAAD0"] [Sat Aug 29 05:07:32.441423 2026] [security2:error] [pid 1028675:tid 1028930] [client 158.158.54.35:24306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/alfa-rex.php7"] [unique_id "apK9dNdHPfW2QFvhmL7pHAAAAHg"] [Sat Aug 29 05:07:32.443873 2026] [security2:error] [pid 1028675:tid 1028919] [client 4.205.62.107:8971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/txets.php"] [unique_id "apK9dNdHPfW2QFvhmL7pHQAAAG0"] [Sat Aug 29 05:07:32.444680 2026] [security2:error] [pid 1028675:tid 1028862] [client 20.63.81.20:20972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-settings.php"] [unique_id "apK9dNdHPfW2QFvhmL7pHgAAADQ"] [Sat Aug 29 05:07:32.453291 2026] [security2:error] [pid 1028675:tid 1028821] [client 52.139.37.240:19389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/admin/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7pHwAAAAs"] [Sat Aug 29 05:07:32.455939 2026] [security2:error] [pid 1028675:tid 1028825] [client 168.107.94.195:54937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9dNdHPfW2QFvhmL7pIQAAAA8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:32.466925 2026] [security2:error] [pid 1028675:tid 1028842] [client 68.155.159.216:2021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/asd.php"] [unique_id "apK9dNdHPfW2QFvhmL7pIwAAACA"] [Sat Aug 29 05:07:32.472495 2026] [security2:error] [pid 1028675:tid 1028746] [remote 136.108.23.170:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.23.108.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thesmartpm.com"] [uri "/apps/wp-login.php"] [unique_id "apK9dNdHPfW2QFvhmL7pJAAANUE"], referer: https://thesmartpm.com/apps/wp-admin/ [Sat Aug 29 05:07:32.473088 2026] [security2:error] [pid 1028675:tid 1028757] [remote 136.108.23.170:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.23.108.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thesmartpm.com"] [uri "/apps/wp-login.php"] [unique_id "apK9dNdHPfW2QFvhmL7pJQAANUw"], referer: https://thesmartpm.com/apps/wp-admin/ [Sat Aug 29 05:07:32.473914 2026] [security2:error] [pid 1018003:tid 1018094] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/config.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWHwAFvEk"] [Sat Aug 29 05:07:32.474527 2026] [authz_core:error] [pid 1028675:tid 1028765] [remote 136.108.23.170:55262] AH01630: client denied by server configuration: /home4/sortthru/public_html/thesmartpm/.htpasswd [Sat Aug 29 05:07:32.475884 2026] [core:error] [pid 1028675:tid 1028732] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.475894 2026] [core:error] [pid 1028675:tid 1028732] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.483646 2026] [security2:error] [pid 1028675:tid 1028897] [client 158.23.147.79:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/nf_tracking.php"] [unique_id "apK9dNdHPfW2QFvhmL7pKgAAAFc"] [Sat Aug 29 05:07:32.493775 2026] [security2:error] [pid 1028675:tid 1028867] [client 146.70.194.254:59652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/shop/wp-includes/wlwmanifest.xml"] [unique_id "apK9dNdHPfW2QFvhmL7pKwAAADk"] [Sat Aug 29 05:07:32.494923 2026] [security2:error] [pid 1028675:tid 1028880] [client 20.104.18.15:13715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lunar-festival.com"] [uri "/w.php"] [unique_id "apK9dNdHPfW2QFvhmL7pLQAAAEY"] [Sat Aug 29 05:07:32.497863 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.151.200.44:46585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/sko.php"] [unique_id "apK9dNdHPfW2QFvhmL7pLgAAAAE"] [Sat Aug 29 05:07:32.506091 2026] [core:error] [pid 1028675:tid 1028756] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.roycehomesales.com [Sat Aug 29 05:07:32.506107 2026] [core:error] [pid 1028675:tid 1028756] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.roycehomesales.com [Sat Aug 29 05:07:32.507571 2026] [core:error] [pid 1028675:tid 1028785] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.515142 2026] [security2:error] [pid 1018003:tid 1018266] [client 4.205.62.107:53152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/lm15.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWIQAABio"] [Sat Aug 29 05:07:32.516660 2026] [core:error] [pid 1018003:tid 1018216] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.516678 2026] [core:error] [pid 1018003:tid 1018216] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.529026 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.529040 2026] [core:error] [pid 1018003:tid 1018077] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.529227 2026] [core:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.529238 2026] [core:error] [pid 1018003:tid 1018027] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.530330 2026] [security2:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/cms/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EWKgAGByw"] [Sat Aug 29 05:07:32.533098 2026] [core:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.533113 2026] [core:error] [pid 1018003:tid 1018107] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.541578 2026] [security2:error] [pid 1028675:tid 1028855] [client 68.155.159.216:33555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/about/function.php"] [unique_id "apK9dNdHPfW2QFvhmL7pNAAAAC0"] [Sat Aug 29 05:07:32.541779 2026] [security2:error] [pid 1018003:tid 1018248] [client 146.70.36.124:49994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.airviewconcept.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apK9dDAh5Y1i2tUxg4EWMQAABhg"] [Sat Aug 29 05:07:32.547528 2026] [security2:error] [pid 1028675:tid 1028761] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "apK9dNdHPfW2QFvhmL7pNwAAZVA"] [Sat Aug 29 05:07:32.550545 2026] [core:error] [pid 1028675:tid 1028735] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.550559 2026] [core:error] [pid 1028675:tid 1028735] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.551449 2026] [core:error] [pid 1028675:tid 1028776] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.551473 2026] [core:error] [pid 1028675:tid 1028776] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.556173 2026] [security2:error] [pid 1028675:tid 1028878] [client 158.23.147.79:35830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/index/function.php"] [unique_id "apK9dNdHPfW2QFvhmL7pOQAAAEQ"] [Sat Aug 29 05:07:32.557758 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.557777 2026] [core:error] [pid 1028675:tid 1028866] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.559708 2026] [core:error] [pid 1028675:tid 1028902] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.559727 2026] [core:error] [pid 1028675:tid 1028902] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.559898 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.559907 2026] [core:error] [pid 1028675:tid 1028818] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.572997 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.573011 2026] [core:error] [pid 1028675:tid 1028848] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.578942 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.63.81.20:20968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-signup.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWMwAABec"] [Sat Aug 29 05:07:32.584424 2026] [security2:error] [pid 1018003:tid 1018157] [client 52.139.37.240:51879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/essexec.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWNQAABb4"] [Sat Aug 29 05:07:32.589727 2026] [core:error] [pid 1028675:tid 1028777] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.589744 2026] [core:error] [pid 1028675:tid 1028777] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.593833 2026] [security2:error] [pid 1018003:tid 1018119] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "apK9dDAh5Y1i2tUxg4EWOQAF22I"] [Sat Aug 29 05:07:32.595895 2026] [core:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.595907 2026] [core:error] [pid 1018003:tid 1018061] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.620700 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.620719 2026] [core:error] [pid 1028675:tid 1028840] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.621709 2026] [core:error] [pid 1028675:tid 1028907] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.621725 2026] [core:error] [pid 1028675:tid 1028907] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.626035 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.626052 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.627717 2026] [security2:error] [pid 1028675:tid 1028816] [client 20.104.104.62:25615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/info.php"] [unique_id "apK9dNdHPfW2QFvhmL7pRAAAAAY"] [Sat Aug 29 05:07:32.627874 2026] [security2:error] [pid 1028675:tid 1028876] [client 20.104.104.62:20822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/sllolx.php"] [unique_id "apK9dNdHPfW2QFvhmL7pRQAAAEI"] [Sat Aug 29 05:07:32.647559 2026] [security2:error] [pid 1028675:tid 1028837] [client 52.139.37.240:19297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/makeasmtp.php"] [unique_id "apK9dNdHPfW2QFvhmL7pRwAAABs"] [Sat Aug 29 05:07:32.652000 2026] [security2:error] [pid 1028675:tid 1028920] [client 185.104.184.230:49132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jia.zbw.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "apK9dNdHPfW2QFvhmL7pSAAAAG4"] [Sat Aug 29 05:07:32.662836 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.662852 2026] [core:error] [pid 1018003:tid 1018183] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.673114 2026] [security2:error] [pid 1028675:tid 1028843] [client 158.23.147.79:26593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-login.php"] [unique_id "apK9dNdHPfW2QFvhmL7pSQAAACE"] [Sat Aug 29 05:07:32.698184 2026] [security2:error] [pid 1028675:tid 1028824] [client 20.203.141.11:38189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "apK9dNdHPfW2QFvhmL7pTAAAAA4"] [Sat Aug 29 05:07:32.703492 2026] [security2:error] [pid 1018003:tid 1018161] [client 114.119.135.182:45301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classiclightingusa.com"] [uri "/catalog/product_info.php/products_id/857/action/notify/osCsid/5543e7812b759b0a003a973ae85b9fd8"] [unique_id "apK9dDAh5Y1i2tUxg4EWPwAABcI"], referer: http://www.classiclightingusa.com/catalog/product_info.php/products_id/857 [Sat Aug 29 05:07:32.711754 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.203.141.11:13319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/t.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWQAAABd8"] [Sat Aug 29 05:07:32.712183 2026] [security2:error] [pid 1018003:tid 1018172] [client 20.63.81.20:20991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-conffg.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWQQAABc0"] [Sat Aug 29 05:07:32.750337 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.104.49.130:36302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.carlosmua.com"] [uri "/ms-edit.php"] [unique_id "apK9dNdHPfW2QFvhmL7pTQAAAFI"] [Sat Aug 29 05:07:32.776328 2026] [security2:error] [pid 1018003:tid 1018267] [client 52.139.37.240:3349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/fw.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWRAAABis"] [Sat Aug 29 05:07:32.823763 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.104.62:25636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/wp-admin/admin.php"] [unique_id "apK9dNdHPfW2QFvhmL7pUQAAAE8"] [Sat Aug 29 05:07:32.832181 2026] [security2:error] [pid 1018003:tid 1018071] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/config/config.inc.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWSgAFyDI"] [Sat Aug 29 05:07:32.832197 2026] [security2:error] [pid 1018003:tid 1018032] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/config/aws.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWSwAFyAs"] [Sat Aug 29 05:07:32.833156 2026] [security2:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/config/config.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWUAAFyBY"] [Sat Aug 29 05:07:32.835860 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.835875 2026] [core:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.835888 2026] [core:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.835901 2026] [core:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.837500 2026] [security2:error] [pid 1018003:tid 1018234] [client 168.107.94.195:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWUgAABgo"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:32.838068 2026] [core:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.838087 2026] [core:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.838234 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.838245 2026] [core:error] [pid 1018003:tid 1018021] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.838800 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.838808 2026] [core:error] [pid 1018003:tid 1018036] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.842907 2026] [security2:error] [pid 1028675:tid 1028841] [client 20.63.81.20:20915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-validate.php"] [unique_id "apK9dNdHPfW2QFvhmL7pVAAAAB8"] [Sat Aug 29 05:07:32.851571 2026] [security2:error] [pid 1018003:tid 1018159] [client 52.139.37.240:19283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/paku.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWVQAABcA"] [Sat Aug 29 05:07:32.857077 2026] [security2:error] [pid 1028675:tid 1028930] [client 20.151.200.44:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/zoz.php"] [unique_id "apK9dNdHPfW2QFvhmL7pVQAAAHg"] [Sat Aug 29 05:07:32.864119 2026] [security2:error] [pid 1018003:tid 1018277] [client 68.155.159.216:24500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWVwAABjU"] [Sat Aug 29 05:07:32.874129 2026] [security2:error] [pid 1018003:tid 1018270] [client 4.205.62.107:21602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/php-details.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWWQAABi4"] [Sat Aug 29 05:07:32.885342 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.885366 2026] [core:error] [pid 1028675:tid 1028862] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:32.898009 2026] [security2:error] [pid 1028675:tid 1028853] [client 158.158.54.35:5267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7pVwAAACs"] [Sat Aug 29 05:07:32.912920 2026] [security2:error] [pid 1028675:tid 1028926] [client 213.202.253.4:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bv-place.com"] [uri "/userfuns.php"] [unique_id "apK9dNdHPfW2QFvhmL7pWAAAAHQ"], referer: www.google.com [Sat Aug 29 05:07:32.929808 2026] [access_compat:error] [pid 1028675:tid 1028842] [client 67.20.76.220:22480] AH01797: client denied by server configuration: /home4/eastacar/public_html/guraonline.com/wp-cron.php [Sat Aug 29 05:07:32.930980 2026] [security2:error] [pid 1028675:tid 1028910] [client 158.23.147.79:48179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/.well-knownold/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7pWgAAAGQ"] [Sat Aug 29 05:07:32.934918 2026] [security2:error] [pid 1018003:tid 1018266] [client 158.23.147.79:17441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWXAAABio"] [Sat Aug 29 05:07:32.941674 2026] [security2:error] [pid 1018003:tid 1018217] [client 158.158.54.35:11170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/c.php"] [unique_id "apK9dDAh5Y1i2tUxg4EWXgAABfo"] [Sat Aug 29 05:07:32.970651 2026] [security2:error] [pid 1028675:tid 1028811] [client 20.63.81.20:20874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/700.php"] [unique_id "apK9dNdHPfW2QFvhmL7pXAAAAAE"] [Sat Aug 29 05:07:32.973072 2026] [security2:error] [pid 1028675:tid 1028825] [client 52.139.37.240:3363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/zwso.php"] [unique_id "apK9dNdHPfW2QFvhmL7pXQAAAA8"] [Sat Aug 29 05:07:32.984546 2026] [security2:error] [pid 1028675:tid 1028925] [client 68.155.159.216:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/wp-includes/css/index.php"] [unique_id "apK9dNdHPfW2QFvhmL7pXwAAAHM"] [Sat Aug 29 05:07:33.002017 2026] [security2:error] [pid 1028675:tid 1028878] [client 40.83.93.50:5590] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "wagnerfarmscbd.com"] [uri "/wp-content/1.php"] [unique_id "apK9dddHPfW2QFvhmL7pZAAAAEQ"] [Sat Aug 29 05:07:33.002097 2026] [security2:error] [pid 1028675:tid 1028878] [client 40.83.93.50:5590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-content/1.php"] [unique_id "apK9dddHPfW2QFvhmL7pZAAAAEQ"] [Sat Aug 29 05:07:33.006021 2026] [core:error] [pid 1028675:tid 1028780] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.006040 2026] [core:error] [pid 1028675:tid 1028780] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.007946 2026] [core:error] [pid 1028675:tid 1028786] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.009175 2026] [core:error] [pid 1028675:tid 1028786] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.018517 2026] [security2:error] [pid 1028675:tid 1028867] [client 20.104.104.62:25628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/wp-content/plugins/about.php"] [unique_id "apK9dddHPfW2QFvhmL7paAAAADk"] [Sat Aug 29 05:07:33.023987 2026] [security2:error] [pid 1028675:tid 1028916] [client 68.155.159.216:49193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/admin.php"] [unique_id "apK9dddHPfW2QFvhmL7pagAAAGo"] [Sat Aug 29 05:07:33.037865 2026] [security2:error] [pid 1028675:tid 1028894] [client 20.104.104.62:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/small.php"] [unique_id "apK9dddHPfW2QFvhmL7pbQAAAFQ"] [Sat Aug 29 05:07:33.049724 2026] [security2:error] [pid 1028675:tid 1028901] [client 52.139.37.240:19339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/rtx.php"] [unique_id "apK9dddHPfW2QFvhmL7pbgAAAFs"] [Sat Aug 29 05:07:33.068428 2026] [core:error] [pid 1028675:tid 1028798] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.068451 2026] [core:error] [pid 1028675:tid 1028798] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.070032 2026] [core:error] [pid 1028675:tid 1028789] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.070059 2026] [core:error] [pid 1028675:tid 1028789] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.070136 2026] [core:error] [pid 1028675:tid 1028779] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.070150 2026] [core:error] [pid 1028675:tid 1028779] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.112237 2026] [security2:error] [pid 1028675:tid 1028872] [client 20.63.81.20:20937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/c4.php"] [unique_id "apK9dddHPfW2QFvhmL7pdAAAAD4"] [Sat Aug 29 05:07:33.127730 2026] [security2:error] [pid 1028675:tid 1028816] [client 4.205.62.107:26644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/server-info.php"] [unique_id "apK9dddHPfW2QFvhmL7pdQAAAAY"] [Sat Aug 29 05:07:33.140089 2026] [core:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.140108 2026] [core:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.149805 2026] [security2:error] [pid 1028675:tid 1028781] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/web.config"] [unique_id "apK9dddHPfW2QFvhmL7peAAAJ2Q"] [Sat Aug 29 05:07:33.155350 2026] [security2:error] [pid 1028675:tid 1028875] [client 4.205.62.107:58461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/ws62.php"] [unique_id "apK9dddHPfW2QFvhmL7peQAAAEE"] [Sat Aug 29 05:07:33.186111 2026] [security2:error] [pid 1028675:tid 1028850] [client 52.139.37.240:51882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/admin/function.php"] [unique_id "apK9dddHPfW2QFvhmL7pegAAACg"] [Sat Aug 29 05:07:33.194273 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.194289 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.199208 2026] [security2:error] [pid 1028675:tid 1028820] [client 20.203.141.11:18229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/css/wp-login.php"] [unique_id "apK9dddHPfW2QFvhmL7pewAAAAo"] [Sat Aug 29 05:07:33.205531 2026] [security2:error] [pid 1028675:tid 1028815] [client 20.151.200.44:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/mga.php"] [unique_id "apK9dddHPfW2QFvhmL7pfAAAAAU"] [Sat Aug 29 05:07:33.214131 2026] [security2:error] [pid 1018003:tid 1018231] [client 20.104.104.62:25639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWZwAABgc"] [Sat Aug 29 05:07:33.220507 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.220523 2026] [core:error] [pid 1028675:tid 1028881] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.243289 2026] [security2:error] [pid 1028675:tid 1028900] [client 20.203.141.11:13328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/i.php"] [unique_id "apK9dddHPfW2QFvhmL7pfgAAAFo"] [Sat Aug 29 05:07:33.245041 2026] [security2:error] [pid 1028675:tid 1028892] [client 20.63.81.20:20990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-tymanage.php"] [unique_id "apK9dddHPfW2QFvhmL7pfwAAAFI"] [Sat Aug 29 05:07:33.250911 2026] [security2:error] [pid 1028675:tid 1028888] [client 168.107.94.195:55787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9dddHPfW2QFvhmL7pgAAAAE4"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:33.254649 2026] [security2:error] [pid 1018003:tid 1018185] [client 185.104.184.230:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.184.104.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.jia.zbw.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWaAAABdo"] [Sat Aug 29 05:07:33.254716 2026] [security2:error] [pid 1028675:tid 1028837] [client 52.139.37.240:19307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/update/da222.php"] [unique_id "apK9dddHPfW2QFvhmL7pgQAAABs"] [Sat Aug 29 05:07:33.255408 2026] [security2:error] [pid 1028675:tid 1028879] [client 158.23.147.79:30586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/bk/index.php"] [unique_id "apK9dddHPfW2QFvhmL7pggAAAEU"] [Sat Aug 29 05:07:33.264028 2026] [security2:error] [pid 1028675:tid 1028889] [client 68.155.159.216:51212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/nf_tracking.php"] [unique_id "apK9dddHPfW2QFvhmL7pgwAAAE8"] [Sat Aug 29 05:07:33.265403 2026] [security2:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/config/env.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWawAGKXs"] [Sat Aug 29 05:07:33.266260 2026] [core:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.266270 2026] [core:error] [pid 1018003:tid 1018142] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.266584 2026] [core:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.266595 2026] [core:error] [pid 1018003:tid 1018052] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.274213 2026] [security2:error] [pid 1028675:tid 1028884] [client 4.205.62.107:22412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/config_dev.php"] [unique_id "apK9dddHPfW2QFvhmL7phAAAAEo"] [Sat Aug 29 05:07:33.277368 2026] [security2:error] [pid 1028675:tid 1028841] [client 68.155.159.216:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/lv.php"] [unique_id "apK9dddHPfW2QFvhmL7phQAAAB8"] [Sat Aug 29 05:07:33.277655 2026] [security2:error] [pid 1028675:tid 1028930] [client 68.155.159.216:33730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/makeasmtp.php"] [unique_id "apK9dddHPfW2QFvhmL7phgAAAHg"] [Sat Aug 29 05:07:33.277778 2026] [core:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.277790 2026] [core:error] [pid 1018003:tid 1018143] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.294944 2026] [security2:error] [pid 1028675:tid 1028919] [client 158.23.147.79:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-content/x/index.php"] [unique_id "apK9dddHPfW2QFvhmL7piAAAAG0"] [Sat Aug 29 05:07:33.316292 2026] [core:error] [pid 1028675:tid 1028762] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.316316 2026] [core:error] [pid 1028675:tid 1028762] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.320548 2026] [security2:error] [pid 1018003:tid 1018177] [client 20.104.49.130:46529] ModSecurity: Access denied with connection close (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1032"] [id "900036"] [msg "Wordpress BOT exploit :: No UA/Referer"] [hostname "mail.flatlandsfoto.com"] [uri "/wp-login.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWcQAABdI"] [Sat Aug 29 05:07:33.333287 2026] [core:error] [pid 1028675:tid 1028792] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.333287 2026] [core:error] [pid 1028675:tid 1028796] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.333307 2026] [core:error] [pid 1028675:tid 1028792] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.333308 2026] [core:error] [pid 1028675:tid 1028796] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.342044 2026] [core:error] [pid 1028675:tid 1028791] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.342058 2026] [core:error] [pid 1028675:tid 1028791] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.342103 2026] [security2:error] [pid 1018003:tid 1018095] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/config/module.config.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWdAAFzUo"] [Sat Aug 29 05:07:33.342155 2026] [security2:error] [pid 1018003:tid 1018100] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/config/nexmo.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWcwAFzU8"] [Sat Aug 29 05:07:33.346845 2026] [security2:error] [pid 1018003:tid 1018189] [client 20.151.200.44:46632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/mmm.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWdwAABd4"] [Sat Aug 29 05:07:33.347647 2026] [security2:error] [pid 1028675:tid 1028843] [client 158.158.54.35:5285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/upload.php"] [unique_id "apK9dddHPfW2QFvhmL7pkAAAACE"] [Sat Aug 29 05:07:33.355724 2026] [security2:error] [pid 1028675:tid 1028784] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "apK9dddHPfW2QFvhmL7pkQAAD2c"] [Sat Aug 29 05:07:33.355774 2026] [security2:error] [pid 1028675:tid 1028783] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "apK9dddHPfW2QFvhmL7pkgAAD2Y"] [Sat Aug 29 05:07:33.371920 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.371930 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.371939 2026] [core:error] [pid 1018003:tid 1018238] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.371942 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.376897 2026] [security2:error] [pid 1018003:tid 1018186] [client 52.139.37.240:3381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/zoom1.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWfAAABds"] [Sat Aug 29 05:07:33.386140 2026] [security2:error] [pid 1028675:tid 1028883] [client 158.158.54.35:34850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/f.php"] [unique_id "apK9dddHPfW2QFvhmL7pkwAAAEk"] [Sat Aug 29 05:07:33.401118 2026] [security2:error] [pid 1018003:tid 1018271] [client 68.155.159.216:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWfQAABi8"] [Sat Aug 29 05:07:33.407587 2026] [security2:error] [pid 1028675:tid 1028910] [client 20.104.104.62:25752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "apK9dddHPfW2QFvhmL7plAAAAGQ"] [Sat Aug 29 05:07:33.411058 2026] [security2:error] [pid 1028675:tid 1028925] [client 20.63.81.20:20940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/ajfto.php"] [unique_id "apK9dddHPfW2QFvhmL7plQAAAHM"] [Sat Aug 29 05:07:33.411919 2026] [security2:error] [pid 1028675:tid 1028878] [client 68.155.159.216:18336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apK9dddHPfW2QFvhmL7plgAAAEQ"] [Sat Aug 29 05:07:33.452416 2026] [security2:error] [pid 1028675:tid 1028794] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "apK9dddHPfW2QFvhmL7pmAAAdnE"] [Sat Aug 29 05:07:33.456301 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.104.104.62:20855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/style-js.php"] [unique_id "apK9dddHPfW2QFvhmL7pmwAAAF4"] [Sat Aug 29 05:07:33.459402 2026] [security2:error] [pid 1028675:tid 1028801] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "apK9dddHPfW2QFvhmL7pmgAAJng"] [Sat Aug 29 05:07:33.461350 2026] [core:error] [pid 1018003:tid 1018048] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.461378 2026] [core:error] [pid 1018003:tid 1018048] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.462212 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.462224 2026] [core:error] [pid 1018003:tid 1018078] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.462918 2026] [security2:error] [pid 1018003:tid 1018134] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/config/stripe.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWhAAGJXE"] [Sat Aug 29 05:07:33.469344 2026] [core:error] [pid 1028675:tid 1028787] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.469370 2026] [core:error] [pid 1028675:tid 1028787] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.471709 2026] [security2:error] [pid 1028675:tid 1028832] [client 40.83.93.50:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-content/about.php"] [unique_id "apK9dddHPfW2QFvhmL7pnwAAABY"] [Sat Aug 29 05:07:33.478821 2026] [security2:error] [pid 1028675:tid 1028936] [client 52.139.37.240:33579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/aged.php"] [unique_id "apK9dddHPfW2QFvhmL7poAAAAH4"] [Sat Aug 29 05:07:33.480525 2026] [security2:error] [pid 1028675:tid 1028847] [client 68.155.159.216:38677] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.juntoohki.com"] [uri "/1.php"] [unique_id "apK9dddHPfW2QFvhmL7poQAAACU"] [Sat Aug 29 05:07:33.480607 2026] [security2:error] [pid 1028675:tid 1028847] [client 68.155.159.216:38677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/1.php"] [unique_id "apK9dddHPfW2QFvhmL7poQAAACU"] [Sat Aug 29 05:07:33.486172 2026] [security2:error] [pid 1028675:tid 1028800] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "apK9dddHPfW2QFvhmL7ppAAARnc"] [Sat Aug 29 05:07:33.487783 2026] [core:error] [pid 1028675:tid 1028782] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.487797 2026] [core:error] [pid 1028675:tid 1028782] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.487811 2026] [core:error] [pid 1028675:tid 1028795] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.487821 2026] [core:error] [pid 1028675:tid 1028795] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.493390 2026] [security2:error] [pid 1028675:tid 1028872] [client 158.23.147.79:30497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/first.php"] [unique_id "apK9dddHPfW2QFvhmL7ppQAAAD4"] [Sat Aug 29 05:07:33.500486 2026] [security2:error] [pid 1028675:tid 1028839] [client 158.23.147.79:32699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "database.rfsoftware.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apK9dddHPfW2QFvhmL7ppgAAAB0"] [Sat Aug 29 05:07:33.502110 2026] [security2:error] [pid 1018003:tid 1018056] [remote 35.231.104.225:42404] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "www.qandlcondos.com"] [uri "/static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ"] [unique_id "apK9dTAh5Y1i2tUxg4EWhgAGMyM"] [Sat Aug 29 05:07:33.505823 2026] [http2:warn] [pid 1018003:tid 1018269] [client 57.141.14.38:38056] h2_stream(1018003-201-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Sat Aug 29 05:07:33.540394 2026] [security2:error] [pid 1018003:tid 1018266] [client 52.139.37.240:19340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-admin/min.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWiwAABio"] [Sat Aug 29 05:07:33.542877 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.542896 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.543665 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.543685 2026] [core:error] [pid 1028675:tid 1028844] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.557368 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.63.81.20:20951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apK9dddHPfW2QFvhmL7pqgAAACw"] [Sat Aug 29 05:07:33.567554 2026] [security2:error] [pid 1028675:tid 1028903] [client 68.155.159.216:2031] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.drjrae.com"] [uri "/1.php"] [unique_id "apK9dddHPfW2QFvhmL7pqwAAAF0"] [Sat Aug 29 05:07:33.567685 2026] [security2:error] [pid 1028675:tid 1028903] [client 68.155.159.216:2031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/1.php"] [unique_id "apK9dddHPfW2QFvhmL7pqwAAAF0"] [Sat Aug 29 05:07:33.571610 2026] [security2:error] [pid 1028675:tid 1028816] [client 52.139.37.240:51883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/about.php7"] [unique_id "apK9dddHPfW2QFvhmL7prQAAAAY"] [Sat Aug 29 05:07:33.581621 2026] [security2:error] [pid 1028675:tid 1028902] [client 20.104.49.130:34559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.termoenvases.do"] [uri "/term.php"] [unique_id "apK9dddHPfW2QFvhmL7prgAAAFw"] [Sat Aug 29 05:07:33.588019 2026] [security2:error] [pid 1028675:tid 1028900] [client 158.23.147.79:25443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wzy.php"] [unique_id "apK9dddHPfW2QFvhmL7prwAAAFo"] [Sat Aug 29 05:07:33.630268 2026] [security2:error] [pid 1018003:tid 1018248] [client 168.107.94.195:56347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWjAAABhg"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:33.640147 2026] [security2:error] [pid 1028675:tid 1028790] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "apK9dddHPfW2QFvhmL7psQAAH20"] [Sat Aug 29 05:07:33.660695 2026] [core:error] [pid 1028675:tid 1028788] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.660715 2026] [core:error] [pid 1028675:tid 1028788] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.662577 2026] [security2:error] [pid 1018003:tid 1018169] [client 158.23.147.79:35728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-e6f9789b.mcconnellsweb.com"] [uri "/.well-known/content.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWjwAABco"] [Sat Aug 29 05:07:33.663336 2026] [core:error] [pid 1028675:tid 1028797] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.663350 2026] [core:error] [pid 1028675:tid 1028797] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.663469 2026] [security2:error] [pid 1028675:tid 1028853] [client 4.205.62.107:53331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/cxc.php"] [unique_id "apK9dddHPfW2QFvhmL7ptgAAACs"] [Sat Aug 29 05:07:33.663837 2026] [core:error] [pid 1028675:tid 1028770] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.663848 2026] [core:error] [pid 1028675:tid 1028770] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.663937 2026] [security2:error] [pid 1018003:tid 1018255] [client 68.155.159.216:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/admin.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWkAAABh8"] [Sat Aug 29 05:07:33.664379 2026] [security2:error] [pid 1028675:tid 1028830] [client 68.155.159.216:12191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/packed.php"] [unique_id "apK9dddHPfW2QFvhmL7ptwAAABQ"] [Sat Aug 29 05:07:33.670231 2026] [core:error] [pid 1028675:tid 1028802] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.670243 2026] [core:error] [pid 1028675:tid 1028802] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.671289 2026] [core:error] [pid 1028675:tid 1028803] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.671300 2026] [core:error] [pid 1028675:tid 1028803] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.674124 2026] [security2:error] [pid 1028675:tid 1028858] [client 52.139.37.240:32854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/essexec.php"] [unique_id "apK9dddHPfW2QFvhmL7puwAAADA"] [Sat Aug 29 05:07:33.674319 2026] [security2:error] [pid 1028675:tid 1028825] [client 4.205.62.107:53296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/test.config.php"] [unique_id "apK9dddHPfW2QFvhmL7pvAAAAA8"] [Sat Aug 29 05:07:33.688781 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.203.141.11:38599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/images/index.php"] [unique_id "apK9dddHPfW2QFvhmL7pvQAAAEE"] [Sat Aug 29 05:07:33.689549 2026] [security2:error] [pid 1028675:tid 1028923] [client 20.63.81.20:20908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apK9dddHPfW2QFvhmL7pvgAAAHE"] [Sat Aug 29 05:07:33.731880 2026] [security2:error] [pid 1028675:tid 1028887] [client 20.203.141.11:5784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/deepseek_d.php"] [unique_id "apK9dddHPfW2QFvhmL7pvwAAAE0"] [Sat Aug 29 05:07:33.735131 2026] [security2:error] [pid 1028675:tid 1028843] [client 52.139.37.240:19333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "apK9dddHPfW2QFvhmL7pwAAAACE"] [Sat Aug 29 05:07:33.767320 2026] [core:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.767336 2026] [core:error] [pid 1018003:tid 1018085] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.772975 2026] [security2:error] [pid 1018003:tid 1018246] [client 52.139.37.240:51901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/cron.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWkwAABhY"] [Sat Aug 29 05:07:33.776134 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.776145 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.776147 2026] [core:error] [pid 1018003:tid 1018051] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.776153 2026] [core:error] [pid 1018003:tid 1018136] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.822321 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.822340 2026] [core:error] [pid 1018003:tid 1018268] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.822947 2026] [security2:error] [pid 1028675:tid 1028912] [client 20.63.81.20:20984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apK9dddHPfW2QFvhmL7pyQAAAGY"] [Sat Aug 29 05:07:33.829484 2026] [security2:error] [pid 1028675:tid 1028918] [client 20.151.200.44:64638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/inwp.php"] [unique_id "apK9dddHPfW2QFvhmL7pywAAAGw"] [Sat Aug 29 05:07:33.834341 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.834366 2026] [core:error] [pid 1018003:tid 1018265] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.834940 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.834951 2026] [core:error] [pid 1018003:tid 1018240] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.836353 2026] [core:error] [pid 1028675:tid 1028936] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.836370 2026] [security2:error] [pid 1018003:tid 1018191] [client 158.158.54.35:2189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/av.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWowAABeA"] [Sat Aug 29 05:07:33.836379 2026] [core:error] [pid 1028675:tid 1028936] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.843680 2026] [security2:error] [pid 1028675:tid 1028907] [client 158.23.147.79:26615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apK9dddHPfW2QFvhmL7pzQAAAGE"] [Sat Aug 29 05:07:33.853846 2026] [core:error] [pid 1028675:tid 1028807] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.853864 2026] [core:error] [pid 1028675:tid 1028807] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.869182 2026] [core:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.869208 2026] [core:error] [pid 1018003:tid 1018034] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.869230 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.869238 2026] [core:error] [pid 1018003:tid 1018087] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.881061 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.104.104.62:25605] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/1.php"] [unique_id "apK9dddHPfW2QFvhmL7p0wAAAFA"] [Sat Aug 29 05:07:33.881149 2026] [security2:error] [pid 1028675:tid 1028890] [client 20.104.104.62:25605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/1.php"] [unique_id "apK9dddHPfW2QFvhmL7p0wAAAFA"] [Sat Aug 29 05:07:33.881600 2026] [security2:error] [pid 1018003:tid 1018250] [client 52.139.37.240:33541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/fw.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWrAAABho"] [Sat Aug 29 05:07:33.887639 2026] [core:error] [pid 1018003:tid 1018047] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.887654 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.887657 2026] [core:error] [pid 1018003:tid 1018047] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.887666 2026] [core:error] [pid 1018003:tid 1018164] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.889805 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.889825 2026] [core:error] [pid 1018003:tid 1018236] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.902885 2026] [core:error] [pid 1018003:tid 1018156] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.902906 2026] [core:error] [pid 1018003:tid 1018156] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.916192 2026] [core:error] [pid 1028675:tid 1028856] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.916215 2026] [core:error] [pid 1028675:tid 1028856] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.918466 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.918487 2026] [core:error] [pid 1018003:tid 1018234] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.931957 2026] [security2:error] [pid 1018003:tid 1018226] [client 52.139.37.240:19310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-content/themes/min.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWtgAABgM"] [Sat Aug 29 05:07:33.950693 2026] [security2:error] [pid 1028675:tid 1028876] [client 74.7.230.51:41962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "durancefarm.com"] [uri "/robots.txt"] [unique_id "apK9dddHPfW2QFvhmL7p2QAAQgM"] [Sat Aug 29 05:07:33.952648 2026] [security2:error] [pid 1018003:tid 1018198] [client 40.83.93.50:5478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-content/admin-header.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWugAABec"] [Sat Aug 29 05:07:33.959052 2026] [security2:error] [pid 1018003:tid 1018266] [client 20.63.81.20:20941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-mini.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWuwAABio"] [Sat Aug 29 05:07:33.971043 2026] [security2:error] [pid 1018003:tid 1018271] [client 52.139.37.240:3437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/wp-2019.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWvQAABi8"] [Sat Aug 29 05:07:33.971977 2026] [security2:error] [pid 1018003:tid 1018217] [client 68.155.159.216:24553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-admin.php"] [unique_id "apK9dTAh5Y1i2tUxg4EWvgAABfo"] [Sat Aug 29 05:07:33.974202 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:33.974217 2026] [core:error] [pid 1018003:tid 1018159] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.011271 2026] [security2:error] [pid 1028675:tid 1028937] [client 168.107.94.195:56738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9dtdHPfW2QFvhmL7p2gAAAH8"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:34.029804 2026] [security2:error] [pid 1018003:tid 1018122] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/cron/.env"] [unique_id "apK9djAh5Y1i2tUxg4EWwAAFxGU"] [Sat Aug 29 05:07:34.029805 2026] [security2:error] [pid 1018003:tid 1018063] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/crm/.env"] [unique_id "apK9djAh5Y1i2tUxg4EWvwAFxCo"] [Sat Aug 29 05:07:34.031125 2026] [core:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.031137 2026] [core:error] [pid 1018003:tid 1018124] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.031844 2026] [core:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.031866 2026] [core:error] [pid 1018003:tid 1018084] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.034930 2026] [security2:error] [pid 1028675:tid 1028812] [client 158.23.147.79:48196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apK9dtdHPfW2QFvhmL7p2wAAAAI"] [Sat Aug 29 05:07:34.035789 2026] [security2:error] [pid 1018003:tid 1018240] [client 4.205.62.107:22405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/routes.php"] [unique_id "apK9djAh5Y1i2tUxg4EWwwAABhA"] [Sat Aug 29 05:07:34.065576 2026] [security2:error] [pid 1028675:tid 1028837] [client 158.23.147.79:17533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/content.php"] [unique_id "apK9dtdHPfW2QFvhmL7p3gAAABs"] [Sat Aug 29 05:07:34.067901 2026] [core:error] [pid 1028675:tid 1028682] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.067923 2026] [core:error] [pid 1028675:tid 1028682] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.069523 2026] [core:error] [pid 1028675:tid 1028806] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.069545 2026] [core:error] [pid 1028675:tid 1028806] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.073772 2026] [core:error] [pid 1028675:tid 1028804] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.073786 2026] [core:error] [pid 1028675:tid 1028804] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.074585 2026] [security2:error] [pid 1028675:tid 1028877] [client 158.158.54.35:22171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/wp-content/file.php"] [unique_id "apK9dtdHPfW2QFvhmL7p4gAAAEM"] [Sat Aug 29 05:07:34.075247 2026] [core:error] [pid 1028675:tid 1028684] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.075258 2026] [core:error] [pid 1028675:tid 1028684] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.075573 2026] [core:error] [pid 1028675:tid 1028691] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.075583 2026] [core:error] [pid 1028675:tid 1028691] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.075921 2026] [security2:error] [pid 1028675:tid 1028816] [client 20.104.104.62:25796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/admin/function.php"] [unique_id "apK9dtdHPfW2QFvhmL7p4wAAAAY"] [Sat Aug 29 05:07:34.076714 2026] [security2:error] [pid 1028675:tid 1028902] [client 52.139.37.240:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/zwso.php"] [unique_id "apK9dtdHPfW2QFvhmL7p5AAAAFw"] [Sat Aug 29 05:07:34.084342 2026] [security2:error] [pid 1018003:tid 1018059] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/current/.env"] [unique_id "apK9djAh5Y1i2tUxg4EWxAAF3yY"] [Sat Aug 29 05:07:34.087626 2026] [security2:error] [pid 1018003:tid 1018157] [client 20.63.81.20:20947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/xmini4.php"] [unique_id "apK9djAh5Y1i2tUxg4EWxQAABb4"] [Sat Aug 29 05:07:34.107765 2026] [security2:error] [pid 1028675:tid 1028889] [client 20.104.104.62:64749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/style.php"] [unique_id "apK9dtdHPfW2QFvhmL7p5wAAAE8"] [Sat Aug 29 05:07:34.111395 2026] [security2:error] [pid 1028675:tid 1028884] [client 68.155.159.216:30711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-content/cong.php"] [unique_id "apK9dtdHPfW2QFvhmL7p6AAAAEo"] [Sat Aug 29 05:07:34.126677 2026] [security2:error] [pid 1018003:tid 1018184] [client 68.155.159.216:49249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-admin/admin.php"] [unique_id "apK9djAh5Y1i2tUxg4EWxgAABdk"] [Sat Aug 29 05:07:34.127269 2026] [security2:error] [pid 1028675:tid 1028911] [client 52.139.37.240:19290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "apK9dtdHPfW2QFvhmL7p6QAAAGU"] [Sat Aug 29 05:07:34.136906 2026] [core:error] [pid 1028675:tid 1028686] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.136922 2026] [core:error] [pid 1028675:tid 1028686] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.168917 2026] [security2:error] [pid 1028675:tid 1028897] [client 52.139.37.240:3343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/gecko-new.php"] [unique_id "apK9dtdHPfW2QFvhmL7p7AAAAFc"] [Sat Aug 29 05:07:34.170777 2026] [authz_core:error] [pid 1018003:tid 1018170] [client 20.203.141.11:12508] AH01630: client denied by server configuration: /home2/newfloo1/public_html/wp-includes/PHPMailer/error_log [Sat Aug 29 05:07:34.209606 2026] [security2:error] [pid 1018003:tid 1018053] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/developer/.env"] [unique_id "apK9djAh5Y1i2tUxg4EWyAAGNSA"] [Sat Aug 29 05:07:34.209606 2026] [security2:error] [pid 1018003:tid 1018092] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apK9djAh5Y1i2tUxg4EWyQAGNUc"] [Sat Aug 29 05:07:34.217695 2026] [security2:error] [pid 1018003:tid 1018156] [client 20.63.81.20:20875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/reop3.php"] [unique_id "apK9djAh5Y1i2tUxg4EW0AAABb0"] [Sat Aug 29 05:07:34.220827 2026] [security2:error] [pid 1018003:tid 1018099] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/demo/.env"] [unique_id "apK9djAh5Y1i2tUxg4EW0wAGNU4"] [Sat Aug 29 05:07:34.221630 2026] [core:error] [pid 1018003:tid 1018118] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.221646 2026] [core:error] [pid 1018003:tid 1018118] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.225709 2026] [security2:error] [pid 1018003:tid 1018076] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apK9djAh5Y1i2tUxg4EW1gAGNTc"] [Sat Aug 29 05:07:34.231568 2026] [security2:error] [pid 1018003:tid 1018081] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/develop/.env"] [unique_id "apK9djAh5Y1i2tUxg4EW2AAGNTw"] [Sat Aug 29 05:07:34.237510 2026] [core:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.237520 2026] [core:error] [pid 1018003:tid 1018023] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.244107 2026] [core:error] [pid 1028675:tid 1028886] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.244129 2026] [core:error] [pid 1028675:tid 1028886] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.245173 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.245186 2026] [core:error] [pid 1028675:tid 1028843] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.247711 2026] [core:error] [pid 1028675:tid 1028910] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.247722 2026] [core:error] [pid 1028675:tid 1028910] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.250612 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.250624 2026] [core:error] [pid 1028675:tid 1028925] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.251015 2026] [core:error] [pid 1028675:tid 1028842] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.251025 2026] [core:error] [pid 1028675:tid 1028842] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.270553 2026] [security2:error] [pid 1028675:tid 1028936] [client 4.205.62.107:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.body-benefits.net"] [uri "/gk.php"] [unique_id "apK9dtdHPfW2QFvhmL7p8wAAAH4"] [Sat Aug 29 05:07:34.270817 2026] [security2:error] [pid 1028675:tid 1028858] [client 52.139.37.240:33581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/admin/function.php"] [unique_id "apK9dtdHPfW2QFvhmL7p9AAAADA"] [Sat Aug 29 05:07:34.273518 2026] [security2:error] [pid 1028675:tid 1028929] [client 20.104.104.62:25824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/autoload_classmap.php"] [unique_id "apK9dtdHPfW2QFvhmL7p9QAAAHc"] [Sat Aug 29 05:07:34.293757 2026] [security2:error] [pid 1028675:tid 1028847] [client 4.205.62.107:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cisagency.com"] [uri "/wp-class.php"] [unique_id "apK9dtdHPfW2QFvhmL7p9wAAACU"] [Sat Aug 29 05:07:34.300961 2026] [security2:error] [pid 1018003:tid 1018250] [client 158.158.54.35:20547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/file.php"] [unique_id "apK9djAh5Y1i2tUxg4EW3AAABho"] [Sat Aug 29 05:07:34.317870 2026] [security2:error] [pid 1018003:tid 1018066] [remote 35.231.104.225:42418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.qandlcondos.com"] [uri "/web.config"] [unique_id "apK9djAh5Y1i2tUxg4EW4AAFwy0"] [Sat Aug 29 05:07:34.319039 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.319052 2026] [core:error] [pid 1028675:tid 1028839] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.332264 2026] [security2:error] [pid 1018003:tid 1018270] [client 20.151.200.44:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/ad1.php"] [unique_id "apK9djAh5Y1i2tUxg4EW4wAABi4"] [Sat Aug 29 05:07:34.333731 2026] [security2:error] [pid 1018003:tid 1018233] [client 20.203.141.11:12508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/inputs.php"] [unique_id "apK9djAh5Y1i2tUxg4EW5AAABgk"] [Sat Aug 29 05:07:34.353908 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.63.81.20:20955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-mail.php"] [unique_id "apK9djAh5Y1i2tUxg4EW5gAABfU"] [Sat Aug 29 05:07:34.363262 2026] [security2:error] [pid 1028675:tid 1028815] [client 158.23.147.79:30642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glowt-shirts.glowt-shirt.com"] [uri "/wp-content/packed.php"] [unique_id "apK9dtdHPfW2QFvhmL7p_gAAAAU"] [Sat Aug 29 05:07:34.363497 2026] [security2:error] [pid 1028675:tid 1028907] [client 52.139.37.240:3348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/add_actualites.php"] [unique_id "apK9dtdHPfW2QFvhmL7p_wAAAGE"] [Sat Aug 29 05:07:34.375519 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.203.141.11:45465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "apK9djAh5Y1i2tUxg4EW6AAABbw"] [Sat Aug 29 05:07:34.379036 2026] [security2:error] [pid 1018003:tid 1018271] [client 68.155.159.216:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snackgaro.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apK9djAh5Y1i2tUxg4EW6QAABi8"] [Sat Aug 29 05:07:34.391926 2026] [security2:error] [pid 1018003:tid 1018182] [client 168.107.94.195:57133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9djAh5Y1i2tUxg4EW8gAABdc"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:34.392074 2026] [security2:error] [pid 1018003:tid 1018203] [client 68.155.159.216:51514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julieandmartin.strangeworx.com"] [uri "/wzy.php"] [unique_id "apK9djAh5Y1i2tUxg4EW8QAABew"] [Sat Aug 29 05:07:34.411839 2026] [security2:error] [pid 1028675:tid 1028898] [client 52.139.37.240:19296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "apK9dtdHPfW2QFvhmL7qBAAAAFg"] [Sat Aug 29 05:07:34.420719 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.420734 2026] [core:error] [pid 1028675:tid 1028892] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.422120 2026] [security2:error] [pid 1028675:tid 1028835] [client 4.205.62.107:22481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitestage.biz"] [uri "/oc460l3x.php"] [unique_id "apK9dtdHPfW2QFvhmL7qBwAAABk"] [Sat Aug 29 05:07:34.422766 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.422778 2026] [core:error] [pid 1028675:tid 1028813] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.427249 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.427262 2026] [core:error] [pid 1028675:tid 1028903] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.431290 2026] [security2:error] [pid 1018003:tid 1018224] [client 68.155.159.216:33700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "isasi.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apK9djAh5Y1i2tUxg4EW9QAABgE"] [Sat Aug 29 05:07:34.433099 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.433113 2026] [core:error] [pid 1028675:tid 1028837] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.434372 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.434385 2026] [core:error] [pid 1028675:tid 1028870] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.437200 2026] [core:error] [pid 1018003:tid 1018161] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.437214 2026] [core:error] [pid 1018003:tid 1018161] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.439703 2026] [core:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.439718 2026] [core:error] [pid 1018003:tid 1018058] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.447228 2026] [security2:error] [pid 1028675:tid 1028863] [client 40.83.93.50:5466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-content/admin.php"] [unique_id "apK9dtdHPfW2QFvhmL7qCwAAADU"] [Sat Aug 29 05:07:34.467147 2026] [security2:error] [pid 1018003:tid 1018186] [client 20.104.104.62:25804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/classwithtostring.php"] [unique_id "apK9djAh5Y1i2tUxg4EW-QAABds"] [Sat Aug 29 05:07:34.468519 2026] [security2:error] [pid 1018003:tid 1018097] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/erp/.env"] [unique_id "apK9djAh5Y1i2tUxg4EW_AAGHEw"] [Sat Aug 29 05:07:34.472213 2026] [security2:error] [pid 1018003:tid 1018121] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/etc/apache2/apache2.conf"] [unique_id "apK9djAh5Y1i2tUxg4EXAAAGHGQ"] [Sat Aug 29 05:07:34.473286 2026] [core:error] [pid 1018003:tid 1018109] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.473298 2026] [core:error] [pid 1018003:tid 1018109] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.474103 2026] [security2:error] [pid 1018003:tid 1018248] [client 52.139.37.240:33567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/zoom1.php"] [unique_id "apK9djAh5Y1i2tUxg4EXAgAABhg"] [Sat Aug 29 05:07:34.505314 2026] [security2:error] [pid 1028675:tid 1028926] [client 68.155.159.216:63809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.harnessenrgy.com"] [uri "/asd.php"] [unique_id "apK9dtdHPfW2QFvhmL7qEQAAAHQ"] [Sat Aug 29 05:07:34.507061 2026] [core:error] [pid 1028675:tid 1028841] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.507077 2026] [core:error] [pid 1028675:tid 1028841] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.508827 2026] [security2:error] [pid 1018003:tid 1018112] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/etc/boto.cfg"] [unique_id "apK9djAh5Y1i2tUxg4EXAwAGHFs"] [Sat Aug 29 05:07:34.510553 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.510566 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.511105 2026] [core:error] [pid 1028675:tid 1028897] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.511113 2026] [core:error] [pid 1028675:tid 1028897] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.514175 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.514185 2026] [core:error] [pid 1028675:tid 1028853] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.517915 2026] [security2:error] [pid 1018003:tid 1018184] [client 20.104.49.130:48582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.hatchigan.com"] [uri "/well.php"] [unique_id "apK9djAh5Y1i2tUxg4EXBAAABdk"] [Sat Aug 29 05:07:34.522511 2026] [security2:error] [pid 1018003:tid 1018187] [client 158.158.54.35:13056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/files.php"] [unique_id "apK9djAh5Y1i2tUxg4EXBQAABdw"] [Sat Aug 29 05:07:34.522552 2026] [security2:error] [pid 1028675:tid 1028873] [client 68.155.159.216:18401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cisagency.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apK9dtdHPfW2QFvhmL7qFQAAAD8"] [Sat Aug 29 05:07:34.534182 2026] [security2:error] [pid 1028675:tid 1028875] [client 20.63.81.20:20868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-conffg.php"] [unique_id "apK9dtdHPfW2QFvhmL7qFwAAAEE"] [Sat Aug 29 05:07:34.552373 2026] [security2:error] [pid 1028675:tid 1028821] [client 52.139.37.240:3330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/browse.php"] [unique_id "apK9dtdHPfW2QFvhmL7qGQAAAAs"] [Sat Aug 29 05:07:34.553836 2026] [security2:error] [pid 1028675:tid 1028867] [client 185.104.184.230:49144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jia.zbw.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "apK9dtdHPfW2QFvhmL7qGgAAADk"] [Sat Aug 29 05:07:34.580630 2026] [security2:error] [pid 1028675:tid 1028916] [client 158.23.147.79:53760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sunflowerorganicsupply.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apK9dtdHPfW2QFvhmL7qGwAAAGo"] [Sat Aug 29 05:07:34.587162 2026] [security2:error] [pid 1028675:tid 1028910] [client 68.155.159.216:38554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juntoohki.com"] [uri "/ws.php"] [unique_id "apK9dtdHPfW2QFvhmL7qHAAAAGQ"] [Sat Aug 29 05:07:34.604219 2026] [security2:error] [pid 1028675:tid 1028923] [client 52.139.37.240:19326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-info.php"] [unique_id "apK9dtdHPfW2QFvhmL7qHgAAAHE"] [Sat Aug 29 05:07:34.655280 2026] [security2:error] [pid 1018003:tid 1018250] [client 68.155.159.216:33659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avondalegroveshoa.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9djAh5Y1i2tUxg4EXEAAABho"] [Sat Aug 29 05:07:34.670125 2026] [security2:error] [pid 1018003:tid 1018198] [client 20.104.104.62:25627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/content.php"] [unique_id "apK9djAh5Y1i2tUxg4EXEwAABec"] [Sat Aug 29 05:07:34.670761 2026] [security2:error] [pid 1018003:tid 1018277] [client 52.139.37.240:33596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/about.php7"] [unique_id "apK9djAh5Y1i2tUxg4EXFAAABjU"] [Sat Aug 29 05:07:34.684621 2026] [security2:error] [pid 1018003:tid 1018212] [client 20.63.81.20:20973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/filefuns.php"] [unique_id "apK9djAh5Y1i2tUxg4EXFQAABfU"] [Sat Aug 29 05:07:34.686538 2026] [security2:error] [pid 1018003:tid 1018172] [client 68.155.159.216:1929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.drjrae.com"] [uri "/ws.php"] [unique_id "apK9djAh5Y1i2tUxg4EXFgAABc0"] [Sat Aug 29 05:07:34.690866 2026] [security2:error] [pid 1018003:tid 1018155] [client 158.23.147.79:25427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mjallenbooks.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apK9djAh5Y1i2tUxg4EXFwAABbw"] [Sat Aug 29 05:07:34.707278 2026] [security2:error] [pid 1018003:tid 1018065] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/fe/.env"] [unique_id "apK9djAh5Y1i2tUxg4EXGAAGHyw"] [Sat Aug 29 05:07:34.726261 2026] [security2:error] [pid 1018003:tid 1018267] [client 146.70.194.254:57188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "modelbasenjis.com"] [uri "/cgi-sys/suspendedpage.cgi/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apK9djAh5Y1i2tUxg4EXGgAABis"] [Sat Aug 29 05:07:34.745306 2026] [security2:error] [pid 1018003:tid 1018233] [client 52.139.37.240:51840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/contentloader1.php"] [unique_id "apK9djAh5Y1i2tUxg4EXHAAABgk"] [Sat Aug 29 05:07:34.751370 2026] [security2:error] [pid 1028675:tid 1028842] [client 158.158.54.35:29635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apK9dtdHPfW2QFvhmL7qIQAAACA"] [Sat Aug 29 05:07:34.767642 2026] [security2:error] [pid 1018003:tid 1018222] [client 20.104.104.62:20694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.motherssandals.com"] [uri "/Success.php"] [unique_id "apK9djAh5Y1i2tUxg4EXHgAABf8"] [Sat Aug 29 05:07:34.770805 2026] [security2:error] [pid 1028675:tid 1028846] [client 168.107.94.195:57522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-login.php"] [unique_id "apK9dtdHPfW2QFvhmL7qIgAAACQ"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:34.773487 2026] [security2:error] [pid 1028675:tid 1028844] [client 68.155.159.216:9237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.philadelphialawworks.org"] [uri "/wp-admin/admin.php"] [unique_id "apK9dtdHPfW2QFvhmL7qIwAAACI"] [Sat Aug 29 05:07:34.775814 2026] [security2:error] [pid 1028675:tid 1028866] [client 103.240.76.112:42586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.76.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9dtdHPfW2QFvhmL7qJAAAADg"] [Sat Aug 29 05:07:34.776038 2026] [security2:error] [pid 1028675:tid 1028866] [client 103.240.76.112:42586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "philadelphialawworks.org"] [uri "/xmlrpc.php"] [unique_id "apK9dtdHPfW2QFvhmL7qJAAAADg"] [Sat Aug 29 05:07:34.776538 2026] [security2:error] [pid 1018003:tid 1018141] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/front/.env"] [unique_id "apK9djAh5Y1i2tUxg4EXIgAF23g"] [Sat Aug 29 05:07:34.785542 2026] [security2:error] [pid 1028675:tid 1028914] [client 68.155.159.216:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.corralestractor.org"] [uri "/wp-content/packed.php"] [unique_id "apK9dtdHPfW2QFvhmL7qKAAAAGg"] [Sat Aug 29 05:07:34.800416 2026] [security2:error] [pid 1018003:tid 1018246] [client 52.139.37.240:19314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/wp-wordfence-waf.php"] [unique_id "apK9djAh5Y1i2tUxg4EXKAAABhY"] [Sat Aug 29 05:07:34.802081 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.802094 2026] [core:error] [pid 1018003:tid 1018157] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.802993 2026] [security2:error] [pid 1028675:tid 1028850] [client 4.205.62.107:9212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.barkerpubliclibrary.com"] [uri "/gjm.php"] [unique_id "apK9dtdHPfW2QFvhmL7qKgAAACg"] [Sat Aug 29 05:07:34.803869 2026] [core:error] [pid 1028675:tid 1028909] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.803881 2026] [core:error] [pid 1028675:tid 1028909] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.804312 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.804322 2026] [core:error] [pid 1018003:tid 1018189] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.805123 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.805136 2026] [core:error] [pid 1018003:tid 1018258] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.811851 2026] [core:error] [pid 1028675:tid 1028689] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.811870 2026] [core:error] [pid 1028675:tid 1028689] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.811883 2026] [core:error] [pid 1028675:tid 1028695] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.811887 2026] [core:error] [pid 1028675:tid 1028688] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.811892 2026] [core:error] [pid 1028675:tid 1028695] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.811903 2026] [core:error] [pid 1028675:tid 1028688] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.816105 2026] [core:error] [pid 1028675:tid 1028701] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.816120 2026] [core:error] [pid 1028675:tid 1028701] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.816288 2026] [security2:error] [pid 1018003:tid 1018190] [client 20.151.200.44:64627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.narrowgate-electrical.com"] [uri "/1vbqo.php"] [unique_id "apK9djAh5Y1i2tUxg4EXKwAABd8"] [Sat Aug 29 05:07:34.819804 2026] [security2:error] [pid 1028675:tid 1028892] [client 4.205.62.107:56045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dynamictestingsolutions.com"] [uri "/gecko-litespeed.php"] [unique_id "apK9dtdHPfW2QFvhmL7qMAAAAFI"] [Sat Aug 29 05:07:34.820039 2026] [security2:error] [pid 1028675:tid 1028835] [client 20.63.81.20:20977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-cron.php"] [unique_id "apK9dtdHPfW2QFvhmL7qMQAAABk"] [Sat Aug 29 05:07:34.852159 2026] [core:error] [pid 1028675:tid 1028685] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.852182 2026] [core:error] [pid 1028675:tid 1028685] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.852454 2026] [core:error] [pid 1028675:tid 1028696] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.852475 2026] [core:error] [pid 1028675:tid 1028696] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.865645 2026] [security2:error] [pid 1028675:tid 1028917] [client 20.104.104.62:25792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/function/function.php"] [unique_id "apK9dtdHPfW2QFvhmL7qNQAAAGs"] [Sat Aug 29 05:07:34.888861 2026] [security2:error] [pid 1028675:tid 1028848] [client 52.139.37.240:33542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/cron.php"] [unique_id "apK9dtdHPfW2QFvhmL7qNwAAACY"] [Sat Aug 29 05:07:34.896955 2026] [security2:error] [pid 1018003:tid 1018188] [client 20.203.141.11:38651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.newflooringhawaii.com"] [uri "/alfa.php"] [unique_id "apK9djAh5Y1i2tUxg4EXMQAABd0"] [Sat Aug 29 05:07:34.917842 2026] [security2:error] [pid 1028675:tid 1028819] [client 40.83.93.50:6093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wagnerfarmscbd.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "apK9dtdHPfW2QFvhmL7qOAAAAAk"] [Sat Aug 29 05:07:34.942166 2026] [security2:error] [pid 1028675:tid 1028877] [client 52.139.37.240:3384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/upfile.php"] [unique_id "apK9dtdHPfW2QFvhmL7qOQAAAEM"] [Sat Aug 29 05:07:34.949670 2026] [security2:error] [pid 1018003:tid 1018132] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env"] [unique_id "apK9djAh5Y1i2tUxg4EXNQAGM28"] [Sat Aug 29 05:07:34.950415 2026] [security2:error] [pid 1018003:tid 1018167] [client 158.23.147.79:26451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.olker.us"] [uri "/wp-admin/images/about.php"] [unique_id "apK9djAh5Y1i2tUxg4EXNgAABcg"] [Sat Aug 29 05:07:34.950669 2026] [security2:error] [pid 1018003:tid 1018261] [client 20.151.200.44:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rjselectricalservices.com"] [uri "/advanced.php"] [unique_id "apK9djAh5Y1i2tUxg4EXNwAABiU"] [Sat Aug 29 05:07:34.962965 2026] [security2:error] [pid 1028675:tid 1028854] [client 20.63.81.20:20892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/lock360.php"] [unique_id "apK9dtdHPfW2QFvhmL7qOwAAACw"] [Sat Aug 29 05:07:34.966147 2026] [security2:error] [pid 1028675:tid 1028694] [remote 34.138.144.127:58722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.roycehomesales.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "apK9dtdHPfW2QFvhmL7qPAAARQ4"] [Sat Aug 29 05:07:34.966468 2026] [core:error] [pid 1028675:tid 1028740] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.966480 2026] [core:error] [pid 1028675:tid 1028740] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.968048 2026] [security2:error] [pid 1028675:tid 1028813] [client 158.158.54.35:6988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traditionalslateroofing.com"] [uri "/o.php"] [unique_id "apK9dtdHPfW2QFvhmL7qPwAAAAM"] [Sat Aug 29 05:07:34.992262 2026] [core:error] [pid 1028675:tid 1028841] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.992289 2026] [core:error] [pid 1028675:tid 1028841] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.992944 2026] [core:error] [pid 1028675:tid 1028926] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.992961 2026] [core:error] [pid 1028675:tid 1028926] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.996490 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.996501 2026] [core:error] [pid 1028675:tid 1028833] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:34.998218 2026] [security2:error] [pid 1028675:tid 1028872] [client 52.139.37.240:19356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/ws49.php"] [unique_id "apK9dtdHPfW2QFvhmL7qQwAAAD4"] [Sat Aug 29 05:07:35.016092 2026] [security2:error] [pid 1018003:tid 1018046] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/info.php"] [unique_id "apK9dzAh5Y1i2tUxg4EXPgAF5xk"] [Sat Aug 29 05:07:35.018096 2026] [security2:error] [pid 1018003:tid 1018044] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/infophp.php"] [unique_id "apK9dzAh5Y1i2tUxg4EXQAAF5xc"] [Sat Aug 29 05:07:35.019368 2026] [core:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.019387 2026] [core:error] [pid 1018003:tid 1018043] [remote 93.123.109.228:48258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.043072 2026] [core:error] [pid 1028675:tid 1028886] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.043099 2026] [core:error] [pid 1028675:tid 1028886] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.043902 2026] [security2:error] [pid 1018003:tid 1018155] [client 20.203.141.11:25472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.141.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xbdorthodontics.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "apK9dzAh5Y1i2tUxg4EXQgAABbw"] [Sat Aug 29 05:07:35.044500 2026] [core:error] [pid 1028675:tid 1028889] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.044516 2026] [core:error] [pid 1028675:tid 1028889] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.060503 2026] [security2:error] [pid 1028675:tid 1028897] [client 20.104.104.62:25656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/item.php"] [unique_id "apK9d9dHPfW2QFvhmL7qRwAAAFc"] [Sat Aug 29 05:07:35.078125 2026] [security2:error] [pid 1028675:tid 1028932] [client 52.139.37.240:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/wp-2019.php"] [unique_id "apK9d9dHPfW2QFvhmL7qSAAAAHo"] [Sat Aug 29 05:07:35.087918 2026] [security2:error] [pid 1018003:tid 1018130] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.flir.in.th"] [uri "/infos.php"] [unique_id "apK9dzAh5Y1i2tUxg4EXSAAF7G0"] [Sat Aug 29 05:07:35.090127 2026] [security2:error] [pid 1018003:tid 1018137] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/laravel/.env"] [unique_id "apK9dzAh5Y1i2tUxg4EXRgAF7HQ"] [Sat Aug 29 05:07:35.090154 2026] [security2:error] [pid 1018003:tid 1018035] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/lms/.env"] [unique_id "apK9dzAh5Y1i2tUxg4EXRwAF7A4"] [Sat Aug 29 05:07:35.090475 2026] [security2:error] [pid 1028675:tid 1028899] [client 68.155.159.216:24516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjrae.managemymood.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apK9d9dHPfW2QFvhmL7qSQAAAFk"] [Sat Aug 29 05:07:35.094306 2026] [security2:error] [pid 1028675:tid 1028904] [client 20.63.81.20:20920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/wp-theme.php"] [unique_id "apK9d9dHPfW2QFvhmL7qSwAAAF4"] [Sat Aug 29 05:07:35.114910 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.114924 2026] [core:error] [pid 1028675:tid 1028922] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.118702 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.118717 2026] [core:error] [pid 1018003:tid 1018221] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.123405 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.123417 2026] [core:error] [pid 1018003:tid 1018267] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.132682 2026] [security2:error] [pid 1028675:tid 1028839] [client 68.155.159.216:6139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thenearanddear.photoboothhawaii.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apK9d9dHPfW2QFvhmL7qTwAAAB0"] [Sat Aug 29 05:07:35.141299 2026] [security2:error] [pid 1028675:tid 1028811] [client 158.23.147.79:48321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lapoutine.co.uk"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apK9d9dHPfW2QFvhmL7qUQAAAAE"] [Sat Aug 29 05:07:35.149862 2026] [security2:error] [pid 1028675:tid 1028858] [client 168.107.94.195:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.107.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grizzcustomcabinets.com"] [uri "/wp-admin/index.php"] [unique_id "apK9d9dHPfW2QFvhmL7qUgAAADA"], referer: http://grizzcustomcabinets.com/wp-login.php [Sat Aug 29 05:07:35.150129 2026] [core:error] [pid 1018003:tid 1018159] [client 20.203.141.11:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.150139 2026] [core:error] [pid 1018003:tid 1018159] [client 20.203.141.11:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.152273 2026] [security2:error] [pid 1028675:tid 1028923] [client 52.139.37.240:51900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "databases-ap.medulae.com"] [uri "/form.php"] [unique_id "apK9d9dHPfW2QFvhmL7qUwAAAHE"] [Sat Aug 29 05:07:35.156504 2026] [core:error] [pid 1028675:tid 1028823] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.156520 2026] [core:error] [pid 1028675:tid 1028823] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.166895 2026] [security2:error] [pid 1028675:tid 1028849] [client 185.104.184.230:49158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jia.zbw.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "apK9d9dHPfW2QFvhmL7qVQAAACc"] [Sat Aug 29 05:07:35.170785 2026] [security2:error] [pid 1028675:tid 1028909] [client 158.23.147.79:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.steveslivemusic.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apK9d9dHPfW2QFvhmL7qVgAAAGM"] [Sat Aug 29 05:07:35.181490 2026] [security2:error] [pid 1028675:tid 1028824] [client 4.205.62.107:22479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.superbusy.com"] [uri "/aww.php"] [unique_id "apK9d9dHPfW2QFvhmL7qWAAAAA4"] [Sat Aug 29 05:07:35.187245 2026] [security2:error] [pid 1028675:tid 1028929] [client 52.139.37.240:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.luxuryweddingphotographer.com"] [uri "/xxx.php"] [unique_id "apK9d9dHPfW2QFvhmL7qWQAAAHc"] [Sat Aug 29 05:07:35.194042 2026] [security2:error] [pid 1028675:tid 1028878] [client 158.158.54.35:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gregblacker4rexburg.freeadobeflashtutorials.com"] [uri "/gmo.php"] [unique_id "apK9d9dHPfW2QFvhmL7qWgAAAEQ"] [Sat Aug 29 05:07:35.212511 2026] [security2:error] [pid 1028675:tid 1028892] [client 68.155.159.216:30644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thepsychicintuitive.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apK9d9dHPfW2QFvhmL7qXAAAAFI"] [Sat Aug 29 05:07:35.229017 2026] [security2:error] [pid 1028675:tid 1028919] [client 20.63.81.20:20822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.peakperformanceplus.com"] [uri "/2d7433/index.php"] [unique_id "apK9d9dHPfW2QFvhmL7qXQAAAG0"] [Sat Aug 29 05:07:35.234698 2026] [security2:error] [pid 1018003:tid 1018265] [client 68.155.159.216:49203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tiaandephraim.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apK9dzAh5Y1i2tUxg4EXUgAABik"] [Sat Aug 29 05:07:35.234720 2026] [security2:error] [pid 1018003:tid 1018270] [client 128.90.161.20:46246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.161.90.128.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.greenfieldparts.com"] [uri "/wp-login.php"] [unique_id "apK9dzAh5Y1i2tUxg4EXUQAABi4"] [Sat Aug 29 05:07:35.255101 2026] [security2:error] [pid 1018003:tid 1018133] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/local/.env"] [unique_id "apK9dzAh5Y1i2tUxg4EXVwAGFnA"] [Sat Aug 29 05:07:35.255104 2026] [security2:error] [pid 1018003:tid 1018108] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/marketing/.env"] [unique_id "apK9dzAh5Y1i2tUxg4EXVQAGFlc"] [Sat Aug 29 05:07:35.255570 2026] [security2:error] [pid 1018003:tid 1018022] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/market/.env"] [unique_id "apK9dzAh5Y1i2tUxg4EXVAAGFgE"] [Sat Aug 29 05:07:35.256423 2026] [security2:error] [pid 1028675:tid 1028856] [client 20.104.104.62:25826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.horseventure-net.penmarketing.org"] [uri "/ms-edit.php"] [unique_id "apK9d9dHPfW2QFvhmL7qXwAAAC4"] [Sat Aug 29 05:07:35.258221 2026] [security2:error] [pid 1018003:tid 1018144] [remote 93.123.109.228:48258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.flir.in.th"] [uri "/___proxy_subdomain_cpcontacts/media/.env"] [unique_id "apK9dzAh5Y1i2tUxg4EXWwAGFns"] [Sat Aug 29 05:07:35.261912 2026] [security2:error] [pid 1028675:tid 1028819] [client 20.48.250.41:35089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stoolsample.superbusy.com"] [uri "/gettest.php"] [unique_id "apK9d9dHPfW2QFvhmL7qZQAAAAk"] [Sat Aug 29 05:07:35.269155 2026] [security2:error] [pid 1028675:tid 1028815] [client 52.139.37.240:32865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxuryweddingphotographer.com"] [uri "/gecko-new.php"] [unique_id "apK9d9dHPfW2QFvhmL7qZgAAAAU"] [Sat Aug 29 05:07:35.278398 2026] [security2:error] [pid 1018003:tid 1018187] [client 20.48.250.41:49145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.grizzcustomcabinets.com"] [uri "/gettest.php"] [unique_id "apK9dzAh5Y1i2tUxg4EXXQAABdw"] [Sat Aug 29 05:07:35.303045 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.303060 2026] [core:error] [pid 1018003:tid 1018185] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.317009 2026] [security2:error] [pid 1028675:tid 1028912] [client 158.23.147.79:50006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljamesmcgrath.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apK9d9dHPfW2QFvhmL7qawAAAGY"] [Sat Aug 29 05:07:35.319340 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.319362 2026] [core:error] [pid 1018003:tid 1018170] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.319489 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.319497 2026] [core:error] [pid 1018003:tid 1018252] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.326043 2026] [core:error] [pid 1028675:tid 1028710] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.326057 2026] [core:error] [pid 1028675:tid 1028710] [remote 34.138.144.127:58722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.328034 2026] [core:error] [pid 1028675:tid 1028883] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.328045 2026] [core:error] [pid 1028675:tid 1028883] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.329599 2026] [core:error] [pid 1018003:tid 1018207] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.329610 2026] [core:error] [pid 1018003:tid 1018207] [client 93.123.109.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Sat Aug 29 05:07:35.335682 2026] [security2:error] [pid 1028675:tid 1028821] [client 20.151.200.44:64654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "